Privacy Policy
1. Data controller
The controller for personal data collected via may-secret.fr is:
- Christian Meneux, sole trader (trade name: May Software)
- SIRET: 414 577 734 00042
- Contact: privacy@may-secret.fr
2. Data collected
We collect the following data:
- Email address — used for authentication and account-related communications.
- Display name — optional, visible only to you.
- Cryptographic public key — stored on our servers to allow encryption of your files.
- Encrypted private key — stored encrypted with your password. May Software cannot decrypt it.
- Encrypted files — your files are encrypted in your browser before being sent. We have no access to their content.
- Billing data — processed exclusively by Stripe. We do not store your banking details.
- Technical data — IP address, access logs, kept for 12 months for security purposes.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service | Performance of contract |
| Subscription management | Performance of contract |
| Security and fraud prevention | Legitimate interest |
| Legal and accounting obligations | Legal obligation |
| Service communications (email) | Performance of contract |
4. End-to-end encryption
May·Secret is built around the zero-knowledge principle: your files are encrypted in your browser with libsodium (xchacha20poly1305) before any transmission. Your private key never leaves your device in clear text.
Important consequence: May Software cannot technically access the content of your files nor recover your private key if you lose your password.
5. Cookies and local storage
May·Secret does not use tracking or advertising cookies. Only the following are used:
- sessionStorage — authentication JWT token and profile metadata, deleted when the tab is closed.
- RAM only — the decrypted private key is never written to browser storage.
6. Retention period
- Account data: account lifetime + 3 years after deletion (accounting obligations).
- Deleted files: kept in trash for 30 days, then permanently deleted from the server.
- Access logs: 12 months.
- Stripe billing data: per Stripe's retention policy (7 years for accounting data).
7. Data recipients
- Stripe (United States / EU) — payment processing. Stripe is PCI DSS Level 1 certified.
- o2switch (France) — hosting of the server and encrypted files.
- No other data is shared with third parties for commercial or advertising purposes.
8. Your rights (GDPR)
Under the GDPR, you have the following rights:
- Access — obtain a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure — delete your account and all your data from the "My account" area.
- Portability — export your data via the "My account" area.
- Objection — object to certain processing.
- Restriction — request restriction of processing.
To exercise these rights: privacy@may-secret.fr
You may also lodge a complaint with the French data protection authority, the CNIL.
9. Security
Security measures in place:
- Client-side E2E libsodium (xchacha20poly1305) encryption.
- Password hashing with Argon2id.
- JWT authentication signed with RSA (RS256), stateless.
- Secure HTTPS/TLS transport.
- Storage quota checked before every disk write.
- Files permanently deleted after 30 days in trash.
10. Changes
Any significant change to this policy will be notified by email with 15 days' notice. The last update date is shown at the bottom of this page.
Last updated: June 30, 2026