In Case
Back

Privacy Policy

Last updated: July 17, 2026

in-case.me is owned and operated by Lingbaoshi Wuxian Lingyu Wangluokeji Gongzuoshi (灵宝市无限领域网络科技工作室), a registered business in the People's Republic of China. “In Case” is the trading name under which the service is offered.

In Case ("we," "us," or "our") values your privacy. This Privacy Policy explains how we collect, use, and protect your information when you use our service.

1. Information We Collect

Information we collect: (a) Contact information — phone number and/or email address you provide for identity verification and notification alerts. (b) Encrypted content — asset inventories and letter drafts, encrypted in your browser using AES-256-GCM before upload; we cannot and do not access plaintext. For transparency, the following metadata is stored unencrypted to allow you to browse your vault: entry name (aliasName), memory hint (memoryHint), and category tag (categoryTag). These contain no sensitive content — all core data resides in the encrypted content field. (c) Account metadata — subscription status, protection threshold settings, and trusted contact relationships. (d) Essential cookies — a session token to recognize your device and keep you signed in. (e) Guided chat messages — inventory, letter-writing, and wishlist conversations use locally-scripted dialogues on our server. No conversation data is sent to any third-party AI provider. This is an intentional design choice to preserve zero-knowledge architecture.

2. How We Use Your Information

How we use your information: (a) To verify your identity and restore your account across devices. (b) To send notification alerts (SMS/email) when your protection threshold is reached. (c) To process subscriptions and maintain your account. (d) To communicate service updates or critical security notices. We do NOT use your information for advertising, user profiling, or automated decision-making.

3. SMS / Text Messaging

SMS / Text Messaging: If you provide a phone number, we use it solely for identity verification and delivering notification alerts. With your explicit consent, we may send SMS messages including verification codes, spare key invitations, and protection threshold alerts. Message frequency varies and is typically low (a few messages per month). Message and data rates may apply as determined by your mobile carrier. You may opt out of SMS at any time by replying STOP to any message or updating your settings. After opting out, we will only send a single confirmation message and will not contact you via SMS again unless you re-enroll.

SMS consent is collected through an explicit opt-in checkbox, displayed alongside the phone number input before any SMS message is sent. The checkbox is unchecked by default and must be manually checked by the user. You can view the exact consent prompt at in-case.me/sms-consent.

4. Data Sharing & Disclosure

Data sharing & disclosure: We do NOT sell, rent, trade, or share your personal information — including your phone number, email address, and SMS opt-in data — with any third party for their marketing or promotional purposes. We may share information only: (a) with service providers (e.g., Twilio for SMS delivery, Resend for email delivery, Supabase for database hosting) who are contractually bound to use your data solely to provide services to us; (b) if required by law, court order, or government regulation; (c) to protect our rights, property, or safety. All service providers are GDPR and CCPA compliant.

5. Data Retention

Data retention: We retain your account information for as long as your account is active. Encrypted content is stored until you delete it. If you delete your account, all associated data is permanently removed within 30 days. Log data is retained for a maximum of 90 days.

6. Your Rights

Your rights: Depending on your jurisdiction, you may have the right to: access the personal data we hold about you; correct inaccurate data; delete your account and all associated data; export your data in a portable format; withdraw consent for SMS/email communications at any time; lodge a complaint with your local data protection authority. To exercise these rights, contact us at [email protected].

7. GDPR & CCPA Compliance

GDPR & CCPA compliance: We comply with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Under GDPR, our lawful basis for processing your contact information is your explicit consent and our legitimate interest in providing the service. We do not sell personal data as defined by CCPA. EU users have the right to data portability and the right to be forgotten. You may designate an authorized agent to submit requests on your behalf.

8. Children's Privacy

Children's privacy: In Case is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child under 16 has provided us with personal data, we will delete it promptly.

Contact: For privacy-related inquiries, to exercise your data rights, or to report a security vulnerability, please email [email protected]. Response time is typically within 48 hours.