How WarpDesk Handles Your Data and Privacy
Privacy policy pages are legalese. Here's the plain-English version of what we do and don't do with your data.
What we store
Vault entries (encrypted at rest by the database), inbox messages (sanitized on ingest), family membership, activity logs, and billing records.
What we don't store
Your browsing history, your device fingerprint, your location, or anything about you outside the WarpDesk surface. We don't build ad profiles.
Who can read your data
You and your family members (via RLS). Our on-call engineers if you file a support ticket and explicitly authorize access. That's the whole list.
Third parties
Stripe for payments, Logo.dev for logos, Google AdSense for ads (if enabled), our hosting provider for infrastructure. Each has a defined scope.
Ads and privacy
AdSense sees a page view and an ad slot. It does not see your vault contents. It does not see your inbox contents. Ads run on marketing pages, not authenticated surfaces.
Data export
You can export your vault and inbox at any time from account settings. The export is JSON, machine-readable, and includes everything we have on you.
Data deletion
Deleting your account triggers a hard delete of your family's vault, inbox, and profile data within 30 days. Backups are purged on their normal rotation.
Regulatory
GDPR and CCPA rights are honored regardless of where you live — data export, deletion, and correction are available to everyone.
A worked example
A family in Germany asks for a full data export. They get a JSON file with every vault entry, every inbox message, every activity row, and every billing record within seven days.
What we haven't done yet
Client-side zero-knowledge encryption of vault fields. That's on the roadmap and we won't claim it before it ships.