Privacy statement
Last updated on
SecretsMonkey is built to know as little about you as possible. This statement describes exactly which data we store, why, for how long, and what we can and cannot see of your secrets. Nothing in it claims anything the software does not actually do.
Who is responsible
SecretsMonkey is a service of MonkeySoft, established in the Netherlands. MonkeySoft is the data controller for the data processed on this website.
Questions about this statement or about your data go to hallo@monkeysoft.nl. We respond within thirty days.
- MonkeySoft, Eiland van Surya 23, 1705 SH Heerhugowaard
- Chamber of Commerce number 37133843
- Email hallo@monkeysoft.nl
What we cannot see of your secret
The content of a secret is encrypted and decrypted in your own browser, using its built-in WebCrypto functions. The key is created there and never leaves your browser, except as part of the share link — and even then only in the part after the # sign, which no browser ever sends to a server. We never hold that key at any point, not even briefly during creation or reveal.
Whoever gets hold of the database — us, an administrator, an intruder or a judicial authority — has only encrypted text and an irreversible fingerprint of the link's lookup id, and nothing to open that text with. The full link, including the part after the # sign, is the key, and you have it.
The same design applies to a secret request: whoever answers it encrypts directly to your public key in their own browser, and only your own passphrase-locked private key can open the answer again. That step, too, happens entirely in the browser.
One exception, which we name explicitly because it differs: the label you give a secret yourself is encrypted with the application key, not with the key from the link. It has to be, because the label appears in your own overview and needs to be readable there. So do not put confidential information in it.
What we store per capability
For each part of the service, this is what gets recorded. There is nothing beyond it.
- Account: your name, email address, a fingerprint of your password, and, if you set them up, the details for two-factor authentication or passkeys. You can use the service perfectly well without an account.
- Secret: the encrypted content, the encrypted label, the kind of secret, the expiry time, how often it may be viewed and how often that has happened.
- Request: the description you write yourself, the expiry time and the encrypted answer from whoever fills it in.
- Access log: for every attempt to open or answer a secret, a fingerprint of the network block, a coarse device label and the outcome — succeeded, expired, wrong password, not found.
- Audit log: which action happened when, and whether it succeeded. Never the content of a secret, never a password, never a token.
- Email: if you switch on a notification, we send a message to your own address. It never contains the content of a secret, only that something is waiting.
- Session and preferences: a session cookie once you sign in, a cookie for your language choice, and your light or dark preference in your own browser storage.
Why we do not keep your IP address
To be able to spot abuse — someone walking thousands of links to guess one — we need to be able to tie attempts together. A full IP address is not required for that.
The address is therefore first truncated to its network block: for IPv4 the first three numbers remain, for IPv6 the first six bytes. Only then does it go through a keyed fingerprint function with a secret addition. The result is a string that makes two attempts from the same block recognisable and that cannot be calculated back to an address — precisely because information was thrown away before the fingerprint was taken.
Of your browser we keep only a coarse label such as "Chrome on macOS". The full browser string is a fingerprint and we do not store it.
No tracking, no advertising
There is no analytics software on this site, no advertising network, no social buttons and no script from any other party at all. The security settings of the site actively forbid loading those, so none can slip in unnoticed either.
We set no cookies that follow your behaviour. The cookies that do exist — session and language choice — are needed to make the service work and therefore require no consent.
How long we keep it
We keep things for as short a time as the capability allows. These are the periods:
- The content of a secret: until it has been viewed or until its expiry passes, and no longer. After that the encrypted text is erased and only the empty record remains for your overview.
- A secret without an account: twenty-four hours at most, even if nobody looks.
- Access logs: ninety days.
- Notifications: ninety days.
- Audit logs: twelve months.
- Account data: until you delete your account.
Where it runs
SecretsMonkey runs on our own servers at Hetzner in Germany. All data — the database, the backups and the log files — stays within the European Economic Area.
There is no transfer to countries outside the EEA. We use no American cloud storage, no American analytics services and no content network that handles your requests outside Europe.
The General Data Protection Regulation applies to this processing, as does Dutch law.
Who else can reach it
As few parties as possible. This is the complete list:
- Hetzner, Germany — supplies the servers the service runs on.
- Lettermint, the Netherlands — sends the service emails. Sees the receiving address in doing so, never the content of a secret.
Your rights
You have the right to access your data, to have it corrected, to have it erased, to receive it in a readable file, and to object to the processing.
Erasure you can do yourself: under Settings there is a button that permanently wipes your account and everything attached to it. Your secrets go with it. The security logs keep the fact that something happened, but the reference to you is severed — the security trail survives, the identity does not.
For access and portability you can download a readable file of your data yourself: there is a button for that under Settings. For correction, send a message to hallo@monkeysoft.nl; we respond within thirty days.
If something goes wrong
In the event of a data breach carrying a risk to you, we report it to the Dutch Data Protection Authority within seventy-two hours, and directly to you when the risk is high.
What a breach would mean in practice is limited by the design: a stolen database contains no readable secrets and no IP addresses.
Changes
If what we store changes, this statement changes with it and the date at the top moves forward. For a material change, account holders are notified by email.