Privacy Notice
This notice explains how OpenE2EE handles personal information across the website, documentation, console, OpenE2EE Relay, licensing, billing, and communications.
This is the immutable copy of that version. It is what this notice said while version 2026-08-26 was current, and it does not change. The notice that governs today is the current Privacy Notice.
1. Scope and controller
OpenE2EE LLC (“OpenE2EE,” “we,” “us,” or “our”) is responsible for personal information covered by this notice. It applies to open-e2ee.dev, the OpenE2EE documentation and console, OpenE2EE Relay, commercial licensing and billing, support and sales communications, and related security operations.
This notice does not govern information processed solely inside software that you operate. When a customer uses the SDK in its own product, that customer determines its application data practices and is responsible for its notices. For Managed Relay, OpenE2EE processes the service data described below on that customer’s instructions.
2. Information we collect
Information you or your organization provides
- contact information, such as name, business email, organization, and communication content;
- commercial-license information, including licensee, covered product, plan, and support requests;
- billing information, such as billing address and tax identifier; and
- security reports, feedback, and other information you choose to send.
Information from connected services
- WorkOS: when you sign in, WorkOS provides an account identifier, authentication events, organization information, and available profile information such as name and email.
- Stripe: Stripe provides customer, subscription, invoice, payment-status, billing, and tax information needed to complete and administer a license. OpenE2EE does not intentionally receive or store complete payment-card numbers.
- Your organization: an authorized purchaser or administrator may provide information about license users, billing contacts, or the covered product.
Managed Relay information
- customer-encrypted envelopes, shared encrypted group bodies, and encrypted attachment bytes;
- public key material and signed public certificates needed for device registration and authenticated or sealed-sender delivery;
- opaque project, account, device, mailbox, operation, routing, usage, lifecycle, recovery, and deletion identifiers and state;
- push-provider tokens and generic best-effort wake requests, which may include a generic encrypted-message alert but no message plaintext; and
- exact aggregate usage, plan, spend-limit, billing, reconciliation, security, and audit records needed to operate the service.
Relay does not need message plaintext, device private keys, ratchet state, attachment keys, decrypted attachment content, or a server-side social graph. Network providers can process the request metadata inherent in carrying traffic.
Technical information
Our hosting and security providers may process IP address, request time, URL, referring page, browser and device information, authentication and session events, request size and timing, error information, and security signals. Relay also processes bounded operational telemetry, such as delivery state, queue lag, retry, capacity, and lifecycle outcomes. The console uses signed, secure cookies needed for authentication, request integrity, and account access. The marketing site additionally records a small set of anonymous events with no identifier attached, described in full in Cookies and analytics.
3. How and why we use information
We use personal information to:
- authenticate users and operate the website, documentation, console, Relay, and billing portal;
- create, fulfill, document, renew, support, and enforce commercial licenses;
- process payments, invoices, taxes, cancellations, and accounting records;
- answer support, sales, licensing, privacy, and security communications;
- protect the Services, investigate abuse, debug failures, and prevent fraud;
- improve documentation, reliability, and product experience; and
- comply with law and establish, exercise, or defend legal claims.
Where the law requires a legal basis, we rely on performance of a contract, steps requested before entering a contract, compliance with legal obligations, our legitimate interests in operating and securing the Services, and consent where required. You may withdraw consent for future processing when consent is the basis.
4. How we disclose information
We disclose information only as reasonably necessary to:
- Service providers: Cloudflare for Relay, encrypted storage, the public site, DNS, TLS, and security; Vercel for the console and documentation; WorkOS for authentication and organization identity; Stripe for payments, subscriptions, tax information, and the billing portal; Expo, Apple, Google, and browser push services for best-effort device wakes; Better Stack for availability monitoring and public status; and Google Workspace for business email. The current list is at Subprocessors.
- Professional advisers: accountants, lawyers, insurers, auditors, and security specialists subject to appropriate duties.
- Legal and safety recipients: authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate fraud or abuse, or respond to lawful process.
- Business transactions: a buyer, successor, or adviser in a financing, reorganization, acquisition, or sale, subject to appropriate confidentiality and continued protection.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising or use it for targeted advertising, and we have not done so during the preceding 12 months. We do not use personal information for automated decisions that produce legal or similarly significant effects.
5. Cookies and analytics
The public marketing site sets no cookies, stores nothing in your browser, and uses no advertising or cross-site behavioral analytics. It does measure which parts of the site people use, and this section describes that measurement exactly, because a privacy notice that describes it vaguely is not worth reading.
The site sends a short message to our own servers when one of ten things happens: you run the live demo on the home page, open the quickstart, choose a runtime, copy the install command, follow the closing link of an article or the architecture guide, open one of our GitHub repositories, view the security model page, view the pricing page, open the console, or begin an enterprise enquiry. Each message contains the name of the event, the path of the page it happened on, and one further word on a single one of them: which of the three runtimes a runtime choice was. That is the whole message.
The live demo is the one place on this site where you type something. What you type is encrypted and decrypted inside your own browser tab and never leaves it, and the message that records the run carries neither the sentence nor anything derived from it — not its length, not the size of the ciphertext, not how long the encryption took. The message reads demo_run /, and one is sent per page, not per sentence.
It contains no identifier of any kind. We set no cookie, read no cookie, and write nothing to local storage; we do not fingerprint your browser or device; we assign you no visitor or session identifier; and your IP address is not recorded alongside these events. Because there is nothing that distinguishes one visitor from another, these events cannot be linked to you, to each other, or into a journey through the site, either by us or by anyone who obtained the data. What they show is how many people took each step, and nothing else. The measurement is handled by our own code on our own infrastructure, and no third-party analytics service receives it.
The console uses essential authentication, security, and session cookies. Cloudflare, Vercel, WorkOS, and Stripe may use their own necessary security or service cookies when you interact with their infrastructure or hosted pages.
Because we do not sell or share information for targeted advertising, there is no advertising opt-out needed for the current Services. We will honor legally required browser signals if our practices change in a way that makes them applicable.
6. Retention and security
We retain personal information only as long as reasonably necessary for the purposes above. Retention depends on the record:
- console authentication data is primarily maintained in signed session cookies and connected-provider records;
- Relay ciphertext follows the project retention setting: the Development environment uses 24 hours by default and permits no more than seven days, while production permits no more than 30 days;
- incomplete attachment uploads expire after 24 hours and completed attachments have a 30-day maximum retention;
- opaque usage, billing, reconciliation, security, recovery, and deletion records follow their documented retry, accounting, audit, and legal periods after payload deletion;
- license, subscription, invoice, and transaction records may be kept for the relationship and up to seven years afterward for accounting, tax, audit, and dispute purposes;
- support, sales, and security communications are kept as needed to resolve the matter and maintain appropriate records; and
- request and security logs are generally kept for shorter periods determined by operational and provider settings, unless needed to investigate an incident.
The Relay Retention Statement explains account and project deletion, recipient mailbox boundaries, group state, and lifecycle backstops.
We use administrative, technical, and organizational safeguards appropriate to the nature of the information, including encrypted transport, restricted credentials, least-privilege service keys, secure session cookies, and access controls. No system is perfectly secure, and we cannot guarantee absolute security.
7. Your privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, or a copy of personal information; to object to or restrict certain processing; to withdraw consent; and to appeal a decision. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
California residents may request the categories and specific pieces of personal information collected, the sources, purposes, and disclosure categories; request correction or deletion subject to exceptions; and receive equal service when exercising these rights. OpenE2EE does not sell or share personal information as those terms are defined by California law.
Submit a request to support@open-e2ee.dev. Describe the request and the account or email involved. We may need to verify your identity and authority before acting. An authorized agent may submit a request where applicable. You may appeal a denial by replying with “Privacy appeal” in the subject. You may also complain to your local data-protection authority.
Children
The Services are intended for developers and businesses and are not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child provided it.
8. International transfers
OpenE2EE is based in the United States, and service providers may process information in the United States and other countries. Those countries may have different data-protection laws. Where required, we rely on recognized transfer mechanisms and contractual safeguards made available through our providers.
9. Changes and contact
We may update this notice as our practices or legal obligations change. We will publish a new effective date and provide additional notice when a change is material. We will not apply a materially more permissive use or disclosure practice retroactively to previously collected information without appropriate notice and consent where required.
Version 2026-07-28: the marketing site began recording the anonymous usage events described in Cookies and analytics, nine of them at that date. No cookie, storage, identifier, or IP-address record was introduced with them, and nothing collected under an earlier version of this notice is affected.
Version 2026-08-07: a tenth event was added, recording that the live demo on the home page was run. It carries nothing about what was typed into the demo, as described in Cookies and analytics. Nothing else about the measurement changed: still no cookie, no storage, no identifier, and no IP-address record.
Version 2026-08-07.2: a second change on the same day, and the reason that version carries a suffix rather than a later date. An eleventh event was added, recording which scenario was opened. The name of the scenario is the second and last word any event on this site carries, and it describes the page rather than the visitor, as described in Cookies and analytics. Nothing else about the measurement changed: still no cookie, no storage, no identifier, and no IP-address record.
Version 2026-08-09: no new event, no new category of information, and nothing additional collected. The failure scenarios moved from a page of their own onto the home page, and the message that records one names the page it happened on, so the path in that message changed with the move — it then read scenario_opened / followed by the name of the scenario. This notice is versioned for it because the words the site transmits changed, and a notice that quotes those words exactly, as this one does, cannot describe them and stay unversioned. Still no cookie, no storage, no identifier, and no IP-address record.
Version 2026-08-16: an event was removed. The failure scenarios left the site, and the message that recorded one — scenario_opened / followed by the name of the scenario — is no longer sent at all. The site now records ten things rather than eleven, and no event carries a scenario name. The name of a scenario was the only label any event but a runtime choice ever carried, so a runtime choice is now the one event on this site that carries a second word at all. Nothing was added, no category of information is new, and nothing already collected is affected: still no cookie, no storage, no identifier, and no IP-address record.
Version 2026-08-26: OpenE2EE Relay was added to the service scope. This version identifies the encrypted content, public key material, opaque routing and usage state, push tokens, providers, and retention boundaries that managed delivery requires. It also corrects the console authentication provider from GitHub to WorkOS. The anonymous website measurement did not change.
For privacy questions or requests, email support@open-e2ee.dev. For suspected vulnerabilities or security incidents, email security@open-e2ee.dev.