Exit Protocol
Privacy & data protection

Your data, and how we look after it

This notice explains, in plain language, who stands behind Exit Protocol, what personal data we hold, and the rights you have over it under the Data Protection (Jersey) Law 2018. For the cryptographic detail behind the promises here, see the security architecture.

Last updated: July 2026

Who we are

Exit Protocol is a registered business in Jersey, Channel Islands ([JFSC registration no. pending]). We are the data controller for the personal data described here.

We are registered with the Jersey Office of the Information Commissioner ([JOIC registration no. pending]) and handle personal data in line with the Data Protection (Jersey) Law 2018.

The privacy-first principle

Exit Protocol is built so that we hold as little of your information as the service can possibly work with — and so that the most sensitive part, the contents of your vault, is one we cannot read at all.

Your vault is encrypted on your own device with a key derived from your master password before anything is sent to us. What reaches our servers is a sealed, unreadable box. We have no master key and no way to open it. This means most of what you entrust to Exit Protocol never exists, in readable form, anywhere we can see.

What this means for a data request
Because we genuinely cannot read your vault contents, we cannot export or hand over their plaintext — to you, to your recipients, or to anyone who compels us. We can only act on the data we do hold, listed next.

What personal data we hold

The personal data we actually hold about you is limited to:

  • Your account
    Your email address, a salted hash used to authenticate you (never your password itself), your chosen timezone, and account timestamps.
  • Your vault, sealed
    Encrypted vault contents and encrypted file attachments. We store these as ciphertext and cannot decrypt them.
  • Your recipients
    The names, contact details, and delivery settings you enter for the people who should receive a vault. You provide these; please only add people whose details you are entitled to share.
  • Your Pulse
    Check-in and delivery scheduling data — when you last checked in, when the next deadline falls, and the switch's state.
  • Billing
    Subscription and payment status. Card details are handled by our payment provider and are never stored on our servers.
  • Technical logs
    Limited security and operational logs (for example, sign-in events and error diagnostics) needed to keep the service safe and working.

Why we hold it

We only process this data to run the service you have signed up for: to authenticate you, to keep your Pulse ticking, to deliver sealed vaults to the recipients you have chosen when the switch fires, to take payment, and to keep the platform secure. We do not sell your data, and we do not use it for advertising.

Who we share it with

We do not sell or trade your personal data. To run the service we rely on a small number of trusted service providers (“processors”) who handle data on our behalf, under contract and only on our instructions. Each one receives only the specific data it needs to do its job — not everything we hold, and never all of it together:

  • Hosting, storage & database
    The providers that run our servers and store our data. This is the only place your sealed vault ever sits — and it sits there as ciphertext, so they cannot read its contents any more than we can. They also hold your account record, recipients, and Pulse state.
  • Email delivery
    Receives the email addresses we send to — yours and your recipients' — and the messages themselves: check-in reminders, and, when the switch fires, the single-use link and verification code a recipient uses to open the vault. Your vault contents are never placed in an email; they stay in sealed storage and are opened in the app.
  • Payment processing
    Receives your billing and subscription status and handles your card details directly. It never sees your vault, your recipients, or who they are.
  • Bot-protection
    Receives the technical signals from your browser needed to tell a real person from an automated attack at sign-up and sign-in. It never sees your vault or your recipients.

We will also disclose data where the law requires it — but, as noted above, what we can technically disclose about your vault is limited to sealed ciphertext we cannot open.

How long we keep it

We keep your data for as long as your account is active. If you close your account, we delete your vaults, recipients, and account data, retaining only what we are legally required to keep (such as limited billing records) for as long as the law requires.

Your rights

Under the Data Protection (Jersey) Law 2018 you have the right to access the personal data we hold about you, to have inaccurate data corrected, to have your data erased, to object to or restrict how we process it, and to data portability. To exercise any of these, contact us using the details below.

A note on erasure
You can delete recipients, vaults, and your whole account from within the app at any time. Because your vault is sealed to us, deletion is genuinely final: once removed, encrypted contents cannot be recovered by us or anyone else.

Contact & complaints

For any privacy question or to exercise your rights, reach us through our secure contact form. We will respond within the timeframes the law requires.

If you are unhappy with how we have handled your data, you have the right to complain to the Jersey Office of the Information Commissioner, the independent regulator with whom we are registered.

Privacy & data protection — Exit Protocol