Privacy Policy
Last updated: 23 July 2026
This policy explains what personal data Tracston Secrets (“the Service”, sec.tracston.com) processes, why, and the rights you have. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR) and the UK GDPR.
1. Who we are (Data Controller)
Tracston is the data controller for personal data processed through the Service. For any privacy request or to reach our data protection contact, email privacy@tracston.com.
2. The secret content you share
A shared secret is encrypted before it is stored (envelope encryption with a per-secret key). We cannot read its plaintext. Once a secret is viewed, burned, or expires, its ciphertext and key material are cryptographically deleted so the content can no longer be recovered — including from us. Do not place data in a secret that you are not permitted to share.
3. Personal data we process
- Account data (registered users): email address, hashed password, and authentication factors.
- Secret metadata: creation/expiry times, view state, and a hashed IP of the creator — never the secret’s content.
- Security & audit logs: event type, timestamp, truncated/hashed IP, and user-agent category, to prevent abuse and secure the Service.
- Cookies: a session cookie and a CSRF token for signed-in users. We do not use advertising or cross-site tracking cookies.
4. Lawful bases (GDPR Art. 6)
- Contract — to provide the Service you request (creating and delivering secrets, accounts).
- Legitimate interests — securing the Service, preventing abuse, and maintaining audit records, balanced against your rights.
- Legal obligation — where we must retain limited records to comply with law.
- Consent — where separately requested (e.g. optional communications); you may withdraw it at any time.
5. Retention
Secret content is retained only until it is viewed or expires, then it is cryptographically deleted. Minimal, content-free audit metadata may be retained to operate and secure the Service. Account data is retained while your account is active and deleted on request or after prolonged inactivity.
6. Your rights (GDPR Art. 15–22)
- Access a copy of your personal data;
- Rectify inaccurate data;
- Erase your data (“right to be forgotten”);
- Restrict or object to processing;
- Data portability;
- Withdraw consent where processing relies on it;
- Lodge a complaint with your supervisory authority (e.g. your national Data Protection Authority).
To exercise any right, email privacy@tracston.com. We respond within one month as required by GDPR.
7. International transfers
Where data is processed outside the EEA/UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
8. Security
We apply envelope encryption, per-secret keys, atomic one-time retrieval, hashed-IP-only audit logging, and strict controls that keep secret plaintext out of logs and URLs. No system is perfectly secure; report concerns to security@tracston.com.
9. Changes
We may update this policy; material changes will be reflected by the “Last updated” date above. Questions? See Support.

