Information we process
- Workspace or tenant identifiers, installation tokens, conversation coordinates, and user identifiers supplied by Microsoft Teams, Slack, or Outlook.
- Secret metadata such as sender and recipient references, creation and expiry times, view limits, status, and audit events.
- Encrypted secret material. Depending on the selected security level, content is encrypted by the service or in the sender's browser before upload.
- Operational records such as request timestamps, error details, rate-limit counters, and security events. We do not intentionally write secret plaintext or access tokens to logs.
Why we process it
We process this information to deliver one-time secrets to intended recipients, verify platform requests, prevent abuse, enforce expiry and reveal policies, provide audit history, and operate and secure the service.
Retention and deletion
Secret material is destroyed when its reveal policy completes or when it expires. Metadata and security audit records may be retained longer for abuse prevention, support, compliance, and incident investigation. Removing the app revokes the removed conversation as a delivery destination; an organisation may still have other active installations and records.
Security and international processing
SecretBridge uses encryption in transit, encrypted storage, tenant-scoped routing, short-lived grants, and access controls. Browser-created public links encrypt and decrypt the secret on the user's device. No system can guarantee absolute security. Information may be processed in the regions selected by the service operator and its cloud and collaboration-platform providers.
Read the Security overview for current trust boundaries and limitations.
Your choices
Your organisation controls installation and may remove the app. Contact your organisation's administrator or the support contact shown in the app marketplace listing to request access, correction, export, or deletion where applicable. We may need to verify the request and preserve records when legally required.
Changes
We may update this policy as the service or legal requirements change. The effective date above identifies the current version.