Transparent privacy practices for maximum privacy
Our Principles: Encipher.Me was developed according to the Zero-Knowledge principle - we technically cannot decrypt your messages, even if we wanted to. Your privacy is protected by architecture, not just by promises.
Responsible party under GDPR:
[Your Company/Name]
[Street and House Number]
[ZIP City]
Germany
Contact:
E-Mail: privacy@encipher.me
Website: Contact Form
What: Encrypted data blocks of your messages
How long: Maximum 30 days or until configured access limit
Purpose: Providing encryption services
Special note: Zero-Knowledge - we cannot decrypt this data
What: Email address, encrypted password, usage statistics
How long: Until account deletion
Purpose: Account management and extended features
Legal basis: Art. 6 para. 1 lit. b GDPR (contract fulfillment)
What: Session cookies, CSRF protection, theme settings
How long: Session end or up to 30 days
Purpose: Security and functionality of the website
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
What: IP addresses, browser information (User-Agent), session IDs, login times
How long: Active sessions up to 1 hour, security logs up to 30 days
Purpose: Account security, session management, fraud detection, security dashboard
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in account security)
๐ Note: This data is stored exclusively for security purposes and is viewable in your account's security dashboard.
All encryption operations take place in your browser. Encryption keys are never transmitted to our servers.
Decryption keys are transmitted in the URL fragment (#). Browsers never send these fragments to servers.
Our servers only receive encrypted data blocks. Even in the event of a complete server hack, your messages remain protected.
You have the following rights:
๐ Zero-Knowledge Notice: Since we cannot decrypt your messages, providing information about specific message content is technically impossible. We can only provide metadata (number of messages, creation times).
AES-256-GCM encryption, TLS 1.3 for all transmissions, secure hash procedures for passwords.
CSRF protection, rate limiting, secure session management, regular security updates.
All data is automatically deleted after expiration - no backups, no recovery possible.
Cookie | Purpose | Duration |
---|---|---|
PHPSESSID |
Session management for login | Session end |
csrf_token |
Protection against CSRF attacks | Session end |
theme |
Light/dark mode setting | 30 days (localStorage) |
cookieConsent |
Stores cookie consent | 1 year (localStorage) |
Data Protection Officer:
E-Mail: privacy@encipher.me
Contact: Contact Form
Supervisory Authority:
You have the right to complain to the competent supervisory authority:
The Federal Commissioner for Data Protection and Freedom of Information
Graurheindorfer Str. 153
53117 Bonn
Phone: +49 (0)228-997799-0
Website: www.bfdi.bund.de
This privacy policy may be updated as needed. Changes will be published on this page and take effect immediately.
Last updated: 25.08.2025
We are happy to help with questions about your data and our privacy practices.
We use essential cookies for security and functionality: session management for login, CSRF protection against attacks, theme settings, and rate limiting for protection against abuse. All data is encrypted and processed in compliance with Zero-Knowledge principles.
These cookies are required for the basic functions of the website:
These cookies store your preferences:
All cookies are stored encrypted and contain no personal data except the email address for logged-in users. We do not use tracking cookies, analytics, or advertising.
You can disable cookies at any time in your browser settings. Note that this may limit the functionality of the website.