Privacy Policy
Last updated: September 9, 2026
1. Controller
Theka.dev SINGLE MEMBER P.C. (Theka.dev ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε.) (GEMI 194371006000, VAT EL803312906) is the controller for personal data processed by the Kryptic cloud service. Contact: [email protected].
2. What we process
Account data (name, email, role, organization), authentication data (password hashes - Argon2id - or SSO identifiers), operational data (audit logs with actor, action, IP address and timestamp; daemon session metadata such as device name and platform), and billing data processed by Stripe. The content of your secrets is encrypted end-to-end on your devices; we hold no key that can read it.
3. Why we process it (legal bases)
To provide the service you contracted for (Art. 6(1)(b) GDPR), to secure it and keep audit trails (Art. 6(1)(f) - legitimate interest in security), to comply with bookkeeping and tax law (Art. 6(1)(c)), and, where you opt in, to send product updates (Art. 6(1)(a) - withdrawable at any time).
4. Processors and transfers
We use a small set of processors: EU-region infrastructure providers for hosting, Stripe for payments, and an email delivery provider for transactional mail. Customer data is hosted in the EU. Where a processor transfers data outside the EEA, standard contractual clauses apply.
5. Retention
Account data is kept while the account exists and deleted or anonymized within 30 days of deletion. Audit logs follow your plan's retention window. Invoicing data is kept as long as Greek tax law requires.
6. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority - in Greece, the Hellenic Data Protection Authority (dpa.gr). Write to [email protected] to exercise them.
7. Cookies
The marketing site keeps your cookie-dialog choice and, if you allow it, your theme preference in local storage. Starting Google, GitHub, or Microsoft signup on kryptic.dev/register sets one first-party cookie named kryptic-oauth (httpOnly, SameSite=Lax, 10 minutes) so the provider can return you to this site. After signup the session is handed to app.kryptic.dev, which stores a refresh token and your theme preference in local storage. Advertising conversion measurement (Google Ads) runs in cookieless consent mode: consent for ad storage is permanently denied, so no advertising cookies or identifiers are stored on either site.