Privacy Policy

Last updated: February 19, 2026

Introduction

At Reveal Once ("we," "our," or "us"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our secure secret-sharing service. By using our service, you agree to the collection and use of information in accordance with this policy.

This policy complies with United States privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

Zero-Knowledge Architecture

We cannot access your secrets. Reveal Once uses end-to-end encryption with a zero-knowledge architecture:

  • All secrets are encrypted on your device before transmission
  • We store only encrypted data that we cannot decrypt
  • Even with full server access, we cannot read your secrets

This means we act as a blind data processor - we store and transmit encrypted data but have no technical ability to access the content.

Information We Collect

Information You Provide

  • Encrypted Secrets: Only encrypted versions of your secrets (which we cannot decrypt)
  • Passwords: Optional passwords for additional secret protection (hashed, not stored in plaintext)

Information Collected Automatically

  • Log Data: IP address, browser type, browser version, pages visited, time and date of visit, time spent on pages
  • Device Information: Device type, operating system, unique device identifiers
  • Cookies: We use essential cookies for authentication and security purposes
  • Analytics: Anonymous usage statistics to improve our service

Information We Do NOT Collect

  • Content of your secrets (we only receive encrypted data)
  • Plaintext passwords or sensitive personal information

How We Use Your Information

We use the information we collect for the following purposes:

  • Service Provision: To provide, maintain, and improve our secret-sharing service
  • Security: To monitor for security threats, fraud, and abuse
  • Communication: To send service-related notifications and respond to inquiries
  • Analytics: To analyze usage patterns and improve our service
  • Legal Compliance: To comply with legal obligations and enforce our terms

Data Retention

We retain information only as long as necessary to provide our service and fulfill the purposes described in this policy:

  • Secrets: Automatically deleted after expiration time (1 hour to 7 days) or after being accessed (if burn-after-reading is enabled)
  • Log Data: Retained for security and debugging purposes, typically 30-90 days
  • Analytics Data: Aggregated and anonymized data may be retained longer for service improvement

Your Privacy Rights (US)

California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know: Request information about the categories and specific pieces of personal information we collect
  • Delete: Request deletion of your personal information (subject to certain exceptions)
  • Opt-Out: Opt-out of the sale or sharing of your personal information
  • Correct: Request correction of inaccurate personal information
  • Limit: Limit the use of sensitive personal information

Other US States

Depending on your state of residence, you may have similar rights. We honor these rights regardless of your location within the United States.

Data Security

We implement appropriate technical and organizational measures to protect your information:

  • Encryption: All data transmission uses HTTPS/TLS encryption
  • Zero-Knowledge: Your secrets are encrypted before reaching our servers
  • Access Controls: Strict access controls and authentication measures
  • Regular Audits: Regular security assessments and monitoring
  • Data Minimization: We collect only the minimum data necessary
  • Secure Infrastructure: Industry-standard cloud infrastructure with security certifications

Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately so we can remove the information.

International Users

Our servers are located in the United States. By using our service, you consent to the transfer of your information to the United States and its processing in accordance with US privacy laws, which may differ from those in your jurisdiction.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new policy on this page
  • Updating the "Last updated" date at the top
  • Providing additional notice for significant changes

Your continued use of our service after any changes constitutes your acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

Email: privacy@revealonce.link

Exercise Your Privacy Rights

To exercise your privacy rights, including accessing, deleting, or correcting your personal information:

Email: Send your request to privacy@revealonce.link with "Privacy Request" in the subject line

Verification: We may need to verify your identity before processing your request

This Privacy Policy was last updated on February 19, 2026 and applies to all users of Reveal Once.