Secretus logo

Secretus legal center

Privacy Policy

How Secretus processes account, billing, support and operational data while keeping secret-content boundaries explicit.

Updated September 1, 2026Effective September 1, 2026

Secretus is designed to keep plaintext secret content away from its servers. We nevertheless process encrypted ciphertext and operational metadata in some modes; this Policy describes that processing without treating encryption as a legal exemption.

1. Who Is Responsible and What This Policy Covers

This Policy explains how personal data is processed when you visit secretus.app, create or use an account, use a share or request link, install the browser extension, purchase a plan, join a team, use an API, or contact us.

Controller
MUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ, trading as Secretus, ONRC F2026008193001, CUI 53962936, with registered address at București, Sector 1, Bulevardul Bucureștii Noi, Nr. 136, Cod poștal 012366, România.
Contacts
Privacy: privacy@secretus.app; legal and DPA requests: legal@secretus.app; support: support@secretus.app. WhatsApp contact is available through the link in the Privacy Contact section below. We have not appointed a Data Protection Officer because we do not currently consider the GDPR Article 37 thresholds to be met, and reassess that conclusion as processing changes.
Our controller role
Secretus acts as controller for website visitors, individual users, account administration, authentication, subscriptions, service security, abuse prevention, audit history, product communications, and direct support.
Our processor role
Where a business customer determines why and how personal data is placed in Secretus and we process it only to provide the service on that customer's instructions, the customer is controller and Secretus is processor. Our Data Processing Agreement governs that processing. Encryption reduces access but does not, by itself, mean encrypted personal data falls outside data-protection law.

2. Personal Data We Process

Account and authentication data
Email address; display name and avatar if supplied; Cognito subject and identity-provider identifiers; password verifier and authentication attributes managed by AWS Cognito; MFA/TOTP status; sign-in, token, session, verification, recovery, security-event, and trial-reminder metadata. Amazon SES receives the recipient email address, transactional message type, and the time-limited Cognito verification code or temporary password needed for native email/password messages. For the trial-expiry reminder, SES receives the recipient email address, optional display name, trial-end date, and delivery metadata. Secretus does not receive your Google password or your plaintext account password.
Profile, plan, and usage data
Internal profile ID, account region and timestamps, tier and entitlement status, trial and subscription dates, usage counters, feature selections, and other settings needed to operate your account.
Team and API data
Team owner/member identifiers, email address, membership and invitation status and dates; API-key label, prefix, hash, permissions/status, creation and revocation metadata. We do not store the plaintext API key after it is displayed.
Secret and request data
Depending on mode, encrypted ciphertext, random identifiers, encrypted size/type metadata, selected expiry, access/claim/revocation status, optional plaintext labels, request identifiers, signalling/session state, and delivery events. A URL fragment containing a decryption key or Team Split share is processed by the user's browser and is not intentionally sent to Secretus servers. Do not put personal data in an optional plaintext label unless necessary.
Network, device, and security data
IP address and forwarded-address headers, user agent, timestamps, route/method, request size and status, approximate region, rate-limit keys, connection and WebRTC/TURN metadata, error diagnostics, integrity and anti-abuse signals, and security/audit events. Depending on network conditions, a P2P peer may learn the other peer's IP address; a TURN relay can process encrypted traffic and network metadata.
Billing data
Selected plan, subscription and entitlement status, period dates, transaction/customer/subscription references, and limited checkout outcome data. Payment-card and bank details are entered directly into Stripe/Link's hosted checkout and are not received or stored by Secretus.
Support and legal communications
Your contact details, message content, attachments, verification information, and records needed to resolve a support, sales, privacy, security, illegal-content, or legal request.
Cookies and browser storage
Consent state, essential authentication and security data, session and interface state, regional preferences, temporary OAuth return context, locally displayed secret metadata, and optional analytics identifiers only after consent where required.

3. Sources and Whether You Must Provide Data

Directly from you
We receive data when you register, authenticate, configure an account, create or receive a secret, use an API or extension, purchase, join a team, change consent, or contact us.
Other users and organisations
A sender, recipient, request creator, team owner, business customer, or administrator may provide your email address, membership details, a link, or content involving you. That party is responsible for its lawful basis and notices where it acts as controller.
Providers and technical systems
AWS Cognito and Amazon SES for native authentication and trial-reminder email, Google if chosen for sign-in, Stripe/Link for purchases, browsers, cloud and network systems, and consented analytics may generate or return operational data within their roles. The consent interface itself is hosted by Secretus and stores the choice in a first-party cookie.
Required and optional data
Core account, authentication, security, and service-routing data is required to provide the relevant feature. If you do not provide it, the feature may not work. Google sign-in, profile name/avatar, optional labels, analytics consent, and the content you choose to share are optional; email/password sign-in is available as an alternative to Google sign-in.

4. Purposes and GDPR Legal Bases

The applicable basis depends on the processing and your relationship with us. We do not rely on consent where processing is genuinely necessary to perform the contract or comply with law.

Contract — GDPR Article 6(1)(b)
To register and authenticate you; provide the selected secret-sharing, request, team, API, extension, subscription, and account functions; manage entitlements and cancellation; and answer service-related requests. Pre-contract steps requested by you use the same basis.
Legitimate interests — Article 6(1)(f)
To secure and defend the service, prevent fraud and abuse, enforce one-time limits, maintain audit and operational records, diagnose failures, protect users, establish or defend legal claims, and improve reliability. We document and periodically review the balancing assessment for these purposes. You may object where the law permits by contacting privacy@secretus.app.
Legal obligations — Article 6(1)(c)
To meet tax, accounting, consumer, data-protection, sanctions, incident-reporting, court-order, and other binding legal duties.
Consent — Article 6(1)(a) and ePrivacy rules
For optional analytics and non-essential cookies or browser technologies where consent is required. You may withdraw consent as easily as you gave it, without affecting earlier lawful processing.
Customer instructions
Where Secretus is processor, the business customer must identify and maintain its own lawful basis for Customer Personal Data. We process that data under the DPA and the customer's documented instructions, not for independent advertising purposes.

5. Encryption and Processing by Delivery Mode

Standard mode
The browser encrypts the payload before upload. Secretus and AWS process and temporarily store ciphertext and metadata but do not receive the fragment decryption key through the documented workflow. Ciphertext can still be personal data if it relates to an identifiable person, including where the operator does not hold the decryption key.
Maximum/P2P mode
Secretus processes signalling, authentication, safety-number state, audit, and connection metadata. The payload is delivered through WebRTC and is not stored by Secretus; encrypted traffic may traverse TURN. Users must compare the safety number to address signalling-substitution risk.
Team Split
Shares are created, held, and reconstructed in participating browsers. The Team Split workflow does not upload share material to Secretus, but we may process account, entitlement, audit, and locally generated feature metadata. Users control copies of fragment links outside our service.
Special-category or highly sensitive data
We cannot reliably determine the nature of encrypted content. If you choose to process health, biometric, political, religious, trade-union, sexual-life, criminal-offence, children's, or similarly sensitive data, you or your organisation must establish the additional lawful condition, safeguards, notices, and sector permissions. Do not use Secretus where a specific certification or regulated repository is legally required unless separately agreed.

6. Cookies, Local Storage, and Analytics

Strictly necessary technologies
We use essential browser storage for authentication, security, consent, OAuth return handling, region and interface state, and local product functions. These cannot always be disabled without breaking the requested service.
Consent management
Secretus serves the consent interface from its own website and stores your choice in a first-party cookie on your device. No external consent-management provider receives that choice. Optional analytics is disabled unless the current consent state permits analytics.
Google Analytics
Google Analytics loads only after analytics consent where required. We disable further analytics events when consent is withdrawn. We do not use analytics on secret, authentication, or account routes covered by the service's stricter third-party policy.
Current cookie and storage summary
secretus_consent stores the consent choice on this device for up to 12 months. If analytics consent is given, Google Analytics may set _ga and _ga_<container-id> (normally up to 2 years) and _gid (normally 24 hours). Authentication tokens are held in session storage for the browser tab; a temporary OAuth return context may remain in same-origin local storage for up to 10 minutes. We may change this list when providers or configurations change.
Change or withdraw consent
Use the Cookie settings control in the site footer to reopen the consent tool. Withdrawal stops future optional analytics processing; it does not make prior consent-based processing unlawful. You may also clear browser cookies and site data.

7. Recipients and Provider Roles

We disclose only data reasonably needed for the stated purpose, under contracts and access controls appropriate to each provider's actual legal role. We do not sell personal data or share it for cross-context behavioural advertising.

Amazon Web Services
AWS provides EU-region hosting, storage, databases, networking, logging, security, Cognito authentication, and Amazon SES transactional email delivery. For account-verification, password-reset, temporary-password, account-security, and trial-expiry reminder emails, SES receives the recipient email address, message type, delivery metadata, and the time-limited code or temporary password required where applicable; a trial reminder also includes the optional display name and trial-end date. AWS does not receive Secretus plaintext secret content or URL-fragment decryption keys through these email flows. AWS generally acts as our processor and may use approved affiliates and sub-processors under its Data Processing Addendum and applicable transfer safeguards.
Google sign-in
If you choose Google sign-in, Google processes identity and security data under its own terms and may act as an independent controller for its authentication service; AWS Cognito passes the resulting identity attributes needed by Secretus.
Stripe and Link
Stripe/Link hosts checkout and, through Stripe Managed Payments, Link acts as merchant of record for payment, fraud, tax, receipts, and payment support. They act as independent controllers for those purposes. Secretus receives limited subscription and entitlement data needed to supply the service.
Self-hosted consent interface and Google Analytics
The consent interface is version-locked, bundled with the Secretus website, and does not send the choice to a consent-management provider. Google provides optional public-page analytics only after consent. Google does not receive plaintext secret content from Secretus.
Business customers and users
Team owners and authorised customer administrators receive limited membership and audit information. Senders and recipients receive content and status information inherent in the sharing flow. Their independent use of data is their responsibility.
Authorised personnel access
Authorised Secretus personnel, including technical administrators, may access account, subscription, team/organisation, and audit data only where necessary to provide the service, maintain security, prevent fraud or abuse, provide support, troubleshoot, meet compliance duties, or establish, exercise, or defend legal claims. Access is role-based and restricted by the need-to-know principle.
Authorities and professional advisers
We may disclose data to courts, regulators, law enforcement, tax authorities, insurers, auditors, or advisers where legally required or reasonably necessary to protect rights, users, or the service. We assess requests and challenge overbroad demands where legally and practically appropriate.
Corporate transactions
Data may be disclosed under confidentiality in a financing, reorganisation, sale, or transfer of the service. Any recipient must respect applicable data-protection law, and users will be notified where required.
Current provider list
The public provider and sub-processor register at https://secretus.app/subprocessors explains purposes, locations, safeguards, and role distinctions. A Business customer for whom Secretus acts as processor is covered by the applicable DPA before that customer instructs processing; bespoke DPA requests go to the legal email address.

8. International Transfers

Primary location
Core Secretus infrastructure is currently configured in AWS eu-central-1 (Frankfurt, Germany). The operator is established in Romania. This reduces but does not eliminate international access or transfer.
Transfer safeguards
Where personal data is transferred outside the EEA, we use an applicable adequacy decision, the European Commission's controller/processor Standard Contractual Clauses, supplementary measures, or another lawful mechanism. Provider support, identity, payment, consent, or analytics operations may involve third countries.
Obtaining information
Contact privacy@secretus.app for information about the applicable safeguard and, where the law provides, a copy or summary with confidential information protected.

9. Retention and Deletion

Retention is measured by data type and purpose. Expiry and account deletion remove active records but cannot erase recipient-made copies or provider records held under an independent legal duty.

Standard-mode ciphertext
Stored until first successful claim, revocation, or the user-selected expiry, which is no more than 30 days. After access or revocation we invalidate the one-time metadata and request object deletion; a storage lifecycle rule expires objects at 37 days as a cleanup backstop. Brief technical delay or residual provider copies may exist during deletion processing.
P2P and Team Split payloads
Secretus does not store the P2P payload or Team Split shares through those workflows. Short-lived signalling/session data is discarded when no longer needed. Copies held by users, browsers, recipients, networks, or external messaging services are outside our deletion control.
Account and profile
Active records are retained while the account exists. Self-service deletion removes the active profile and Cognito account and revokes API keys and team relationships. Encrypted backups and point-in-time recovery copies of profile infrastructure may persist for up to 35 days and are isolated for disaster recovery, after which they age out under provider controls.
Trial-eligibility digest after account deletion
When you delete your account we keep one record: a keyed one-way cryptographic digest of your email address, computed with a secret key held only on our servers. The address itself is not kept, and the digest cannot be reversed into an address by anyone who does not hold that key. It exists solely so the same mailbox does not receive a second free trial, and it is used for no other purpose — not for marketing, profiling, or linking accounts. It is deleted automatically 90 days after account deletion. The basis is our legitimate interest in preventing repeated use of a one-time offer (Article 6(1)(f)); we have documented the balancing assessment, and you may object at privacy@secretus.app. Because this record is a pseudonym rather than anonymous data, it remains personal data and your rights continue to apply to it. Deleting your account is never blocked by this record: if it cannot be written, the deletion still completes.
Audit and security events
Product audit events normally expire after 90 days for Starter/Pro and anonymous/system events, or 365 days for an active Business entitlement. Account deletion attempts to purge the user's existing audit history, but a limited deletion/security event and queued or recovery copies can remain until their normal expiry. Serverless application logs are retained for 90 days. Security and troubleshooting logs are reviewed at least every 90 days and deleted or anonymised when no longer needed; an active security investigation or legal hold may require a narrower, longer retention.
Billing, legal, and support records
Stripe/Link retains payment and tax records under its own legal schedules. We retain subscription references, invoices received by us, legal notices, disputes, and necessary communications only for the applicable accounting, tax, limitation, fraud-prevention, and defence periods. An online-withdrawal processing record and receipt are retained for three years to make retries safe and demonstrate the declared name, statement, contract reference, receipt time, processing, and any refund; they do not contain card data or the account email. Routine support material is reviewed every 90 days and deleted or anonymised when no longer needed for support, security, or legal claims.
Consent records
Consent choices and evidence are retained for the duration needed to apply the choice and demonstrate compliance, then renewed, anonymised, or deleted in accordance with the consent provider's configuration and applicable limitation periods.
Legal holds
A narrowly scoped record may be retained beyond the ordinary period where required by law, a binding order, an active security investigation, or the establishment, exercise, or defence of legal claims. Access is restricted and deletion resumes when the hold ends.

10. Security

Measures
Risk-based measures include browser-side payload encryption or sharing, TLS in transit, EU-region cloud deployment, encryption at rest for stored ciphertext and managed data, access controls and least-privilege roles, MFA-capable authentication, scoped API-key hashes, one-time conditional claims, rate limiting, restrictive security headers, audit logging, monitoring, backups where appropriate, and controlled deployment procedures.
Your part
Use a secure and updated device, protect credentials and links, enable MFA where available, verify P2P safety numbers through an independent trusted channel, select suitable expiry, avoid unnecessary plaintext labels, and promptly revoke a link or key if exposure is suspected.
Limits
No system is perfectly secure. Client-side encryption does not protect plaintext already compromised on an endpoint, copied by a recipient, exposed through a full link, or revealed through user-selected labels. Security materials are not a certification, penetration-test report, or guarantee unless explicitly identified as such.
Personal data breaches
We investigate suspected incidents and notify the competent authority within the GDPR deadline where required. We notify affected individuals without undue delay where a breach is likely to result in a high risk, unless an applicable exception applies. Where we act as processor, we notify the customer without undue delay after becoming aware of a breach of Customer Personal Data.

11. Your Data-Protection Rights

Rights
Subject to legal conditions and exceptions, you may request access, rectification, erasure, restriction, and portability; object to processing based on legitimate interests or direct marketing; and withdraw consent at any time. We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects.
How to exercise them
Use available account controls or email privacy@secretus.app. The self-service data export includes the Terms of Service and Privacy Policy acceptance history retained for your account. Describe any other request and the account or interaction concerned. We may request proportionate identity verification and will not use verification data for unrelated purposes.
Timing and fees
Under GDPR we normally respond within one month. We may extend by up to two further months for a complex or numerous request and will explain the extension within the first month. Requests are normally free; a reasonable fee or refusal is possible only for manifestly unfounded or excessive requests as permitted by law.
When we are processor
If your data was supplied by a business customer and Secretus acts only as processor, we will normally direct the request to that customer and assist it under the DPA, unless law requires us to respond directly.
Account deletion
Self-service deletion removes the active account data described above. It does not automatically erase Stripe/Link records, recipient copies, lawfully retained records, or already-created ciphertext before its access/expiry cleanup. Signing in again may create a new account.
Complaints
You may complain to the supervisory authority in the country where you live, work, or believe an infringement occurred. Because we are established in Romania, you may also contact Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) at https://www.dataprotection.ro/. You may seek a judicial remedy and may contact us first, but are not required to do so.
Other jurisdictions
We honour additional applicable privacy rights. We do not sell personal data or use it for cross-context behavioural advertising. If local law grants an appeal from a denied request, reply to our decision with “Privacy appeal” and we will review it as required.

12. Authentication and Browser Extension Details

Web authentication storage
Short-lived web access and ID tokens are kept in session storage; the web refresh token is memory-only. Temporary same-origin OAuth return context may use local storage for up to 10 minutes. Request keys may be held in session storage, with a short OAuth handoff fallback. Browser storage can be read by code running in that browser profile, so device and extension security matters.
Extension storage
The extension stores an authentication refresh token in browser session storage, cleared when the browser session closes and not synchronised; preferred expiry; and local metadata for secrets created from that browser. It does not intentionally store secret content, full share links, or decryption keys.
Extension page access
The extension reads selected page text only when you invoke its share-selection action. It does not collect general browsing history or run analytics. It communicates with AWS Cognito and the Secretus API for the functions you request.

13. Children

Age limit
Secretus is not intended for children under 16 and we do not knowingly solicit their personal data. A business customer must not authorise under-age users or place children's data in the service without every required lawful basis, notice, authorisation, and safeguard.
Removal
If you believe a child has provided data unlawfully, contact privacy@secretus.app. We will investigate and delete or restrict data where required, subject to verification and legal retention duties.

14. Changes to This Policy

Updates
We update this Policy when processing, providers, retention, or law changes. The page shows the last-updated and effective dates. Material changes will also be communicated by reasonable email or in-product notice where appropriate or legally required.
No retroactive reduction
A new policy does not retroactively make prior unlawful processing lawful or remove rights that have already accrued. Where a new purpose requires consent or another step, we will take that step before relying on it.

Provider details are maintained in our Provider and Sub-processor List.

Contractual service rules are in our Terms of Service.

Privacy Contact

MUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ

Trading as: Secretus

ONRC F2026008193001

CUI 53962936

EU VAT (VIES): RO54197611

București, Sector 1, Bulevardul Bucureștii Noi, Nr. 136, Cod poștal 012366, România

Romania, European Union

WhatsApp: Contact us on WhatsApp

Privacy: privacy@secretus.app