Legal
Privacy Policy
Last updated: March 19, 2026
Summary
ChronoCypher is built so that your files and decryption keys stay under your control. We process account and billing data needed to run the service, but we do not have access to the plaintext of your vault or your decryption password.
Who we are
ChronoCypher is a product of DAPP CDN LTD ("we", "us"), the company behind dappcdn.com. Billing for this service is processed by DAPP CDN LTD. For privacy-related requests, contact us at [email protected].
Information we collect
- Account & access: email address for magic-link authentication and vault-related notifications (e.g. life-check reminders, beneficiary notices when configured).
- Vault metadata: identifiers and configuration needed to operate the service (e.g. vault ID, unlock rules, beneficiary contact details you provide, storage references). Encrypted payloads are stored as opaque data—we cannot read their contents.
- Payment data: Billing for this service is processed by DAPP CDN LTD. Card payments are handled by our payment provider (e.g. Stripe) on behalf of DAPP CDN LTD (DAPP CDN / dappcdn.com). We do not store full payment card numbers on our servers.
- Technical & security: standard server logs, diagnostics, and abuse-prevention signals (e.g. IP address, user agent, timestamps) as needed to secure and improve the service.
Encryption & zero-knowledge design
Vault encryption and decryption are designed to run in your browser. Your decryption password is not sent to our servers in a form that allows us to decrypt your files. We may store encrypted blobs and related metadata required for delivery and recovery flows, but we cannot turn ciphertext into plaintext without your key.
You are responsible for storing your decryption key and Legacy Certificate safely and sharing access instructions with your beneficiaries outside the product if you choose to.
How we use information
- Provide, secure, and improve the ChronoCypher service.
- Authenticate you, send transactional emails, and execute vault logic you configure.
- Process payments and comply with legal obligations.
- Detect fraud, abuse, and technical issues.
Legal bases (EEA/UK)
Where GDPR applies, we rely on appropriate bases such as: performance of a contract, legitimate interests (security, product improvement, balanced against your rights), consent where required, and legal obligation.
Sharing
We do not sell your personal information. We share data with:
- Infrastructure & storage partners (e.g. hosting, email, blockchain/permanent storage providers) strictly as needed to operate the service.
- Payment processors for billing processed by DAPP CDN LTD (e.g. Stripe).
- Authorities when required by law or to protect rights and safety.
Retention
We retain information for as long as your account is active and as needed for legal, tax, and security purposes. Encrypted archives may persist on permanent storage networks as part of the service design; metadata retention follows our operational and legal requirements.
Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, and to object or port certain data. Contact [email protected] to make a request. You may also lodge a complaint with your local supervisory authority.
International transfers
We may process data in countries other than your own. Where required, we use appropriate safeguards (such as standard contractual clauses) for transfers.
Children
ChronoCypher is not directed at children under 16. We do not knowingly collect personal information from children.
Changes
We may update this policy from time to time. We will post the updated version on this page and revise the "Last updated" date. Material changes may be communicated by email or in-product notice where appropriate.