Privacy Policy
Last updated: July 22, 2026
1. Information we collect
- Account data: your email address and a securely hashed (Argon2id) password — we never store your password in plain text.
- Two-factor secret: your TOTP secret, encrypted at rest and shown to you only once, at setup.
- Check-in PIN: a securely hashed PIN used solely to confirm you are checking in.
- Documents: files you upload, encrypted at rest before storage.
- Recipient details: the contact information you provide for the people you choose to receive documents.
- Identity verification (KYC) details: if you complete verification, the name and address details you submit, used to enable higher-risk features such as escalation ladders or staged release.
- Usage & security logs: login/check-in timestamps, IP addresses, and audit trail entries, used for rate limiting, abuse prevention, and account security.
2. How we use your information
We use this information to operate the Service: authenticate you, run the check-in and escalation process, deliver documents to your chosen recipients when your policy calls for it, prevent abuse, and communicate with you about your account.
3. How we protect your information
Passwords are hashed with Argon2id and never stored in plain text. Login access is additionally protected by TOTP two-factor authentication. Documents and TOTP secrets are encrypted at rest using envelope encryption. Access to administrative functions is role-gated and logged in an audit trail.
4. Notifications & third parties
Reminder notifications and portal-invite delivery are currently logged internally rather than sent through an outside email provider. Webhook deliveries are sent directly to the URL you configure. If we introduce a third-party email or payment provider in the future, this policy will be updated to name that provider and describe what data it processes.
5. Data retention
We retain account, document, and audit data for as long as your account is active, plus any additional period required to meet legal obligations or resolve disputes. You may request deletion of your account and associated data, subject to any retention we're legally required to keep.
6. Your rights
You may request access to, correction of, or deletion of your personal data by contacting us using the details below. You may also delete your own documents and recipients directly from your account at any time.
7. Cookies
We use a single session cookie to keep you logged in. We do not use third-party advertising or tracking cookies.
8. Children's privacy
The Service is not directed at, and may not be used by, anyone under the age of 18.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above when we do.
10. Contact
Questions about this policy can be sent to noreply@agathon.one [replace with a monitored support address before launch].