Who is responsible

Sesame operates the desktop application and the website at usesesame.app. For the optional website account, Sesame is the data controller. Privacy requests can be sent to privacy@usesesame.app. The public beta remains invite-only; its operator identity and postal contact must be supplied in every invitation before the service is opened to the public.

What we process

The desktop app keeps vault entries, unlock material, imported exports, TOTP seeds, backup codes, and recovery notes on your device. The website and account API are not built to receive them. If you create an invited website account, the account service processes:

  • Account data: email address, verification state, a salted password hash, and the Terms and Privacy Policy versions recorded when the account was created.
  • Access data: beta eligibility, licence records, private-beta download eligibility, and connected-desktop identifiers.
  • Session and security data: session, CSRF, and temporary passkey-ceremony tokens; session timestamps; and short-lived rate-limit data derived from network information.
  • Support data: text you deliberately submit through the attachment-free support form. The form rejects likely secrets before sending.

We do not use advertising, behavioural analytics, profiling, session replay, or third-party trackers. We do not sell or rent personal data.

Why we process it

For EEA and UK users, the account service relies on contract to provide the account, beta access, private-beta download eligibility, sessions, desktop connections, and recovery; and legitimate interests to prevent abuse, protect the service, and respond to a support request. Agreeing to the Terms is required to create the account; acknowledging this policy is not permission for marketing or tracking. The local desktop vault does not require a website account.

Retention and recipients

Account records remain until you ask for deletion or the beta is closed. Website sessions last up to 30 days unless revoked or signed out sooner. The CSRF token lasts up to one hour and a passkey ceremony token lasts up to ten minutes. Support reports have no automatic expiry in this beta; do not put sensitive information in them and request deletion by email when it is no longer needed. Sesame does not currently operate analytics or advertising processors. Before any public launch, Sesame will publish the hosting and other processor details that apply to the deployed service.

International transfers

The private beta is not offered as a public service. If Sesame later uses a processor outside the EEA or UK, the public policy will name the processor and describe the applicable transfer safeguard before that processing begins.

Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, and portability of your data, and object to processing based on legitimate interests. Email privacy@usesesame.app to exercise these rights. You may also complain to your local data-protection authority. Sesame aims to respond within one month where the GDPR applies.

Contact and changes

Privacy questions and requests: privacy@usesesame.app or the support page. We will publish a new version and highlight material changes before applying them to existing website accounts.

Version 2026-07-14 · Updated 14 July 2026.