Privacy Notice
This notice explains how OpenE2EE handles personal information across the website, documentation, console, licensing, billing, and communications.
1. Scope and controller
OpenE2EE LLC (“OpenE2EE,” “we,” “us,” or “our”) is responsible for personal information covered by this notice. It applies to open-e2ee.dev, the OpenE2EE documentation and console, commercial licensing and billing, support and sales communications, and related security operations.
This notice does not govern information processed solely inside software that you operate. When a customer uses the SDK in its own product, that customer determines its own data practices and is responsible for its notices.
2. Information we collect
Information you or your organization provides
- contact information, such as name, business email, organization, and communication content;
- commercial-license information, including licensee, covered product, plan, and support requests;
- billing information, such as billing address and tax identifier; and
- security reports, feedback, and other information you choose to send.
Information from connected services
- GitHub: when you sign in, GitHub provides an account identifier and available profile information such as username, display name, email, and avatar.
- Stripe: Stripe provides customer, subscription, invoice, payment-status, billing, and tax information needed to complete and administer a license. OpenE2EE does not intentionally receive or store complete payment-card numbers.
- Your organization: an authorized purchaser or administrator may provide information about license users, billing contacts, or the covered product.
Technical information
Our hosting and security providers may process IP address, request time, URL, referring page, browser and device information, authentication and session events, error information, and security signals. The console uses signed, secure cookies needed for authentication, request integrity, and account access. The marketing site additionally records a small set of anonymous events with no identifier attached, described in full inCookies and analytics.
3. How and why we use information
We use personal information to:
- authenticate users and operate the website, documentation, console, and billing portal;
- create, fulfill, document, renew, support, and enforce commercial licenses;
- process payments, invoices, taxes, cancellations, and accounting records;
- answer support, sales, licensing, privacy, and security communications;
- protect the Services, investigate abuse, debug failures, and prevent fraud;
- improve documentation, reliability, and product experience; and
- comply with law and establish, exercise, or defend legal claims.
Where the law requires a legal basis, we rely on performance of a contract, steps requested before entering a contract, compliance with legal obligations, our legitimate interests in operating and securing the Services, and consent where required. You may withdraw consent for future processing when consent is the basis.
4. How we disclose information
We disclose information only as reasonably necessary to:
- Service providers: Cloudflare for the public site, DNS, TLS, and security; Vercel for the console and documentation; GitHub for authentication; Stripe for payments, subscriptions, tax information, and the billing portal; and Google Workspace for business email.
- Professional advisers: accountants, lawyers, insurers, auditors, and security specialists subject to appropriate duties.
- Legal and safety recipients: authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate fraud or abuse, or respond to lawful process.
- Business transactions: a buyer, successor, or adviser in a financing, reorganization, acquisition, or sale, subject to appropriate confidentiality and continued protection.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising or use it for targeted advertising, and we have not done so during the preceding 12 months. We do not use personal information for automated decisions that produce legal or similarly significant effects.
5. Cookies and analytics
The public marketing site sets no cookies, stores nothing in your browser, and uses no advertising or cross-site behavioral analytics. It does measure which parts of the site people use, and this section describes that measurement exactly, because a privacy notice that describes it vaguely is not worth reading.
The site sends a short message to our own servers when one of eleven things happens: you run the live demo on the home page, open one of the failure scenarios further down it, open the quickstart, choose a runtime, copy the install command, follow the closing link of an article or the architecture guide, open one of our GitHub repositories, view the security model page, view the pricing page, open the console, or begin an enterprise enquiry. Each message contains the name of the event, the path of the page it happened on, and one further word on two of them: which of the three runtimes a runtime choice was, and which scenario was opened. That is the whole message.
The live demo is the one place on this site where you type something. What you type is encrypted and decrypted inside your own browser tab and never leaves it, and the message that records the run carries neither the sentence nor anything derived from it — not its length, not the size of the ciphertext, not how long the encryption took. The message reads demo_run /, and one is sent per page, not per sentence.
The failure scenarios further down the home page run the same way, in your own browser, and the message that records one reads scenario_opened / followed by the name of the scenario — the same name that appears in the page address when you open it. It carries nothing about what the scenario produced: no message content, no sizes, no timings. One is sent the first time each scenario is opened, and opening the same one again sends nothing further.
It contains no identifier of any kind. We set no cookie, read no cookie, and write nothing to local storage; we do not fingerprint your browser or device; we assign you no visitor or session identifier; and your IP address is not recorded alongside these events. Because there is nothing that distinguishes one visitor from another, these events cannot be linked to you, to each other, or into a journey through the site, either by us or by anyone who obtained the data. What they show is how many people took each step, and nothing else. The measurement is handled by our own code on our own infrastructure, and no third-party analytics service receives it.
The console uses essential authentication, security, and session cookies. Cloudflare, Vercel, GitHub, and Stripe may use their own necessary security or service cookies when you interact with their infrastructure or hosted pages.
Because we do not sell or share information for targeted advertising, there is no advertising opt-out needed for the current Services. We will honor legally required browser signals if our practices change in a way that makes them applicable.
6. Retention and security
We retain personal information only as long as reasonably necessary for the purposes above. Retention depends on the record:
- console authentication data is primarily maintained in signed session cookies and connected-provider records;
- license, subscription, invoice, and transaction records may be kept for the relationship and up to seven years afterward for accounting, tax, audit, and dispute purposes;
- support, sales, and security communications are kept as needed to resolve the matter and maintain appropriate records; and
- request and security logs are generally kept for shorter periods determined by operational and provider settings, unless needed to investigate an incident.
We use administrative, technical, and organizational safeguards appropriate to the nature of the information, including encrypted transport, restricted credentials, least-privilege service keys, secure session cookies, and access controls. No system is perfectly secure, and we cannot guarantee absolute security.
7. Your privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, or a copy of personal information; to object to or restrict certain processing; to withdraw consent; and to appeal a decision. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
California residents may request the categories and specific pieces of personal information collected, the sources, purposes, and disclosure categories; request correction or deletion subject to exceptions; and receive equal service when exercising these rights. OpenE2EE does not sell or share personal information as those terms are defined by California law.
Submit a request to support@open-e2ee.dev. Describe the request and the account or email involved. We may need to verify your identity and authority before acting. An authorized agent may submit a request where applicable. You may appeal a denial by replying with “Privacy appeal” in the subject. You may also complain to your local data-protection authority.
Children
The Services are intended for developers and businesses and are not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child provided it.
8. International transfers
OpenE2EE is based in the United States, and service providers may process information in the United States and other countries. Those countries may have different data-protection laws. Where required, we rely on recognized transfer mechanisms and contractual safeguards made available through our providers.
9. Changes and contact
We may update this notice as our practices or legal obligations change. We will publish a new effective date and provide additional notice when a change is material. We will not apply a materially more permissive use or disclosure practice retroactively to previously collected information without appropriate notice and consent where required.
Version 2026-07-28: the marketing site began recording the anonymous usage events described in Cookies and analytics, nine of them at that date. No cookie, storage, identifier, or IP-address record was introduced with them, and nothing collected under an earlier version of this notice is affected.
Version 2026-08-07: a tenth event was added, recording that the live demo on the home page was run. It carries nothing about what was typed into the demo, as described in Cookies and analytics. Nothing else about the measurement changed: still no cookie, no storage, no identifier, and no IP-address record.
Version 2026-08-07.2: a second change on the same day, and the reason that version carries a suffix rather than a later date. An eleventh event was added, recording which scenario was opened. The name of the scenario is the second and last word any event on this site carries, and it describes the page rather than the visitor, as described in Cookies and analytics. Nothing else about the measurement changed: still no cookie, no storage, no identifier, and no IP-address record.
Version 2026-08-09: no new event, no new category of information, and nothing additional collected. The failure scenarios moved from a page of their own onto the home page, and the message that records one names the page it happened on, so the path in that message changed with the move — it now reads scenario_opened / followed by the name of the scenario. This notice is versioned for it because the words the site transmits changed, and a notice that quotes those words exactly, as this one does, cannot describe them and stay unversioned. Still no cookie, no storage, no identifier, and no IP-address record.
For privacy questions or requests, email support@open-e2ee.dev. For suspected vulnerabilities or security incidents, email security@open-e2ee.dev.