Operated by KRYPTHQ LTD, a company registered in England and Wales (company number 17254962), with registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.
This Privacy Policy explains how Krypt ("Krypt", "we", "us", or "our") collects, uses, stores, and shares personal data when you use our website at krypthq.com and our developer secrets management service (the "Service").
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.
1. Who we are
Krypt is operated by KRYPTHQ LTD, a company registered in England and Wales (company number 17254962), with its registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF. KRYPTHQ LTD is the Data Controller responsible for your personal data. KRYPTHQ LTD is registered with the Information Commissioner's Office under registration number ZC198503.
Contact: hello@krypthq.com
2. Personal data we collect
We collect the following categories of personal data:
2.1 Account data
- Email address
- Name (if provided)
- Password (handled and stored by our authentication provider, Clerk — we never see or store your password directly)
- Authentication tokens and session identifiers
2.2 Billing data
- Payment card details (handled by Stripe — we never see or store full card numbers)
- Billing address
- Stripe customer ID
- Subscription status, plan, and invoice history
2.3 Service data
- Project, environment, and team metadata you create in the Service
- Secret values you store in the Service ("Secrets") — all Secrets are encrypted at rest using industry-standard encryption
- Audit log entries (who did what, when)
2.4 Technical data
- IP address (collected for security, abuse prevention, and rate limiting)
- Browser type and version
- Device and operating system information
- Time zone and locale
- Pages visited, features used, and timestamps (usage analytics)
2.5 Communications data
- Support enquiries you send to us
- Email correspondence
- Onboarding and feedback responses
We do not intentionally collect special category data (such as health data, biometric data, or political opinions). Please do not store such data as Secrets in the Service.
3. Lawful bases for processing
Under UK GDPR, we rely on the following lawful bases:
| Purpose | Lawful basis |
|---|---|
| Providing the Service to you (account, secrets storage, billing) | Performance of a contract (Article 6(1)(b)) |
| Securing the Service, preventing fraud and abuse, keeping audit logs | Legitimate interests (Article 6(1)(f)) — our legitimate interest in operating a secure, reliable service |
| Sending service emails (account changes, billing, security alerts) | Performance of a contract (Article 6(1)(b)) |
| Sending marketing or product update emails | Consent (Article 6(1)(a)) — you can withdraw at any time |
| Complying with legal obligations (tax, accounting, lawful requests) | Legal obligation (Article 6(1)(c)) |
| Responding to support requests | Legitimate interests / performance of a contract |
| Specific public-interest processing (where applicable, e.g. fraud prevention, network security) | Recognised legitimate interest under the Data (Use and Access) Act 2025 (Article 6(1)(ea)) |
The lawful bases above reflect the UK GDPR as updated by the Data (Use and Access) Act 2025 (DUAA), which came into force on 5 February 2026. The DUAA introduced "recognised legitimate interests" as an additional lawful basis for specific public-interest processing.
4. How we use your data
We use your personal data to:
- Create and manage your Krypt account.
- Provide, operate, and improve the Service.
- Encrypt, store, and serve your Secrets to the projects and environments you authorize.
- Process payments and manage subscriptions.
- Send transactional emails (account confirmations, password resets, billing receipts, security notifications).
- Detect, investigate, and prevent abuse, fraud, or unauthorized access.
- Provide customer support.
- Comply with legal and regulatory obligations.
- Send product updates or marketing emails — only if you have opted in.
5. Sub-processors
We use the following third-party sub-processors to deliver the Service. Each is bound by a data processing agreement (or equivalent contractual terms) and processes data only on our instructions.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Clerk Inc. | Authentication and user management | Email, name, password (hashed), session tokens, IP address | United States |
| Supabase Inc. | Database hosting (account, project, and encrypted Secret data) | Account data, Service data, encrypted Secrets, audit logs | eu-west-1, Ireland |
| Stripe Payments Europe Limited | Payment processing | Name, email, billing address, payment card details, transaction history | Ireland |
| Resend | Transactional email delivery | Email address, name, email content metadata | eu-west-1, Ireland |
| Railway | Backend application hosting | All data processed by the backend in transit; logs may include IP and request metadata | europe-west4, Netherlands |
| Vercel Inc. | Frontend hosting and CDN | IP address, request metadata, basic technical data | Global edge network |
| Sentry | Error monitoring and observability | IP address, request metadata, error stack traces (with automatic redaction of sensitive fields) | United States |
[REVIEW] If we add analytics (e.g., Plausible or PostHog), error tracking (e.g., Sentry), or other sub-processors, this list will be updated and existing customers will be notified.
We will give reasonable notice (at least 30 days where practicable) before adding or replacing a sub-processor that materially changes how your data is processed.
EU users: Krypt is a UK-based service. If you are located in the European Economic Area (EEA), Krypt is offered to you on the basis that your data may be transferred to and processed in the United Kingdom under the EU-UK adequacy decision. We do not currently maintain a separate EU representative under Article 27 of the EU GDPR. By using the Service, you acknowledge this arrangement.
6. International data transfers
Some of our sub-processors are based in the United States or operate global infrastructure. Your data may therefore be transferred outside the United Kingdom and the European Economic Area.
Where we transfer personal data outside the UK, we rely on one or more of the following safeguards:
- The UK Adequacy Regulations for the European Economic Area (where applicable).
- The UK Extension to the EU-US Data Privacy Framework, where the recipient is certified.
- Standard Contractual Clauses (SCCs) issued or recognized by the UK, supplemented by the UK International Data Transfer Addendum (IDTA) where required.
- Additional technical and organizational measures (such as encryption in transit and at rest) where appropriate.
International data transfers: Our authentication provider, Clerk, and our error-monitoring provider, Sentry, process personal data in the United States. These transfers rely on the EU-US Data Privacy Framework adequacy decision adopted by the European Commission on 10 July 2023, the UK Extension to the EU-US Data Privacy Framework, and Standard Contractual Clauses where applicable. Clerk has self-certified to the Data Privacy Framework. All other sub-processors (Supabase, Resend, Railway, and Stripe) operate within the European Union; Vercel uses a global edge network with EU presence.
7. How long we keep your data
We retain personal data only for as long as necessary for the purposes set out in this Policy.
| Data | Retention period |
|---|---|
| Account data | For the lifetime of your account, plus up to 30 days after deletion to allow recovery and to complete deletion across all systems and sub-processors. We will complete data export requests within 30 days. |
| Encrypted Secrets | Until you delete them, or until 30 days after account deletion |
| Billing and invoice records | At least 6 years, to comply with UK tax and accounting law |
| Audit logs | [REVIEW] suggested 12 months for security and compliance review |
| Email communications and support tickets | [REVIEW] suggested 24 months |
| Marketing consent records | Until you withdraw consent, plus a reasonable period to evidence the withdrawal |
| Server access logs | [REVIEW] suggested 30–90 days |
After the retention period, data is deleted or anonymized.
8. Your rights under UK GDPR
You have the following rights in relation to your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — ask us to delete your data, subject to legal exceptions.
- Right to data portability — receive your data in a structured, commonly used, machine-readable format, and request that it be transmitted to another controller where technically feasible.
- Right to object — object to processing based on legitimate interests, including for direct marketing.
- Right to restrict processing — ask us to limit how we use your data in certain circumstances.
- Right to withdraw consent — where processing is based on consent, you can withdraw it at any time.
- Right not to be subject to automated decision-making — we do not currently make decisions about you using solely automated means.
How to exercise your rights
You can exercise your rights at any time:
- Email: hello@krypthq.com
- Data export: call
GET /api/me/exportfrom within your authenticated session to download your account data. - Account deletion: call
DELETE /api/mefrom within your authenticated session, or email us to request deletion.
We will respond within one month of receiving your request. We may need to verify your identity before responding.
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concerns first.
9. Security
We take security seriously. Our measures include:
- Encryption of Secrets at rest using industry-standard encryption.
- Encryption of all data in transit using TLS.
- Access controls and least-privilege principles for staff access.
- Audit logging of sensitive actions.
- Regular review of dependencies and infrastructure.
[REVIEW] Add specific details (e.g., AES-256-GCM, key management approach, SOC 2 status if/when achieved) once finalized.
No system is 100% secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and notify affected users without undue delay where required.
10. Children's data
Krypt is intended for software developers and businesses. The Service is not directed at children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact hello@krypthq.com and we will delete it.
11. Cookies
We use cookies and similar technologies as described in our Cookies Policy.
12. Changes to this Policy
We may update this Privacy Policy from time to time. The "Effective date" at the top of this document indicates when it was last revised. For material changes, we will notify you by email or by a notice within the Service at least 30 days before the change takes effect, where practicable.
13. Contact
If you have questions about this Privacy Policy or how we handle your data:
Email: hello@krypthq.com Data Controller: KRYPTHQ LTD Registered office: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF