Privacy policy
SealedBrief is a local-first product. The desktop application processes your documents on your machine and never sends them, or anything derived from them, to us. The website you are reading collects only what is required to sell, deliver, and support a software license. This policy enumerates exactly what is collected and where it lives.
1. What we collect on this website
When you buy a SealedBrief license, the checkout is handled by
Stripe. Stripe holds your card
data; we never see it. Stripe sends us a webhook containing the customer email address, the
price ID, and a Stripe customer ID. We persist the resulting license record — a binding of license_id to email address — in a private database operated solely for license issuance and revocation.
We run no third-party analytics or tracking on this website. There is no Google Analytics, no Meta Pixel, no third-party advertising script, and no first-party cookies set by us. No third party receives anything about your visit from your browser.
Two first-party exceptions, stated plainly. First, our CDN keeps standard server access logs of requests to this website and to the download host — see section 3. Second, if you arrive from one of our own ads or a tagged link, including the links in our own emails, a small script stores that link's campaign identifier in your browser's local storage and appends it to the checkout and installer-download links, so that if you buy or download we can tell which link brought you. It sets no cookie, it loads nothing from a third party, and it sends nothing anywhere unless you start a checkout or a download. Clearing site data removes it.
Email signups. If you ask for the security whitepaper or for the Windows download
link, we store your email address, the form you used, when you used it, the profession you picked
if the form asked, how many times you used it, whether you are on our mailing list, a random reference
number, and where you are in the series. We send what the form says: the whitepaper form sends
the whitepaper and then a series of four short emails over three weeks; the Windows form sends
the download link. After that, we write to an address left through either form only when there
is real news, such as a new release, until you unsubscribe. The emails are plain text, with no
open tracking and no link redirection. Each link to our site in a series email carries your reference
number (ref=nl-…), so a download or a purchase that follows from that email can
be attributed to it in our own logs and checkout records. When the download log shows that
such a link led to a complete download of the app, we add two things to your entry: when
that download finished, and for which operating system. Nothing else from the log line, such
as your IP address, is copied to it. Every series email has a one-click unsubscribe link,
run by our email provider, Postmark. Once you use it, nothing more from the series is
delivered to you, and we delete your address from our list; Postmark keeps only a record
that the address unsubscribed, so it is never mailed again.
2. What the desktop app collects
None of your documents, and nothing derived from them. The desktop application has no
network egress from the compute plane (the part that touches your documents) by design: that
plane declares no outbound network endpoints, a build gate fails the release if it ever
does, and a runtime guard in the process refuses any non-loopback connection or external DNS
lookup. Those are properties of how the software is built and run — not a measurement we
took on your machine, which is why the procedure for checking it yourself is published at /verify. The presentation plane connects to our license server only to validate your license_id on launch and to fetch the revocation list. Neither connection sends document contents, queries,
or any derived data.
AI model files are downloaded from our CDN over plain HTTPS — no account, no identifier, no
cookie; the CDN sees your IP address for that request, as any web server does, and nothing
else. Every download is verified against an Ed25519-signed manifest before it is ever used,
and an offline import path exists so a machine with no internet never needs this connection.
On Linux and macOS this happens only if you choose to add the optional larger model
(Settings → Models). On Windows it also happens during installation,
because the Windows installer format cannot carry a file as large as the model: the same CDN
that served you the installer a moment earlier serves the model too, from the same IP, under
the access logging described in section 3. It is more requests, not a different kind of
information. Passing /SKIPMODELS=1 to the Windows installer skips it entirely.
Crash reports are on by default for new installations. When the presentation plane crashes or records an internal error, it sends an anonymous crash report — the stack trace, the error type, and the app, operating-system and Python versions — to our error tracker, Sentry. Before a report leaves your machine, file paths, email addresses and key-shaped strings are removed, and the values of variables in the crashing code are never captured, so a report never contains document text, your questions, or the answers the app generated. Turning it off is one click: untick "Send anonymous crash reports" during first-run setup, or switch it off in Settings, and the app stops sending immediately. Installations from before 2026-10-05 keep the choice they already had. The daily license check-in is a separate switch and stays off unless you turn it on.
The Windows installer reports a failed installation. If setup fails once files
have started copying (or the model download fails afterwards), the installer sends the tail of
its setup log to Sentry, with your user folder, user name and computer name removed. A successful
install, or one you cancel before the copy starts, sends nothing. Untick the box on the installer's
licence page, or install with /SENDLOG=0, and it never sends.
3. What we share
We share data with the following subprocessors:
- Stripe — payment processing. Stripe handles your payment data under their own privacy policy.
- Postmark — email delivery: the license email after purchase, refund confirmation, and the emails you asked for through a signup form on this website (section 1). Postmark sees your email address and the message body. It does not see anything about your documents. Open and link tracking are switched off for every message we send.
- Amazon Web Services — hosts the license-minting microservice (Lambda + API
Gateway), the audit-log S3 bucket holding signed license records, and the CloudFront distributions
serving both this website and the binary downloads at
downloads.sealedbrief.com. AWS sees the customer email address (forwarded inside Stripe's webhook payload) and CloudWatch logs of Lambda invocations. AWS does not see anything about your documents. - CloudFront access logs (first-party). Our CDN writes a standard server access log line for each request to this website and to the download host, recording the timestamp, the URL requested, the response status and byte count, your browser's user-agent string, the country your IP resolves to, and your IP address. We store these logs in our own AWS account and query them to count page visits and completed downloads — so, unlike the statement above about third-party analytics, we do measure aggregate traffic, using our own server logs. We never join them against license or customer records; the one exception is the email reference number described in section 1, which ties a download made from one of our series emails to the subscriber it was sent to. Nobody outside AWS receives these logs. Retention is 90 days; see section 4.
- Sentry — crash reporting from the desktop app (section 2), hosted in the United States. Sentry sees the scrubbed crash report and the IP address it was sent from. It does not see anything about your documents.
- Cloudflare — DNS for the sealedbrief.com zone only. Cloudflare resolves the domain name; it is not in the path of this website's content and holds no request logs for it.
We do not share data with anyone else. We do not sell, trade, or rent any data we hold.
4. How long we keep data
We keep your license_id ↔ email binding for as long as your license is active. If
you ask us to delete your account, we delete the binding within 30 days. Stripe retains its own
copy of the transaction record per its policy, which we cannot influence.
Transactional email logs at Postmark are retained per their retention policy (default 45 days). AWS CloudWatch logs of Lambda invocations are retained 30 days per our configured policy. We do not extend either retention window.
CloudFront access logs, including the IP address they contain, are deleted automatically 90 days after they are written, by a storage lifecycle rule rather than by anyone remembering to run it.
Crash reports are kept in Sentry for at most 90 days and then deleted automatically.
5. Your rights and contact
You can request access to, correction of, or deletion of the data we hold about you by writing to privacy@sealedbrief.com. We respond within 30 days. If you are an EU or UK resident, the legal basis we rely on for processing customer data is the contract you entered into when buying the license. For website access logs, where no contract exists, the basis is our legitimate interest in operating, securing, and measuring the traffic to our own site; you can object by writing to the address above.
This policy is a v1 stub written by the engineering team ahead of V1.0 launch. A formal legal review is queued for the post-launch backlog. If our practices change, we will publish an updated policy at this URL with a new "last updated" date.