Is my data encrypted at rest?
All traffic to and from DeSpy is encrypted in transit with HTTPS (HSTS enabled). At rest, the contact details submitted through our data-removal process are encrypted with AES-256-GCM, and we are extending encryption at rest to cover all personal data we store. Where data is not yet individually encrypted it is held on a hardened, access-controlled server, and IP addresses are stored only as salted one-way hashes — never as raw addresses.
Are backups encrypted, and how long are they retained?
Yes. Every nightly database backup is individually encrypted (X25519 + ChaCha20-Poly1305, via age) before it is written to disk, and each one is deleted automatically after 7 days. They also sit on full-disk-encrypted storage on the same hardened, access-controlled server.
The part that matters most: the decryption key is not on that server. The server holds only the public half, which can encrypt a backup but cannot open one — so anyone who took the machine would get ciphertext and nothing else. The private key is held offline by the operator. The trade is deliberate and absolute: if that key were lost, the backups would be unrecoverable, because there is no copy of it on our infrastructure for anyone to seize or for us to be compelled to hand over.
A backup nobody has restored is a hope rather than a backup, so restoring is part of the process and not an assumption: on 2026-07-31 an encrypted nightly backup was decrypted on separate hardware and verified against production — database integrity check, and a row-by-row content comparison that matched exactly.
Which countries host production and backup data?
All production and backup data is hosted in the United States.
Are users notified of legal requests for their data?
Yes — where we are legally permitted to do so, we notify affected users of any legal request for their data. We disclose personal data only when compelled by valid legal process, and only to the extent required.
Does administrator access require multi-factor authentication?
Yes. All administrative access requires multi-factor authentication, using a time-based one-time passcode (TOTP) in addition to a password.
Is internal access to personal data restricted?
Yes. Access to personal data is limited to personnel with a legitimate business need, under a least-privilege model. Administrative actions are recorded in a tamper-evident (hash-chained) audit log.
Do you conduct security audits or penetration tests?
We run adversarial (“red team”) reviews of our code on every security-relevant change, and before launch we ran repeated multi-dimension security audits of the whole system — the findings and fixes are tracked in our engineering records. We have not yet engaged an external penetration-testing firm; when we do, this answer will say so. Every claim on this page is written to match what is actually running, and we update it when reality changes.
Do you use a third-party email provider?
Yes — Twilio SendGrid relays the email DeSpy sends: account confirmations, beta-program mail, replies to data requests, and the newsletter. It receives the recipient address and the message itself, solely to deliver it, and is listed as a sub-processor in our privacy policy. It is not used for advertising, profiling, or analytics, and we send it no other personal data.
We never sell or give your personal data to third parties. If we add or change a processor that handles personal data, it is listed in the privacy policy. And if we were ever legally compelled to disclose data, we would notify every affected user wherever we are permitted to do so.
More questions?
Email privacy@despy.app, or exercise your data rights any time via the data-removal form.