Privacy Policy
Last updated: August 19, 2026
This Privacy Policy explains how Cybegon LLC (“VegaCrypt,” “we,” “us”) processes information when you use VegaCrypt, including the website, the web application, company workspaces, and official integrations we provide (such as the Outlook add-in).
It should be read together with our Terms of Use.
1. General Principles
1.1. VegaCrypt is built for confidential, time-limited transfer of files and messages. Transfer content is encrypted on your device before upload. We store ciphertext. We do not have the keys required to decrypt that content and do not inspect its plaintext.
1.2. We do process personal and account data needed to operate the service (for example email addresses, sessions, billing records, and security logs). We do not sell personal data and do not use transfer content for advertising or profiling.
1.3. Registration is not required for basic Password Access transfers. An account, a company workspace, Dual-Key Link, Vault, Safebox, billing, and official integrations involve additional information, as described below.
2. Information We Process
The information we process depends on how you use VegaCrypt.
2.1. Anonymous transfers
If you send a Password Access transfer without an account, we process:
- The encrypted payload (ciphertext) and technical metadata needed to store and expire it;
- The transfer settings you choose (lifetime, delete-after-first-open, and similar);
- A password hash used only as an access check — not the password that decrypts the content;
- Security and anti-abuse signals (such as IP address and form-protection tokens).
We do not require a name or email to create that transfer. If you enter a recipient email or enable notifications, we process that email to send the message you requested.
2.2. Accounts
If you create an account or sign in, we process:
- Email address and hashed account password, or identifiers provided by a supported single sign-on provider (such as Google or LinkedIn);
- Profile and plan information (tier, language, notification preferences);
- Session records (including IP address and browser user agent) to keep you signed in and to secure the account;
- Encryption Master Password (EMP) material and recovery data only in wrapped/encrypted form. We do not receive EMP or the recovery code in a form that allows us to decrypt your Vault content. EMP is not your sign-in password.
Account password reset is performed by email.
2.3. Recipients, Dual-Key Link, Vault, and Safebox
Depending on the feature, we may process:
- Recipient or guest email addresses that you enter;
- Dual-Key Link verification codes and the server-held key half (which is not sufficient to decrypt the content without the link fragment);
- Vault public-key material and wrapped private keys;
- Encrypted Inbox metadata (sender, type, time, channel name — not plaintext content);
- Safebox channel settings, invite emails, and guest submission metadata.
2.4. Company workspaces
If you use or administer an organization workspace, we process company name, subdomain, admin and member emails, seat/license assignments, and tenant administration records needed to run that workspace.
2.5. Billing
Paid plans are processed by Stripe. VegaCrypt does not store full card numbers. We store Stripe customer and subscription identifiers, plan status, and invoice records needed to provide and account for paid service.
2.6. Support and contact
If you use the website contact form or in-app Support tickets, we process the contact details and messages you submit, including any attachments you upload to a ticket.
2.7. What we do not collect for advertising
We do not build advertising profiles from transfer content. We do not sell personal data.
3. Cookies
3.1. Necessary cookies
We use strictly necessary cookies and similar technologies for sign-in, session management, CSRF and form protection, and security of official integrations (for example authentication token, session, CSRF token, and short-lived Outlook or embed security cookies). These are required for the service to function.
3.2. Marketing cookies (marketing website only, with consent)
On our marketing website, if you choose “Accept all” in the cookie banner, we may load Google tag (gtag) to measure site usage and run advertising. You can refuse by choosing “Only necessary”; then no marketing cookies are set. Your choice is stored for 12 months, after which we may ask again.
We do not use advertising or analytics cookies without your explicit consent. You can change your mind by clearing the consent cookie or contacting us.
4. Technical Logs and Other Records
4.1. Standard web server and security logs (such as IP address, browser type, and operating system) are kept for security monitoring and attack prevention. These logs are rotated and stored for no more than 15 days. They are not used to profile users for advertising.
4.2. Account sessions, transfer history metadata, company administration records, billing records, and support tickets are retained separately as needed to operate the service. They are not limited to the 15-day security-log window.
5. Encryption and Storage of Transfer Content
5.1. For File Transfer, Text Message, Voice Message, and Video Message, content is encrypted on the user’s device before upload (Password Access, Dual-Key Link, or Send to VegaCrypt user). The server stores ciphertext and method-specific key material that is not enough, on its own, to read the content.
5.2. Ciphertext may be stored on our servers or with our cloud storage provider. Storage providers hold encrypted objects; they do not receive plaintext transfer content from us.
5.3. We cannot decrypt transfer content. If a link, link fragment, transfer password, EMP, or recovery code is lost, we cannot restore access.
6. Sharing and Processors
We do not sell personal data. We share information only as needed to operate VegaCrypt:
- Payment: Stripe, to process subscriptions and invoices;
- Sign-in: Google or LinkedIn, only if you choose to sign in with that provider;
- Infrastructure: Hosting, cloud storage, and email delivery used to run the service and send transactional messages (verification, password reset, Dual-Key or Safebox emails, billing notices);
- Advertising measurement: Google, only if you consent to marketing cookies on the marketing website;
- Legal: If required by law or to protect the service, users, or others.
Third parties process data under their own terms where you interact with them directly (for example Stripe Checkout or a Google sign-in screen).
7. Retention and Deletion
7.1. Transfer content. Encrypted transfers are deleted after the first download or view (if that option is enabled), when the selected storage period expires, or when the sender or authorized account holder removes the item. Maximum transfer lifetime depends on account type and plan and is stated on the website. The current maximum is 30 days, except where a company workspace is configured otherwise within the limits shown in the product.
7.2. Account and operational data. Account records, Encrypted Inbox items, Safebox settings, company records, billing records, and support tickets are kept while needed to provide the service and as required by law (for example invoice records). They are not subject to the same short lifetime as an anonymous one-time transfer.
7.3. Account deletion. Signed-in users may delete their account in the application. We then delete or anonymize account data we no longer need. Some records may remain in anonymized form (for example transfer history events with the user unlinked) or as required for tax, security, or legal obligations.
8. Your Rights
8.1. Depending on applicable law, you may request access to, correction of, or deletion of personal data we hold about you, or object to certain processing.
8.2. Account holders can review and update profile information in the application and can delete their account. For other requests, contact us using the details in section 11.
8.3. We cannot provide plaintext of transfer content, and we cannot restore access to encrypted content if you have lost the required link, password, EMP, or recovery code.
8.4. We will not refuse a request on the false ground that “no personal data is stored.” Account, billing, support, and security records are personal data where they identify you.
9. Children’s Privacy
The service is not intended for children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it where required.
10. Changes to This Policy
We may change this Privacy Policy at any time. The current version is always published on this page. Continued use of the service after changes are published means acceptance of the new version.
11. Contact
For questions about privacy or this Policy, contact us via the form on the website, by email at [email protected], or — if you have an account — through Support tickets in the application.