Data Policy

What actually happens to your data.

The strongest way to protect sensitive data is to never be able to read it in the first place. That principle shapes how doconvoy is built. Here's what we hold, what we can't, and where it lives.

We never hold the plaintext of your secrets or submissions, and we don't use advertising or cross-site tracking.

Account data

Your email and name, sign-in sessions, and billing contact. This is what lets you log in and run a workspace.

Content you share or collect

Encrypted in your browser before it reaches us. We hold the scrambled result and can't read it.

Access metadata

Timestamps and view counts for your audit trail. Inside the app, device, location, and IP are off unless you turn them on.

End-to-end encryption

Content is encrypted on your device before it reaches us. We store only ciphertext and don't hold the keys, so there's nothing readable for us to lose, leak, or hand over.

Erasure that actually erases

We erase by destroying keys (crypto-shredding): immediately for a person, and across an entire workspace when it's deleted. No chasing copies through backups.

Data minimisation & clean deletion

We keep as little as possible, and we handle email addresses so they're easy to erase. An address is encrypted and kept in a separate store, and the rest of the app refers to it by a stand-in token. Destroy the key and the email is gone everywhere at once.

A complete, exportable audit trail

Every share, access, and key change is recorded in an immutable log you can export. It's evidence you can show, and the basis for access and portability requests.

Application data is hosted with AWS in the EU, so personal data stays in a known region rather than wherever a vendor happens to put it. A self-hosted option for stricter residency needs is on our roadmap, not available today.

A short list of providers process data on our behalf — AWS for hosting, storage and email, and Stripe for payments. Our marketing site uses cookieless analytics. The full list, with what each one handles, is on our sub-processors page.

A plain look at where our design meets common data-protection principles, and where the responsibility stays with you.

PrincipleWhat doconvoy doesBuilt in?
Data minimisation (Art. 5)We store ciphertext only, and tokenise identifying details.By design
Storage limitation (Art. 5)Expiry is mandatory (default 3 months, max 1 year); no “never expires”.By default
Integrity & confidentiality (Art. 5)Client-side end-to-end encryption; keys never reach our servers.By design
Right to erasure (Art. 17)Crypto-shredding — per item, per person (immediate), or per workspace.Supported
Access & portability (Art. 15 / 20)List who accessed what, and export data for a subject request.Supported
Lawful basis for collecting the dataWe give you the tools; the lawful basis for your collection is yours to hold.Your call

Ready to collect and share sensitive data without handing it to a third party to read?

Start sharing securely