Privacy

Privacy Policy

Effective: July 29, 2026Last updated: July 29, 2026

VanishKey is a one-time secret-sharing service operated by KPT Industries, LLC ("KPT," "we," "us," or "our"), 4700 S. Mill Avenue, Tempe, AZ 85282. This policy explains how we handle information when you use vanishkey.com and its related services (the "Service").

1. Who we are and scope

This policy applies to visitors, people who create or reveal a one-time link, recipients of direct-email links, and people who contact support. VanishKey is designed for temporary delivery, not long-term storage or account-based recordkeeping.

2. Information we handle

2.1 Encrypted secret data

When you create a link, your browser sends us a random secret identifier, an initialization vector, ciphertext produced with AES-256-GCM, and a one-way verifier for an independent reveal capability. The plaintext secret is encrypted before upload. The decryption key and reveal capability appear after the # in the complete URL; URL fragments are not sent to our server in a normal browser request.

2.2 Direct-email delivery

If you choose "Email the one-time link," you provide a recipient email address and explicitly send the complete one-time URL—including its fragment key—to VanishKey and our email provider, Mailgun, for delivery. After Mailgun accepts a message for delivery, VanishKey keeps a normalized record of the recipient address, when it was first and most recently accepted, and the number of accepted submissions. We do not store the complete one-time URL, secret content, ciphertext, or fragment key with that email record. Mailgun processes the message and delivery metadata under its own service and retention practices. Email tracking, open tracking, and click tracking are disabled for these messages.

2.3 Support communications

The support form collects the name you choose to provide, your email address, and your message. These details are delivered to KPT's support mailbox through Mailgun and used to respond to your request. Do not paste a password or other secret into the support form; create a VanishKey link if support asks you to share sensitive information.

2.4 Technical and security data

Our hosting systems may automatically process an IP address, browser and device information, request path, timestamps, response status, and error or performance logs. The decryption fragment is not part of the request path and is not included in ordinary server access logs. For direct-email and support abuse prevention, VanishKey keeps short-lived, keyed one-way fingerprints derived from IP addresses and, for direct email, recipient addresses.

3. How one-time secrets work

  • Encryption and decryption occur on the sender's and recipient's devices.
  • The server stores ciphertext and its initialization vector in Redis with a fixed maximum lifetime of one hour.
  • Opening the complete link loads a confirm-to-reveal page. Only after the recipient chooses "Reveal once" does the browser prove possession of the independent reveal capability and atomically retrieve and delete the encrypted server copy. The AES decryption key is not sent to the reveal API. Agent clients that call the reveal API directly consume immediately.
  • An unopened secret is automatically deleted when its one-hour time limit expires.
  • We cannot recover an expired, revealed, deleted, or lost secret or decryption key.

4. How we use information

We use the limited information described above to:

  • create, deliver, reveal, and delete one-time secrets;
  • send a link when a sender explicitly chooses direct email;
  • answer support requests;
  • protect the Service from spam, abuse, and security threats;
  • diagnose errors and maintain availability; and
  • comply with legal obligations.

We do not use secret content for advertising, profiling, model training, or product analytics.

5. How we share information

5.1 Service providers

We use service providers for hosting, infrastructure, Redis storage, security, and transactional email. They may process information only as needed to provide those services to us, subject to their contractual and legal obligations.

5.2 Legal disclosures

We may disclose information when required by law or legal process, or when we reasonably believe disclosure is necessary to protect the rights, safety, and security of KPT, our users, or the public. Where legally permitted, we will use reasonable efforts to notify affected users.

5.3 Business transfers

Information may transfer as part of a merger, acquisition, financing, reorganization, or sale of assets, subject to this policy's commitments until a replacement policy takes effect.

6. No sale, advertising, or AI training

We do not sell personal information, share it for cross-context behavioral advertising, use third-party advertising cookies, or use secret content to train AI models. Because we do not sell or share personal information for targeted advertising, there is no sale or advertising-sharing opt-out required for the current Service.

7. Your rights and choices

We extend rights to access, correct, delete, and receive a portable copy of personal information we can reasonably identify and verify as yours, regardless of where you live. Submit a request through the Support link below or email support@kptindustries.com.

VanishKey has no user accounts, and encrypted payloads are not indexed by a person's name or email. We cannot search, identify, decrypt, export, or restore secret content based on your identity. A sender or recipient may simply allow an unopened link to expire; a revealed link is already deleted.

We may verify a privacy request using your email address and reasonable additional information. You may use an authorized agent where applicable. We will not discriminate against you for exercising a privacy right.

8. US state privacy disclosures

Depending on where you live and whether a particular law applies to KPT, you may have rights to know, access, correct, delete, or obtain a portable copy of personal information; to opt out of sale, targeted advertising, or certain profiling; to limit some uses of sensitive information; and to appeal a denied request. VanishKey does not sell personal information, use it for targeted advertising, or make decisions producing legal or similarly significant effects through profiling.

California notice at collection

CategoryExamplesPurposeTypical retention
IdentifiersIP address; email and name if providedSecurity, direct email, and supportSee Section 9
Internet activityRequest, browser, device, and log dataOperate, secure, and diagnose the ServiceGenerally up to 90 days
CommunicationsSupport message and direct-email delivery dataRespond and deliver requested messagesSee Section 9
Electronic contentCiphertext and initialization vectorOne-time secret deliveryOne hour maximum or first reveal

We do not sell or share these categories for advertising. We treat Global Privacy Control signals as applicable, though there is currently no sale or advertising sharing to opt out of. We do not respond separately to legacy "Do Not Track" signals because VanishKey does not use behavioral advertising trackers.

9. Data retention

DataRetention
Encrypted secret payloadUntil the complete link is first opened or one hour after creation, whichever comes first
Decryption keyNot stored by VanishKey; handled transiently for direct email if the sender chooses that feature
Rate-limit hashesApproximately 15 minutes
Direct-email recipient recordWhile the direct-email service operates, unless earlier deleted in response to a verified privacy request or as required by law
Support communicationsAs needed to resolve the request and for legitimate security, fraud-prevention, or legal purposes
Operational logsGenerally up to 90 days, or longer when needed to investigate a security incident or meet legal obligations

10. Data security

VanishKey uses encryption in transit, browser-side AES-256-GCM encryption, a 256-bit random link identifier, authenticated binding between each ciphertext and its exact link, independent 256-bit encryption and reveal capabilities, proof-gated atomic retrieval and deletion, short retention, access controls, and abuse-prevention measures. No transmission or storage method is completely secure, and we cannot guarantee absolute security. Anyone with the complete one-time URL can reveal the secret, so send it only through a channel you trust.

11. Cookies and tracking

VanishKey currently does not use cookies, advertising trackers, or behavioral analytics. Our infrastructure still receives the technical request data described in Section 2.4. If our cookie practices materially change, we will update this policy and provide any notice or choices required by law.

12. Children's privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact support and we will take appropriate steps to delete it.

13. International users

The Service is operated from the United States. If you use it from another country, information may be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.

14. Changes to this policy

We may update this policy as the Service or applicable law changes. We will post the revised policy here, update the "Last updated" date, and provide additional notice where required by law.

15. Contact us

KPT Industries, LLC
4700 S. Mill Avenue
Tempe, AZ 85282

Email: support@kptindustries.com