Legal

Privacy Policy

Effective date: July 19, 2026

This policy explains what deadkey.net ("we," "us," "the service") collects, why, how long we keep it, and who we share it with. It is meant to be read alongside our Security page, which describes our security model and goes into full technical detail about our zero-knowledge design. If anything here and on that page ever appears to conflict, please contact us at the address below so we can fix the discrepancy — none is intended.

deadkey.net is operated by Zero Trust Holdings LLC, a company based in the United States. The governing law and jurisdiction that apply to your use of the service are set out in our Terms of Service.

1. What data we collect

Category What we collect Why
Owner contact information Your email address (required at setup), and a phone number (optional, only if you opt in to SMS notifications) To reach you if a trusted person ever triggers a countdown, and to send the one-time setup-confirmation email
Encrypted record data An encrypted coordinate sequence, an encrypted release message, and cryptographic hashes used to verify trusted-person credentials This is the core of the service — a sealed, unreadable record we hold until a legitimate trigger or expiration
Trusted person credentials A code and email address you assign to each trusted person, stored only as one-way hashes (path_id, auth_hash) To let a trusted person authenticate a trigger request without us ever holding their credentials in reusable form
Payment information Handled by Stripe. We retain only a Stripe payment intent ID, the amount charged, and a count of trusted people — no cardholder data To process your one-time payment and keep basic financial records, without linking payment to any specific record
Beta/promo code usage (if applicable) Whether a beta or promo code was redeemed for a free record To administer the current beta program; no payment data is generated for these records
Technical/security signals Cloudflare Turnstile bot-detection signals on state-changing forms (setup, trigger, cancel); minimal application logs containing request IDs, HTTP status codes, and timestamps To keep the service available and prevent abuse

2. What we do NOT collect or see

  • Your secret. The PIN, code, or password you are protecting is never transmitted to us, in any form, at any time.
  • The codebook. The mapping that lets your secret be decoded is generated and used entirely in your browser or on paper. We never see it.
  • Your plaintext contact information, with two narrow, disclosed exceptions. Your email and phone number are encrypted under a key only your trusted person can derive. We hold only ciphertext we cannot read, except: (1) for a few seconds at setup, to send a one-time "your deadkey is set up" confirmation email — this address is never written to any database, backup, or log, and is discarded immediately after that single send; and (2) for the duration of an active, genuine 10-day countdown, because we need a readable address to send you countdown-warning reminders and your cancel link. That plaintext is deleted the moment the countdown ends — by cancellation, release, or expiry. Full technical detail is on the Security page.
  • Any link between your payment and your record. Payment records and record data are stored in separate systems with no shared identifier connecting them.
  • Any account, login, or identity. There are no user accounts. We cannot look up "who owns a record" from our own data.
  • Trusted-person codes or emails in reusable form. These are hashed at setup and, during a trigger, used momentarily and then discarded — never stored as standalone, readable values.

3. How we use your data

We use the data described above only to operate the service: to hold your encrypted record until a trigger or expiration; to notify you (by email and, if opted in, SMS) if a trusted person starts a countdown; to let a trusted person authenticate a genuine trigger; to process payment; and to maintain basic security and abuse prevention. We do not use your data for advertising, profiling, or any purpose unrelated to running deadkey.net, and we do not sell personal information.

4. Data retention

Data Retention
Active record (ciphertexts, hashes, state) Up to 3 years from creation
Owner's plaintext email (setup-confirmation send) Never persisted — held in memory only for the few seconds needed to send the email, then discarded
Owner's plaintext contact info (during an active countdown only) Deleted immediately on cancellation or release completion; at most 10 days
Records after release Retained up to 30 days after release for audit purposes, then permanently deleted
Records after expiration Permanently deleted approximately 30 days after the 3-year expiration date
Payment records (payments_audit) Retained only as long as required for financial, tax, and audit purposes, then permanently deleted. Payment data is kept separate from record data, with no shared identifier.

5. SMS / text messaging (opt-in, transactional only)

deadkey.net offers optional SMS notifications. If you choose to opt in during record setup, you provide a mobile phone number and we send you:

  • A one-time phone verification code, to confirm the number is yours and reachable, at setup; and
  • A countdown-started alert if a trusted person ever triggers your record, containing a one-tap cancel link, sent roughly every 3 days across the 10-day countdown window (about 4 messages, only if a trigger actually occurs).

These are the only kinds of SMS messages we send. We do not send marketing, promotional, or any other message type by SMS. SMS is entirely optional — declining it does not prevent you from using deadkey.net; you will still receive the same notifications by email.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.

  • Opt-in: You opt in affirmatively, by checking a box and entering your number during setup. We do not add a phone number to your record without this explicit action.
  • Opt-out: Reply STOP to any message from us at any time to opt out of SMS notifications. You may also opt out by not providing a phone number in the first place, or by contacting us at the address below.
  • Help: Reply HELP to any message from us for assistance, or contact support@deadkey.net.
  • Message frequency: Low. Outside of the one-time verification code, you will only receive messages if a trusted person actually triggers a countdown on your record — most owners never trigger a countdown at all.
  • Message and data rates may apply, depending on your mobile carrier and plan.
  • Our SMS provider is Twilio. See the third-party section below for what Twilio can and cannot see.

6. Third parties (subprocessors)

We rely on a small number of service providers to operate deadkey.net. None of them can see your secret, your codebook, or the decrypted contents of your record — because we never send them that information, since we never have it ourselves.

Provider Purpose What they can see
AWS (Amazon Web Services) Application hosting, database storage, infrastructure Encrypted record data (ciphertext and hashes only), in the form it is stored on our servers
Stripe Payment processing Payment details you provide to Stripe directly (card number, billing info); we receive only a payment intent ID and amount, with no link to your record
AWS SES Email delivery (setup confirmation, countdown reminders, release notifications) The recipient email address and message content, at the moment each email is sent
Twilio SMS delivery (phone verification, countdown-alert texts) Your phone number and message text, at the moment each SMS is sent
Cloudflare (Turnstile) Bot detection on setup, trigger, and cancel forms Browser signals used for bot detection; not the values you enter into the form

We do not sell your data to any of these providers or anyone else. We share only what each provider needs to perform its specific function.

7. Your rights and choices

  • Deletion. You can permanently delete your record at any time using your owner email and delete code at /delete. This removes the encrypted record and all associated data immediately.
  • Access. Because your record is designed so that we cannot decrypt it, we cannot show you a "readable copy" of your own secret from our side — you already hold everything needed to reconstruct it. We can confirm whether a record with a given identifier exists and its current state (active, triggered, released, cancelled, or expired) via /status.
  • Correction. There is currently no way to update contact details on an existing record after setup. If your email or phone number changes, keep this in mind, since a missed notification could prevent you from cancelling a countdown.
  • SMS opt-out. See Section 5 above.
  • Questions or requests regarding your data can be sent to privacy@deadkey.net.

Depending on where you live, you may have additional rights under laws such as the GDPR (EU/UK) or the CCPA/CPRA (California) — including rights to access, correct, delete, or obtain a copy of your personal information. We do not sell or share your personal information, and we never share SMS opt-in or consent data with third parties. To exercise any of these rights, contact us at the address below.

8. Children's privacy and eligibility

deadkey.net is intended for use by adults age 18 and older. We do not knowingly collect personal information from anyone under 18. See our Terms of Service for the full eligibility requirement.

9. Security

We describe our cryptographic design and security practices in detail on our Security page. In short: all sensitive cryptography (Argon2id, AES-256-GCM, HKDF, HMAC) happens in your browser, and our servers only ever store encrypted material we cannot decrypt.

10. Changes to this policy

If we make material changes to this policy, we will update the effective date above and, where required by law, provide additional notice. Continued use of deadkey.net after a change takes effect constitutes acceptance of the updated policy.

11. Contact

Questions about this policy or your data should be directed to:

privacy@deadkey.net

We aim to respond to privacy inquiries within 5 business days. For legal requests (subpoenas, court orders), contact us at support@deadkey.net.