Tools/Privacy Policy

Privacy Policy

Kleopatra Neo is RGPD (GDPR) compliant and zero-knowledge by design: every cryptographic operation runs on your device, and your vault only ever reaches us as ciphertext we cannot decrypt. This policy explains, for the whole Service (website, web app, desktop apps, browser extension, sync API, email aliases, checkout), what we process, why, and your rights. Last updated September 11, 2026.

Zero-knowledge by design

1. Who is responsible (data controller)

The data controller is LEETCRAFT EI, the operator of Kleopatra Neo. For any privacy matter, contact contact@support.kleopatra.app.

2. What we can never see

Encryption, decryption, signing, verification and key generation happen locally on your device, using the open-source OpenPGP.js library and the Web Crypto API. Your vault is encrypted with AES-256 using a key derived from your secret before anything is uploaded. The following never reaches us in readable form:

  • Your private keys, master password, recovery phrase or security-key secrets
  • The decrypted contents of your vault: passwords, notes, OTP secrets
  • Any message you type, paste, encrypt, decrypt or sign
  • Session-recording content: every input and text node is masked before capture
  • Advertising profiles - we never sell or rent personal data, to anyone

3. What we process, and why

To operate the Service we process the following, limited to what each purpose requires:

  • Account data: your email address, a one-way sign-in verifier (it cannot decrypt your vault, and is not derived from your vault key), plan status
  • Your vault as AES-256 ciphertext with version metadata (we cannot decrypt it)
  • Device records for sync: an identifier, a name like 'Chrome browser', platform, last-seen time
  • Email alias routing data: alias addresses, forwarding target, message routing metadata
  • Billing data: payments go through Stripe's embedded checkout form, so card details go directly to Stripe - we never see your full card number
  • Pseudonymous product analytics: feature usage, page views without query strings, coarse device info
  • Support communications you send us (email, Discord)

The legal bases under the RGPD are:

  • Performance of a contract (art. 6(1)(b)): account data, vault ciphertext storage and sync, device records, alias routing, billing.
  • Legitimate interest (art. 6(1)(f)): security, anti-abuse and rate limiting, fraud prevention, pseudonymous product analytics to improve the Service.
  • Legal obligation (art. 6(1)(c)): accounting and tax records for payments.
  • Consent (art. 6(1)(a)) where required; you can withdraw it at any time without affecting prior processing.

4. Analytics, honestly described

We use PostHog (EU region) to understand which features are used and to fix problems. Events are sent first-party through kleopatra.app/posthog-gpdr to PostHog’s EU servers. Signed-in users are identified by a one-way pseudonymous hash of the email - never the address itself - so your devices form one timeline without your identity leaving the platform. Events carry flags, counts and coarse types only: never key material, vault contents, messages, or raw error text. Session recordings mask every input, textarea and sensitive text node before capture; we technically cannot replay what you typed. We do not use advertising trackers and we do not sell or share personal data for advertising.

5. Processors and recipients

We share data only with processors needed to run the Service, under data-processing agreements:

  • Cloudflare - API hosting, database and file storage for sync, releases and email alias routing.
  • Vercel - hosting of the website and web application.
  • Stripe - payment processing via its embedded checkout form; card data goes directly to Stripe and never touches our servers.
  • Brevo - sending transactional email (verification codes).
  • PostHog (EU) - pseudonymous product analytics, as described above.

We may also disclose data where required by law or to protect the rights, safety and integrity of the Service, and in connection with a merger or acquisition, under confidentiality.

6. Where data lives, and transfers

We favor EU processing: analytics stays in the EU, and our infrastructure providers process data in or with appropriate safeguards for the EU. Where a processor transfers data outside the EEA, the transfer is covered by an adequacy decision or Standard Contractual Clauses. Your encrypted vault is ciphertext wherever it is stored.

7. How long we keep data

  • Verification codes: 10 minutes.
  • Sessions: 30 days of validity; revoked sessions are deleted.
  • Account, vault ciphertext, device and alias data: for the life of the account.
  • Encrypted vault backups (from resets and password changes): kept so a lost vault can be restored with its old secret; deleted with the account.
  • Billing records: as long as tax and accounting law requires.
  • Analytics: per PostHog’s retention, pseudonymous throughout.

When you delete your account, associated personal data is deleted or anonymized without undue delay, except what we must keep by law.

8. Security

Beyond the zero-knowledge architecture itself (client-side AES-256; your secret is split on your device into a vault key that never leaves it and a separate sign-in credential, of which we store only a one-way hash), we use TLS everywhere, rate limiting, least-privilege infrastructure and EU-region processing. No system is perfectly secure; if a breach affects your rights, we will notify you and the competent authority as the RGPD requires.

9. Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time. Exercise them at contact@support.kleopatra.app - we answer within one month. You can also lodge a complaint with your supervisory authority; in France, the CNIL (cnil.fr). Note that we cannot read, and therefore cannot hand over or modify, the contents of your encrypted vault - you can export it yourself from the app at any time.

10. Local storage and cookies

The app keeps your keys and vault in your browser’s local storage so they persist between visits, on your device only. We use no advertising cookies. PostHog stores a pseudonymous identifier to avoid counting the same visitor twice; it is never linked to your keys or messages. Blocking it does not break the app.

11. Children

The Service is not directed at children under 16, and we do not knowingly process their data.

12. Changes to this policy

We will update this policy as the Service evolves and change the date at the top. For material changes we will notify you in the app or by email before they take effect.

13. Contact

Privacy questions or requests: contact@support.kleopatra.app, or reach the community on Discord.