Last updated: February 16, 2026
SealedFor ("we," "us," "our") operates the website sealedfor.com and is the data controller responsible for your personal data. For questions, contact support@sealedfor.com.
SealedFor collects only data strictly necessary to provide the service:
| Data | Purpose | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Sender email address | Edit token delivery, Dead Man's Switch check-ins, token recovery | Contract performance (Art. 6(1)(b)) |
| Sender display name | Shown in delivery emails to recipients | Contract performance (Art. 6(1)(b)) |
| Recipient email address(es) | Capsule delivery only — max 10 per capsule | Legitimate interest (Art. 6(1)(f)) |
| Capsule files (videos, photos, audio, documents) | Encrypted at rest with AES-256-GCM — stored only for delivery | Contract performance (Art. 6(1)(b)) |
| Capsule text message | Stored as plaintext in database — not encrypted in either mode | Contract performance (Art. 6(1)(b)) |
| Payment data | Processed entirely by Paddle (Merchant of Record) — we store only Paddle transaction IDs | Contract performance (Art. 6(1)(b)) |
| IP address | Rate limiting and abuse prevention only — not stored persistently | Legitimate interest (Art. 6(1)(f)) |
| Locale preference | Language selection (essential cookie) | Contract performance (Art. 6(1)(b)) |
All capsule files are encrypted with AES-256-GCM using server-side envelope encryption. Each file receives a unique per-file encryption key, which is itself encrypted with a master key. Encryption keys are stored separately from file data.
Data is stored across:
We share data only with processors necessary to deliver the service:
| Processor | Role | Data Shared | Location |
|---|---|---|---|
| Paddle.com | Merchant of Record — payment processing, tax compliance, invoicing | Payment info (collected directly by Paddle) | UK/US |
| AWS (Amazon Web Services) | Encrypted file storage (S3 Glacier Deep Archive) | Encrypted files only — AWS cannot read content | US (us-east-1) |
| Cloudflare | Encrypted file storage (R2) and delivery to recipients | Encrypted files only | US/Global Edge |
| Resend (via AWS SES) | Transactional email delivery | Recipient email, subject, email body | US |
| Supabase | Database hosting (PostgreSQL) | All metadata, encrypted encryption keys | US (us-east-1) |
| Vercel | Application hosting | Request handling — no persistent data storage | US/Global Edge |
Our services are primarily hosted in the United States. If you are located in the EU/EEA, your data is transferred to the US under the EU–US Data Privacy Framework (where applicable) and Standard Contractual Clauses (SCCs) with our processors. All capsule files are encrypted before transfer — processors cannot access file content. The written text message is stored unencrypted in the database.
If you are in the EU/EEA, you have the following rights under GDPR:
To exercise these rights, email support@sealedfor.com. We will respond within 30 days as required by GDPR.
Depending on your state, you may have rights under the CCPA (California), CPA (Colorado), CTDPA (Connecticut), VCDPA (Virginia), or similar state privacy laws:
To exercise these rights, email support@sealedfor.com.
SealedFor uses only essential cookies:
We do not use tracking cookies, advertising cookies, or any third-party cookies. No cookie consent banner is required because we only use strictly necessary cookies (ePrivacy Directive Art. 5(3) exemption).
SealedFor staff never access capsule content during normal operations. In the case of a recipient report (e.g., suspected illegal content), admin may view content only if the recipient explicitly consents via a checkbox in the report form. Without consent, admin sees only metadata (dates, status, file types). All admin actions are logged.
SealedFor is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has used our service, contact us and we will delete the data promptly.
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically.
For privacy inquiries: support@sealedfor.com
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority (e.g., the ICO in the UK, CNIL in France, BfDI in Germany, UODO in Poland).