Skip to content
Sealed
Menu

Privacy policy

Effective

Sealed lets consultants, agencies and freelancers share work with their clients in private rooms. This policy explains what personal data we handle when you use Sealed, and what you can do about it.

Sealed is in early access. We keep this policy short and plain, and we will tell you before anything important changes.

Who we are

Sealed is operated by APPINE L.L.C-FZ, a company registered in the United Arab Emirates, at Business Center 1, M Floor, The Meydan Hotel, Nad Al Sheba, Dubai, United Arab Emirates ("we", "us"). For anything about your data, email intro@appine.io.

Who this policy covers

  • Senders: people who sign up for Sealed and share work from a workspace.
  • Recipients: people who open something a sender shared with them, such as a client.
  • Visitors to this website.

When a sender shares files with you, the sender decides what to share and with whom. For the content of those files, the sender is responsible and we process it on their behalf. If you have a question about a file someone shared with you, ask them first; we will help if they cannot.

What we collect

From senders:

  • Account details: your name, email address and sign-in details. Sign-in is handled by our provider Clerk.
  • Workspace details: the workspace name, logo, brand colour, team members and their roles.
  • Your content: files and documents you upload or publish, their versions, folder names, notes, and the access settings you choose.
  • Access settings: passcodes are stored as a one-way hash, plus an encrypted copy so you can reveal and re-send them. Email addresses you allow are stored as you enter them.
  • AI agents and API keys you connect: their names and when they were last used.

From recipients:

  • The email address you enter if a document asks you to confirm it, and the one-time code we send you.
  • That a document was opened, when, which version, and for roughly how long it stayed on screen.
  • Basic technical details: browser and operating system family, device type, and a hashed form of your network address used to tell repeat opens apart and to stop abuse.
  • A cookie that remembers this device once you have unlocked a page, for the period shown when you unlock it.

From website visitors: this website uses no analytics and sets no cookies. Our servers keep standard technical logs (such as the address requested and the time) to keep the site running.

How we use it

  • To provide Sealed: store your work, show it to the people you share it with, and tell you when it is opened.
  • To keep accounts and shared content secure, including rate limits and abuse prevention.
  • To send service emails, such as confirmation codes, invitations and important notices.
  • To answer you when you contact us, and to meet our legal obligations.

We do not sell personal data, we do not show ads, and we do not use your content to train AI models.

Who can see it

  • Your content is visible to members of your workspace and to the people you share it with, under the access setting you choose.
  • When a recipient opens something, the workspace that shared it can see that it was opened. Shared pages say so.
  • Our service providers process data only to run the service for us (see below).
  • We disclose data to authorities only when the law requires it.

Service providers and where data is stored

  • Railway: hosting. Our database is in the United States and stored files are in the Netherlands.
  • Clerk: sign-in and account security, in the United States.
  • Resend: delivery of service emails, in the United States.

This means your data may be processed outside your country, including outside the United Arab Emirates. We use providers that protect data in transit and at rest, and we share only what each one needs.

How long we keep it

  • Account and workspace data: while your account is open.
  • Content: until you delete it. Items moved to Trash are removed for good after 30 days, or at once when you choose Delete forever.
  • Open records: counted opens for up to 13 months; other open events, and the hashed network address, for 30 days.
  • When you close your account, we delete your workspace data within 30 days, except what we must keep by law. Backups are overwritten on a rolling basis.

Your rights

You can ask us to give you a copy of your personal data, correct it, delete it, or stop or limit how we use it. You can also object to processing and ask for your data in a portable format. These rights come from the UAE Personal Data Protection Law and, where they apply to you, laws such as the EU GDPR.

Email intro@appine.io and we will reply within 30 days. If you are a recipient asking about a sender's content, we may pass your request to that sender. You can also complain to your local data protection authority.

Security

We encrypt data in transit, store passcodes as hashes, keep each workspace's data separate, and show shared pages in an isolated frame. No system is perfectly secure, so please use strong passcodes and share links only with people you trust.

Cookies

  • The Sealed app uses cookies that keep you signed in. They are necessary for the service.
  • Shared pages use a cookie to remember a device that has unlocked a page, so the reader is not asked again.
  • We use no advertising or analytics cookies.

Children

Sealed is a business service and is not meant for anyone under 18.

Changes to this policy

If we change this policy, we update the effective date above. If a change matters, we will tell signed-up users by email before it takes effect.

Contact

APPINE L.L.C-FZ, Business Center 1, M Floor, The Meydan Hotel, Nad Al Sheba, Dubai, United Arab Emirates. Email: intro@appine.io.