Skip to main content

Legal

Disclaimer

What the guidance on this site is, what it is not, and where our responsibility ends and yours begins.

Last reviewed Reviewed by Inkrypt Editorial

General information, not personal advice

Everything published on this site — articles, feature pages, the glossary, the security architecture and threat model documents — is general information about encryption, privacy and secure communication practice. It is written carefully and reviewed before publication, but it is written without knowledge of your particular circumstances.

Security decisions depend heavily on context: what you are protecting, who might want it, what the consequences of loss would be, and what obligations you are already under. Guidance that is correct for a freelance designer sharing a client login may be entirely wrong for a healthcare provider handling patient records. We cannot know which situation you are in.

We are not lawyers, and nothing here is legal advice. Where we mention regulatory concepts — data minimisation, storage limitation, the GDPR — we are describing the concept, not advising you on your obligations under it.

No tool makes an organisation compliant

Compliance is a property of an organisation's processes, not of any software it uses. Using client-side encryption may support principles like data minimisation, but it does not by itself satisfy any regulatory requirement. Consult your data-protection lead or legal counsel about your specific obligations.

Specifically, because Inkrypt has no accounts, it produces no attributable access logs. Any control requiring you to demonstrate who accessed what and when cannot be satisfied by it. If you are subject to such requirements, factor that in before adopting it.

No warranty of security

We document our cryptographic design in detail on the security architecture page precisely so it can be evaluated rather than taken on faith. We also document its known limitations on the threat model page. Both are honest accounts, and neither is a guarantee.

  • No software is free of defects. Ours has not been independently audited, which we state plainly rather than let you infer.
  • Cryptographic practice changes. Parameters considered adequate today may not be in five years.
  • Availability is not guaranteed. This is a free service with no uptime commitment. Do not rely on it for anything you cannot afford to lose access to.
  • No recovery exists. A forgotten password means a permanently unreadable note. This is by design and cannot be worked around by us.

Inkrypt is provided as-is. If the consequences of a note being lost or exposed would be severe, use a tool with an independent audit, a support contract, and a recovery model that matches your risk tolerance.

Accuracy and currency

We fact-check against primary sources and re-review pages on a schedule described in our editorial policy. Every substantial page shows a last-reviewed date. Despite that, information here may become outdated between reviews, or may simply be wrong.

If you find an error, tell us at work.securetext@gmail.com. Material corrections are published with a dated note on the affected page rather than made silently.

We link to standards documents, security guidance and third-party tools where they are genuinely useful. We do not control those sites and are not responsible for their contents, accuracy or availability. A link is not an endorsement of everything on the destination.

Where we describe another product, we do so from its own public documentation at the time of writing. Products change. Verify against the vendor's current documentation before making a decision.

Your responsibility

You are responsible for what you put into a note, who you share it with, and how you send the password. Nothing on this site removes that responsibility.

  1. Assess your own risk before deciding this tool is appropriate. If you are unsure, that uncertainty is itself information.
  2. Keep independent copies of anything you cannot afford to lose. There is no recovery.
  3. Follow your organisation's policies. They may prohibit third-party tools for certain data regardless of how the tool works.
  4. Do not use Inkrypt for unlawful purposes. See the terms of service and our abuse reporting page.

Frequently asked questions

Is the guidance on this site professional security advice?

No. It is general information, written and reviewed carefully but without knowledge of your specific circumstances. For decisions with significant consequences, consult a security professional who can assess your actual situation.

Does using Inkrypt make my organisation GDPR compliant?

No. Compliance is a property of your processes, not of any tool. Client-side encryption and expiry can support principles such as data minimisation, but they satisfy no requirement on their own. Consult your data-protection lead.

Do you guarantee my notes will be secure?

No. We document the design and its known limitations so you can evaluate it, but no software is defect-free and Inkrypt has not been independently audited. It is provided as-is.

What if I lose access to a note?

There is no recovery — we hold no key. Keep an independent copy of anything you cannot afford to lose, and do not treat Inkrypt as a backup system.

Read the threat model first

If you are deciding whether Inkrypt fits your situation, the threat model is the most useful page on this site.

Open the notepad