How we collect, use, and protect your information.
Last revised: July 11, 2026
This privacy policy describes how Privatt Inc. ("Privatt", "we", "us") collects, uses, discloses, and retains personal information when you use privatt.com and our products: the encrypted Vault, Send (when available on your account or environment), Kept (when available), our website, and related support and billing services (together, the "Service").
We may update this policy from time to time. When we do, we revise the date at the top of this page. Material changes will be reflected in the published policy. We encourage you to review it when you use the Service. Questions about personal information should go to our person in charge of the protection of personal information at privacy@privatt.com (see below).
Privatt Inc. is a company based in Quebec, Canada. We operate under the laws of Quebec and Canada, including Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25, and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies.
Depending on what you use, we may process personal information in connection with:
Some modules may be turned on or off by configuration. This policy describes how those products handle personal information when they are available to you.
We collect information you give us directly, including:
We do not ask for a postal mailing address as part of ordinary account registration. If you voluntarily include an address or other details in a support message, we process them only to respond to you.
Vault files are always encrypted. What differs is who holds the key. You choose your mode in account settings.
Your content key is derived from a passphrase that only you know. We do not receive or store that passphrase. We store ciphertext (and, for Two-key vault, an outer server-side wrap that still cannot open your content without your key). In these modes we cannot read your vault contents. If you lose both your passphrase and recovery key, the data cannot be recovered by you or by us.
We hold the encryption key so you can sign in from any device without a separate vault passphrase. This mode is not zero-knowledge. We can process file plaintext on our systems for limited, purpose-bound operations such as malware scanning and delivering downloads. Before you enable this mode we require an explicit, versioned consent in settings. We keep an audit trail of plaintext-access events (what kind of access occurred and when, not the file contents) for 24 months, then delete those events.
When Send is available, messages are encrypted in your browser before they reach us. We store ciphertext, key-wrap material we cannot use without the recipient's passphrase proof, and operational metadata (for example expiry time, view counts, and lockout state). We never store the message passphrase.
If you choose to notify a recipient by email, we store that recipient address encrypted at rest and only while the message remains openable. We scrub it when the message is revoked, expires, or reaches its view limit. Transactional email for Send is delivered through our email provider with open and click tracking disabled.
When you use Kept, we process business and personal information you enter into your books: contacts, invoices, bills, expenses, payments, tax configuration, journal data, bank import results, and related settings. That information can include third-party personal information (for example customer or vendor names and emails). You are responsible for having a lawful basis to record it.
Receipt and supporting-document attachments are encrypted with a Kept-managed key that is separate from your vault passphrase. During upload we may briefly handle plaintext in memory to validate type, scan for malware, and generate a server-side thumbnail. We serve originals only as downloads (not inline browser rendering of untrusted files). Malware-scan failures fail closed: files are not downloadable until a clean scan result is recorded.
Account deletion permanently destroys Kept books and attachments only after you complete a current Kept export of your books. The generic account data-export tool includes Kept configuration and counts; full transactional books are provided through the Kept export path so you can keep records your business may still need. Until that export is completed, account deletion is blocked for accounts that still hold Kept transactional records.
When you use the Service we automatically collect:
We do not use web beacons or tracking pixels in our emails to measure marketing campaign effectiveness. Outbound mail is configured so open and click tracking are disabled at the provider.
Account sign-in is email and password only. We do not offer social login. If you connect Google Drive or OneDrive as a vault storage backend, we receive OAuth tokens and limited account identifiers from those providers solely to store and retrieve your vault files in the folders our app is permitted to use. Those integrations are optional and described under "Google User Data" and "Microsoft User Data" below.
We use personal information to:
We do not sell personal information. We do not use vault file contents, Send message contents, or Kept book contents to train generalized or large language models, or to serve third-party advertising.
We keep website visit records for 90 days (truncated IP, as described above). Application logs are kept for approximately two weeks. Detailed metered billing usage events are deleted after 13 months. Managed-vault plaintext-access audit events are deleted after 24 months.
We retain subscription and billing records (plan history, invoices, tax-related records, and related audit events) for as long as necessary to operate the Service and to meet legal, tax, accounting, audit, and fraud-prevention obligations. After account deletion, a limited set of those records may be detached from your account and stripped of directly identifying information where feasible, then kept only as long as those obligations require (internally scheduled up to seven years for tax and similar duties).
When you delete your account, we cancel any active subscription and permanently destroy vault contents, encrypted files, Send messages associated with the account, connected cloud-storage authorizations, Kept books (after a required current Kept export), and account credentials, subject to the limited retained billing and audit records above.
Disaster-recovery backups: We do not currently operate a separate off-host disaster-recovery backup system for customer vault data beyond the primary production storage and database we use to run the Service. When you delete data or your account, we remove it from our active systems according to the product rules above. If we later introduce encrypted off-host backups, we will update this policy before claiming a specific backup retention window, and we will design lifecycle deletion so restored systems cannot silently revive deleted personal information without re-applying those deletions.
We may share personal information as follows:
We may also share aggregated or anonymized information that does not identify you.
Our services include an optional Google Drive integration that lets you store your encrypted Privatt vault files in your own Google Drive account. When you choose to connect a Google account, we use Google's standard sign-in to request a single Google Drive permission, the drive.file scope, which grants access only to the specific files our application creates in your Drive. We cannot see or access any other files in your Google Drive.
Before any file is uploaded to Google Drive, Privatt encrypts it according to your vault encryption mode. When you use a device-held mode, encryption happens in your browser using keys derived from your passphrase, which we do not store. Google receives ciphertext for those uploads.
The Google account tokens we receive (used to upload, download, and manage your vault files on your behalf) are encrypted at rest in our database, and we use them only to perform actions you have initiated within our services.
Our use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
You can disconnect Privatt from your Google account at any time through your account settings in our services. You can also revoke our access directly from Google at myaccount.google.com/permissions. Revoking access does not delete files already stored in your own Google Drive account; those files remain in your control.
Our services include an optional OneDrive integration that lets you store your encrypted Privatt vault files in your own OneDrive account. When you choose to connect a Microsoft account, we use Microsoft's standard sign-in to request a single OneDrive permission, Files.ReadWrite.AppFolder, which grants access only to a dedicated application folder that Privatt creates in your OneDrive. We cannot see or access any other files in your OneDrive.
Before any file is uploaded to OneDrive, Privatt encrypts it according to your vault encryption mode. When you use a device-held mode, encryption happens in your browser using keys derived from your passphrase, which we do not store. Microsoft receives ciphertext for those uploads.
The Microsoft account tokens we receive (used to upload, download, and manage your vault files on your behalf) are encrypted at rest in our database, and we use them only to perform actions you have initiated within our services.
Our use of information received from Microsoft Graph APIs adheres to the Microsoft APIs Terms of Use and applicable Microsoft Identity Platform terms. Specifically, we do not:
You can disconnect Privatt from your Microsoft account at any time through your account settings in our services. For a personal Microsoft account, you can also revoke our access directly at account.live.com/consent/Manage. For a work or school account, contact your administrator or visit the My Apps portal at myapps.microsoft.com. Revoking access does not delete files already stored in your own OneDrive account; those files remain in your control.
When you purchase a subscription, your payment is processed by our third-party payment processor, Stripe, Inc. Your payment card details are provided by you directly to Stripe and are handled under Stripe's privacy policy; we do not collect or store your card number. We store limited billing records, such as your subscription and invoice history and a reference that links your account to your Stripe customer record, which we use to provide the Service, prevent fraud, and meet our tax and accounting obligations. See "Retention" above for how long we keep these records, including after you delete your account.
We take reasonable technical and organizational measures to help protect personal information from loss, theft, misuse, and unauthorized access, disclosure, alteration, and destruction. Those measures include encryption in transit, encryption at rest for sensitive fields and stored files as described above, access controls, monitoring, and malware scanning on applicable upload paths. No method of transmission or storage is perfectly secure.
Most browsers accept cookies by default. You can usually set your browser to remove or reject cookies. If you reject essential cookies, sign-in and other authenticated features of the Service will not work correctly. We do not use non-essential third-party analytics or advertising cookies on the Service.
If we send promotional emails, you may opt out using the instructions in those emails. We may still send non-promotional messages about your account, security, or billing.
Privatt Inc. is based in Quebec, Canada. Files you store on Privatt-hosted storage are kept in a data center located in Quebec. Some service providers process limited personal information outside Quebec: subscription payments are processed by Stripe, Inc. in the United States, and transactional emails (such as account and security notifications) are delivered through SendGrid (Twilio Inc.) in the United States. Where you connect Google Drive or OneDrive, your encrypted files are stored in your own account with those providers, wherever they keep it.
Before we entrust personal information to a service provider outside Quebec, we assess whether the information will receive adequate protection, taking into account the sensitivity of the information, the purposes for which it will be used, and the contractual and technical measures that apply to it. By using the Service, you acknowledge that your information may be processed in and transferred to Canada and other countries, including the United States.
Subject to applicable law, you have the right to:
You can change your email or password, export much of your account information, and delete your account from settings. If you use Kept, complete a current Kept export before account deletion so you retain your business records; deletion is blocked until that export is available. To exercise any of these rights, or for any question about how we handle your personal information, contact the person in charge of the protection of personal information (below). If you are not satisfied with our response, you may file a complaint with the Commission d'accès à l'information du Québec (CAI).
In accordance with Quebec's Law 25, Privatt Inc. has designated a person in charge of the protection of personal information. You can reach the Person in Charge of the Protection of Personal Information at privacy@privatt.com for any question or request concerning your personal information or this policy.
For general questions about this privacy policy, contact us at support@privatt.com. For requests or questions specifically about your personal information (access, correction, deletion, or portability), please contact our person in charge of the protection of personal information at privacy@privatt.com.
We take your privacy seriously. If you have any concerns, please get in touch.
Contact Us