Privacy Policy
Last updated: 7 July 2026
The short version. Files you send through OpaqueShare are encrypted on your device before they reach us. We store ciphertext only; we can't read your files even if we wanted to. We collect the minimum personal data required to run the service — email, an optional username, purchase records — and nothing more. You can delete your account entirely from inside the app.
1. Who we are
OpaqueShare is operated by Zihne ([PLACEHOLDER: registered company name, Companies House number, and registered UK address]), the "data controller" for the purposes of the UK GDPR and (where applicable) the EU GDPR.
Contact for privacy matters: contact@zihne.com.
2. Data we collect
Account data
- Email address — required to create an account. Stored encrypted at rest; used for verification, password reset, and account-related notifications.
-
Handle (username) — optional. Lets other users
look you up as
@yournameinstead of by email. Stored encrypted at rest. - Password hash — a one-way hash (Argon2id) of the password you chose. We never store the password itself.
- Public identity keys — cryptographic public keys that identify you to other users. These are inherently non-secret and are shared with senders when they look you up.
- MFA secret (only if you enable two-factor authentication) — the shared secret between your authenticator app and our server, plus recovery codes. Encrypted at rest.
Transfer data
- Ciphertext of your files — stored temporarily in encrypted object storage. We hold the encrypted bytes without any ability to read them: the decryption key never leaves your device (or, in link mode, is embedded in a URL fragment we never see).
- Encrypted metadata — filename, size, MIME type. Encrypted with the same per-transfer key as the file itself; we cannot read it.
- Transfer size and timing — how large a transfer is, and when it was created / downloaded / deleted. Used for storage quotas, billing, and enforcing the burn-after-read policy.
Billing data
- Google Play purchase tokens — sent to Google to verify your subscription or credit purchase. We don't see your card number, address, or payment credentials. Google Play's own privacy policy governs how they handle your payment.
- Subscription and credit balance — what plan you're on, how many prepaid credits remain, and a ledger of past purchases (needed for statutory refunds and tax records).
Operational data
- IP address — seen transiently by our servers when you make API requests, used only for rate limiting and abuse prevention. Not persistently linked to your account.
- Device push token — only if you consent to push notifications about incoming transfers. Stored linked to your account so we can notify the right device.
- Server logs — request paths, HTTP status codes, and timing. Do not contain your files, keys, tokens, or plaintext personal data; this is a design-enforced invariant.
3. Data we don't collect
- The plaintext content of your files.
- The plaintext filenames, MIME types, or file metadata.
- Your location.
- Your contacts (we never scan your address book).
- Advertising identifiers.
- Cross-app behaviour or fingerprinting data.
4. Why we process this data (lawful bases)
Under UK GDPR / EU GDPR Article 6, our lawful bases are:
- Performance of a contract (Art. 6(1)(b)) — for everything strictly required to deliver the service you signed up for: authenticating you, storing your encrypted files, delivering them to recipients, tracking your subscription state.
- Legitimate interests (Art. 6(1)(f)) — for rate limiting, abuse prevention, and integrity monitoring. We believe these are necessary to keep the service safe for everyone and don't override your fundamental rights.
- Legal obligation (Art. 6(1)(c)) — for retaining certain records (tax, refunds, moderation audit trails) where required by UK or EU law.
- Consent (Art. 6(1)(a)) — for anything optional, such as push notifications. You can withdraw consent at any time inside the app.
5. Where your data is stored
Our infrastructure runs on Amazon Web Services and Cloudflare R2. Encrypted file objects and account data are stored in European Union regions by default. Cloudflare R2 may cache encrypted objects across regions to accelerate downloads; because those objects are ciphertext with no access to the decryption keys, this is not a personal-data transfer of readable content.
When we do transfer personal data outside the UK or the EU (e.g. to Google for IAP verification, or to email providers for transactional email), we rely on the recipient's certifications and, where applicable, on Standard Contractual Clauses approved by the UK Information Commissioner's Office or the European Commission.
6. How long we keep your data
- Account data: for as long as your account exists. When you delete your account (see Account deletion) we pseudonymise the row immediately — email, handle, password hash, MFA secret, session tokens, and push tokens are wiped. We retain the user ID (a UUID), your public keys, and any moderation audit-log entries because past transfers reference them; these no longer identify you personally.
- Ciphertext of your files: deleted after the recipient acknowledges the download ("burn after read") OR after 7 days if no download occurs, whichever comes first.
- Billing records: retained for 7 years to meet UK tax record-keeping requirements.
- Server logs: rotated within 30 days.
7. Who we share your data with
We share only what's necessary for the service to run:
- Recipients you send files to — they receive the encrypted file and the metadata you provided.
- Google (Play Billing) — to verify in-app purchases and manage subscription lifecycle events. Google's privacy policy governs their handling of payment data.
- Amazon Web Services and Cloudflare — as infrastructure providers. Bound by data-processing agreements; they never see your decryption keys.
- Transactional email provider — [PLACEHOLDER: AWS SES or similar; name to be confirmed at go-live], used only to send verification emails, password resets, and other account-related notifications.
We never sell your data. We never share it for advertising purposes. We never share it with data brokers.
8. Your rights
Under UK GDPR / EU GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you. The app has a self-serve data export button (Settings → Export my data) that returns the full JSON blob.
- Rectification — correct inaccurate data (change your email or handle from Settings).
- Erasure ("right to be forgotten") — delete your account and associated data. See Account deletion.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a machine- readable format (the same data-export JSON above).
- Object — to processing based on legitimate interests.
- Withdraw consent — for anything you consented to (e.g. push notifications), at any time.
Most of these you can exercise from inside the app. For anything that isn't self-serve, email contact@zihne.com — we'll respond within 30 days.
If you believe we've mishandled your data, you can complain to your supervisory authority. In the UK that's the Information Commissioner's Office; in the EU, your national data protection authority.
9. California residents (CCPA)
If you're a California resident, the California Consumer Privacy Act gives you additional rights that are functionally equivalent to the GDPR rights above: right to know, right to delete, right to correct, right to opt out of "sale" (we don't sell), and right to non-discrimination for exercising your rights. Exercise any of these via the app's Settings screen or by emailing contact@zihne.com.
10. Children
OpaqueShare is not directed at children under 13, and we don't knowingly collect personal data from anyone under that age. If we learn that we've collected data from a child under 13, we'll delete it and terminate the account. If you believe a child has created an account, contact us.
11. Cookies
This marketing website uses no tracking cookies and no analytics. The app itself uses local storage on your device to remember your login and preferences — that data stays on your device and is never transmitted to us for tracking.
12. Changes to this policy
We'll update this page when our practices change. Material changes will be surfaced in-app or by email before they take effect. The "last updated" date at the top of this page reflects the current version.
13. Contact us
For any privacy-related question, email contact@zihne.com.