Privacy Policy

Last updated: September 4, 2026

Core principle

PARAMANT collects only what is strictly required to operate your account and run the service.

An email address is required to create an account and recover access; it is personal data, and it is stored. No phone number. We do not log IP addresses for analytics or profiling. An IP is processed for security and abuse-prevention only (rate limiting, the session record, an audit log, and the DPA signature record), the audit trail keeps a masked address for up to 400 days, and one log holds a full address for longer than any timer; both are named below. Only a strictly-necessary session cookie (no tracking cookies). No tracking pixels. No analytics. No advertisements. We never sell your data.

How Ghost Pipe & ParaShare (the ParaSend web app) work

Files sent through the web app are encrypted client-side in your browser using post-quantum cryptography (ML-KEM-768 + ECDH P-256 + AES-256-GCM + HKDF-SHA256) before they ever reach our servers. The relay never sees plaintext on that path. The one place it does is the hosted signing ceremony on the /v1 API, where the document is sent to us so that we can run the ceremony; we hold it, sealed at rest under our own key, until that envelope ends.

Files are split into 5 MB encrypted chunks. Each chunk exists only in RAM on our relay server. On the Community plan it is permanently and irreversibly destroyed after the first download (burn-on-read); a paid plan buys more reads per link through the API before that same destruction, up to 10 on Firm and 100 on Enterprise. Encrypted payload data is never written to disk. From a transfer, the only thing persisted to disk is cryptographic hashes in the public Certificate Transparency log: no file content, no keys, no plaintext. (Account data, listed below, is stored separately to run your account.)

Community plan blobs expire after 1 hour maximum. Firm blobs after 24 hours. Enterprise blobs after 7 days. All are destroyed earlier once the last read of the link is spent.

How ParaSign document delivery works

When you request signatures, your browser encrypts the document with AES-256-GCM before upload. The signing relay stores the encrypted capsule with the envelope until its expiry: 30 days unless the request asks for another term, and never longer than 365 days. The relay does not receive document plaintext or the document key. The personal signing link contains the key in its URL fragment; browsers do not send that fragment to the relay.

When a signer places a visible seal or date, the relay stores the signed field type, page number and normalized coordinates in the envelope. It does not receive document text, a drawn signature image or free-form field content. The placement is covered by the signer’s ML-DSA-65 signature.

The recipient must also sign in with the exact invited email address. The link alone cannot retrieve the ciphertext. If you choose Paramant email delivery, Resend processes the recipient address, message and complete signing link. It does not receive document plaintext. You can instead create links without sending email.

What we process

DataPurposeStorageShared
Encrypted blob (5 MB padded chunks)One-time secure transferRAM only · burn-on-readNever
ParaSign encrypted document capsuleDeliver the document with a signing requestRedis · expires with the envelopeHosting provider stores ciphertext only
Personal ParaSign invitation linkBind one recipient to one encrypted document and signing slotProcessed during delivery; not written to application logsResend only when you choose email delivery
SHA-256 hash of blobRouting & delivery confirmationRAM only · deleted after its last readNever
API key (Firm/Enterprise)Authentication & rate limitingLoaded from config at startupNever
Device ID (SDK users)Key routing between sender and receiverRAM only · cleared on restartNever
Device ID hash (CT log)Public tamper-evident audit logDisk · /data/ct-log.json · SHA3-256 one-way hash onlyNever
Signed delivery receiptProof that a transfer was deliveredRedis · 15 minutes, then deletedNever
Aggregated relay statisticsSystem health monitoringIn-process counters onlyNever
Email addressAccount identity, login, recovery, signing-invite deliveryStored (server) · also kept as a hash for rate-limitingEmail provider (Resend) for messages we send you
Sign-in factors: passkey public keys, TOTP secret (encrypted), recovery codes (hashed)Account authenticationStored (server)Never
ParaSign signing public key + fingerprintVerifiable signing identityStored (server) · public half only; the private key never leaves your browserPublic (its hash is in the CT log)
Plan + anonymised billing referenceFirm/Enterprise billingStored (server)Payment processor (Mollie, EU)
Client IP + user-agentSecurity, rate limitingSession/rate-limit TTLNever
Masked IP in the audit log (1.2.x.x)Account audit trailRedis · at most 400 days, and at most 1000 entries per accountNever

What we never do

No third-party requests

Every byte your browser loads on paramant.app comes from paramant.app. No web fonts from Google, no JavaScript or CSS from a CDN, no analytics, no tracking pixels, no embedded third-party widgets. Open your browser’s network inspector on any page: every request goes to one origin, and nowhere else.

This is deliberate. A single request to a third party leaks your IP address and the page you are viewing to that party before you have agreed to anything. So we self-host everything: fonts (a plain system font stack, zero font files downloaded), scripts, styles, and images all come from paramant.app.

What runs the service is operational, never tracking: our own edge (Caddy) terminates TLS directly on our server (see below); transactional email is sent server-side via our email provider; and a payment processor handles billing on its own pages. None of these is loaded into the site, and none follows you across it.

Local storage in your browser

For technical functionality, the following data is stored locally in your browser only. It never leaves your device:

You can delete all local data at any time: browser settings → paramant.app → Clear site data.

Your API key, and which pages hold it

Your account has an API key. It is stored on our servers; nothing in the list above keeps it in your browser, and no page writes it to local storage. Some pages do load it into memory for as long as their tab is open, and we would rather name them than leave you to guess.

Nothing on this list survives the tab. Closing the page ends it, and a later visit starts again from the server.

Servers & jurisdiction

All relay servers run on Hetzner infrastructure in Nuremberg, Germany (EU/DE). There is no infrastructure in the United States or outside the EU. No CLOUD Act exposure. All data is subject to EU/GDPR jurisdiction only.

Network edge

TLS is terminated by our own edge (Caddy), running on the same Hetzner infrastructure in Germany, with post-quantum key exchange. There is no third-party reverse proxy or CDN in front of the site: your connection reaches our server and nowhere else. Short-lived connection metadata (IP, timestamp) is processed transiently for security and abuse-prevention as described above, never for analytics.

Logs that hold an address

One log holds a full client address, and it is not bounded by a timer. We name it rather than let the word “transient” do work it cannot do.

None of these is used for analytics, profiling or advertising, and none is shared with a third party.

Subprocessors

A few operational providers are needed to run the service. None is loaded into the site, and none is used for tracking:

GDPR / AVG

We process the minimum personal data needed to run your account, on a lawful basis (performing the service you request, and our legitimate interest in keeping it secure). You can request access to, or deletion of, your account data by emailing us. The standard Data Processing Agreement (DPA) is published at /dpa and applies to all plans; anyone can sign it electronically, with no account and no paid tier required.

Temporary relay data is never retained longer than the applicable TTL (1 hour for Community, 24 hours for Firm, 7 days for Enterprise). In practice it is destroyed much earlier on download.

Children

PARAMANT is not directed at children under 13. We do not knowingly collect data from minors.

Changes to this policy

We may update this policy. Material changes will be noted via the "Last updated" date above. Continued use of the service after a change constitutes acceptance.

Contact

Questions about this Privacy Policy? Email info@paramant.app.