Privacy Policy

Effective date: 2026-07-10

法的文書は現在、英語と韓国語で提供しています。以下は英語の正文です。

manage-env (the "Service") stores environment variables with end-to-end encryption. Secret values are encrypted on your device before they are sent to our servers, so the Service cannot read them. This policy describes the information the Service actually collects and how it is handled.

1. Information we collect

The Service collects only the following:

  • Account information: your email address, a verifier derived from your password (the password itself is never sent to the server), and your two-factor authentication settings if enabled
  • Service data: encrypted secret data (which the server cannot decrypt) and value-free metadata such as project names, key names, and version numbers
  • Usage records: value-free audit entries recording when actions (push, pull, sync, …) happened, and connection IP addresses used for security and rate limiting

2. How we use it

Collected information is used only to:

  • Authenticate your account and provide the Service (storing and syncing encrypted data)
  • Respond to security incidents and prevent abuse and excessive requests
  • Comply with legal obligations

3. Retention

Account information and service data are kept while your account exists. When you request account deletion, we delete your data without undue delay, except where retention is required by law. Encrypted version payloads beyond your plan’s retention limit are deleted automatically.

4. Sharing and processors

We do not sell personal information. We use Cloudflare, Inc. for server infrastructure, encrypted data storage, and verification email delivery.

Paid billing is not currently available, so we do not collect payment information or send it to Paddle. Before launching the Team plan, we will update this policy with the actual billing flow and processor.

  • Cloudflare, Inc.: server infrastructure, encrypted data storage, and verification email delivery

5. Cookies and browser storage

The Service uses no advertising or tracking cookies. Your session token is kept in the browser’s sessionStorage and disappears when the tab closes. Theme and language preferences are kept in localStorage.

6. Your rights

You may request access to, correction of, or deletion of your personal information at any time via the contact below. We verify that a request comes from the account holder before acting on it.

7. Security

Secret values are encrypted on your device (XChaCha20-Poly1305) before they reach our servers, and the encryption key is derived from your password on your device (Argon2id). The server stores only ciphertext and value-free metadata, so even a server breach does not expose your secret values.

For the same reason, if you lose both your password and your recovery key, the Service cannot recover your encrypted data. This is by design.

8. Changes and contact

If this policy changes materially, we will notify you in the Service or by email. For privacy inquiries, contact support@manage-env.com.