CipherKem  ›  Privacy Policy

Privacy Policy

CipherKem — published by CIPHERPLUS PTE. LTD.  ·  Last updated: June 2026  ·  Effective: June 2026
Plain-English summary: CipherKem encrypts and decrypts files entirely on your device. We do not upload your files, your encryption keys, or any analytics. The only time we receive any data from you is when you email us to request a paid license — in which case we receive your email address and a one-way hash of your hardware identifier (so the license can be bound to your machine).

1. Who we are

This Privacy Policy is published by CIPHERPLUS PTE. LTD. (UEN 202316039M, Singapore), the developer and publisher of CipherKem, a quantum-safe file and folder encryption desktop application distributed via the Microsoft Store.

Contact: [email protected]  ·  Website: cipherplus.io/cipherkem

2. What data CipherKem handles, where, and why

This section satisfies the disclosure requirements of GDPR Article 13, Singapore PDPA Section 13, and Microsoft Store ADA Section 5(h).

ActivityData handledWhere it goes
Reading files you encrypt or decrypt The file or folder bytes you explicitly select via the file picker Stays on your device. Read into memory only.
Creating a CipherKem identity Name, organisation, ML-KEM key pair (for encapsulation) and ML-DSA key pair (for signing) you enter / generate Local storage only: %LOCALAPPDATA%\CipherKem\keys\ and a backup copy in ~\Documents\CipherKem\keys\
Encrypting a file or folder A session folder containing an .envelope file (KEM ciphertext + DSA signature) and one or more .parcel files (AES-256-GCM encrypted content) Written to your chosen output folder. CipherKem does NOT upload it. You may then send it to recipients (which is your choice and outside our control).
Decrypting a parcel The session folder (.envelope + .parcel files) you select Stays on your device. Decryption uses only your local private key and the session key established by the sender's envelope.
Verifying an envelope The .envelope file you select Stays on your device. Verification uses only the sender's public key from your local Contacts.
Importing a Contact Card The peer's name, organisation, ML-KEM public key, ML-DSA public key, and fingerprint (from a .card file) Local storage only: %LOCALAPPDATA%\CipherKem\contacts\
Creating or managing a group Group name, member fingerprints, group descriptor signed with your ML-DSA key Local storage only: %LOCALAPPDATA%\CipherKem\groups\
Requesting a paid license Your email address (you send it to us) plus a one-way cryptographic hash of a hardware identifier (the underlying identifier never leaves your machine — only its irreversible hash) Sent to us by email at [email protected]. We use it to bind the issued license file to your specific machine.
Using the app day-to-day None No telemetry. No analytics. No crash reports. CipherKem performs no network communication during normal operation.
Files you encrypt may themselves contain personal information. CipherKem does not inspect file content. A document you encrypt may contain names, addresses, financial data, or other personal data. The privacy of that content is governed by you — you decide what to encrypt and who to send the encrypted session to. CipherKem is the cryptographic tool; it is not a data controller for file content.

3. What we DO NOT collect

For total clarity, CipherKem and CIPHERPLUS PTE. LTD. do not collect, store, or transmit any of the following:

  • The bytes of files or folders you encrypt or decrypt
  • Your CipherKem identity (private keys or public keys) — they stay on your device
  • Your Contact Cards or contact list
  • Your group definitions or group descriptors
  • Your session folders, envelope files, or parcel files
  • Usage analytics, telemetry, or performance metrics
  • Crash reports (unless you choose to email us a crash log manually)
  • Your IP address, geolocation, browser fingerprint, or similar identifiers
  • Advertising identifiers — CipherKem serves no ads
  • Your underlying hardware identifier — only an irreversible, one-way hash of it (for license binding) is ever transmitted, and only when you request a license

4. The Machine ID hash — why it's safe

Paid licenses are bound to a specific machine. To do this, CipherKem computes a one-way cryptographic hash of a stable hardware identifier on your device (derived from the system firmware table or registry, in preference order). The hash is irreversible — given the hash, no party (including us) can recover the original identifier or use it to identify your device on a network.

When you request a paid license, you email us this Machine ID hash. We sign a license file (using ML-DSA-44) binding that hash to a subscription expiry date. The license file is delivered back to you by email. We never request, receive, or store the underlying hardware identifier itself — only its irreversible hash.

5. Local storage layout

All data CipherKem handles stays on your device under your Windows user profile. The primary storage locations are:

  • %LOCALAPPDATA%\CipherKem\keys\ — your identity files
  • %LOCALAPPDATA%\CipherKem\contacts\ — imported Contact Cards from peers
  • %LOCALAPPDATA%\CipherKem\groups\ — your group definitions
  • %LOCALAPPDATA%\CipherKem\sessions\ — active session state (counters, session keys)
  • %LOCALAPPDATA%\CipherKem\license\ — your license file
  • ~\Documents\CipherKem\keys\ — automatic backup of identity files

All of this is protected by Windows' built-in user-profile permissions. We strongly recommend backing up your identity files — the application provides guidance for this.

6. Storage and security — our side

On our side, we store only your email address, Machine ID hash, license tier, and license expiry date in our internal customer records, used solely to support license re-issuance, renewal, and dispute resolution. These records are kept in a Singapore-based system protected by industry-standard access controls.

7. Third parties

CipherKem uses no third-party services in its operation: no analytics SDK, no advertising network, no cloud storage, no remote logging, no third-party fonts, no third-party telemetry.

The application is distributed via the Microsoft Store. When distributed via Microsoft Store, Microsoft may provide us, the publisher, with aggregate acquisition statistics (downloads, country breakdown, ratings) through its standard developer dashboards. This data is aggregated and does not identify individual users to us. Microsoft's own privacy practices for Store users are governed by the Microsoft Privacy Statement.

8. Your rights

Because CipherKem collects no personal data through the application itself, there is no application-side data to access, modify, or delete on our side. Your local data (identity files, contacts, groups, encrypted files) is in your control on your own device.

For customer records on our side (email, Machine ID hash, license expiry):

  • Access: email [email protected] to request a copy of your records.
  • Correction: email us to update your email address or correct any record.
  • Deletion: email us to delete your customer records. Note that deletion ends your ability to renew or re-issue a license under your existing record.
  • Portability: the data we hold is so minimal that we can provide it as a plain-text email on request.

EU and UK users have these rights under GDPR / UK-GDPR. California users have equivalent rights under the CCPA / CPRA. Singapore users have equivalent rights under the PDPA. We respond to all such requests within 30 days.

9. Children

CipherKem is a business productivity tool and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has supplied us with personal information, contact us and we will delete it.

10. International transfers

Because CipherKem processes all data locally on your device, no cross-border transfer of personal data occurs through the application itself. Customer records on our side are stored in Singapore. If you contact us by email from another country, that email is transmitted via your email provider and ours under their respective privacy practices.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top and (where the change is significant) by a notice on the CipherKem product page. The current version is always available at cipherplus.io/cipherkem/privacy.html.

12. Governing law

This policy is governed by the laws of the Republic of Singapore, in accordance with the Personal Data Protection Act 2012. The application is also designed to comply with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the California Consumer Privacy Act ("CCPA"), to the extent those laws apply to non-EU / non-California developers serving users in those jurisdictions via international app distribution.

13. Contact

CIPHERPLUS PTE. LTD.
Green House, SMU Connexion, 40 Stamford Road, Singapore 178908
Email: [email protected]
Product page: cipherplus.io/cipherkem

For privacy-related queries please write to the email above with subject line "Privacy request — CipherKem" so we can route the request appropriately.