Privacy Policy
Last updated: August 17, 2026
Operated by Vassbrekke AS. These pages are not a substitute for legal advice about your situation.
Our approach: collect as little as possible
PrivyDeck is a privacy product. We do not monetize your data, run advertising trackers, or build profiles about you for marketing. We only process information that is necessary to give you an account and the features you choose to use.
In short: you can create an account with a passkey only (no email). If you choose Google, GitHub, Apple, or email magic link, we store that email (and optionally a display name). Everything else (devices, vault files, blocker stats, data-request letters, digests, breach checks) is data you add by using specific features. Optional features that leave our servers (cloud AI tips via xAI, email digests, breach lookups, Web Push) are off by default or only run when you opt in. We do not ask for your phone number, home address, date of birth, or government ID.
Who we are (data controller)
Vassbrekke AS, a privacy-focused company established in Norway, operates the PrivyDeck personal privacy dashboard ("PrivyDeck," "we," "us"). For the hosted service, Vassbrekke AS is the data controller of account and service data described in this policy. Customer accounts and vault ciphertext live on infrastructure operated by Vassbrekke AS.
Organization number: 835834212
Registered address: Stolevegen, 5514 Haugesund, Norway
Privacy contact (also acts as privacy officer for inquiries): privacy@privydeck.com
What we collect (and only when needed)
Always (to run your account)
- Account ID, creation date, and subscription tier
- Email address: only if you sign in with OAuth/email or attach one later (not required for passkey-only accounts)
- Display name and profile image: only if your provider or you supply them
- Passkey public keys / counters and hashed recovery codes when you use those features: never biometrics or plaintext recovery codes after display
- In-app notifications we create for you (for example DSAR deadline nudges): title, body, read state, and timestamps
- Optional product progress signals (privacy score components, XP/streak for checklist engagement) used only inside your account
Only if you subscribe (paid plans)
- Stripe customer ID and subscription status on our side: card numbers and full payment details stay with Stripe, not us
Only if you use Personal Shield or a home hub
- Device labels you enter (name, platform) and protection status for phones, browsers, and optional home network agents
- Extension sync metadata: last sync time, rule counts, and aggregated blocked totals (not full browsing history or URLs you visit)
- Aggregated blocker statistics and top blocked domain names from alerts you or your agents report (not your full browsing history, page paths, or search queries)
- False-positive reports (suggestions) and allowlist exceptions you explicitly confirm
- Active lockdown mode selection and blocklist preference toggles
- VPN connection status when a home agent is connected (server, protocol; IP only if you opt in under Settings → Privacy preferences)
- Pi-hole or agent summary telemetry your hub sends (for example query/block counts), used only to power your dashboard
Only if you use the vault
- Encrypted title/category ciphertext and encryption parameters (salt/IV): we cannot read labels without your passphrase
- File sizes and encrypted file blobs: ciphertext you upload; we cannot read contents without your passphrase
- Legacy items uploaded before label encryption may still have plaintext titles until re-uploaded
- Image EXIF metadata is stripped in the browser when possible before upload
Only if you create DSAR letters
- Company name, contact email, template choice, letter text, status, and due dates you set: stored so you can edit and track them; we never mail letters to companies on your behalf
Only if you join or create a household
- Household membership links (who is owner vs member) and invite tokens (hashed) needed to accept invites
- Each member keeps a separate account and vault; members do not gain access to each other's vault ciphertext
Only if you opt in to cloud AI coaching
- Blocked domain name, hit count, and coarse categories sent to xAI (Grok) in the United States: no email, name, account ID, browsing history, or vault data in the prompt; off by default
- Local rules tips always run without calling xAI or any other model provider
Only if you opt in to weekly digests
- In-app digest content built from your score trend, blocked totals, and open checklist items (off by default)
- Optional email delivery of that digest when you enable it, your account has an email, and email delivery is configured
Only if you enable Web Push
- Push subscription endpoint and encryption keys (p256dh/auth) for your browser or device so we can deliver digests and alerts you asked for
Only if you opt in to exposure / breach checks
- Password checks use k-anonymity: only a partial SHA-1 hash prefix is sent to Have I Been Pwned (HIBP); your full password never leaves your browser
- Email exposure checks (when configured with an HIBP API key) send your account email to HIBP and may store breach count and breach names on your account for dashboard display
Technical minimum (security, not profiling)
- Session, CSRF, and GPC preference cookies: strictly necessary for sign-in, security, and recording an opt-out signal (see Cookie Policy)
- IP address: used in memory for rate limiting only; not stored as a field in our application database
- Hosting server logs: standard web-server logs (IP, request path, user agent) retained by our host for a limited period; not used for advertising or product analytics profiles
What we do not collect
We do not collect, buy, or infer any of the following:
- Phone number, postal address, date of birth, government ID, or Social Security number
- Precise geolocation or GPS data
- Your full browsing history, page visits, search queries, or DNS query content from third-party resolvers you configure yourself
- Advertising profiles, cross-site tracking, or behavioral segments for marketing
- Third-party product analytics (no Google Analytics, Mixpanel, Segment, PostHog, or similar on PrivyDeck)
- Marketing or retargeting pixels
- Your vault passphrase: it never leaves your browser
- Plaintext vault contents: encrypted on your device before upload
- Contents of DSAR letters as delivered to companies: you send those; we are not in that mail loop
- Biometrics, health records, or financial account numbers (unless you choose to store such files in your encrypted vault, which we cannot read)
We do not sell personal information and do not share it for cross-context behavioral advertising. See Do Not Sell or Share.
Purposes and legal bases (GDPR / UK GDPR)
Where GDPR or UK GDPR applies, we rely on:
- Contract (Art. 6(1)(b)): account, sign-in, sync, vault storage, household, extension/hub protection, and subscription features you use
- Legitimate interests (Art. 6(1)(f)): security (CSRF, rate limits, hashed tokens), fraud prevention, and basic service reliability (not marketing)
- Consent (Art. 6(1)(a)): optional cloud AI tips (xAI), optional email digests, optional Web Push, optional breach/exposure checks, and optional storage of VPN IP from a home agent (all off by default where applicable)
- Legal obligation (Art. 6(1)(c)): tax, accounting, and lawful authority requests
California (CCPA / CPRA) notice at collection
Categories we may collect: identifiers (email; name if provided; account ID), internet/network activity (aggregated blocker domain statistics and device protection status, not full browsing history), commercial information (subscription status if you pay), and inferences limited to in-product privacy scores you see in the dashboard.
We do not collect sensitive personal information as defined by CPRA unless you voluntarily upload encrypted files to your vault, and we cannot access the contents of those files.
Sources: you, devices and agents you connect, sign-in providers you choose, and (only when you opt in) HIBP or xAI for specific features. Business purposes: provide the service, security, and billing only. We do not sell or share for behavioral advertising. We honor Global Privacy Control (GPC). Rights: Your Privacy Rights. Non-discrimination notice.
Other US and global privacy laws
We apply the same minimal-collection standard everywhere. If you live in a US state with a comprehensive privacy law, Brazil, Canada, Australia, Japan, South Korea, Singapore, Thailand, the EU, UK, Switzerland, or elsewhere with similar rights, you have access, deletion, correction, and opt-out rights as described on Your Privacy Rights. We do not sell personal data or use it for targeted advertising in any jurisdiction.
Browser extension (Personal Shield)
The PrivyDeck browser extension runs on your device to block ads, trackers, malware, and annoyances according to lists and lockdown rules synced from your account. It may report aggregated block counts and device labels to your PrivyDeck account so the dashboard stays accurate. It does not send your full browsing history to us. Store listings point to this Privacy Policy.
Third-party payment processing (Stripe)
Paid plans load Stripe only at checkout and in the billing portal. Stripe processes payments and may set cookies for fraud prevention, not for advertising. Card details are held by Stripe: stripe.com/privacy. Stay on the free tier to avoid Stripe entirely. See Cookie Policy.
Subprocessors and third parties
We share data only with providers needed to operate features you use. Categories include:
- Hosting / infrastructure: stores the application database, vault ciphertext blobs, and standard server logs
- Stripe: payment processing (only if you subscribe)
- Sign-in provider you choose: passkey (on-device), Google, GitHub, Apple, and/or email magic link delivery (SMTP provider if email auth is enabled)
- xAI (Grok): blocked domain + hit count + coarse categories only, when you enable cloud AI tips (United States)
- Have I Been Pwned: hash prefix (password checks) or account email (email checks), only when you opt in to breach checks
- Browser push services (for example FCM, Mozilla Autopush, Apple, Windows Notification Service): only if you enable Web Push, using the subscription endpoint your browser provides
Privacy DNS resolvers you configure on your phone or PC (for example Mullvad, Quad9, Control D, AdGuard, NextDNS) are independent services under their own policies. PrivyDeck does not receive your DNS query content from those providers.
We do not use data brokers. DSAR letters you generate are sent by you, not by us.
International transfers
Vassbrekke AS is established in Norway. If you access PrivyDeck from another country, or if a subprocessor (for example a global cloud host, Stripe, HIBP, or xAI) processes data outside your country, your data may be transferred internationally. Where GDPR requires safeguards, we use Standard Contractual Clauses or equivalent measures with subprocessors as applicable. Account data for the hosted service is processed on infrastructure operated for Vassbrekke AS.
Retention
- Account data: until you delete your account, plus up to 30 days for backup purge where backups exist
- Score history, tracker alerts, and related protection telemetry: auto-deleted after your chosen window (default 30 days; 7, 30, 90, or until account delete in Settings → Privacy preferences, including purge now)
- Devices, vault ciphertext, DSAR letters, household membership, push subscriptions, and notifications: until you delete items or your account
- Cloud AI tips we save on your tracker alerts: until the alert is resolved, retention purge, or account delete. xAI may retain the API request and response for up to 30 days for abuse auditing unless Zero Data Retention is enabled on our xAI account; xAI states it does not train on API data
- Breach check results on your account: until you turn the feature off (clears stored results) or delete your account
- Server logs: typically 30–90 days (hosting provider dependent)
- Stripe and tax records: as required for tax and accounting (typically 7 years)
Cookies and similar technologies
Strictly necessary cookies only (session, CSRF, GPC preference). No advertising or product analytics cookies. Cookie Policy.
Automated processing and AI (xAI)
Optional cloud AI coaching is off by default. Local tips always run without calling an external model. If you opt in (Guardian or Household, Settings → Privacy preferences), we send a blocked domain name, hit count, and coarse categories to xAI (Grok) in the United States to generate a short suggestion when your environment reports tracker alerts. We do not send your email, name, account ID, browsing history, or vault data.
Hosted PrivyDeck calls api.x.ai with conversation storage disabled on the request. xAI states it does not train on API inputs or outputs. By default xAI may retain API requests and responses for up to 30 days for abuse auditing, unless Zero Data Retention is enabled on our xAI account. If the xAI request fails, we fall back to local tips and do not call another model provider. This is not automated decision-making with legal or similarly significant effects.
xAI processes that prompt as our subprocessor under their enterprise terms, data processing addendum, and privacy policy. Enable or disable anytime in Settings → Privacy preferences.
Your privacy rights
Details: Your Privacy Rights. Signed-in users:
- Access & portability: Settings → Privacy data export
- Erasure: Settings → Delete account (type DELETE to confirm)
- Rectification: update profile via your sign-in provider, or contact us
- Object / restrict / withdraw consent: turn off optional features in Settings → Privacy preferences, or contact us
- Opt in to optional xAI tips, digests, push, breach checks, or VPN IP storage: Settings → Privacy preferences (off by default where applicable)
- Opt out of sale/sharing: we do not sell; GPC honored (see Do Not Sell)
Email privacy@privydeck.com for requests you cannot complete in Settings. We respond within 30 days (GDPR) or 45 days (CCPA/CPRA, extendable once where the law allows).
EU/EEA/UK residents may lodge a complaint with a supervisory authority. As a Norway-established controller, the Norwegian Data Protection Authority (Datatilsynet) is our lead authority; you may also contact your local authority.
Children
PrivyDeck is not directed at children under 16. We do not knowingly collect data from children under 16. Household "Family Safe" mode is for adult account holders configuring shared devices; the adult remains responsible for compliance with local children's privacy laws. Contact privacy@privydeck.com to request deletion if you believe a child provided data.
Security
Vault files and labels are encrypted in your browser before upload (AES-GCM). Agent and extension tokens are stored as hashes. We use CSRF protection, content security policy, rate-limited exports, and hashed recovery codes. Use a strong vault passphrase and keep devices updated. No method of transmission or storage is 100% secure; report issues to privacy@privydeck.com.
Data breaches
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify you and relevant authorities as required by applicable law (for example GDPR Art. 33–34).
Changes to this policy
We may update this policy when the product or law changes. Material changes will be reflected in the "Last updated" date on this page. Continued use after the effective date constitutes acceptance of the updated policy where permitted by law. For significant changes that require consent, we will ask again where required.
Contact
Privacy: privacy@privydeck.com
General support: support@privydeck.com
Help center: /help
Postal: Stolevegen, 5514 Haugesund, Norway