DigiSafe

Privacy Policy

Your privacy at DigiSafe

We built DigiSafe so your documents are private by design, not by promise. Here is exactly what we can and can’t see, in plain words.

Last updated

On this page
  1. The short version
  2. Who we are
  3. What we can’t see
  4. What we store that we can read
  5. What stays on your device
  6. Cookies and tracking
  7. How we use your information
  8. Who helps us run DigiSafe
  9. Where your data is stored
  10. How long we keep it
  11. Your choices and rights
  12. How we protect it
  13. Age
  14. Details for your country
  15. Changes to this policy
  16. Contact us

The short version

  • Your documents, their names and details, and the answers you give when you sign up are encrypted on your device before they are uploaded. We can’t read them.
  • We can read a small amount: your name, email address, sign-in and consent records, and the dates and sizes needed to keep your devices in sync.
  • Your encrypted data is stored with Supabase in Tokyo, Japan.
  • No adverts, no analytics, no trackers. We don’t sell your information.
  • You can download everything, or delete your account, from Account at any time.

Nobody can recover a lost vault

If you forget both your password and your PIN, your documents cannot be opened again, by you or by us. We never hold a key that could open them.

Who we are

DigiSafe is made and run by Kavion Solutions (“we”, “us”). This policy explains what information the DigiSafe app and website handle, why, and the choices you have. It applies wherever you use DigiSafe: on a phone, a tablet or a computer.

To ask about anything here, contact Kavion Solutions through its website.

What we can’t see

DigiSafe is built so that your private information is locked before it leaves your device. It is encrypted in your browser with AES-256-GCM, using a key that only exists on devices you have unlocked. What reaches our servers is scrambled data we have no way to open. This covers:

  • Your documents: every scanned page, thumbnail and PDF.
  • Folder details: names, descriptions, icons and colours. Folder identifiers are also blinded (turned into a code using a key from your vault), so we can’t tell a passport folder from any other.
  • Document details: names, notes, page counts, file types and sizes, numbers read from your documents, and bill and warranty details.
  • Your profile: the countries you picked, your mobile number, state or province, the kinds of documents you care about, whose documents you keep, whether you want reminders, and your note that you understand how recovery works.
  • Family folders: folder names and everything inside them, locked with a key only the folder’s members hold.

Your password and PIN

Your password is not sent to us. Your device turns it into a sign-in token, and we store only a one-way hash of that token. We also keep a copy of your vault key that is locked with your password, so you can open your vault on a new device. Without your password that copy is useless.

Your PIN is never sent to us either. So that one PIN works on all your devices, we store a sealed check of it that can only be opened with your unlocked vault key. If you turn on fingerprint or face unlock, that stays on your device: we never receive fingerprint or face data.

Numbers such as a PAN or passport number are read from your pages on your own device. Pages are not sent anywhere to be read.

What we store that we can read

To run your account and keep it safe, we store some information we can read:

  • Account: your name, your email address, whether and when you confirmed it, and when your account was created and last changed. We use your name to greet you in emails.
  • Sign-in and sessions: a hash of your sign-in token, a hash of each session token with its start and end dates, and counts of failed sign-ins and temporary lockouts. Failed sign-ins are counted against a hash of the email address, not the address itself.
  • Consent records: which version of the Terms and this policy you agreed to and when, when you confirmed you are 18 or older, and whether (and when) you chose to get product emails.
  • Sync information: the blinded folder codes, random document identifiers, when each item was last changed or deleted, when your profile and PIN were last changed, and the size of each encrypted file in storage. Deleted items leave a small marker so your other devices remove their copies too.
  • Sign-up codes and email links: while you sign up, your name, email and a hash of your sign-in token and the emailed code, for up to 10 minutes. Password reset and email confirmation links are stored as hashes with an expiry time.
  • Abuse protection: to slow down attacks, we count requests for a short time. The count is linked to a one-way hash of your IP address, your email address or your account, depending on the action, never the address in readable form.
  • Share links: if you share a document by link, we keep the file type, size, expiry time, how many times it may be opened and has been opened, wrong code attempts, and a hash of the optional code. The document copy is encrypted with a key that sits in the link itself and is never sent to us.
  • Family folders: if you use them, we can see who is in which family folder, each person’s role, whether an invitation was accepted, and when things change. We store each member’s public keys so others can share folders with them. Members of a folder can see each other’s names and email addresses.

Like any website, the servers that deliver DigiSafe also receive technical details with each request, such as your IP address and browser type. Our hosting providers may keep these in short-term logs for security and to fix problems.

What stays on your device

DigiSafe works offline, so it keeps a copy of your vault in your browser’s storage on each device you use:

  • Your document pages, stored encrypted.
  • A locked copy of your vault key and, if you turned it on, the fingerprint unlock copy.
  • Your folder and document details (such as names, notes and numbers read), your sealed profile, and your settings such as theme, font and auto-lock time.

Folder and document details are kept readable in the browser so the app can open quickly and offline. Protect your device with a screen lock, and before you give a device away, clear DigiSafe’s data on it (in your browser’s site settings, or by removing the installed app).

In supported browsers, DigiSafe also saves its own program files (pages, scripts and the on-device number reader) so it can start offline. Your documents and the answers from our servers are never saved in that cache.

Cookies and tracking

We use one cookie, named digisafe_session. It keeps you signed in for up to 30 days. It is strictly necessary, can’t be read by scripts on the page, and is removed when you sign out.

We don’t use advertising, analytics or tracking tools, and we don’t load scripts, fonts or images from other companies. Your settings (such as theme and font) are saved in your own browser, not sent to us.

How we use your information

  • To create your account, sign you in and keep your session secure.
  • To store your encrypted data and keep it in sync across your devices.
  • To send emails you need: your sign-up code, a welcome email, email confirmation, password reset links, and a notice if someone tries to sign up with your address.
  • To send product news, only if you ticked the box for it. It is never pre-ticked.
  • To run share links and family folders when you use them.
  • To prevent abuse, investigate problems and keep the service safe.
  • To keep a record of your consent, and to meet legal duties.

We don’t sell your information, use it for advertising, or build profiles about you.

Who helps us run DigiSafe

We use a small number of service providers, who handle data only to run the service for us:

  • Supabase hosts our database and file storage in Tokyo, Japan. It holds your encrypted data and the readable account records described above.
  • Vercel runs the app’s website and servers. Requests pass through its network, which may handle them in more than one country.
  • Our email delivery provider sends account emails. It receives your name, email address and the content of the email.

We may also share information if the law requires it, for example a valid court order. Even then, we can only hand over what we can read: we can’t decrypt your documents or your profile for anyone.

If DigiSafe or Kavion Solutions is ever reorganised or sold, your information may move to the new owner, who must keep protecting it as this policy describes.

Where your data is stored

Your encrypted data and your account records are stored in Japan (Tokyo). This means your information is transferred to and stored in Japan, whichever country you live in. Parts of it may also pass through other countries while our providers deliver the service, such as the United States.

The privacy laws in those countries may differ from yours. Where your law asks for extra safeguards when data leaves your country, we rely on the protections it allows, such as contract terms with our providers. Most of what is transferred is encrypted before it leaves your device.

How long we keep it

  • Your account and vault: until you delete your account.
  • Sessions: up to 30 days, or until you sign out.
  • Sign-up codes: they stop working after 10 minutes.
  • Deleted folders and documents: their stored files are removed when you delete them. A small encrypted marker stays so your other devices hear about it, and is cleaned up after 90 days.
  • Abuse protection counts: short-lived. Counts older than a day are cleared regularly.
  • Share links: a link lasts at most 7 days. Expired links and their files are removed automatically.
  • After you delete your account: removed from our live systems straight away (see below). Copies in our hosting provider’s routine backups may last a limited time until those backups are replaced.

Your choices and rights

See and download your data

In Account, use Download all my data. It builds one file on your device with your documents in their original format, your folder and document details, your profile, and your account and consent details.

Correct your data

You can rename folders and documents, and change your profile answers such as your countries, in the app. For anything you can’t change yourself, such as your name or email address, contact Kavion Solutions through its website.

Delete your account

In Account, choose Delete account and confirm with your password. It happens straight away and can’t be undone. We remove:

  • your account, sessions, sign-in records and consent records;
  • your vault: the locked keys, PIN check and profile;
  • all your folders, documents and their stored files;
  • your share links and their files;
  • family folders you own, with their files, and your place in other people’s.

Documents you added to someone else’s family folder stay in that folder for its other members. The device you delete from is cleared at once. Your other devices are signed out the next time they connect, but copies saved on them stay there, encrypted, until you clear the app’s data on each one.

Product emails

Product emails are optional. You can withdraw that consent at any time, and it won’t affect your account. To stop them, turn off Product update emails in Account, under Privacy. It takes effect straight away.

Questions and complaints

If you are unhappy with how we handle your information, please contact Kavion Solutions through its website first so we can put it right. You can also complain to the privacy regulator where you live (see the country details below).

How we protect it

Beyond encryption on your device, we use HTTPS everywhere, store passwords, codes and session tokens only as hashes, limit repeated attempts, lock the vault automatically after a period you choose, and use strict browser security rules that block content from other websites.

No system is perfectly secure. If a security incident affects your information, we will tell you and the relevant authorities where the law requires it.

Age

DigiSafe is only for people aged 18 or older, and you confirm this when you sign up. We don’t knowingly hold information about children. If you believe a child has an account, contact Kavion Solutions through its website and we will delete it.

Details for your country

DigiSafe is used in India, the United Kingdom, the United States, Canada and Australia. These extra details apply depending on where you live.

India

Under the Digital Personal Data Protection Act, 2023, Kavion Solutions is the Data Fiduciary for the personal data it processes, and you are the Data Principal. You can ask for information about how your data is processed, and ask us to correct, complete, update or erase it. You can withdraw consent as easily as you gave it, nominate someone to act for you if you die or can’t act yourself, and use our grievance process by contacting us. If we don’t resolve your grievance, you can go to the Data Protection Board of India.

United Kingdom

Under the UK GDPR and the Data Protection Act 2018, Kavion Solutions is the controller of your personal data. We rely on these legal bases: providing the service you signed up for (contract), keeping it secure and preventing abuse (legitimate interests), product emails (consent), and meeting legal duties (legal obligation).

You have the right to access, correct and erase your data, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent. You can complain to the Information Commissioner’s Office at ico.org.uk.

United States

We don’t sell your personal information or share it for targeted advertising. If you live in California, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to know what personal information we collect and how we use it, and to access, correct and delete it. We use sensitive information such as account sign-in details only to provide the service, and we won’t treat you differently for using your rights. You can make a request yourself or through an authorised agent.

DigiSafe is not a healthcare provider, health plan or healthcare clearinghouse, and it is not a HIPAA covered entity. If you store medical records, you are keeping your own copies of your own documents, encrypted so we can’t read them.

Canada

We handle personal information in line with the Personal Information Protection and Electronic Documents Act (PIPEDA). You can ask to access and correct the personal information we hold about you, and withdraw consent, subject to legal limits. Because your data is stored in Japan and may pass through other countries, it may be accessible to courts and authorities there. You can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.

Australia

We handle personal information in line with the Privacy Act 1988 and the Australian Privacy Principles. Your information is disclosed to providers overseas, mainly in Japan and the United States, as described above. You can ask to access and correct the personal information we hold. If you are not satisfied with our answer to a complaint, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.

Changes to this policy

When we change this policy, we update the date at the top. If a change matters to how your information is handled, the app will ask you to read and agree to the new version before you carry on.

Contact us

DigiSafe is run by Kavion Solutions. To ask a question, use a right, or make a complaint, contact Kavion Solutions through its website.

Many requests are quickest in the app itself: Download all my data and Delete account are both in Account.