Privacy

Privacy Policy

What we collect, what we genuinely cannot see, how long we keep it, and the awkward bits most policies bury.

Version 1.0 · 17 July 2026 · Early access

The short version. Your document contents are encrypted in your browser before they reach us, so we cannot read them and could not hand them over if compelled. We can see the surrounding details: your email, the title you typed, the recipient's name and number, and the activity log. We do not sell anything, we run no advertising or analytics, and there are no third-party trackers on any page.

Who we are

SightSealer is an early-access product operated by its founder from the United Arab Emirates. It is not yet a registered company. That matters to you, so we are saying it rather than implying a corporate entity that does not exist. Contact: hello@sightsealer.com.

What we cannot see

When you create a protected send, your browser generates a random encryption key and encrypts the content with AES-256-GCM before uploading. The key travels only in the part of the link after the # symbol, which browsers never transmit to any server.

The practical consequence: the file contents and secret text are opaque to us. Not "we promise not to look" — we hold ciphertext and no key. If we lost the entire database tomorrow, or a court ordered us to produce your document, we could produce only unreadable bytes.

What we do collect

DataWhyLawful basis
Your emailTo create and secure your accountContract
Send titleSo you can identify your own sends. Not encrypted — we can read it.Contract
Recipient name and mobileYou type these so the link can be watermarked and identity-boundLegitimate interests
Encrypted contentTo deliver it. Unreadable to us.Contract
Activity logOpens, duration, blocked prints/copies, IP address, browser user-agentLegitimate interests
Access code hashVerification. Hashed with PBKDF2; the code itself is not stored.Contract

We do not use cookies for tracking. The only browser storage we use is your login session and, on your own device, the encryption keys for sends you created.

The awkward part, stated plainly.

When you enter a recipient's name and mobile number, you are giving us another person's personal data, and that person has not agreed to anything with us. Their name and number are then burned into the watermark and recorded in the activity log, along with their IP address when they open the link.

By using SightSealer you confirm you have a lawful basis to share that person's details with us for this purpose. If you are in the UK or EU, you are the data controller for that information and we are your processor. We are telling you this because most products in this category quietly make you responsible without mentioning it.

Recipients: what happens when you open a link

If someone sent you a SightSealer link, we record: the name and number you type in, your IP address, your browser's user-agent, when you opened it, how long you viewed, and any blocked action (a print attempt, a copy attempt, leaving the window). The sender sees all of this. That is the entire point of the product, and the viewing page tells you so before you open anything.

We do not build a profile of you, we do not track you across sites, and we do not contact you.

How long we keep it

We do not currently run automatic deletion of old sends. If that matters to you, delete them yourself in the dashboard.

Who else touches your data

We use two subprocessors and no others:

No advertising networks, no analytics, no session recording, no data brokers. Nothing is sold, ever.

Where your data lives

Our database and file storage are hosted in Singapore (AWS ap-southeast-1) and the site is served from Cloudflare's global network. If you are in the UK or EU, this means your data is transferred outside the UK/EEA. Content is encrypted before it leaves your browser, which substantially limits what that transfer exposes, but the metadata described above is not encrypted. If that is unacceptable for your use case, do not use the product for that data.

Your rights

Depending on where you live you may have rights to access, correct, delete or export your data, and to object to processing. Email hello@sightsealer.com and we will action it. There is no form and no queue; it is currently one person reading the inbox.

One genuine limitation: we cannot give you the contents of your own sends, because we cannot decrypt them. Only the link holds that key.

Security, honestly

What we do: content encrypted in your browser; TLS everywhere; encrypted storage; row-level database rules so accounts cannot read each other; access codes hashed with PBKDF2 and rate-limited; strict content security policy; no third-party scripts.

What we do not have: SOC 2, ISO 27001, an independent penetration test, or a bug bounty. We are early access and we will not pretend otherwise. If your organisation requires those before onboarding a vendor, we do not meet that bar today.

If you find a security problem, email hello@sightsealer.com. We will not threaten you.

Children

SightSealer is not for anyone under 18 and we do not knowingly collect their data.

Changes

If we change this materially we will update the version and date at the top. There is no mailing list to notify yet.

This policy is written to be honest and readable rather than to be exhaustive legal cover. It has not been reviewed by a lawyer. See also our Terms of Use.