# Privacy policy

Canonical URL: https://burnthesecret.com/privacy
Markdown URL: https://burnthesecret.com/privacy.md

# Privacy Policy

Last updated: September 17, 2026

## 1\. Information We Collect

Burn the Secret is designed with privacy as a core principle. We collect minimal information necessary to provide our service:

-   **Secret Content:** The browser and CLI encrypt content on your device before transmission; the decryption key is not sent to us. The optional plaintext API is different: it sends plaintext to our server for encryption, so it is not zero-knowledge. Filenames, MIME types, sizes, expiry, and access status are server-visible metadata.
-   **Operational Data:** Request counts and network identifiers for abuse prevention and service operation. Third-party analytics scripts are disabled in the application.
-   **Account Information:** Email address, optional name and profile image, authentication-provider account records, and sessions for registered users.

## 2\. How We Use Your Information

We use collected information solely to:

-   Provide and maintain the Burn the Secret service
-   Improve user experience and service reliability
-   Send important service notifications to registered users
-   Ensure security and prevent abuse

## 3\. Data Retention

New secrets have a maximum lifetime of 90 days from creation; shorter selected expiries still apply. Existing secrets keep their saved expiry dates. Access stops at expiry, when burned, or when the view limit is reached. Unlimited views do not extend the expiry date. Encrypted content is removed when burned or its view limit is reached; status metadata remains until expiry cleanup. Hourly cleanup deletes expired secrets, attachments, and status metadata from the active database, normally within one hour of expiry. These secrets cannot be recovered through this service. Active-database deletion does not promise immediate erasure from infrastructure backups. Account data is retained until you delete your account in Settings. This also removes its API keys, sessions, and associated secrets and attachments. Anonymous secrets are not associated with an account. Backup and processor retention require separate operational review; this page is not a compliance certification.

## 4\. Contact Us

If you have questions about this Privacy Policy, please contact us at [hello@burnthesecret.com](mailto:hello@burnthesecret.com)
