Privacy Policy
Last updated: July 12, 2026
This Privacy Policy explains what envdotweb ("we", "us") collects and how we use it. The short version: your secret values are encrypted in your browser and we can never read them.
1. The data we can never see
envdotweb is zero-knowledge. Secret values, your passphrase, and your unwrapped encryption keys never leave your device in readable form. We store only ciphertext, your public key, and wrapped (encrypted) private and project keys. We cannot decrypt your secrets, and we cannot recover them if you lose your passphrase and recovery code.
2. Data we do collect
- Account information — your email address, and (if you sign in with GitHub) your GitHub username, avatar and an OAuth token used only to list repositories you choose to import.
- Workspace metadata — team, project and environment names, key names, roles, and invite records.
- Audit & security logs — actions taken (e.g. "secret updated"), timestamps and IP addresses, used for security and to power your audit log.
- Billing information — handled by Polar (our merchant of record); we store only a customer/subscription identifier, never card numbers.
3. How we use it
- To operate the service and sync your encrypted data.
- To authenticate you and enforce roles and plan limits.
- To send transactional email (magic links, invites, alerts).
- To detect abuse and keep the service secure.
We do not sell your data or use it for advertising.
4. Subprocessors
We rely on a small set of infrastructure providers to run the service, such as a database host, an email provider, and a payments processor. Each only receives the data necessary for its function — and none of them receive plaintext secrets.
5. Data retention
We keep your data while your account is active. One-time secrets created with our /share tool are deleted after they're viewed or when they expire. You can delete projects, secrets and your account at any time; deleting an object removes its ciphertext from our systems.
6. Your rights
You can access, export (as a decrypted .env), correct, or delete your data from within the app. For any privacy request, contact us at privacy@envdotweb.xyz.
7. Changes
We'll update this policy as the product evolves and revise the date above. Material changes will be announced in the changelog.
Questions? Email privacy@envdotweb.xyz.
