Who is responsible

Sesame operates the desktop application and the website at usesesame.app. For the optional website account, Sesame is the data controller. Privacy requests can be sent to privacy@usesesame.app. The public beta is open to download; its operator identity and postal contact will be published before the beta ends.

What we process

The desktop app keeps vault entries, unlock material, imported exports, TOTP seeds, backup codes, and recovery notes on your device. The website and account API are not built to receive them. If you create a website account, the account service processes:

  • Account data: email address, verification state, a salted password hash, and the Terms and Privacy Policy versions recorded when the account was created.
  • Access data: licence records and connected-desktop identifiers.
  • Session and security data: session, CSRF, and temporary passkey-ceremony tokens; session timestamps; and short-lived rate-limit data derived from network information.
  • Support data: text you deliberately submit through the attachment-free support form. The form rejects likely secrets before sending.

We do not use advertising, behavioural analytics, profiling, session replay, or third-party trackers. We do not sell or rent personal data.

The browser extension

The Sesame browser extension has no server and no account. It asks the desktop app for the value you requested over native messaging, and the desktop app answers only after you approve that request. To do this, the extension reads the structure of the eligible form on the active tab and writes the approved value into it. If you choose Save this login after a Sesame registration fill, it reads the new password and username from that form and sends them to the desktop app for approval. Credential values stay in memory only for the request. They are not written to browser storage, logs, or any server. Browser storage holds only the origins where you paused the inline button and whether onboarding was shown. Nothing is sent to Sesame or to any third party.

Why we process it

For EEA and UK users, the account service relies on contract to provide the account, licences, sessions, desktop connections, and recovery; and legitimate interests to prevent abuse, protect the service, and respond to a support request. Agreeing to the Terms is required to create the account; acknowledging this policy is not permission for marketing or tracking. The local desktop vault does not require a website account.

Retention and recipients

Account records remain until you ask for deletion or the beta is closed. Website sessions last up to 30 days unless revoked or signed out sooner. The CSRF token lasts up to one hour and a passkey ceremony token lasts up to ten minutes. Support reports have no automatic expiry in this beta; do not put sensitive information in them and request deletion by email when it is no longer needed. Sesame operates no analytics, advertising, or profiling processors.

The service runs on two processors, and no others:

  • Hetzner Online GmbH, Falkenstein, Germany. Hosts the server, the account database, and the mail relay that sends account email. All account data is stored here, inside the EU.
  • Cloudflare, Inc., United States. Provides authoritative DNS for the domain, and forwards mail addressed to published contact addresses such as the privacy address to an operator mailbox.

Account email is sent from Sesame's own mail relay on the Hetzner server rather than a third-party sending provider, so the contents of verification, recovery, and email-change messages are not processed by an external mail service.

International transfers

Account records, the database, and outbound account email stay on infrastructure located in Germany, inside the EEA. No transfer safeguard is required for that processing.

Cloudflare, Inc. is established in the United States. Its role is limited to authoritative DNS and to forwarding mail sent to Sesame's published contact addresses, which means the contents of a message you send to those addresses pass through a processor outside the EEA. That transfer relies on the data processing terms Cloudflare offers its customers, including the European Commission's standard contractual clauses. If you would rather not use a US processor for that route, contact details published on this site can also be reached through the account portal's support form, which does not involve Cloudflare mail routing.

Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, and portability of your data, and object to processing based on legitimate interests. Email privacy@usesesame.app to exercise these rights. You may also complain to your local data-protection authority. Sesame aims to respond within one month where the GDPR applies.

Contact and changes

Privacy questions and requests: privacy@usesesame.app or the support page. We will publish a new version and highlight material changes before applying them to existing website accounts.

Version 2026-09-14 · Updated 14 September 2026.