Privacy Policy
In effect since September 9, 2026.
The short version
Your documents never leave your browser. Watermarking, redaction, and signing all happen locally — we never receive, see, or store the file you're working on, or its content, because there is no route on this server that could receive one. That is a property of how the service is built rather than a promise about how we behave. What we do handle is limited to what's needed to run your account and subscription: your email, security credentials, billing identifiers, and — for the hosted registry — hashes and metadata about documents you've issued, never the documents themselves.
Who we are
Lightfast is operated by Rafael Arciniegas (lightfast.co) — full details in the legal notice. For any privacy question or request, contact the contact form. The legal notice carries an address for anyone who needs one.
What we collect
To operate an account:
- Email address.
- Recovery codes, stored as one-way hashes — we can check a code you give us, and we cannot read or reissue the codes themselves.
- If you use a passkey: a public key and credential identifier. The biometric or device unlock that authorizes it never leaves your device and never reaches us.
- If you enable two-step verification: whether it's active, not the underlying secret in readable form (it's encrypted at rest).
- Session data: a hashed session token, your browser's user-agent string, and timestamps.
To operate billing (Pro and Team plans):
- Billing is handled entirely by Paddle, our merchant of record. We never receive or store your card details — only a customer/subscription reference ID and your plan status.
For the hosted registry (Pro and Team plans, when used):
- A hash chain of issuance records: an opaque document identifier, cryptographic hashes, a timestamp, and which tier issued it. Not the document, not its content, and not the names of people the document was about.
If you write to us through a form on this site:
- Your name, the address you want a reply at, and what you wrote. What else it asks depends on the subject you choose, and it asks nothing the subject does not need. A quote request also asks for the organisation, roughly how many people are in it, where it is registered and — optionally — its website: the size is what the price depends on, and the country decides the invoice and which law the licence is written under. A report that something is not working asks which part of the product it happened in, because they run differently and the downloadable tools can be a version behind. A security report asks where you found the problem. A request about your own data asks — optionally — for the address the account is under, if it is not the one you are writing from, because that is how we find the right account.
- None of it is stored here. The form sends an email and keeps no record: there is no submissions table, so there is nothing to export, nothing to erase, and nothing to leak. It lives in our mailbox for as long as we keep the correspondence, exactly like a letter.
- We answer it and nothing else — you are not added to any list, and there is no marketing to opt out of because none is sent.
What we explicitly do not collect:
- The content of any document you protect, sign, or verify — regardless of plan. This is an architectural fact, not a policy we could choose to change without changing the product: the code that watermarks, redacts, and signs documents runs only in your browser.
Why we process this data
Account and billing data: to perform the contract you enter into by creating an account and, where applicable, subscribing to a paid plan. We don't rely on your consent for this — it's necessary to provide the service you asked for.
Anything you send through the contact form: to answer you. Where you are asking about buying, that is a step towards a contract at your request; where you are asking a question, or for help with something that is not working, it is the plain interest both of us have in a reply — and where you already pay for the product, part of providing it. A report about a security problem is used to investigate and fix it, which is in the interest of everyone using the product. A request about your own data is answered because the law that gives you the right also requires us to act on it. In every case it is used for the answer and for nothing after it.
How long we keep it
- Sessions expire 7 days after they were last used, and 90 days after they were created whatever happens in between. You can end any of them yourself from your account at any time.
- Email-verification links expire in 24 hours and sign-in links in 15 minutes. A pending email change expires too. All of them are deleted once used, and a daily job deletes any that expired without being used.
- An invitation to join a team is deleted when it is accepted, when it is cancelled, or when it expires. This matters most if you were invited and never replied: we hold your address only until the invitation lapses, and then not at all.
- Our record of security events on an account — sign-ins, credential changes — is kept, because it is what lets us and you reconstruct what happened. It contains no email addresses and no IP addresses.
- Registry entries (hashes and metadata, never document content) are kept indefinitely, since their purpose is a durable record you can rely on later — but see "Your rights" below for what happens to them if you delete your account.
Who we share it with
We don't sell your data, and we don't use it for advertising. The following subprocessors handle parts of the account/billing infrastructure on our behalf, each scoped to what they need to do their job:
- Vercel — application hosting.
- Supabase — database hosting.
- Paddle — billing and payment processing (merchant of record).
- Resend — transactional email (account verification, sign-in links, team invites, security alerts).
- Upstash — rate limiting (abuse prevention on login/signup).
- Cloudflare — the “confirm you're human” check on the sign-up and contact forms, and only those two. It sees your IP address and how you interact with that one widget. It stops those forms being used to send mail in your name, or in a stranger's.
- Plausible — website analytics, cookieless by design; it doesn't track you individually or across sites.
- Sentry — error reporting, on our servers only. When something breaks it receives the error itself and the shape of the page's address rather than the address, so the identifier of a document never reaches it. It does not receive the request: that is dropped whole before anything is sent, because it carries your sign-in cookie. Nothing from Sentry runs in your browser. It is not switched on for this site, so it is receiving nothing.
Your rights
If you have an account, you can exercise these yourself at any time, no request needed:
- Access and export: download everything we hold about your account from your account page.
- Deletion: permanently delete your account from the same page. Your email address, sessions, credentials and signing keys go. Two records are kept, and in both cases the link back to you is removed rather than the record:
- Registry entries you issued stay, because they are a chain and removing a link would break the evidence for entries that are not yours. What made them readable does not: the key that opens their sealed contents is destroyed with your account, so who each document went to, what it was called and what was covered up become permanently unreadable — by anyone, including us. What is left is hashes, timestamps and a null where your account used to be.
- The record of security events — sign-ins, credential changes — stays for the same reason a ledger does: it is what lets an incident be reconstructed, including one affecting somebody else. It never held your email address or IP, and after deletion it holds no reference to your account either.
- Correction: change your email from your account settings.
If you're outside the US and this doesn't cover a right your local law gives you, use the contact form.
International transfers
Depending on where you're located, using this service may involve transferring data to countries with different data protection laws than your own. The specifics depend on our final hosting configuration, which isn't finalized yet — this section will be completed before that configuration goes live.
Children's privacy
This service isn't directed at children, and we don't knowingly collect data from anyone under 16. We don't currently have an age-verification mechanism beyond this statement.
Security
There are no passwords on this service: you sign in with a passkey or with a single-use link sent to your email. Recovery codes and sensitive tokens (sessions, sign-in links, email verification) are hashed at rest, not stored raw. Two-step verification secrets and signing-key material are encrypted at rest. Connections are encrypted in transit. To report a security problem, use the contact form and choose that subject — it is marked so it does not sit in with general enquiries. It is the only channel, and the form states the reply time we work to.
Changes to this policy
We'll update the date at the top of this page when this changes, and for material changes we'll make a reasonable effort to notify account holders directly.