Privacy
Effective: 2024-10-01
1 — What we cannot see
Every password, TOTP seed, mask address book, and attached secret is encrypted on your device with a key derived from your master password using Argon2id. The server only ever receives opaque encrypted blobs. We physically cannot read them.
2 — Data controller
Bruiser CyberSec LLC is the data controller for personal data collected through SPCTR. We collect only what is necessary to operate the service and communicate with you.
3 — What we do see
Your account email (for sign-in), timestamps of sync events, coarse device identifiers you name yourself, and any billing information our payment processor (Paddle, our merchant of record) returns to us. That's it.
4 — Analytics
Zero third-party analytics. Zero advertising trackers. Zero session recording. Server logs are retained 14 days for abuse investigation, then dropped.
5 — Data lifecycle
Delete your account from Settings → Delete. Encrypted blobs and metadata are removed within 24 hours. Backups roll off within 30 days.
6 — Data sharing
We share data only with service providers and the Merchant of Record (Paddle) for sale of the product, subscription management, payments, tax compliance, and invoicing. We may also share data with professional advisers or authorities where required by law. No subprocessor sees plaintext vault data.
7 — Subprocessors
Supabase (managed Postgres), Cloudflare (edge network), Paddle (payments / merchant of record), Resend (transactional email). No subprocessor sees plaintext vault data.
8 — Contact
Questions: Legal@bruisercybersec.com. Vulnerabilities: security@bruisercybersec.com (PGP on request).