lockbox

Draft — last updated 2026-10-05

Privacy

Lockbox is run by Opslane. We built it so we can't read what you share. This page says what we do collect, why, and for how long.

The short version

What we collect

DataWhy
Your email addressTo log you in with a code, and so people can share with you.
Public keys for your account and each deviceSo others can encrypt shares that only your devices can open. Public keys can't decrypt anything.
IP addressTo limit how often someone can try codes or create shares. Used for rate limiting.
Share details: sizes, times, view counts, recipient emails, and whether a share is files or a secretSo links can expire, run out of opens, and show up in lockbox status.
Usage events: sign-ups, shares created, opened and revoked, apps connected, and chat-tool calls, with the app used and the email domain only (like @acme.com)So we can see whether Lockbox works and how it’s used. They never include contents, file names, links or full email addresses. They go to our team’s internal Slack and are deleted after 90 days.
Requests: the label you ask for (like STRIPE_KEY), who you asked, and whenSo the person you asked sees what you need, and so you can list your requests. The value they send back is encrypted.
Encrypted dataThe scrambled bytes of your files and secrets, held until they expire or are used up.

What we don't collect

We never receive secret values, file contents, file names, notes, or the keys that unlock them. Encryption happens on your device. The key either travels in the link after the #, which browsers don't send to servers, or is sealed to your recipient's devices.

There is one thing you trust us with. The web pages at lockbox.run and the Lockbox panel in chat apps run code that we serve. If that code were changed, it could read what you open or type there. The lockbox command-line tool runs on your own machine and checks every share itself, so it doesn't depend on our web code. The panel in a chat app also runs inside that app, so the app can see what you open or type in the panel. Connect only apps you trust.

How long we keep it

Who processes data for us

We use Cloudflare to host the service, store encrypted data, and send login emails. Cloudflare handles data under its own terms as our processor. We don't use any other service providers to process your data.

Cookies and tracking

There is one essential cookie, used only when you sign in through the website. It keeps you signed in. There are no analytics, advertising, or tracking cookies, and no third-party scripts on this site.

Claude and ChatGPT apps

When the Lockbox app for Claude or ChatGPT is available, connecting it uses OAuth. We store what's needed to keep that connection working: which account it's linked to and its access tokens. We only receive the tool calls the assistant makes to Lockbox, and what those calls contain. We don't receive the rest of your conversation.

We don't sell your data

We don't sell or rent personal data, and we don't share it for advertising. We would only hand over data if the law required it, and the most we could hand over is what's listed above.

Your rights

You can ask us to show, correct, export or delete your personal data. You can delete a single share at any time with lockbox revoke. To delete your account, email us from the address on the account. Depending on where you live, you may have more rights under laws like the GDPR or CCPA, and you can complain to your local data protection authority.

Changes

If we change this policy, we'll update the date at the top. For big changes, we'll email account holders first.

Contact

Opslane, support@lockbox.run.