This Privacy Policy is published by CIPHERPLUS PTE. LTD. (UEN 202316039M, Singapore), the developer and publisher of CipherKem, a quantum-safe file and folder encryption desktop application distributed via the Microsoft Store.
Contact: [email protected] · Website: cipherplus.io/cipherkem
This section satisfies the disclosure requirements of GDPR Article 13, Singapore PDPA Section 13, and Microsoft Store ADA Section 5(h).
| Activity | Data handled | Where it goes |
|---|---|---|
| Reading files you encrypt or decrypt | The file or folder bytes you explicitly select via the file picker | Stays on your device. Read into memory only. |
| Creating a CipherKem identity | Name, organisation, ML-KEM key pair (for encapsulation) and ML-DSA key pair (for signing) you enter / generate | Local storage only: %LOCALAPPDATA%\CipherKem\keys\ and a backup copy in ~\Documents\CipherKem\keys\ |
| Encrypting a file or folder | A session folder containing an .envelope file (KEM ciphertext + DSA signature) and one or more .parcel files (AES-256-GCM encrypted content) |
Written to your chosen output folder. CipherKem does NOT upload it. You may then send it to recipients (which is your choice and outside our control). |
| Decrypting a parcel | The session folder (.envelope + .parcel files) you select |
Stays on your device. Decryption uses only your local private key and the session key established by the sender's envelope. |
| Verifying an envelope | The .envelope file you select |
Stays on your device. Verification uses only the sender's public key from your local Contacts. |
| Importing a Contact Card | The peer's name, organisation, ML-KEM public key, ML-DSA public key, and fingerprint (from a .card file) |
Local storage only: %LOCALAPPDATA%\CipherKem\contacts\ |
| Creating or managing a group | Group name, member fingerprints, group descriptor signed with your ML-DSA key | Local storage only: %LOCALAPPDATA%\CipherKem\groups\ |
| Requesting a paid license | Your email address (you send it to us) plus a one-way cryptographic hash of a hardware identifier (the underlying identifier never leaves your machine — only its irreversible hash) | Sent to us by email at [email protected]. We use it to bind the issued license file to your specific machine. |
| Using the app day-to-day | None | No telemetry. No analytics. No crash reports. CipherKem performs no network communication during normal operation. |
For total clarity, CipherKem and CIPHERPLUS PTE. LTD. do not collect, store, or transmit any of the following:
Paid licenses are bound to a specific machine. To do this, CipherKem computes a one-way cryptographic hash of a stable hardware identifier on your device (derived from the system firmware table or registry, in preference order). The hash is irreversible — given the hash, no party (including us) can recover the original identifier or use it to identify your device on a network.
When you request a paid license, you email us this Machine ID hash. We sign a license file (using ML-DSA-44) binding that hash to a subscription expiry date. The license file is delivered back to you by email. We never request, receive, or store the underlying hardware identifier itself — only its irreversible hash.
All data CipherKem handles stays on your device under your Windows user profile. The primary storage locations are:
%LOCALAPPDATA%\CipherKem\keys\ — your identity files%LOCALAPPDATA%\CipherKem\contacts\ — imported Contact Cards from peers%LOCALAPPDATA%\CipherKem\groups\ — your group definitions%LOCALAPPDATA%\CipherKem\sessions\ — active session state (counters, session keys)%LOCALAPPDATA%\CipherKem\license\ — your license file~\Documents\CipherKem\keys\ — automatic backup of identity filesAll of this is protected by Windows' built-in user-profile permissions. We strongly recommend backing up your identity files — the application provides guidance for this.
On our side, we store only your email address, Machine ID hash, license tier, and license expiry date in our internal customer records, used solely to support license re-issuance, renewal, and dispute resolution. These records are kept in a Singapore-based system protected by industry-standard access controls.
CipherKem uses no third-party services in its operation: no analytics SDK, no advertising network, no cloud storage, no remote logging, no third-party fonts, no third-party telemetry.
The application is distributed via the Microsoft Store. When distributed via Microsoft Store, Microsoft may provide us, the publisher, with aggregate acquisition statistics (downloads, country breakdown, ratings) through its standard developer dashboards. This data is aggregated and does not identify individual users to us. Microsoft's own privacy practices for Store users are governed by the Microsoft Privacy Statement.
Because CipherKem collects no personal data through the application itself, there is no application-side data to access, modify, or delete on our side. Your local data (identity files, contacts, groups, encrypted files) is in your control on your own device.
For customer records on our side (email, Machine ID hash, license expiry):
EU and UK users have these rights under GDPR / UK-GDPR. California users have equivalent rights under the CCPA / CPRA. Singapore users have equivalent rights under the PDPA. We respond to all such requests within 30 days.
CipherKem is a business productivity tool and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has supplied us with personal information, contact us and we will delete it.
Because CipherKem processes all data locally on your device, no cross-border transfer of personal data occurs through the application itself. Customer records on our side are stored in Singapore. If you contact us by email from another country, that email is transmitted via your email provider and ours under their respective privacy practices.
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top and (where the change is significant) by a notice on the CipherKem product page. The current version is always available at cipherplus.io/cipherkem/privacy.html.
This policy is governed by the laws of the Republic of Singapore, in accordance with the Personal Data Protection Act 2012. The application is also designed to comply with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the California Consumer Privacy Act ("CCPA"), to the extent those laws apply to non-EU / non-California developers serving users in those jurisdictions via international app distribution.
CIPHERPLUS PTE. LTD.
Green House, SMU Connexion, 40 Stamford Road, Singapore 178908
Email: [email protected]
Product page: cipherplus.io/cipherkem
For privacy-related queries please write to the email above with subject line "Privacy request — CipherKem" so we can route the request appropriately.