Privacy Policy
What Offkeep collects, what end-to-end encryption puts permanently out of our reach, and the choices you keep.
Last updated 27 August 2026
Who we are and what this policy covers
This Privacy Policy explains what personal data Offkeep SAS, a French société par actions simplifiée with registered office at 2E Fond Face, 22 avenue Laplace, 94110 Arcueil, France (SIRET 107 024 440 000 11) (“Offkeep”, “we”, “us”) collects, why we collect it, and the rights you have over it. We are the data controller for the personal data described here.
It applies to our website (offkeep.com), our web application (offkeep.com/app), and our desktop and mobile applications, together “the Service”, and is incorporated into our Terms of Service.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and, where applicable, the French Data Protection Act.
What we cannot see
Offkeep is end-to-end encrypted. Your files are encrypted on your device before upload, and so are their names; the encryption keys are derived on your device and never leave it. What we store is ciphertext — encrypted data with no meaning without your keys.
We cannot read, search, scan, index, or analyse the contents of your files, their names, or their structure. We cannot access shared content either: keys for shared folders are sealed to each member’s public key and only the sealed copies are stored, and shared links are protected by a random token that only the link holder can use. In neither case do we hold the means to read the content. This is an architectural limit, not a policy that could change.
One consequence matters enough to state plainly: if you lose your password and your recovery key, we cannot recover your files. There is no back door, and we will not build one.
Data we collect
We collect only the personal data the Service needs to run:
- Account data — the email address you sign up with, your name, your account identifiers, and your account preferences. Required to provide the Service under our contract with you.
- Authentication data — a password verifier (never your password itself) and, depending on the option you choose, the salt and wrapped copy of your encryption key and an encrypted recovery blob you can export. Required so you can sign in, provision new devices, and regain access to your account.
- Usage and device data — the amount of storage and downloads you use, device names and types, app versions, IP addresses (and the approximate location derived from them), and timestamps of activity. Required for billing and synchronisation, and processed for our legitimate interest in keeping the Service secure and functioning.
- Contacts — the names, email addresses, and phone numbers you choose to save in the Service for sharing. Stored because you asked us to.
- Billing data — payment method, billing address, invoices, and transaction history, handled together with our payment provider Airwallex. Required under our contract with you and to comply with accounting and tax law.
- Anti-abuse data — signup fingerprints and account-suspension history, kept to prevent fraud and abuse of the Service.
- If you contact support, send feedback, or file a bug report, we also process what you send us — your messages and any diagnostics — to answer your request.
Why we process your data
We process personal data only on a legal basis recognised by the GDPR:
- Performance of a contract — account, authentication, usage, and billing data, because the Service cannot run without them.
- Legitimate interest — security logs, abuse prevention, and service improvement, weighed against your interests and rights.
- Legal obligation — invoices, transaction records, and audit records, which French accounting and tax law require us to keep.
- Consent — only where we ask for it specifically, for example for optional communications. You can withdraw consent at any time, as easily as you gave it.
What we do not do with your data
We do not use your data for advertising, profiling, or selling it to anyone. We do not run analytics on the Service. There is nothing to monetise: we cannot read your files, and we do not sell what we can see.
Cookies and local storage
The website and web application use only strictly necessary cookies and local storage: an authentication session, security tokens, and your theme and layout preferences. They make the Service work; they do not track you.
We do not run third-party advertising or analytics cookies, and we do not use cross-site trackers. Because there are no optional cookies, there is nothing to opt out of beyond your browser’s built-in controls.
Who else touches your data
We use a small number of processors, each bound by a data-processing agreement, to operate the Service:
- Cloudflare — content delivery, DNS, and edge compute (our backend runs on Cloudflare Workers, and our site is hosted on Cloudflare Pages). Receives requests, IP addresses, and edge logs.
- Turso — the database that stores account metadata, billing, and configuration. Receives the metadata described above, never file contents.
- MEGA S4 (S3-compatible object storage) — stores the ciphertext of your files, audit records, and invoices. Receives encrypted blobs and documents only.
- Airwallex — payment processing. Receives the payment details for the transactions you make.
- Pingram — delivery of transactional email and SMS, such as login codes and invoice notifications. Receives the email address or phone number and the message to deliver.
- Google, Apple, and Facebook — only if you choose to sign in with one of them, in which case they verify your identity. Apple and Google also operate the app stores through which you may install our apps and buy subscriptions.
None of these processors receives your encryption keys or unencrypted file contents. A complete, current list is available on request at hello@offkeep.com.
Where your data lives
Your ciphertext is stored with our object-storage provider, MEGA S4, in data centres in the European Union (the Netherlands), and we do not move it without telling you. Account metadata is processed in data centres in the European Union and the United States.
Where a processor transfers personal data outside the European Economic Area, the transfer is covered by a European Commission adequacy decision or by standard contractual clauses. You can ask for a copy of the applicable safeguards at hello@offkeep.com.
How long we keep data
- Account and usage data — until your account is closed, then deleted within 30 days, except where the law requires longer.
- Ciphertext — deleted within 30 days of account closure. Files you delete are kept restorable for 7 days on the metered option or 30 days on a paid plan, then permanently removed, including from backups within 90 days.
- Frozen accounts — if an account stays frozen with an unpaid invoice, the stored content is deleted 30 days after the freeze, as described in our Terms of Service.
- Billing records, invoices, and audit records — 10 years, as French accounting and tax law requires.
- Security and request logs — up to 90 days.
When a retention period ends, the data is deleted or irreversibly anonymised. Even after your account is closed, we keep the financial and audit records the law requires us to keep, in a form that no longer gives access to your content.
Your rights
You have the right to:
- access the personal data we hold about you and receive a copy of it;
- rectify inaccurate or incomplete data;
- erasure (“right to be forgotten”) of your personal data, subject to legal retention obligations;
- restrict processing in the circumstances set out in the GDPR;
- data portability — receive the personal data you gave us in a structured, machine-readable format;
- object to processing based on legitimate interest;
- withdraw consent at any time, where processing is based on consent.
Exercising your rights
You can exercise these rights by emailing hello@offkeep.com or, where available, from your account settings. We answer within one month, as the GDPR requires. If you are not satisfied with our answer, you can lodge a complaint with the French data protection authority, the CNIL (cnil.fr).
One limit is architectural: because we cannot decrypt your files, access and portability over file contents are provided in encrypted form or through your own devices. We can give you everything we hold — we simply cannot read what we cannot decrypt.
Government and legal requests
If a court or authority asks us for data, we review the request against the law and respond only where legally required. What we hold is limited: account metadata, usage data, and billing records. We never hold decryption keys, so we cannot comply with a request to decrypt or hand over file contents — and we will say so.
We notify you when we receive a request concerning your account, unless the law prohibits it. We do not build back doors, and we will tell our users if we are ever compelled to weaken the encryption the Service relies on.
Security
Your files are encrypted on your device with ChaCha20-Poly1305, an authenticated-encryption algorithm, in 8 MB chunks; each chunk carries an authentication tag, so any tampering or corruption is detected and the file fails closed when it is decrypted. Your password (or recovery passphrase) is run through the memory-hard scrypt key-derivation function, and the server stores only the salt and a wrapped copy of your key — never the key itself.
Data travels over TLS 1.3, and stored ciphertext is additionally encrypted at rest by our storage provider. Because encryption is authenticated end to end, integrity is verified as part of decryption — there is no separate hashing step, and corrupted or tampered-with data never opens.
Our clients are open source, and we are committed to commissioning independent third-party security audits, which we will publish. If a data breach affects your personal data, we will notify you and the relevant authorities as the GDPR requires.
Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, contact us at hello@offkeep.com and we will delete it.
Changes to this policy
If we make material changes to this Privacy Policy, we will notify you by email and in the Service at least 30 days before they take effect and update the “Last updated” date at the top of this page. Continued use of the Service after the effective date means you accept the updated policy.
Contact
Questions, requests, or complaints: hello@offkeep.com. A complete list of our legal documents is on our Legal page.
Questions about this document? Get in touch.
A complete list of our legal documents is on the Legal page.