Draft — last updated 2026-10-05
Privacy
Lockbox is run by Opslane. We built it so we can't read what you share. This page says what we do collect, why, and for how long.
The short version
- Your secrets and files are encrypted on your device before they reach us. We can't decrypt them.
- We store the minimum needed to run the service: email addresses, public keys, and share details like sizes and times.
- We don't sell data, show ads, or use tracking cookies.
What we collect
| Data | Why |
|---|---|
| Your email address | To log you in with a code, and so people can share with you. |
| Public keys for your account and each device | So others can encrypt shares that only your devices can open. Public keys can't decrypt anything. |
| IP address | To limit how often someone can try codes or create shares. Used for rate limiting. |
| Share details: sizes, times, view counts, recipient emails, and whether a share is files or a secret | So links can expire, run out of opens, and show up in lockbox status. |
| Usage events: sign-ups, shares created, opened and revoked, apps connected, and chat-tool calls, with the app used and the email domain only (like @acme.com) | So we can see whether Lockbox works and how it’s used. They never include contents, file names, links or full email addresses. They go to our team’s internal Slack and are deleted after 90 days. |
Requests: the label you ask for (like STRIPE_KEY), who you asked, and when | So the person you asked sees what you need, and so you can list your requests. The value they send back is encrypted. |
| Encrypted data | The scrambled bytes of your files and secrets, held until they expire or are used up. |
What we don't collect
We never receive secret values, file contents, file names, notes, or the keys that unlock them. Encryption happens on your device. The key either travels in the link after the #, which browsers don't send to servers, or is sealed to your recipient's devices.
There is one thing you trust us with. The web pages at lockbox.run and the Lockbox panel in chat apps run code that we serve. If that code were changed, it could read what you open or type there. The lockbox command-line tool runs on your own machine and checks every share itself, so it doesn't depend on our web code. The panel in a chat app also runs inside that app, so the app can see what you open or type in the panel. Connect only apps you trust.
How long we keep it
- Encrypted data is deleted after it expires or its last open is used. This normally happens within about 15 minutes of that point.
- Share records and open logs are kept for 30 days after that, then deleted.
- Login codes are stored only as keyed hashes, never as the code itself, and expire quickly.
- Your account (email and public keys) is kept until you ask us to delete it.
Who processes data for us
We use Cloudflare to host the service, store encrypted data, and send login emails. Cloudflare handles data under its own terms as our processor. We don't use any other service providers to process your data.
Cookies and tracking
There is one essential cookie, used only when you sign in through the website. It keeps you signed in. There are no analytics, advertising, or tracking cookies, and no third-party scripts on this site.
Claude and ChatGPT apps
When the Lockbox app for Claude or ChatGPT is available, connecting it uses OAuth. We store what's needed to keep that connection working: which account it's linked to and its access tokens. We only receive the tool calls the assistant makes to Lockbox, and what those calls contain. We don't receive the rest of your conversation.
We don't sell your data
We don't sell or rent personal data, and we don't share it for advertising. We would only hand over data if the law required it, and the most we could hand over is what's listed above.
Your rights
You can ask us to show, correct, export or delete your personal data. You can delete a single share at any time with lockbox revoke. To delete your account, email us from the address on the account. Depending on where you live, you may have more rights under laws like the GDPR or CCPA, and you can complain to your local data protection authority.
Changes
If we change this policy, we'll update the date at the top. For big changes, we'll email account holders first.
Contact
Opslane, support@lockbox.run.