Data Retention Policy
Last updated: August 2, 2026
This policy describes how long KyberCrypt keeps different categories of data. Our default is to keep as little as possible for as short a time as possible.
Transferred files and messages
- Burn-after-download — a delivered file is permanently deleted the moment the recipient downloads it.
- Undelivered content — content that is never retrieved is deleted when its retention window expires. The window depends on your plan (for example, several days on Free and longer on paid plans) and, where available, on retention settings you configure.
- Deletion method — stored blobs are overwritten and then unlinked. Because they are stored only as ciphertext, expiry also renders any residual bytes unreadable.
Account data
Account records (username, email, encrypted key material, settings) are retained while your account is active. After account closure they are deleted within a limited wind-down period, except where we must retain limited records to comply with law, resolve disputes, or enforce agreements.
Logs and audit records
Operational and security logs, including the tamper-evident audit log, are retained for a limited period appropriate to security and compliance needs, then deleted or aggregated.
Backups
Encrypted backups, where used, are rotated on a defined schedule; deleted content ages out of backups within that cycle.
Contact
Questions about retention: privacy@kybercrypt.com.