Privacy Policy
Key points
- Your documents never leave your device. All encryption, text extraction and recipient checking happens locally. No document content, extracted text or key material is ever sent to us.
- CIBHER contains no telemetry and no analytics, and crash reports are never transmitted.
- Activating a license does disclose a small, enumerated set of values to us, including a code derived from your computer’s serial number. That list is set out in full below and it is closed.
- We keep two different things for two different periods. Accounting records — a purchase, renewal, refund, chargeback or transfer — are kept for six years from that transaction. The record linking a licence to a specific device is kept only while that activation is live, and is erased when the activation is released.
Who is responsible for your data
The controller of the personal data described here is CBPROJEKT sp. z o.o., Wschodnia 6/15, 20-015 Lublin, Poland (KRS 0001221768).
We have not appointed a Data Protection Officer. We are not required to, and we would rather tell you that than leave you looking for one. The route for every privacy question, objection and data-subject request is privacy@cibher.eu, which is read by Rafal Gorny.
You may also write to us at the postal address above.
The short version
CIBHER is built so that the sensitive material never reaches us. That is the product premise, not a setting you have to find:
- Encryption, decryption, key generation, text extraction and recipient checking all run on your machine.
- There is no telemetry, no analytics and no usage reporting of any kind.
- Crash reports stay in the local encrypted store and are never transmitted — there is not even an opt-in to transmit them.
- The software never contacts our payment provider.
What we do process is described below, and we have tried to describe it exactly rather than reassuringly.
What stays on your device
No document content — plaintext, extracted text, or rendered pages — leaves your device before encryption. Text extraction and optical character recognition run locally. The recipient-verification gate compares extracted text against a recipient profile you created, locally.
The local audit log records the outcome of a check, never the data checked. Where a match occurred on an identifier such as a tax number, the log stores a keyed cryptographic digest of the matched value under a key that never leaves the machine — so the log can record that the tax ID matched without recording the tax ID.
Your master password and your private keys never leave the device and are not stored by us in any form. See the License Agreement for what that means if you lose them.
When you use this website
This website is hosted by Netlify. Loading a page produces standard server logs including your IP address, which Netlify processes as our processor to deliver the site and protect it from abuse. Our lawful basis is our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).
Outside the shop, the site itself makes no third-party requests. Fonts are served from our own domain and the location map is a static image, specifically so that no other company learns your IP address merely because you read a page here. We set no analytics cookies and use no tracking pixels. The shop page loads Paddle, our merchant of record, because a checkout cannot function otherwise — see the Cookie Policy.
If you use the contact form, we receive the name, email address and message you type. That is processed by Netlify Forms on our behalf, and we use it only to answer you. Basis: your consent, or our legitimate interest in responding to an enquiry. We keep enquiry correspondence for as long as needed to deal with the matter and normally no longer than 24 months.
When you buy a subscription
Purchases are handled by Paddle.com Market Ltd as merchant of record. Paddle collects your name, email address, billing address, tax identifiers where relevant, and payment details. We never see or store your payment card details.
Paddle is an independent controller for the transaction and also acts for us in respect of the subscription record; its own privacy notice governs what it does with your data. We receive from Paddle the billing email address and the subscription status we need to issue and maintain your license.
What activating and refreshing a license transmits
This is the one place where the software talks to us about your machine, and we set out the complete list. Nothing outside this list is sent; the set is enumerated and closed, and a build that sent anything else would be a defect.
At activation, the software transmits to activate.cibher.eu:
| Value | What it is |
|---|---|
| License Key | The key we issued to you. |
| Hardware fingerprint hash | A hash combining your platform serial number, a hash of a non-exportable device key held in the Secure Enclave or TPM, and a one-bit virtualization flag. The raw serial number never travels. |
| Machine deduplication key | A hash derived from your platform serial number. See the section below — this one needs an honest explanation. |
| Binding class | Whether the device key is hardware- or software-protected. |
| Device public key | The public half of the per-user licensing key. |
| Challenge signature and nonce | Proof that the request came from that device key. |
At each silent refresh, less is sent: the license serial, the hardware fingerprint hash, the device public key, and the challenge signature and nonce. The License Key is not sent on refresh.
We also necessarily learn the timing of each contact and the IP address it came from.
No sending address, no recipient address, no pairing data, no key fingerprint and no filename ever reaches this service.
About the value derived from your serial number
We want to be precise about one value, because it would be easy to describe it in a way that flatters us and misleads you.
Activating sends a code derived from this computer’s serial number, so CIBHER can tell your computers apart. It is not a secret and it is not anonymous — someone who already knows a computer’s serial number can check whether that code came from it. It carries nothing about your files, your keys, or what you do in CIBHER.
The reason is that the value is a hash of your serial number combined with a fixed constant that ships inside every copy of the software. That constant is therefore not a secret, and platform serial numbers are short, structured and guessable. So anyone holding both the value and a guess at your serial number can confirm the guess.
That is the correct security level for what the value is for — an equality test that says “this is the same machine as before” so we can count activations. It is not anonymisation, and we will not call it that. In our own records we store it under a further keyed hash, so a stolen copy of our database is not enough on its own to test serial numbers against it — but that protects the stored copy, not the value in transit.
The activation record, and how long we keep it
Our activation service keeps a ledger containing the hardware fingerprint hash, the blinded deduplication key, the License Key, the license serial, the binding class and the transfer history, joined to the billing identity Paddle gives us.
Lawful basis: our legitimate interests (Art. 6(1)(f) GDPR), specifically fraud prevention, having evidence to resolve license-transfer disputes, and enforcing the number of activations a license allows. You have the right to object — see below.
Retention: two clocks, and they are not the same clock. Accounting records — a purchase, a renewal, a refund, a chargeback, a transfer — are kept for six years from that transaction, each on its own clock. Six years matches Polish accounting record-keeping requirements. The device-correlation record — the data that links a licence to a particular machine — is kept only for the life of that activation, and is erased when the activation is released. A silent refresh is neither a transaction nor a new activation, so it restarts neither clock. Our backups inherit the same clocks.
The honest consequence, stated plainly: we can correlate a specific device with a specific paying customer for as long as that activation stays live. When it is released, that link is erased; what remains is the accounting record of the transactions, on their own six-year clocks.
The ledger holds no key material, no document data, no email address of any kind and no pairing information.
The free-tier allowance marker
The free tier requires no account and no network, so the limited number of encryptions it allows has to be counted on the machine itself. CIBHER stores a small record locally containing a count of the encryptions you have performed, the time of the most recent one, and a value derived from your computer’s serial number so that the record can tell it belongs to this machine. It holds nothing about your documents, your identities or your recipients.
It is written in one place — an entry in your computer’s own secure credential store: the Keychain on macOS, the Credential Manager on Windows. There is no second copy, and nothing is written outside CIBHER’s own storage.
CIBHER does not arrange for the record to survive uninstalling, and does not claim it will. Whether it does is your operating system’s behaviour and not ours. Reinstalling the operating system clears it, and a Key Wipe destroys it along with every other key CIBHER holds. You can remove it yourself, and one supported action does exactly that: Settings › Data › “Leaving this computer” carries “Reset this machine’s free-allowance record”, which deletes the entry and records the reset in your Audit Log. You can also delete the credential-store entry by hand; we neither hide it nor try to stop you. We do not treat this record as a security control — it is friction, and anyone who wants to reset it can. It is never transmitted to us.
Pairing, if you use it
Pairing exchanges public key cards with someone you want to correspond with. It is never silent: you are told what it will disclose before it runs.
Starting a pairing discloses to our pairing service your sending address, your counterpart’s email address, the timing of the exchange, and the public key card — once, per counterpart. No document content and no private key material is ever sent.
We must be careful about how we phrase what follows. We do not retain a record of who you pair with beyond the periods below — but we do observe it at the time, so we cannot honestly say we do not know it, and we will not describe pairing as private.
- Key cards are deleted once delivery is acknowledged.
- Invitation addresses are cleared when the invitation closes, and the row is deleted after 30 days. Invitations expire after 14 days.
- Abuse-prevention counters hold only salted hashes of addresses.
- Verified sending addresses are held in plain text. The published retention clock is about 91 days: the sender token expires 90 days after it is issued, and the row is deleted within 24 hours of that expiry. Re-verifying an address simply creates it again, so nothing is lost. The pairing service is not yet in operation, so no such record exists today.
If you are reading this because you received a CIBHER invitation and are not a customer, the Invitee Privacy Notice is written for you.
Business register look-ups
CIBHER can check a counterparty against a public business register — GUS/KRS in Poland and VIES for EU VAT numbers. This is optional, is never performed silently, and is disclosed to you each time before it runs.
A look-up discloses the queried identifier to the register operator, which for these registers means a government body: in effect it reveals that someone is dealing with that entity. Each query is minimised to the single identifier required.
The identifier comes only from the recipient profile you created or confirmed — never from text extracted out of a document.
Support
Support requests reach us by email at support@cibher.eu, or through the support
portal for license transfers and diagnostic requests. We use what you send only to answer you.
Artifacts submitted through the portal are handled restrictively: a diagnostic request file is deleted immediately once forwarded, a deactivation envelope is never stored at rest, and documents you submit as eligibility evidence are examined and discarded, never archived — we retain only the outcome of the check.
Who else processes your data
We keep this list short on purpose.
| Who | What for | Where |
|---|---|---|
| Paddle.com Market Ltd | Merchant of record: payment, tax, invoicing, subscription records | United Kingdom / EU |
| Netlify | Website hosting and the contact form | EU / United States |
| Microsoft | Sends the email we send you: your License Key after purchase, and pairing invitations. Also our support@, privacy@ and security@ mailboxes. | Azure Communication Services in polandcentral (Poland); mailbox region per our Microsoft 365 tenant |
| Google Cloud KMS | Holds our signing keys. On the pairing attestation path an invited person’s email address is passed to the signing operation, which makes Google a processor for that address. | europe-central2 (Warsaw, Poland) |
When our activation, pairing and support services run, they will run on our own hardware in Poland, so there will be no hosting provider in that path. None of them is running yet — the machines exist and carry no CIBHER service.
Because Google Cloud KMS is used in the Warsaw region, that processing stays inside the EU and no third-country transfer arises from it. Where a processor does process data outside the EEA, we rely on the transfer mechanism in that processor’s data processing agreement. For Netlify, that is the EU–US Data Privacy Framework, and — if the Framework is invalidated or Netlify does not re-certify — the European Commission’s standard contractual clauses (Module Two).
Your rights
Under the GDPR you have the right to: obtain access to your personal data and a copy of it; have inaccurate data corrected; have data erased in the circumstances the law provides; have processing restricted; receive your data in a portable form; and object to processing carried out on the basis of our legitimate interests, which includes the activation ledger.
To exercise any of these, write to privacy@cibher.eu. We will respond within one month. We may need to verify that the request comes from you — usually by confirming control of the billing email address on the subscription.
Where processing relies on your consent, you can withdraw it at any time; that does not affect processing already carried out.
Complaining to a supervisory authority
If you think we have handled your data badly, please tell us first at privacy@cibher.eu. You also have the right to lodge a complaint with a supervisory authority.
Ours is the Polish authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, Poland — uodo.gov.pl. You may also complain to the authority in the EU country where you live or work.
Children
CIBHER is a professional tool sold to adults and organisations. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, write to privacy@cibher.eu and we will delete it.
Changes to this policy
If we change how we process personal data we will update this page, change the date and version at the top, and — for a change that materially affects you — tell subscribers by email before it takes effect.
Version 1.4 (2026-09-03). We named the transfer mechanism we actually rely on. This section said we rely on the European Commission’s standard contractual clauses; for Netlify that is the fallback, not the primary basis. Netlify’s data processing agreement relies first on the EU–US Data Privacy Framework, and applies the standard contractual clauses only if that Framework is invalidated or Netlify does not re-certify. Both are now named, so this statement stays accurate whichever one is operative. Nothing about what we collect, why, or how long we keep it changed.
Versions 1.2 and 1.3. These bumps were published without an entry here, which this policy’s own commitment above did not permit. They carried the split activation-retention clock and the addition of Microsoft as a named sub-processor for invitation delivery. The omission is recorded rather than quietly back-filled.
Version 1.1 (2026-08-21). We corrected the retention statement for verified sending addresses. The published clock is about 91 days: a 90-day sender-token lifetime plus deletion within 24 hours of expiry. The earlier text stated a longer period and attributed it to a purge step that does not exist. We also record here that the pairing service is not yet in operation, and we now state the exception to our no-third-party-requests statement: the shop page loads Paddle.