Draft – not yet reviewed by an attorney. Do not treat as final or publish live until legal review is complete and every
[bracketed placeholder]below has been replaced with real, verified information.
Privacy Policy
Effective date: [Insert date] Last updated: [Insert date]
1. Who We Are
Sissare (“we,” “us,” “our”) provides an end-to-end encrypted document sharing application (“the Service”). This Privacy Policy explains what information we collect, how we use it, and — just as importantly — what we structurally cannot access due to how the Service is built.
2. What We Collect
| Category | What’s included | Why we collect it |
|---|---|---|
| Account information | Email address, account creation date | Authentication, invitation delivery (email-based invites require matching this address) |
| Public key material | Your device’s public keys (classical + post-quantum) | Enables other users to encrypt data specifically for you — public keys are, by design, safe to store and share |
| Device & usage metadata | Last-active timestamp (updated when you use the Service) | Inactivity-based succession features you’ve enabled, support troubleshooting |
| Billing information | Subscription tier, purchase confirmation from Apple/Google, redeem code usage | Managing your plan and entitlements — payment card details are handled entirely by Apple/Google and never reach us directly |
| Support communications | Content of messages you send us for help | Responding to your inquiries |
This table reflects data actually collected by the Service as implemented at the time of writing (audited against the app’s actual, current data model — not just re-typed from an earlier draft). It must be re-audited again if login/session infrastructure gains additional device/login metadata, mobile push notifications are wired in (device push tokens), or any analytics/crash-reporting tooling is ever added — none of that exists in the Service today.
3. What We Explicitly Do NOT Collect or Cannot Access
This is the core of how the Service is designed, and we want to be direct about it:
- We cannot read the content of your documents. Documents are encrypted on your device before upload, using a key that is itself encrypted separately for each person you authorize. We never receive, store, or have access to an unencrypted copy of your documents, nor to the keys needed to decrypt them.
- We do not store your private encryption keys. Only your public keys — which are safe to share — ever reach our servers.
- We do not know who you’ve shared a document with beyond what’s needed to operate the Service (i.e., we store which accounts hold a wrapped copy of a document’s key, since that’s how sharing works technically, but we cannot see the content being shared).
4. How We Use Your Information
- To operate core functionality: authentication, invitation delivery, key-wrapping coordination, quota enforcement, billing.
- To communicate with you: security notices, billing/plan-change consequences (see our in-app notification system for downgrade and succession events), support responses.
- To maintain security: detecting abuse patterns (e.g., excessive invitation attempts), enforcing rate limits.
- We do not sell your information to third parties, and we do not use document metadata for advertising.
5. Third-Party Service Providers
We use the following categories of third-party infrastructure providers, each of which processes only the specific data necessary for their function:
- Cloud storage (Cloudflare R2) — stores your encrypted document content; the provider has no ability to decrypt it.
- Payment processing (Apple App Store / Google Play) — handles all billing; we receive confirmation of your plan tier, not your payment details.
- Email/notification delivery — used to send invitations, security notices, and support communications.
- [Any analytics/crash-reporting provider, if used — list explicitly, or state “We do not currently use third-party analytics or crash-reporting services.”]
6. International Data Transfers
The Service is available globally. Your account information and metadata (not document content, which you control access to via encryption) may be processed on servers located in [list regions/countries where your infrastructure operates]. Where required by law (e.g., GDPR for EU/EEA users), we rely on [Standard Contractual Clauses / adequacy decisions / other applicable mechanism — confirm with counsel] for these transfers.
7. Data Retention & Deletion
- Account data is retained while your account is active.
- On account deletion request: a 30-day grace period applies, during which the account is deactivated but recoverable, and document ownership can still be transferred to a designated successor (see in-app Succession feature).
- After the grace period, we permanently delete your account data and remove all wrapped-key entries associated with your account across all documents. This is an irreversible action.
- Important limitation: because of the encryption design described above, deleting your account (or losing your device without a configured successor) may result in documents becoming permanently unreadable by anyone, including you and us. This is a structural consequence of end-to-end encryption, not a data-loss failure on our part — see our in-app succession and account-recovery guidance for how to avoid this.
8. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or receive a copy of your account information (not document content, which is already exclusively in your control via your own encrypted storage). To exercise these rights, contact us at [Contact Email].
Note on document content specifically: because we cannot decrypt your documents, we cannot provide you a “copy” of document content through a data-access request in the way we could for ordinary account metadata — you already hold the only means of decrypting your own documents, via your device’s keys.
9. Children’s Privacy
The Service is not directed at children under [13 / 16 — confirm applicable age per jurisdiction], and we do not knowingly collect information from children under this age. If you believe a child has provided us information, contact us at [Contact Email] and we will take appropriate action.
10. Security Measures
- End-to-end encryption using XChaCha20-Poly1305 for document content.
- Hybrid classical + post-quantum key exchange (X25519 + ML-KEM-768, NIST FIPS 203) for key wrapping, designed to resist both current and future quantum-computing threats.
- Local key material protected via Argon2id-derived encryption on your device.
- See our published Threat Model at
[link, if made public]for further technical detail.
11. Changes to This Policy
We will notify you of material changes to this Privacy Policy via the app or email before they take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
For privacy questions, data requests, or DMCA/copyright inquiries, contact:
[Company Name]
[Contact Email]
[Postal address, if required by jurisdiction]
[Designated DMCA Agent name/contact, if different — must match U.S. Copyright Office registration]