Legal
Disclaimer
What the guidance on this site is, what it is not, and where our responsibility ends and yours begins.
General information, not personal advice
Everything published on this site — articles, feature pages, the glossary, the security architecture and threat model documents — is general information about encryption, privacy and secure communication practice. It is written carefully and reviewed before publication, but it is written without knowledge of your particular circumstances.
Security decisions depend heavily on context: what you are protecting, who might want it, what the consequences of loss would be, and what obligations you are already under. Guidance that is correct for a freelance designer sharing a client login may be entirely wrong for a healthcare provider handling patient records. We cannot know which situation you are in.
Not legal or compliance advice
We are not lawyers, and nothing here is legal advice. Where we mention regulatory concepts — data minimisation, storage limitation, the GDPR — we are describing the concept, not advising you on your obligations under it.
No tool makes an organisation compliant
Specifically, because Inkrypt has no accounts, it produces no attributable access logs. Any control requiring you to demonstrate who accessed what and when cannot be satisfied by it. If you are subject to such requirements, factor that in before adopting it.
No warranty of security
We document our cryptographic design in detail on the security architecture page precisely so it can be evaluated rather than taken on faith. We also document its known limitations on the threat model page. Both are honest accounts, and neither is a guarantee.
- No software is free of defects. Ours has not been independently audited, which we state plainly rather than let you infer.
- Cryptographic practice changes. Parameters considered adequate today may not be in five years.
- Availability is not guaranteed. This is a free service with no uptime commitment. Do not rely on it for anything you cannot afford to lose access to.
- No recovery exists. A forgotten password means a permanently unreadable note. This is by design and cannot be worked around by us.
Inkrypt is provided as-is. If the consequences of a note being lost or exposed would be severe, use a tool with an independent audit, a support contract, and a recovery model that matches your risk tolerance.
Accuracy and currency
We fact-check against primary sources and re-review pages on a schedule described in our editorial policy. Every substantial page shows a last-reviewed date. Despite that, information here may become outdated between reviews, or may simply be wrong.
If you find an error, tell us at work.securetext@gmail.com. Material corrections are published with a dated note on the affected page rather than made silently.
External links
We link to standards documents, security guidance and third-party tools where they are genuinely useful. We do not control those sites and are not responsible for their contents, accuracy or availability. A link is not an endorsement of everything on the destination.
Where we describe another product, we do so from its own public documentation at the time of writing. Products change. Verify against the vendor's current documentation before making a decision.
Your responsibility
You are responsible for what you put into a note, who you share it with, and how you send the password. Nothing on this site removes that responsibility.
- Assess your own risk before deciding this tool is appropriate. If you are unsure, that uncertainty is itself information.
- Keep independent copies of anything you cannot afford to lose. There is no recovery.
- Follow your organisation's policies. They may prohibit third-party tools for certain data regardless of how the tool works.
- Do not use Inkrypt for unlawful purposes. See the terms of service and our abuse reporting page.
Frequently asked questions
Is the guidance on this site professional security advice?
Does using Inkrypt make my organisation GDPR compliant?
Do you guarantee my notes will be secure?
What if I lose access to a note?
Read the threat model first
If you are deciding whether Inkrypt fits your situation, the threat model is the most useful page on this site.
Open the notepad