securityJune 10, 2026·1 min read

How WarpDesk Handles Your Data and Privacy

Privacy policy pages are legalese. Here's the plain-English version of what we do and don't do with your data.

What we store

Vault entries (encrypted at rest by the database), inbox messages (sanitized on ingest), family membership, activity logs, and billing records.

What we don't store

Your browsing history, your device fingerprint, your location, or anything about you outside the WarpDesk surface. We don't build ad profiles.

Who can read your data

You and your family members (via RLS). Our on-call engineers if you file a support ticket and explicitly authorize access. That's the whole list.

Third parties

Stripe for payments, Logo.dev for logos, Google AdSense for ads (if enabled), our hosting provider for infrastructure. Each has a defined scope.

Ads and privacy

AdSense sees a page view and an ad slot. It does not see your vault contents. It does not see your inbox contents. Ads run on marketing pages, not authenticated surfaces.

Data export

You can export your vault and inbox at any time from account settings. The export is JSON, machine-readable, and includes everything we have on you.

Data deletion

Deleting your account triggers a hard delete of your family's vault, inbox, and profile data within 30 days. Backups are purged on their normal rotation.

Regulatory

GDPR and CCPA rights are honored regardless of where you live — data export, deletion, and correction are available to everyone.

A worked example

A family in Germany asks for a full data export. They get a JSON file with every vault entry, every inbox message, every activity row, and every billing record within seven days.

What we haven't done yet

Client-side zero-knowledge encryption of vault fields. That's on the roadmap and we won't claim it before it ships.