GDPR and data processing

GDPR-oriented data processing boundaries without secret recovery.

This page describes Shhhs GDPR-oriented processing boundaries. It is not a certification claim and does not replace a signed DPA or formal legal review.

01

Scope and roles

Shhhs is designed to minimize personal data. Depending on the feature, Shhhs may act as controller for account, billing, support, security, and abuse metadata, and as a service provider for encrypted payload storage and delivery metadata. Enterprise deployments may require a signed DPA.

  • Metadata-first processing
  • Encrypted payload storage
  • DPA available for Enterprise planning

02

Data minimization

Shhhs minimizes personal data by allowing anonymous free use, optional billing email for paid use, and metadata-only operations. Secret content is not used for analytics, profiling, indexing, or AI processing.

  • Anonymous free use
  • Optional billing email
  • No AI processing on secrets

03

Legal bases

Processing may rely on contract performance for the service, legitimate interests for security and abuse prevention, consent where optional communication is enabled, and legal obligations for billing, tax, and compliance records.

  • Service operation
  • Security and abuse prevention
  • Billing and legal obligations

04

Retention and deletion

Secret content follows configured TTL, view limits, burn actions, request reveal, package expiry, and scheduled cleanup. Operational metadata is retained only for service, abuse, audit, billing, and support needs.

  • TTL and view limits
  • Manual burn
  • Scheduled cleanup

05

Subprocessors and transfers

Cloudflare provides infrastructure and edge security services. Paddle provides billing. These subprocessors process operational and billing data according to their own contractual and compliance programs.

  • Cloudflare infrastructure
  • Paddle billing
  • No secret-content subprocessors for AI

06

Rights requests

Use the contact form for access, correction, deletion, export, objection, or billing-cancellation requests. Shhhs can act on account and metadata records it controls, but cannot decrypt or recover secret content.

  • Metadata access and deletion requests
  • No secret decryption
  • No lost-access restoration promise

FAQ

Does Shhhs process secrets with AI?

No. There is no AI processing on secret content.

Can Shhhs recover a secret?

No. Secret recovery would weaken the privacy model.

What can support recover?

Support can help cancel billing after billing validation, but cannot restore account access or secret content.