Section 11
Your content
Your content is what you send to the API, meaning plaintext, ciphertext, data keys and aad, and the names you give keys and API keys. You own it. You give us the rights we need to process it in order to provide the Service.
How we treat it. We process your content only to provide the Service to you, following the instructions you give through the API, and for no other purpose. We do not sell or share it, use it for advertising, or combine it with other data. Only people at x6c who operate the Service can reach the systems that process it, and they are bound to keep it confidential. The providers named in the privacy policy process it for us. We will tell you if we can no longer meet these commitments, and you may then stop using the Service.
What is stored. The Service does not store your plaintext, ciphertext, aad, or the data keys you send to wrap or unwrap, in its database; the privacy policy and security page describe what is recorded. Key and API key names, and the value of any x-request-id header you send, are stored, so do not put sensitive information in them.
Your responsibilities. You are responsible for your content, for having the right to send it, and for any notice or consent your own users need. We do not offer the agreements that some laws and card-network rules require before regulated health data or payment card data can be processed, so do not send us such data where one is required.
Security incidents and legal demands. If we learn that someone without authorization has accessed your content, your API keys or your account's records, we will tell you without undue delay. Because rypt holds the keys, a lawful demand could require us to decrypt ciphertext under your keys, or to disclose your account's records. Unless the law or a court order forbids it, or there is an emergency, we will tell you before we comply, and we will do only what the demand requires.
Feedback. If you send us feedback or suggestions, we may use them without any obligation to you.