Instacrypt Cloud — Privacy Policy
Effective date: August 26th, 2026 Data controller: 3DF Limited (Hong Kong S.A.R.), Rm 1104, Crawford House, 70 Queen’s Road Central, Central, Hong Kong, operating the Instacrypt Cloud service. Data-protection contact: privacy@instacrypt.io
1. Scope
This Privacy Policy explains what data Instacrypt Cloud (the “Service”) collects, what we can and cannot see, and how we handle it.
The Instacrypt apps, the icc command-line client, and the icfx library are
free, open-source software you can use entirely offline on your own devices. Used
that way — without an Instacrypt Cloud account — they do not send your data to us,
and this Policy does not apply. This Policy covers only your use of Instacrypt
Cloud.
2. Where we’re incorporated vs. where your data lives
We want to be direct about this. The company that operates the Service, 3DF Limited, is incorporated in Hong Kong S.A.R. Our servers and file storage, however, are located in the European Union, and the Service is zero- knowledge.
What this means in practice: where a company is incorporated does not determine who can read your data — the architecture does. Your files, encryption keys, and synced data (contacts, settings, identities, notifications) are encrypted on your device before they ever reach us. We store only ciphertext we cannot decrypt. No demand — from any government or party, in any jurisdiction — can make us hand over plaintext we do not have. The only information we can actually read is the limited plaintext metadata listed in Section 4, which, like any provider’s, may be subject to lawful legal process.
3. Our zero-knowledge model
Instacrypt is designed so that the Service never has access to your private plaintext. Your data is encrypted on your device, and only the ciphertext is uploaded. Even under legal compulsion, there is nothing for us to disclose but encrypted data we cannot read. A small amount of plaintext metadata is unavoidable to operate the account and its convenience features — Section 4 lists exactly what that is.
4. What we collect and what we can see
Data we can read (plaintext / metadata):
- Account & authentication. Your email address; a stored hash of a password verifier that your device derives locally (we never receive your actual password); a per-account salt; whether your email is verified; your plan tier and any “VIP” flag. If you enable two-factor authentication, a time-based one-time-password (TOTP) secret is stored so we can verify your codes (this secret is readable by us to perform verification); WebAuthn/security- key entries are stored as public credential data; recovery codes are stored hashed only.
- Sessions & devices. Hashed session and refresh tokens (the raw tokens are never stored); a device label you choose (shown in your Devices list); session timestamps. Your account record does not include your IP address, though our network infrastructure processes it (see “Infrastructure and security logs”).
- Published directory. Only the identity details you explicitly choose to publish so others can find you — display name, nickname, email, public fingerprint, and your public identity lock. This directory is searchable by design; if you do not publish, you do not appear.
- File-share metadata (while a share is active). The sending account, the recipient’s fingerprint (empty for shares to your own devices), the declared file name and size, timestamps, expiry, and download count. The file contents themselves are encrypted on your device and stored with our storage provider; we cannot read them. To send a “you received a file” notice, we read the recipient’s email from the directory entry they published (only if they published one).
- Billing. We use Stripe to process payments. We store your subscription identifier, tier, status, and renewal date. We send your account email to Stripe to create your customer record. Your card details are held by Stripe, never by us.
- Application logs. Our application’s own logs record a request identifier, method, path, response status, response size, and duration, and do not include IP addresses. We also keep email-send timestamps (by address) to rate-limit outgoing email.
- Infrastructure and security logs. To deliver and protect the Service, your connection passes through our content-delivery and security network (Cloudflare) and our web servers. These layers necessarily process your IP address and connection metadata (such as user-agent and the requested URL) to route traffic, defend against attacks and abuse, and enforce rate limits, and may retain standard access logs for a limited period for security and diagnostics. We do not use these logs to build a profile of you or to link them to your encrypted content.
Data we cannot read (encrypted on your device):
- Your synced blobs — identities, contacts, settings, backups, and notification state — and the encrypted change-log behind them.
- The contents of pending contact-exchange items.
- The contents of the files you share.
5. What we do not collect or cannot access
- Your password (we only ever see a hash of a device-derived verifier).
- Your private keys or encryption passphrase.
- The contents of your shared files, or the names and contents inside your encrypted vault (contacts, settings, identities, notifications).
- Your contact “social graph”: contact lists sync as ciphertext, and we do not keep a record of who sent whom a contact request.
- No advertising, behavioral tracking, cross-site profiling, or sale of your data. We run no ad networks and no invasive analytics SDKs. Our content- delivery network (Cloudflare) may give us aggregate, privacy-preserving traffic statistics (for example, request counts and approximate geography) derived from connection metadata; this is cookieless and is not used to identify or profile individuals. Your IP address is not stored in the application database, though it is processed by our network infrastructure as described in Section 4.
6. How we use your data, and our legal bases
We use the data above to:
- provide and operate the Service, including sign-in, sync, contact discovery, and file sharing (legal basis: performance of our contract with you);
- process payments and manage subscriptions via Stripe (contract);
- send transactional emails — verification codes, sign-in codes, share notices, and account notices (contract);
- keep the Service secure, prevent abuse, and enforce limits (legitimate interests);
- comply with legal obligations, including tax and lawful requests (legal obligation); and
- act on any consent you provide, where consent is the basis (consent).
7. Sub-processors and third parties
We share the minimum necessary data with service providers that process it on our behalf:
- Stripe — payment processing. Receives your account email and holds your card details under its own terms.
- Brevo — transactional email delivery. Receives the recipient email address and message content for the emails listed above.
- Storj (EU1 region) — encrypted file storage. Holds only the encrypted file objects; it never receives plaintext or your keys.
- Netcup — hosting provider (Germany). Runs our application servers on full-disk-encrypted infrastructure.
- Cloudflare — content-delivery network, reverse proxy, and DDoS/WAF protection. Your connections pass through Cloudflare’s global edge, which processes connection metadata (including your IP address, user-agent, and the requested URL) to route and protect the Service, and may provide us aggregate, cookieless traffic statistics. Cloudflare processes this data under its own terms and never receives your plaintext content or keys.
We do not sell your data, and we do not share it with advertising networks or behavioral-analytics providers.
8. Where your data is stored and processed
Our application servers (Netcup) and encrypted file storage (Storj EU1) are located in the European Union (Germany / EU); your encrypted content stays in the EU. Our operating company is in Hong Kong (see Section 2). Your connections are routed through Cloudflare’s global edge network, and Stripe and Brevo may process the limited data described above — in the locations and under the terms set out in their respective privacy policies.
9. Data retention
- Share routing metadata is deleted after a short retention window (currently around 30 days) once a share is downloaded, expires, or is cancelled — so no lasting sharing history or social graph accumulates.
- Account deletion. When you delete your account from the app, it enters a soft-deletion period (currently 30 days) during which signing back in cancels the deletion. After that, we permanently delete your account: encrypted blobs, directory entries, pending items, shares, sessions, two-factor methods, and recovery codes are removed; your stored file objects are deleted from storage; and email-send records and any pending sign-up are purged. Your Stripe customer record is deleted (Stripe may retain invoice records where tax law requires).
- Hashed tokens (sessions, sign-in codes, verification links) expire automatically.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to withdraw consent. Under the EU GDPR, these rights apply to your data, and you may also lodge a complaint with a data-protection supervisory authority.
You can delete your account and its data directly from the app. For any other request, contact privacy@instacrypt.io. Because the Service is zero-knowledge, some data (your encrypted content) is not readable by us and cannot be produced in plaintext — but you can access and export it through the app with your own keys.
11. Security
We protect your data with client-side encryption, hashed credentials and tokens, full-disk-encrypted servers, network-edge DDoS and abuse protection (Cloudflare), and direct-to-storage transfers that keep file bytes off our servers. However, Instacrypt Cloud is alpha software whose security has not yet completed independent expert review or third-party audit, and no method of transmission or storage is ever 100% secure. You use the Service at your own risk during the alpha, and you should keep your own backups of important data.
12. Children
The Service is not directed to children under 16 (or the age of digital consent in your country, if higher), and we do not knowingly collect their data. If you believe a child has provided us data, contact privacy@instacrypt.io.
13. Changes to this Policy
We may update this Policy. We will change the effective date above and, for material changes, provide reasonable notice (in-app or by email). Continued use after changes take effect constitutes acknowledgement of the updated Policy.
14. Contact
Data-protection matters: privacy@instacrypt.io Legal notices: legal@instacrypt.io General support: cs@instacrypt.io 3DF Limited, Rm 1104, Crawford House, 70 Queen’s Road Central, Central, Hong Kong