CLASSIFIED.FI
Policy Document
P-02 · Public
Policy P-02

Privacy Policy

Effective at launch · Written to be read, not skimmed

Most privacy policies exist to disclose how much of you gets collected. Ours is short because the honest answer is: almost nothing, on purpose, by architecture.

⬡ The Zero-Access Fact

Your messages are encrypted with keys derived from your passphrase. We do not have your keys, we cannot decrypt your mail, and no request, breach, or employee can change that. Every promise below is easier to keep because of this one.

01What We Collect

Your address & account emailNeeded to run your mailbox and reach you about your account
BillingHandled by our payment processor — we never see or store card numbers
Operational logsConnection metadata (IPs, timestamps) kept ~7 days for abuse defense and debugging, then deleted on rotation
Aggregate countsTotal messages, storage used — numbers, never contents

02What We Will Never Do

03Legal Requests

We comply with valid legal process. What that yields is what we hold: account registration details and recent connection metadata. Message content is stored as ciphertext and is produced as ciphertext — we possess no means to decrypt it. We deal in lawful cooperation, not backdoors, and we will publish a transparency report counting the requests we receive.

04Your Rights

Our servers are in Finland, in the European Union; if you're in the EU, GDPR rights apply to the account data described above. The service is operated from the United States — jurisdiction stated plainly, because vagueness is what you should distrust in a privacy product.

05The Honest Warning

Zero-access cuts both ways: if you lose your passphrase and your recovery kit, your mail is gone. Not "contact support" gone — mathematically gone. We cannot reset what we cannot read. Print the recovery kit the app offers you. This paragraph is the only part of this policy we hope you never think about again.

classified.fi · Policy P-02 Questions: admin@classified.fi