Back to home

Privacy Policy

Last updated : 2026-07-21

This policy describes how we collect, use and protect your personal data on the QubKey website and related cloud services (account, vault sync, temporary links, and user-to-user sharing).

Data controller

The data controller is the QubKey project (open source project, no company structure to date). Contact: sirrlabs@protonmail.com or via the site form.

Data collected

We collect: (1) Beta form: email address and optional message; (2) Visits and analytics: IP address, page path, referrer, browser language, screen resolution, device and browser type (user-agent); (3) Security logs: site access and blocks are recorded for attack detection and site security; (4) Blog likes: a pseudo-anonymous device identifier (stored locally only after a “Like” click) to prevent duplicate votes without an account; (5) QubKey account (when you register): email, password hash, account status, sessions/devices, and technical vault identifiers for optional sync; (6) Temporary shares and user-to-user share envelopes: service metadata and encrypted payloads as described in the sections below.

Purposes

Beta form data is used for beta registration and communications (launch, news). Visit data measures audience and improves the site. Blog likes record your vote and prevent duplicates without an account. Security logs protect the site and support incident investigation. QubKey account and sync data authenticate you, sync encrypted vault updates across your devices, and operate sharing features. Temporary-link and user-to-user share metadata operate those features and support security and abuse prevention.

Legal basis

Form and communications processing: consent. Visit analytics: consent (via cookie banner). Blog likes: legitimate interest (preventing duplicate votes, strictly necessary for the requested service, Art. 6.1.f GDPR). Security logs: legitimate interest (security of systems and networks, Art. 6.1.f and 32 GDPR).

Retention period

Form data: until unsubscribe or erasure request. Visit data: 12 months. Security logs: 6 to 12 months depending on security needs.

Your rights

You have the right to access, rectify, erase, object, restrict processing and portability of your data. You may withdraw your consent at any time. To exercise these rights: sirrlabs@protonmail.com.

QubKey account and vault sync

If you create a QubKey account (desktop app or My space): we process your email address, a password hash, email verification and password-reset tokens (hashed, time-limited), session and device records, and technical identifiers for cloud-linked vaults (vault UUID, sync timestamps, counters/digests). Vault sync stores encrypted operation payloads — we cannot read entry titles or secrets in plaintext. The master password never leaves your devices. For a plain-language summary, see the documentation page “What the servers can see” under Security.

What the servers can see (documentation)

Sharing with another QubKey user

When you send an entry to another QubKey user, the sync service stores an encrypted package for the recipient, plus service metadata: sender and recipient account identifiers (and related emails), dates, status (pending, accepted, revoked), and granted rights. We cannot read the shared entry contents. There is no dedicated administration screen that lists these envelopes; metadata exists in technical storage as needed to deliver and revoke shares.

What the servers can see (documentation)

Temporary secure links (web tools and app)

For temporary secure links: we process encrypted share payloads, link identifiers, expiration dates, view counters, status, optional creator email when tied to a QubKey account, and an IP fingerprint (hash) for security. We do not store the full decryption key in a form that lets us read the secret (part of the key stays in the URL # fragment on the client). The administration “Secure shares” area can show metadata (creator email, status, views), not plaintext content. On account deletion, active shares are removed according to product rules; residual metadata may be retained for a limited period then purged. You may exercise your rights (access, rectification, erasure, objection) via sirrlabs@protonmail.com.

What the servers can see (documentation)

Contact

For any questions or to exercise your rights: sirrlabs@protonmail.com.

Complaint

You may lodge a complaint with a supervisory authority (in France: CNIL, cnil.fr).