Privacy Policy
Last updated information about our policies and terms.
Last Revised: September 30, 2026
Nothing in this Privacy Statement may be construed to create any obligation for the Company beyond what is required by applicable law.
1. Scope
This Privacy Statement ("Privacy Statement" or "Statement") describes the practices of CredenShare Inc. ("CredenShare," "Company," "we" or "us") with respect to information, including Personally Identifiable Information ("PII" or Personal Data) (which means any information relating to an identified or identifiable natural person), and non-personally identifiable information ("non-PII"), we obtain from and about individuals interacting with us and our websites, mobile applications, products and services (collectively, our "Services"). This Statement does not apply to job applicants or Company employees. Our Services include the CredenShare browser extension, which is addressed specifically in Section 20. CredenShare Inc. is a Canadian-controlled private corporation based in Ottawa, Ontario, and our handling of personal information is governed primarily by Canadian law, including PIPEDA.
This Privacy Statement only applies to the data processing activities of CredenShare. This Privacy Statement does not apply to services, websites or mobile apps offered by third parties, even if this site links to those services or third parties. We encourage you to read the privacy statements of every third party website that collects your PII.
Please read the information below to learn about the information, including PII, collected about you and how it is used. Please note that there is a separate Terms of Service found at the hyperlink located at the bottom of our site.
2. Changes to this Statement
We may change this Statement at any time by posting revisions to the Statement on our Services including, without limitation, this site. Therefore, you should review the Statement from time to time. If you do not accept all of the terms, conditions and notices set forth in the Privacy Statement, you must discontinue using the Services, which includes exiting this site, immediately. The most current version of the Statement may be reviewed by clicking on the "Privacy Statement" link located at the bottom of our site.
3. Collection of Information from Children
We do not intentionally collect information from or regarding minors. The Services are not directed to, or intended for use by, children under the age of 18. Children may not use or submit any information through the Services or its sites. If you are under the age of 18, you may not use our Services. If a child under 18 submits information through any part of the Services, and we become aware that the person submitting the information is a child, we will attempt to delete this information as soon as possible.
4. Information We Collect
We may collect two general types of information when you use our Services or interact with us:
Personally Identifiable Information ("PII"), which may include your first and last name, home or other physical address, telephone number, email address, user id, other identifiers that permit physical or online contact with you, or any information about you collected online and maintained in personally identifiable form in combination with any of the preceding categories. You also may view or engage with our Services through third-party social networking sites or social media plug-ins and applications. When you engage with our Services and its content through such third-party sites, plug-ins or applications, we may have access to certain information from your social media profile, such as your name, photo, gender, birthday, location, videos, your list of friends, etc. This information is included in the definition of PII.
Non-personally identifiable information ("non-PII") such as the type of browser you are using, the type of operating system you are using, the web pages you have visited, sites visited before and after you use our Services, the type of handheld or mobile device used to access the Services or other device-specific information.
Certain features available within the Services will require you to submit PII about yourself as a condition of participation. Some of the features may be offered by us, while others may be offered by third parties. When you choose to submit PII to a third party in connection with your use of the Services, the third party's privacy policy, rather than this Statement, will control the use of your PII.
YOU CAN ALWAYS REFUSE TO PROVIDE PII TO US, BUT THIS MAY RESULT IN DECREASED FUNCTIONALITY OF THE SERVICES FOR YOU AND LIMIT YOUR ABILITY TO RECEIVE INFORMATION ABOUT SERVICES THAT MAY BE OF PARTICULAR INTEREST TO YOU.
5. How Information is Collected
We collect information both actively and passively. For example, we will collect information about you that you voluntarily provide while using our Services. In addition to information provided directly by you, we (and third parties that offer features through the Services) may collect non-PII through the use of "cookies," "web beacons," "Flash cookies" or by other electronic means.
Cookies
In general, a cookie is a small amount of data sent to your browser from a web server and stored on your computer's hard drive, where it can be used to identify your computer. Cookies can be used to measure website usage, improve navigation around websites, and personalize a returning visitor's experience on the websites. In most cases, you can set your browser to turn off cookies or to notify you before you receive one so that you can decide whether to accept it or not. Because cookies allow you to take advantage of some of the features of the Services, we recommend that you leave them turned on. If you block or reject our cookies, some of the features of the Services may not work for you. The specific cookies and browser storage used by our analytics services, and how long they last, are described in Section 21.
Web Beacons
We, our third-party service providers, advertisers and partners also may use "web beacons" or similar technologies. Web beacons are small strings of code placed on a web page to collect data about how visitors use the Services. We do not control tracking technologies used by third parties with the Service.
6. Third-Party Advertising and Third-Party Websites
These websites allow advertising by third parties that provide links to third-party websites. Internet advertising companies and the third-party websites on whose behalf they advertise (collectively "Third Parties") may use the technology described above to send (or "serve") directly to your browser the advertisements that appear on our Services. When this happens, Third Parties automatically receive non-PII, such as information from your computer and browser, including your cookie information. They also may use cookies, JavaScript, Pixel Tags and other technologies to deliver advertisements; collect information about the effectiveness of their advertisements; collect anonymous information about your visits to the Services.
Third Parties will not collect your name, address, or other PII, unless you affirmatively provide it to them. We let Third Parties set and access their cookies on your computer. Third Parties' use of their own cookies is subject to their own privacy policies.
For more information about behavioral advertising or to opt out of this type of advertising for some companies, you can visit https://www.networkadvertising.org.
7. Third Party Links
Please note that our Services may contain links to other websites that do not follow this Privacy Statement. Clicking on an advertisement, links or other elements on the Services may take you to an entirely different website. These websites may send their own cookies to you and may collect data and make use of that data in ways that these Services would not. After you leave our Services, this Privacy Statement will no longer apply to PII or any other data collected from or provided by you. You should check the other websites' applicable privacy policy to determine how it will handle such data.
8. How Information is Used and Shared
We use your PII for the purpose of conducting our business and pursuing our legitimate interests. For example, we use your PII to:
- Facilitate communication from third parties to you at your request
- Create and manage your account
- Provide the products and services you request
- Enroll you in contests, programs or other offers you request
- Tell you about other products and services that may be of interest to you (you can opt out of receiving such communications by following the instructions provided in the communication)
- Process payment for purchases you have made
- Protect against or identify possible fraudulent transactions
- Analyze the use of our Services
- Develop new products and services
- Understand how you arrived at our Services
- Manage the Services, including this site
- Enforce our Terms of Use
- Enforce the terms of this Statement
9. Marketing Communications and Canada's Anti-Spam Legislation (CASL)
We send commercial electronic messages — newsletters, product announcements and offers from CredenShare — only with your consent, as Canada's Anti-Spam Legislation (CASL) requires. That consent is either express, for example when you opt in at sign-up or in your account settings, or implied where CASL permits it, for example for a limited period after a purchase or an inquiry. We do not send marketing on behalf of other companies, and we do not give your contact details to others so that they can market to you.
Every commercial message we send identifies CredenShare, includes our contact information and includes a way to unsubscribe. When you unsubscribe, we give effect to it without delay, and in any case within 10 business days. You can also withdraw your consent at any time by contacting us at privacy@credenshare.io.
Messages that are not marketing — security alerts, billing and payment notices, messages about your account, your shares or your requests, and replies to questions you send us — are part of providing the Services, and we will continue to send them while you have an account.
By providing your telephone number to us, you certify that this is your own number that you own, and not a line owned or used by another, and that you will immediately notify us if your number changes or is reassigned.
10. Sale of Business
In the event that Company is considering a sale of its business, in its entirety or a component thereof, or substantially all of its assets are acquired, PII and non-PII may be one of the transferred assets, and may therefore be used by a third-party acquirer in accordance with this Privacy Statement.
11. Disclosure of PII
We do not sell, rent or trade your personal information, and we do not share it with third parties for their own purposes — including their own marketing or advertising.
We use your personal information within CredenShare: to provide, secure, support and improve the Services, for auditing and record-keeping, and to meet our legal and regulatory obligations. It leaves CredenShare only in the following circumstances:
- Service providers acting for us. We rely on a small number of service providers to operate the Services — hosting and infrastructure, network security, payment processing, email delivery, customer relationship management, analytics and abuse prevention. They include Amazon Web Services (hosting), Cloudflare (network and security), Recurly (payments), MailerLite (email), PostHog and Google (analytics) and Google reCAPTCHA (abuse prevention). They process personal information on our behalf and on our instructions, not for their own purposes. Section 16 explains where they are located and what that means.
- At your direction. When you send a share or a secure request to someone, connect an integration such as Slack, or otherwise ask us to share something, we share what is needed to do what you asked.
- To comply with the law. Where we are required to by law, regulation, court order or other legal process, including a lawful request from a government authority. Section 16 explains how this applies to authorities outside Canada.
- To protect the Services and others. Where reasonably necessary to investigate or prevent fraud, security incidents, violations of our Terms of Service or this Statement, or threats to anyone's safety, and to protect our legal rights.
- In a business transaction. As described in Section 10, if CredenShare's business or assets are sold or transferred.
12. Forums
The Services may include forums (such as message boards, chat rooms, comment boards, and reviews) that enable users to post a comment or communicate with each other. We are under no obligation to moderate or edit the forums and will not be responsible for the content or use of any material posted on any forum within the Services. We retain the right to delete at any time and for any reason any material posted within the Services.
13. Information Security
We take information security seriously, and we use reasonable administrative, technical and physical safeguards to protect the PII we collect from unauthorized access, use or disclosure. But we have no control over the security of other websites on the Internet that you might visit. If you share your computer or use a computer that is accessed by the general public, remember to sign off and close your browser window when you have finished your session.
Additionally, no system can be completely secure. Therefore, although we take commercially reasonable steps to secure your information, we do not promise, and you should not expect, that your PII, searches or other communications will always remain secure. In the event of a breach of the confidentiality or security of your PII, we will notify you if reasonably possible and as reasonably necessary so that you can take appropriate protective steps.
14. Your Rights
Your rights under Canadian privacy law (PIPEDA)
CredenShare Inc. is a Canadian company, and our handling of personal information is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA). Under PIPEDA you have the right to:
- Access the personal information we hold about you, and be told how it has been used and to whom it has been disclosed.
- Challenge its accuracy and have it corrected or amended.
- Withdraw your consent to our collecting, using or disclosing it, subject to legal or contractual restrictions and reasonable notice. We will tell you what withdrawing consent would mean — for example, that we can no longer provide some or all of the Services.
- Challenge our compliance with PIPEDA and with this Statement.
We respond to access requests within 30 days, or tell you within that time if we need an extension that PIPEDA permits. We may need to verify your identity before acting on a request, and in the limited circumstances where PIPEDA permits or requires us to withhold information, we will tell you why.
Our Privacy Officer is accountable for our compliance with PIPEDA and with this Statement, and can be reached at privacy@credenshare.io or at the address in Section 22.
If you are not satisfied with how we have handled your personal information or your request, you may file a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca, or toll-free at 1-800-282-1376.
Breaches. If a breach of our security safeguards involving your personal information creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as PIPEDA requires, and we keep a record of every breach of security safeguards.
Rights under other laws
Depending on where you live, you may also have rights under other laws. These can include the right to: (i) request access to and rectification or erasure of your PII; (ii) obtain restriction of processing or object to processing of your PII; and (iii) ask for a copy of your PII to be provided to you or a third party in a machine readable format. Sections 15 and 17 describe the rights of residents of California and the European Union. To exercise any of these rights, please send us your request using the contact details in Section 22.
15. California Privacy Rights
15.1 Annual disclosure request ("Shine the Light")
Under California law, California residents may request once a year, free of charge, certain information regarding our disclosure of PII to third parties for direct marketing purposes. To make such a request, please contact us using the contact information below. You should put "California Privacy Rights" in the subject line and in your request.
15.2 Your rights under the CCPA/CPRA
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to:
- Know what personal information we collect, use, and disclose
- Delete your personal information
- Correct inaccurate personal information
- Opt-out of the "sale" or "sharing" of your personal information
- Limit the use of sensitive personal information
- Non-discrimination — we will not discriminate against you for exercising your rights
Do Not Sell or Share My Personal Information: CredenShare does not sell your personal information as defined by the CCPA/CPRA, and we do not use cookies for cross-context behavioral advertising.
To exercise any of these rights, contact us at support@credenshare.io. Cookie choices can also be changed at any time through the cookie settings on this site — see our Cookie Policy for detail.
California Do Not Track Disclosure
Certain web browsers may allow you to enable a "do not track" option, or to send a Global Privacy Control signal, indicating that you do not want your online activities tracked. Our product analytics honors both signals: when your browser sends Global Privacy Control or Do Not Track, CredenShare does not start PostHog at all, and it therefore collects nothing. Our website analytics provider, Google Analytics, does not currently respond to those signals. Section 21 describes what each service collects and how to limit it.
16. Where Your Information Is Stored, and the U.S. CLOUD Act
CredenShare Inc. is a Canadian-controlled private corporation based in Ottawa, Ontario. This Statement is governed by the laws of the Province of Ontario and the federal laws of Canada that apply there.
Your information is stored outside Canada. The Services are hosted on Amazon Web Services in the United States (Northern Virginia), and several of our other service providers are located in, or process data in, the United States or other countries outside Canada. Your personal information is therefore stored and processed outside Canada. We remain accountable under PIPEDA for personal information we transfer to a service provider for processing.
Foreign legal requirements. While your information is in another country, it is subject to that country's laws, and may be accessible to that country's courts, law enforcement and national security authorities under those laws. In particular, the United States Clarifying Lawful Overseas Use of Data Act (the CLOUD Act) allows U.S. authorities to require U.S.-based service providers to disclose data in their possession, custody or control, wherever that data is stored. Because our hosting provider and several of our other service providers are U.S. companies, information we hold could be the subject of such a requirement, directed at us or at one of them.
What end-to-end encryption does and does not change. The contents of shares, secure requests and pastes created in the CredenShare web application, the browser extension or our SDKs are encrypted before they reach us, and we hold no key that can open them; a disclosure we or a provider were compelled to make would contain that content only as ciphertext that cannot be read without the key. Shares created through our Slack app are the exception: they are encrypted on our servers rather than before they reach us, so we do hold the key for those. Information that is not end-to-end encrypted could be disclosed in readable form — your account details, billing records, a share's title, description and settings (see Section 20), analytics information (see Section 21), and the logs we keep to operate and secure the Services.
We disclose personal information to an authority, in Canada or elsewhere, only where we are legally required to.
17. Your EU Privacy Rights
If you are using our Services from the EU or where applicable EU data protection laws so provide, you may exercise the following rights regarding your PII:
- Access. You have the right to obtain from us confirmation if your PII is being processed and certain information in this regard.
- Rectification. You have the right to request the rectification of inaccurate PII and to have incomplete data completed.
- Objection. You have the right, when we process PII on the grounds of legitimate interests, to object to the processing of your PII for compelling and legitimate reasons relating to your particular situation. In addition, you have the right to object at any time where your PII is processed for direct marketing purposes.
- Portability. You may receive your PII that you have provided to us in a structured, commonly used and machine-readable format and have the right to transmit them to other data controllers without hindrance. This right only exists if the processing is based on your consent or a contract and the processing is carried out by automated means.
- Restriction. You may request to restrict processing of your PII if (i) you contest the accuracy of it; (ii) the processing is unlawful and you oppose the erasure of it and request restriction instead; (iii) we no longer need it, but you need it to establish, exercise or defend a legal claim; or (iv) you object to processing based on public or legitimate interest.
- Erasure. You may request to erase your PII if it is no longer necessary for the purposes for which we have collected it, you have withdrawn your consent and no other legal ground for the processing exists, or the processing is unlawful.
- Right to lodge a complaint. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your residence.
- Right to refuse or withdraw consent. You are free to refuse to give consent and you can withdraw your consent at any time without any adverse negative consequences.
If you have questions about exercising any of those rights, you may contact us at privacy@credenshare.io or at the contact address provided below.
18. Retention
We retain your PII for as long as you remain a customer and thereafter only for the period necessary to fulfill the purposes outlined in this Privacy Statement, unless a longer retention period is required or allowed by law, including to fulfill a legal obligation.
19. Your Choices
If you do not wish to receive information regarding our products, services, special offers and upcoming events, please click on the "Unsubscribe" link shown on our emails and electronic newsletters to you or contact us at the address or telephone number listed below and we will remove your name from our mailing lists.
You may access your PII and correct, amend, or delete any of the PII you have provided to us on the Services by emailing us at privacy@credenshare.io or at the address provided below. Please include your name, address, and/or email address when you contact us.
20. Browser Extension
The CredenShare browser extension creates encrypted share links from your browser's toolbar. This section describes what the extension does with your data, and it governs the extension specifically wherever it differs from the rest of this Statement.
What the extension can reach
The extension contacts one address and no others: app.credenshare.io, the CredenShare web application, which holds your signed-in session and receives the shares you create. It cannot contact any other website. It does not read the pages you visit, the tabs you have open, or anything you type outside the extension's own window.
When you open the extension it asks the web application who you are, so that it can draw the right screen: your account details, the workspaces you belong to, the plan in force, and a count of your active and expired shares. This is your own account information, retrieved over your own session.
What is encrypted, and what is not
The contents of a share are encrypted inside your browser before they are sent. The key that decrypts them is carried in the share link you give your recipient, and is not transmitted to us along with the share, so what reaches us is ciphertext we cannot read. This is the same end-to-end encryption the web application uses.
Everything you enter as share content is inside that encrypted portion: every field name, every field value, the body of a paste, and the filename of an attachment.
Some parts of a share are not encrypted, because the service needs them in order to work. These are the title, the description, the message shown before a protected view, any IP allowlist, and the settings that govern the share — its expiry, its view limit, its timed-view duration, whether it requires sign-in or multi-factor authentication, and which workspace it belongs to. They are stored with your account in the ordinary way, so that the share appears in your own list and so that its rules can be enforced. Choose a title accordingly.
If you set a passcode on a share, the passcode is not sent to us. The extension sends a one-way verifier derived from it, which lets the service count failed attempts without holding anything that helps it decrypt the share.
Recovering your own links
A share's link can only be rebuilt by something that holds its decryption key, and we do not hold it by default. So that a share you created from the extension does not become one you cannot re-copy later, the extension uses one or both of the following.
On the device that created the share, the extension passes the key to the CredenShare web application so that the app can rebuild your link. The key waits in the extension's memory for up to two hours, and is handed over the next time you open app.credenshare.io in that browser within that window. It is deleted from the extension the moment it is handed over. It is lost if those two hours pass first, if you close your browser first, or if you create a great many shares before opening the app, because only the most recent hundred are held. It stays in your browser throughout and is not sent to us.
If your account has zero-knowledge custody enabled, the extension additionally sends us a copy of that key that has been encrypted to your account's public key, so that you can rebuild your own links on your other activated devices. We store this copy but cannot open it. Opening it requires your account's private key, and although we do hold that key, we hold it only in a form sealed with your encryption passphrase — which is shown to you once, is never sent to us, and without which the sealed copy is unreadable to us. That sealed copy is what lets another of your devices recover the key after you enter the passphrase there. If you create the share inside a team workspace, a second copy is encrypted to that team's key as well, so that colleagues you have granted team access can open the share. Zero-knowledge custody is a feature of paid plans; if your account does not have it, no copy of any key is sent to us.
What the extension stores on your device
The extension remembers your own settings so it does not have to ask you twice: which developer tools you have pinned, how each tool was last configured (for example SHA-256 rather than MD5, or Decode rather than Encode), which screen the popup was last on, and your default expiry, workspace and format for a new share. These are preferences about the extension itself, and they stay on your device. No text you type or paste into a tool is ever stored: the extension deliberately skips text boxes when it remembers how a tool was set up, so a passphrase, a key or a document you were working on is not written to disk. A tool that lets you build up a list, such as the .env generator, also remembers how many rows you had and what kind each one was.
While you are signed in, the extension also keeps a short-lived copy of your account details so that the popup does not have to ask the service again every time you open it: your email address and account identifier, whether multi-factor authentication is switched on, the workspaces you belong to and their names, and the plan in force. Like the draft below, it is held in memory rather than written to disk, is not used once it is more than thirty minutes old, and does not survive closing your browser. It is not sent anywhere.
The extension also keeps a temporary copy of a share you are part-way through composing, so that dismissing the popup by clicking elsewhere does not discard your work. Once you have created a share, that copy also holds the resulting link until you start another one, so that an interruption does not lose a link you have not pasted yet. It is held in memory rather than written to disk, is deleted after five minutes of inactivity, and does not survive closing your browser.
The extension writes to your clipboard when you use a copy control: a newly created share link, or the output of a developer tool, which may itself be a generated password, an API key or other secret. It never reads your clipboard. Anything copied stays in your system clipboard after the popup closes, and your operating system or browser may keep a clipboard history or synchronise it to your other devices — none of which is under the extension's control.
Developer tools
The extension includes fifteen developer utilities — encoders, formatters, hash and key generators and similar. They run entirely on your device. What you enter into them is not transmitted anywhere, is not retained once you close the popup, and does not require a CredenShare account. The way a tool was set up is remembered, as described above, and anything you copy out of one goes to your clipboard and stays there.
Analytics
The extension contains no analytics, no telemetry and no tracking pixels. It does not report your use of it to us or to anyone else. The parts of this Statement describing cookies, web beacons and third-party advertising on our website do not apply to the extension.
Your session
The extension signs you in using your existing CredenShare session on app.credenshare.io, and reads a single security cookie from that site in order to make requests on your behalf. Once you sign out of CredenShare the extension can no longer act for you. The copy of your account details described below is cleared the next time the extension checks, and in any case when you close your browser, so the popup may briefly still show your account after you have signed out elsewhere.
Removing the extension
Uninstalling the extension deletes the settings, any draft, and the copy of your account details it was holding. Keys already handed to the web application belong to that site's own storage and remain until you clear that site's data from your browser. Shares you have already created are unaffected: they remain governed by their expiry and by the rest of this Statement, and you can delete them from your CredenShare account.
21. Product and Website Analytics
We use two analytics services to understand how CredenShare is used so that we can improve it. Neither is used for advertising, neither receives anything you put inside a share, and we do not sell the information either of them collects.
The two services, and where each one runs
PostHog (PostHog, Inc., United States) is our product analytics service. It tells us which features customers use. It runs in the CredenShare web application and on our public SecurePaste pages. It does not run on share links — the pages recipients open to view something you sent — and it does not run at all if your browser sends a Global Privacy Control or Do Not Track signal. Data collected by PostHog is held in PostHog's United States cloud.
Google Analytics is our website analytics service. It tells us how people find and move around our websites. It loads more broadly than PostHog does, including on share-link pages — although on share-link and secure-request pages it never records which page was viewed. Google Analytics does not currently respond to Global Privacy Control or Do Not Track signals; see Section 15 and "Your choices" below.
What PostHog receives when you are signed in
Your CredenShare user identifier and the email address on your account, together with the plan you are on, whether you are in a trial, and which workspace you are working in.
It also receives a record that certain actions happened: signing in and out; creating a share, a secure request or a paste; creating a team; inviting a member; connecting Slack; turning custom branding on or off; changing settings; opting in or out of marketing email; turning multi-factor authentication on or off; completing or skipping onboarding; and opening or using one of the developer tools.
With those actions it receives which options were chosen, never what you put in them. That a share was password-protected, for example, but not the password; that a share had a view limit, but not the limit; that a share was restricted by IP address, but not the addresses. For the developer tools it receives the setting you picked from the tool's own controls — SHA-256 rather than MD5, decode rather than encode — but never what you typed into the tool or what it produced.
What PostHog receives on public SecurePaste pages
If you create a paste without signing in, PostHog receives a randomly generated identifier and a record that a paste was created. That identifier is not connected to any CredenShare account, and each of our sites keeps its own separate identifier, so a paste created without signing in is not joined up with an account you are signed in to elsewhere. Note that this is not the same as being untraceable: as described below, your IP address is still collected.
What is collected automatically
For everyone PostHog tracks, it also receives:
- Your IP address, which is retained, and an approximate location derived from it — typically country and city, not a precise location.
- Your browser, operating system, device type, screen size, language and time zone.
- Which screen of the application you were on. This is drawn from a fixed list of our own screens, with any identifier in the address replaced by a placeholder. It never includes anything after a "?" or a "#" in the address, which is what keeps a share's identifier and its decryption key out of our analytics entirely.
What is not collected
Every event PostHog may receive is defined in advance in a fixed list inside CredenShare, and anything not on that list is discarded in your browser before it is sent — including anything the analytics software might otherwise have added on its own. In practice that means none of the following ever reaches PostHog:
- The contents of a share, a secure request or a paste; its title or description; any filename; and any field name or field value.
- Passphrases, secrets, encryption keys, share links, access tokens, or the short code that identifies a share.
- The email address of anyone other than the signed-in account holder — a recipient's or an invitee's address is discarded however it was attached.
- The IP addresses or domains a share is restricted to.
- Anything you type into, or that is produced by, the developer tools.
There is also no session recording, no screen recording, and no automatic click or form tracking in CredenShare. The analytics software we load does not contain that functionality at all, so it cannot be switched on remotely. PostHog is not sent the page you arrived from or any advertising campaign information.
Cookies and browser storage used by analytics
PostHog sets a first-party cookie named ph_<project key>_posthog, and stores an entry of the same name in your browser's local storage plus one in session storage. The cookie lasts up to 365 days. It is set separately for each of our sites and is not shared across them. Google Analytics sets its own cookies, as described in Section 5.
Retention, and your choices
Information collected by PostHog is retained for seven years, after which it is deleted.
You can stop PostHog collecting anything by enabling Global Privacy Control or Do Not Track in your browser; CredenShare checks for those signals and does not start PostHog at all when it sees one. You can limit Google Analytics through your browser's cookie settings or Google's own opt-out browser add-on. You may also ask us to provide a copy of, or delete, the analytics information associated with your account by emailing privacy@credenshare.io, and we will locate you in PostHog by your user identifier or email address.
22. Contact Information
Unless otherwise stated, CredenShare is a data controller under applicable law for PII processed subject to this Statement. If you have any questions about this Statement or the Service, please contact us:
CredenShare Inc.
Privacy Department
10-150 Elgin St, 10th Floor
Ottawa, ON, K1P-1L4
Canada
Email: privacy@credenshare.io