Privacy policy
SealedBrief is a local-first product. The desktop application processes your documents on your machine and sends nothing to us. The website you are reading collects only what is required to sell, deliver, and support a software license. This policy enumerates exactly what is collected and where it lives.
1. What we collect on this website
When you buy a SealedBrief license, the checkout is handled by
Stripe. Stripe holds your card
data; we never see it. Stripe sends us a webhook containing the customer email address, the
price ID, and a Stripe customer ID. We persist the resulting license record — a binding of license_id to email address — in a private database operated solely for license issuance and revocation.
We run no third-party analytics or tracking on this website. There is no Google Analytics, no Meta Pixel, no third-party advertising script, and no first-party cookies set by us. No third party receives anything about your visit from your browser.
Two first-party exceptions, stated plainly. First, our CDN keeps standard server access logs of requests to this website and to the download host — see section 3. Second, if you arrive from one of our own ads or a tagged link, a small script stores that link's campaign identifier in your browser's local storage and appends it to the checkout URL, so that if you buy we can tell which link brought you. It sets no cookie, it loads nothing from a third party, and it sends nothing anywhere unless you start a checkout. Clearing site data removes it.
2. What the desktop app collects
Nothing. The desktop application has no network egress from the compute plane (the part that
touches your documents) by design: that plane declares no outbound network endpoints, a
build gate fails the release if it ever does, and a runtime guard in the process refuses any
non-loopback connection or external DNS lookup. Those are properties of how the software is
built and run — not a measurement we took on your machine, which is why the procedure for
checking it yourself is published at /verify. The presentation plane
connects to our license server only to validate your license_id on launch and to
fetch the revocation list. Neither connection sends document contents, queries, or any
derived data.
AI model files are downloaded from our CDN over plain HTTPS — no account, no identifier,
no cookie; the CDN sees your IP address for that request, as any web server does, and
nothing else. Every download is verified against an Ed25519-signed manifest before it is
ever used, and an offline import path exists so a machine with no internet never needs this
connection. On Linux and macOS this happens only if you choose to add the optional larger
model (Settings → Models). On Windows it also happens during installation,
because the Windows installer format cannot carry a file as large as the model: the same
CDN that served you the installer a moment earlier serves the model too, from the same IP,
under the access logging described in section 3. It is more requests, not a different kind
of information. Passing /SKIPMODELS=1 to the Windows installer skips it
entirely.
After V1.0 launch, the desktop application may offer an opt-in crash-report channel. If you opt in, anonymised stack traces are sent to a self-hosted error aggregator. The opt-in is off by default and toggleable in app settings; the data sent never contains document text, file paths, or query content.
3. What we share
We share data with three categories of subprocessor:
- Stripe — payment processing. Stripe handles your payment data under their own privacy policy.
- Postmark — transactional email delivery (license email after purchase, refund confirmation). Postmark sees your email address and the message body. It does not see anything about your documents. We send no marketing or newsletter content via Postmark; only the single license-delivery transactional template triggered by a successful Stripe checkout.
- Amazon Web Services — hosts the license-minting microservice (Lambda + API
Gateway), the audit-log S3 bucket holding signed license records, and the CloudFront
distributions serving both this website and the binary downloads at
downloads.sealedbrief.com. AWS sees the customer email address (forwarded inside Stripe's webhook payload) and CloudWatch logs of Lambda invocations. AWS does not see anything about your documents. - CloudFront access logs (first-party). Our CDN writes a standard server access log line for each request to this website and to the download host, recording the timestamp, the URL requested, the response status and byte count, your browser's user-agent string, the country your IP resolves to, and your IP address. We store these logs in our own AWS account and query them to count page visits and completed downloads — so, unlike the statement above about third-party analytics, we do measure aggregate traffic, using our own server logs. We never join them against license or customer records, and nobody outside AWS receives them. Retention is 90 days; see section 4.
- Cloudflare — DNS for the sealedbrief.com zone only. Cloudflare resolves the domain name; it is not in the path of this website's content and holds no request logs for it.
We do not share data with anyone else. We do not sell, trade, or rent any data we hold.
4. How long we keep data
We keep your license_id ↔ email binding for as long as your license is active. If
you ask us to delete your account, we delete the binding within 30 days. Stripe retains its own
copy of the transaction record per its policy, which we cannot influence.
Transactional email logs at Postmark are retained per their retention policy (default 45 days). AWS CloudWatch logs of Lambda invocations are retained 30 days per our configured policy. We do not extend either retention window.
CloudFront access logs, including the IP address they contain, are deleted automatically 90 days after they are written, by a storage lifecycle rule rather than by anyone remembering to run it.
5. Your rights and contact
You can request access to, correction of, or deletion of the data we hold about you by writing to privacy@sealedbrief.com. We respond within 30 days. If you are an EU or UK resident, the legal basis we rely on for processing customer data is the contract you entered into when buying the license. For website access logs, where no contract exists, the basis is our legitimate interest in operating, securing, and measuring the traffic to our own site; you can object by writing to the address above.
This policy is a v1 stub written by the engineering team ahead of V1.0 launch. A formal legal review is queued for the post-launch backlog. If our practices change, we will publish an updated policy at this URL with a new "last updated" date.