Privacy Policy
Effective date: 18 July 2026. XSeal is operated by Website Holding.
XSeal is built so that your documents stay yours. This policy explains exactly what we collect, what we never collect, and the rights you have over your data.
What we never collect
We do not receive, transmit, or store the contents of the files you seal. When you seal a file, its SHA-256 hash is computed and only that digest leaves your browser. The bytes of your document are never sent to or held by XSeal.
What we store
- Seal records: the SHA-256 hash, the file name and size you provide, the UTC timestamp, and the Seal ID and signature.
- Bulk-seal manifests: if you seal a batch of files at once, we store one combined, signed manifest record referencing each file's individual seal, the same way a single seal is stored.
- Account data: your email address and a securely hashed password, if you create an account to keep a seal history.
- API keys: if you create one, only a salted hash of the key is stored — the raw key is shown once and cannot be recovered by us.
- Upgrade requests: if you request a plan upgrade in-app, we store that request (your account and the requested plan) so it can be reviewed.
- Operational logs: minimal request logs used to keep the service secure and reliable.
- Support messages: if you use the contact form, the name, email, topic and message you send, so we can reply.
Data retention
Seal records and account data are kept for as long as your account is active, so your seal history stays verifiable; you can delete individual seals at any time, and closing your account removes your account data. Support messages are kept while we handle your request and for a reasonable period afterwards. Operational logs are rotated on a short cycle. We keep only the minimum needed to run the service and meet our legal obligations.
Third-party processors
We share data only with the processors that help us run XSeal:
- Website Holding: our operator and merchant of record, which handles accounts, billing and support.
- Cloud hosting (Amazon Web Services): the application and database run on AWS infrastructure in the EU.
- Payment processing: when self-serve card checkout is enabled, card payments will be handled by Website Holding's payment provider and we will never see or store full card numbers. Until then, paid plans are arranged directly with the operator and no card data is collected by XSeal at all.
Cookies
We use a single, strictly necessary session cookie to keep you logged in. We do not use advertising or third-party tracking cookies.
Payments
Paid plans are billed by Website Holding as merchant of record. Self-serve card checkout is not yet live: today, an upgrade request you make in-app is reviewed and granted directly by the operator, and no card data is collected. When checkout goes live, card details will be handled by the payment processor and will never be stored by XSeal.
Your rights
Under the GDPR you can request access to, correction of, or deletion of your account data and seal history. You can delete individual seals from your dashboard at any time, or contact us to close your account.
Contact
Questions about privacy? Reach us via the contact page and we will respond promptly.