Privacy Policy
Last updated: July 23, 2026
1. Data Controller
Under the EU General Data Protection Regulation (GDPR), the data controller is the operator of hushhh.cc, a private individual based in Spain. The controller's identification details are available to the competent authorities upon lawful request.
2. Secrets & Zero-Knowledge Guarantee
Content is encrypted in your browser using AES-256 before transmission. The decryption key travels in the URL hash fragment (#key) and never reaches server infrastructure.
Every secret is permanently destroyed from database storage upon first read, or automatically when its TTL expires (up to 30 days max). No backup copies exist.
3. Geolocation & Security Telemetry
To prevent abuse and monitor regional utilization, secret events record timestamp, event type, an anonymized IP address (truncated before storage, e.g. 203.0.113.0) and coarse geographic origin (country/region) derived from the IP. Raw events are kept for a maximum of 30 days, then reduced to aggregate per-region counters containing no identifiers. IPs are never linked to payload content.
4. Infrastructure & EU Storage
Hosted on cloud infrastructure within the European Union (Madrid, Spain). Data at rest does not leave the EU. Proxied through Cloudflare for security & DDoS protection under EU-US Data Privacy Framework guidelines.
5. Cookies & Usage Measurement
Zero advertising cookies, zero user profiling. The public site sets no cookies, which is why there is no cookie banner. Cloudflare may set strictly-necessary security cookies (e.g. __cf_bm), exempt from consent. A session cookie is set only in the private administration area used by site staff, and — if you choose to create an optional account — for your own logged-in session (see below).
We measure aggregate site usage (page views, clicks, scroll depth, load performance) with a self-hosted, cookie-less analytics script operated by the site operator. It stores nothing in your browser, honors the Do Not Track setting, and is stripped of secret URLs at the source: neither secret identifiers nor decryption key fragments are ever transmitted to it.
6. Legal Basis
Storing and delivering your secret is necessary to provide the service you request (art. 6(1)(b) GDPR). Security logging and anonymized aggregate statistics rely on the legitimate interest of keeping the service secure and understanding usage (art. 6(1)(f) GDPR).
7. Optional Member Accounts
Creating an account is entirely optional — anonymous use is unaffected and remains the default. If you register, we store your username, a salted password hash (never the password itself), and an email address only if you choose to provide one. A logged-in session is identified by an HttpOnly cookie; a bearer API token exists only if you generate one yourself.
Being logged in only ever grants us metadata about your secrets (creation time, expiry, encryption flag) so you can review and revoke them before they're read — the encrypted content itself is exactly as inaccessible to us as it is for anonymous secrets. Deleting your account permanently removes your credentials, revokes your live secrets and API tokens, and strips your account association from past security telemetry rather than deleting it outright (kept anonymized, as described in section 3).
8. Your Rights
Under the GDPR you hold the rights of access, rectification, erasure, restriction, portability and objection. Because IPs are anonymized at collection and secrets carry no identity, the service is in most cases technically unable to link stored data to any individual — encrypted secrets destroy themselves, which is rather the point. You may lodge a complaint with the Spanish supervisory authority (AEPD) or your local EU data protection authority.