Privacy policy

Elementik Technologies Pvt. Ltd. — Byteseal

Last updated: 15 September 2026 Effective: 15 September 2026


1. Who we are

This Privacy Policy explains how Elementik Technologies Pvt. Ltd. ("Elementik", "Company", "we", "us", or "our"), the developer and provider of Byteseal, a credential-management platform and associated hardware ("Byteseal", "Platform", or "Services"), collects, uses, stores, shares, and protects personal data.

Registered office: Flat No. 5, Shashivihar Apartment, S. No. 271, Plot No. 25, Shridharnagar, Chinchwad, Pune, Maharashtra 411033, India.

In this Policy, "your device" means your own smartphone or computer on which you run Byteseal. "Byteseal Biometric ID" means the Byteseal biometric hardware credential that comes with the paid version. These are two different things, and the distinction matters for how your data is protected (Section 4).

This Policy applies to both the free (cloud) version and the paid (Byteseal Biometric ID) version of Byteseal, across our website, mobile and desktop applications, browser extensions, and the hardware.

2. Summary — the part that matters most

Byteseal is built as a zero-knowledge system. What this means in practice:

  • The credentials you store in your Byteseal vault (passwords, passkeys, notes, and associated fields) are encrypted on your device (your smartphone or computer) using a key derived on your device, then stored in encrypted form on our cloud servers. Your data never reaches us in unencrypted form. No credentials are stored on the Byteseal Biometric ID — it functions only as a key.
  • We cannot decrypt your vault contents. We hold only ciphertext. We have no ability to read, recover, share, or hand over your stored credentials in usable form — to anyone, including ourselves, and including in response to a lawful demand.
  • Because of this, if you lose your master key, your vault cannot be recovered — by you or by us. This is a deliberate property of the design, not a limitation we can waive.
  • We do collect and can read a limited set of account and operational data needed to run the Service (for example, your account email, phone number for authentication, and order/contact details). That data is described in Section 3 and is the only category we can meaningfully disclose to anyone.

The rest of this Policy sets out the detail.

3. What personal data we collect

We collect the following categories of personal data. We do not collect your stored credentials in readable form (see Section 4 for how those are handled).

a. Information you provide when you register or use the Service

  • Name
  • Email address
  • Phone number (used, among other things, for one-time authentication codes)
  • Account credentials for the Byteseal account itself (your master key is never transmitted to or stored by us — see Section 4)

b. Order and billing information (paid version)

  • Name, phone number, and delivery/billing address needed to fulfil your order. Payment is processed by a third-party payment aggregator; we do not collect or store your card or payment-instrument details on our systems.

c. Technical and device information

  • IP address, device and hardware identifiers, hardware specifications, browser type and language, and — for the Byteseal Biometric ID — Bluetooth (BLE) connection identifiers necessary to pair and operate it.
  • Date and time of requests, and cookies or similar identifiers (see Section 9).

d. Approximate location

  • Derived from your IP address, device information, or an address you provide. We do not collect precise/GPS location unless you separately grant that permission on your device.

e. Encrypted vault data

  • The encrypted objects (ciphertext) representing your stored credentials, which we store and synchronise on your behalf but cannot decrypt (Section 4).

f. Support and communications

  • Information you provide when you contact support, respond to surveys, or communicate with us.

We collect only what is necessary for the purposes in Section 5.

4. How your vault and credentials are protected (zero-knowledge architecture)

This section describes the core of how Byteseal handles the data you most want protected.

  • Client-side encryption. Credentials you save are encrypted on your device (your smartphone or computer) using strong, industry-standard encryption, and then transmitted to and stored on our cloud servers in encrypted form only. The key that protects your vault is derived on your device from your master key. Your data never leaves your device in unencrypted form.
  • Keys stay with you. The keys required to decrypt your vault are derived on, and remain on, your device. They are not transmitted to us and are not stored on our servers in any form that would allow us to decrypt your data.
  • Cloud storage of ciphertext only. Your encrypted vault is stored and synchronised on our cloud servers. We hold only ciphertext — we cannot read it.
  • The Byteseal Biometric ID is a key, not storage. For the paid version, the Byteseal Biometric ID functions as a cryptographic key. It stores no credential data — neither your credentials nor your encryption keys. Losing it does not expose your credentials.
  • No recovery of vault contents. Because we never hold your keys, we cannot recover your vault if you lose your master key, and we cannot produce your credentials in readable form to any third party. See Section 8 on lawful disclosure.

5. Why we process your data

We process personal data for the following specified purposes, and only for these purposes:

  • Creating and administering your account, and authenticating you;
  • Providing the credential-management Service, including sync of your encrypted vault;
  • Processing purchases and fulfilling orders;
  • Providing customer support;
  • Securing the Platform and preventing fraud or abuse;
  • Sending you service and transactional communications;
  • Sending marketing communications, where you have opted in;
  • Improving and developing the Service using aggregated or de-identified data;
  • Complying with our legal and regulatory obligations.

Marketing is opt-in and separable. Agreeing to our Terms does not bundle consent to marketing email. You may consent to, and later withdraw from, marketing communications separately and at any time, without affecting your use of the Service.

6. Biometric data

For the paid version, fingerprint authentication is performed on the Byteseal Biometric ID. Your fingerprint data is stored and matched only on the Byteseal Biometric ID and is never transmitted to or stored by Elementik. You are responsible for the physical security of your Byteseal Biometric ID and for who is enrolled on it.

7. Who we share data with

We do not sell, rent, or trade your personal data. We do not share it for third-party advertising. We share limited personal data only as follows:

  • Service providers who help us operate the Service — for example cloud hosting, the payment aggregator, email delivery, shipping/logistics, and analytics — under contracts that require them to protect the data and use it only for the purposes we specify.
  • In connection with a business transfer (merger, acquisition, reorganisation, or sale of assets), subject to the acquirer honouring this Policy or notifying you of any change.
  • Where required by law, strictly as described in Section 8.

In every case, the encrypted vault contents remain ciphertext we cannot decrypt, and sharing ciphertext conveys nothing usable.

8. Lawful disclosure and law-enforcement requests

We may disclose personal data where we are legally required to do so, or where reasonably necessary to enforce our terms, protect the security and integrity of the Platform, prevent fraud or imminent harm, or establish or defend legal claims.

Two important limits:

  1. Vault contents. Because your credentials are encrypted with keys we do not hold, the most we can ever produce in response to any demand — including a lawful order or a request under the Information Technology Act, 2000 — is the encrypted object, which is unusable without keys in your sole possession. We cannot decrypt it, and we cannot produce something we are architecturally incapable of producing.
  2. Scope. Any disclosure we are able to make is limited to the account and operational data described in Section 3 (for example, account email or order records) — never vault contents, which we cannot read.

Where permitted by law, we will make reasonable efforts to notify you of a legal demand for your data.

9. Cookies and similar technologies

We use cookies and similar technologies to operate the site, remember your preferences, secure your session, and understand usage, including through analytics tools. You can control cookies through your browser and, where offered, through our cookie settings.

10. Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law (for example, tax and accounting records). When personal data is no longer required — including where you withdraw consent or close your account, and no legal ground for retention remains — we will erase or irreversibly de-identify it.

Your encrypted vault data is retained while your account is active and deleted on account closure. Because it is ciphertext we cannot read, we cannot retain any readable form of it.

11. Your choices and rights

We want you to stay in control of your data. Subject to applicable law, you can:

  • Access the personal data we hold about you and request a copy;
  • Correct or update inaccurate or incomplete data;
  • Delete your data, where we are not required to retain it;
  • Withdraw marketing consent at any time;
  • Raise a grievance with our Grievance Officer (Section 13).

To exercise any of these, contact us using Section 13. We may need to verify your identity first. Note that even while verifying you, we still cannot read your vault contents.

12. How we protect your data, and breach notification

We implement reasonable security safeguards appropriate to the risk, including encryption, access controls, and secure development practices, consistent with reasonable security practices under the Information Technology Act, 2000 and the SPDI Rules.

No transmission over the internet is completely secure, and we cannot guarantee absolute security of data in transit outside our systems.

In the event of a breach affecting your personal data, we will take prompt steps to address it and will notify affected users and any authorities as required by applicable law.

13. Contact and grievance redressal

For any question about this Policy, to exercise your rights, or to raise a privacy grievance:

  • Grievance Officer: Sridhar Kotikalapudi — shridhar@byteseal.co/support@byteseal.co
  • Support: Create a ticket at csp.byteseal.app/create-ticket
  • General: support@byteseal.co

We will acknowledge and respond to grievances within the timelines required by law.

14. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will notify you by a reasonable means (for example, by email or an in-app/website notice) and update the "Last updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy, except where your fresh consent is required by law.


This document should be read together with the Byteseal End User License Agreement, and the Return & Refund Policy.