Privacy policy

SealedBrief is a local-first product. The desktop application processes your documents on your machine and sends nothing to us. The website you are reading collects only what is required to sell, deliver, and support a software license. This policy enumerates exactly what is collected and where it lives.

Last updated: 2026-08-30.

1. What we collect on this website

When you buy a SealedBrief license, the checkout is handled by Stripe. Stripe holds your card data; we never see it. Stripe sends us a webhook containing the customer email address, the price ID, and a Stripe customer ID. We persist the resulting license record — a binding of license_id to email address — in a private database operated solely for license issuance and revocation.

We run no third-party analytics or tracking on this website. There is no Google Analytics, no Meta Pixel, no third-party advertising script, and no first-party cookies set by us. No third party receives anything about your visit from your browser.

Two first-party exceptions, stated plainly. First, our CDN keeps standard server access logs of requests to this website and to the download host — see section 3. Second, if you arrive from one of our own ads or a tagged link, a small script stores that link's campaign identifier in your browser's local storage and appends it to the checkout URL, so that if you buy we can tell which link brought you. It sets no cookie, it loads nothing from a third party, and it sends nothing anywhere unless you start a checkout. Clearing site data removes it.

2. What the desktop app collects

Nothing. The desktop application has no network egress from the compute plane (the part that touches your documents) by design: that plane declares no outbound network endpoints, a build gate fails the release if it ever does, and a runtime guard in the process refuses any non-loopback connection or external DNS lookup. Those are properties of how the software is built and run — not a measurement we took on your machine, which is why the procedure for checking it yourself is published at /verify. The presentation plane connects to our license server only to validate your license_id on launch and to fetch the revocation list. Neither connection sends document contents, queries, or any derived data.

AI model files are downloaded from our CDN over plain HTTPS — no account, no identifier, no cookie; the CDN sees your IP address for that request, as any web server does, and nothing else. Every download is verified against an Ed25519-signed manifest before it is ever used, and an offline import path exists so a machine with no internet never needs this connection. On Linux and macOS this happens only if you choose to add the optional larger model (Settings → Models). On Windows it also happens during installation, because the Windows installer format cannot carry a file as large as the model: the same CDN that served you the installer a moment earlier serves the model too, from the same IP, under the access logging described in section 3. It is more requests, not a different kind of information. Passing /SKIPMODELS=1 to the Windows installer skips it entirely.

After V1.0 launch, the desktop application may offer an opt-in crash-report channel. If you opt in, anonymised stack traces are sent to a self-hosted error aggregator. The opt-in is off by default and toggleable in app settings; the data sent never contains document text, file paths, or query content.

3. What we share

We share data with three categories of subprocessor:

  • Stripe — payment processing. Stripe handles your payment data under their own privacy policy.
  • Postmark — transactional email delivery (license email after purchase, refund confirmation). Postmark sees your email address and the message body. It does not see anything about your documents. We send no marketing or newsletter content via Postmark; only the single license-delivery transactional template triggered by a successful Stripe checkout.
  • Amazon Web Services — hosts the license-minting microservice (Lambda + API Gateway), the audit-log S3 bucket holding signed license records, and the CloudFront distributions serving both this website and the binary downloads at downloads.sealedbrief.com. AWS sees the customer email address (forwarded inside Stripe's webhook payload) and CloudWatch logs of Lambda invocations. AWS does not see anything about your documents.
  • CloudFront access logs (first-party). Our CDN writes a standard server access log line for each request to this website and to the download host, recording the timestamp, the URL requested, the response status and byte count, your browser's user-agent string, the country your IP resolves to, and your IP address. We store these logs in our own AWS account and query them to count page visits and completed downloads — so, unlike the statement above about third-party analytics, we do measure aggregate traffic, using our own server logs. We never join them against license or customer records, and nobody outside AWS receives them. Retention is 90 days; see section 4.
  • Cloudflare — DNS for the sealedbrief.com zone only. Cloudflare resolves the domain name; it is not in the path of this website's content and holds no request logs for it.

We do not share data with anyone else. We do not sell, trade, or rent any data we hold.

4. How long we keep data

We keep your license_id ↔ email binding for as long as your license is active. If you ask us to delete your account, we delete the binding within 30 days. Stripe retains its own copy of the transaction record per its policy, which we cannot influence.

Transactional email logs at Postmark are retained per their retention policy (default 45 days). AWS CloudWatch logs of Lambda invocations are retained 30 days per our configured policy. We do not extend either retention window.

CloudFront access logs, including the IP address they contain, are deleted automatically 90 days after they are written, by a storage lifecycle rule rather than by anyone remembering to run it.

5. Your rights and contact

You can request access to, correction of, or deletion of the data we hold about you by writing to privacy@sealedbrief.com. We respond within 30 days. If you are an EU or UK resident, the legal basis we rely on for processing customer data is the contract you entered into when buying the license. For website access logs, where no contract exists, the basis is our legitimate interest in operating, securing, and measuring the traffic to our own site; you can object by writing to the address above.

This policy is a v1 stub written by the engineering team ahead of V1.0 launch. A formal legal review is queued for the post-launch backlog. If our practices change, we will publish an updated policy at this URL with a new "last updated" date.