Legal
Privacy policy
Effective 2 October 2026.
1. Controller
The controller of your personal data is aunoma spółka z ograniczoną odpowiedzialnością (aunoma sp. z o.o.), ul. Górnych Wałów 15/3, 44-100 Gliwice, Poland, KRS 0001072571 (District Court in Gliwice, 10th Commercial Division of the National Court Register), NIP 6312717805, share capital PLN 5,000. Contact us about privacy at contact@lockeon.me.
2. What we cannot see
Sealed deliveries, and files sent through upload requests, are encrypted in the sender’s browser before upload. We store ciphertext only. We never store a delivery password or the secret part of a link, so we cannot read the message, the files, or the file names, and we cannot hand them to anyone. They reach our servers at all only if the sender asks us to pass them on: the link by e-mail, the password by SMS. In that case they are forwarded and not kept.
3. What we do process
- Account data: your e-mail address, a salted hash of your account password, and the time you accepted the terms.
- Delivery metadata: size and number of encrypted files, creation and expiry times, the reference you typed (stored unencrypted), and the recipient’s e-mail address if you asked us to e-mail the link.
- The access record: for each event on a delivery (sealing, password attempts, opening, destruction) the time, the IP address, an approximate location derived from it, and the browser and operating system. This applies to senders and to recipients.
- Mail at private addresses: messages sent to your Lockeon addresses, including sender, subject, text and attachments, until you delete them or burn the address. If you switch on forwarding, we pass them to your account e-mail address.
- Password by SMS: if a sender uses this option, the recipient’s phone number and the delivery password are passed to our SMS provider to send one text message. We keep neither; the access record notes that a text was sent and the last three digits of the number.
- Upload requests: the title of the request (unencrypted), the public key, a copy of the private key locked with a password we never receive, and for each upload the same access record as for a delivery, including the uploader’s IP address and device.
- Encrypted mailbox (Confidential plan): if you turn it on, each message that arrives is sealed to your mailbox key the moment it arrives; afterwards we hold only ciphertext, the sender address and the time. The mailbox password never reaches us; a lost password means the sealed mail cannot be recovered.
- Ordinary IMAP mailbox: if you turn it on, unencrypted copies of received mail are stored in a mailbox you can open with any mail client. They are readable by the server.
- Signatures: message signatures you save in your account, stored unencrypted.
- Subscription data: for paid plans, a customer and subscription identifier from Stripe, the subscription status and its renewal date. Card details go to Stripe only.
- Technical logs: server and mail-gateway logs with IP addresses, kept for security and troubleshooting.
We use one strictly necessary cookie to keep you signed in. We do not use analytics, advertising or tracking cookies, and the site loads no third-party scripts.
4. Why, and on what legal basis
- To provide the service you asked for, including the access record that is part of it: performance of a contract (Art. 6(1)(b) GDPR).
- To keep the service secure, prevent abuse, and establish or defend legal claims: our legitimate interests (Art. 6(1)(f) GDPR).
- To meet legal obligations, for example answering lawful requests from authorities (Art. 6(1)(c) GDPR).
Recipients of a delivery: the sender chose to send you something through Lockeon. We process the access record on the basis of our and the sender’s legitimate interest in proof of access.
5. How long we keep it
- Ciphertext is destroyed when the single view completes, when the delivery expires (at most 7 days), when five wrong passwords lock it, or when the sender revokes it, whichever comes first.
- Access records are kept until the sender deletes the delivery or their account.
- Mail at private addresses is kept until you delete it, burn the address, or delete your account. A burned address name is retained, without content, so that it is never issued to anyone else.
- Account data is kept until you delete your account.
- Technical logs are kept for up to 90 days.
6. Who receives data
We do not sell data and we do not share it for advertising. Data is processed on servers we rent from a hosting provider acting as our processor. E-mail we send on your behalf is handed to the recipient’s mail provider, as with any e-mail. Text messages are sent through an SMS provider acting as our processor. Payments are processed by Stripe Payments Europe, Ltd., which is an independent controller for the payment data it collects. We disclose data to authorities only where the law requires it; for sealed deliveries that can only ever be metadata and ciphertext.
7. Your rights
You have the right to access, correct, erase and export your data, to restrict or object to its processing, and to lodge a complaint with a supervisory authority; in Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw. Most of these you can exercise yourself in the app; for anything else write to contact@lockeon.me.
8. Security
Content is encrypted with AES-256-GCM using a key derived on your device with Argon2id. Connections use TLS. Account passwords are stored as salted scrypt hashes. When you choose an account password we check whether it has appeared in a known data breach using the Pwned Passwords service: only the first five characters of a hash of the password are sent, never the password itself. Found a vulnerability? Write to security@lockeon.me.
9. Changes
We will announce material changes to this policy by e-mail to account holders before they take effect.
IP geolocation by DB-IP. See also the terms of service.