InboxDays
Log inStart free

Legal

Zero-Knowledge Cryptographic & Key Loss Disclaimer

Important disclosure regarding client-side encryption, key ownership, and zero-server data recovery limits for the InboxDays Vault.

Last updated: 2026-08-03 · All policies · In-app legal center

Version 1.0 · Slug: zero-knowledge-disclaimer · Source: content/legal/zero-knowledge.md

Summary for UI display (Vault Unlock Modal): Items stored in the Vault are encrypted client-side using AES-256-GCM. InboxDays never possesses, stores, or transmits your decryption keys. If you lose your hardware passkeys or security credentials, your Vault data cannot be recovered by anyone—including InboxDays support.

1. Architecture & client-side encryption

All messages, attachments, and metadata designated for storage inside the InboxDays Vault (isVault = true) are encrypted directly within your web browser using AES-256-GCM before leaving your local device.

  • Encryption keys are derived client-side via hardware-backed Passkeys, WebAuthn credentials, or local key shares.
  • Plaintext data and raw cryptographic keys are never transmitted to, stored on, or processed by InboxDays servers, databases, or infrastructure providers.

2. Zero-knowledge server boundaries

InboxDays operates on a strict Zero-Knowledge Architecture. Consequently:

  1. No server-side access: InboxDays employees, system administrators, automated scripts, and cloud infrastructure engineers have zero capability to view, read, analyze, or decrypt your Vaulted records.
  2. No backdoors: There are no master recovery keys, escrow services, or administrative backdoors engineered into the InboxDays platform.
  3. Subpoena & legal process limitation: In the event InboxDays receives a subpoena, court order, or legal request for Vaulted data, we can only provide the encrypted ciphertext (AES-256-GCM). We cannot decrypt or render plaintext content under any circumstance.

3. Permanent data loss risk & support limits

Because your encryption keys exist solely within your authorized hardware, browsers, or passkey managers, you assume full and exclusive responsibility for maintaining access to your cryptographic credentials.

Unrecoverable data warning. If you lose access to your registered WebAuthn device, hardware key, or local passkey share without an authorized secondary backup key:

  • InboxDays Support CANNOT reset your encryption key.
  • InboxDays Support CANNOT restore access to your Vaulted items.
  • InboxDays Support CANNOT bypass biometric or passkey authentication.

All data stored within the affected Vault will be rendered permanently unreadable and cryptographically lost.

4. User acknowledgement & liability waiver

By activating and utilizing the InboxDays Vault, you explicitly acknowledge and agree that:

  • You understand the operational mechanics of zero-knowledge client-side encryption.
  • You are solely responsible for maintaining key backups and secure authentication hardware.
  • InboxDays, Inc. disclaims all liability for any loss, corruption, or unrecoverability of data resulting from lost, compromised, or damaged cryptographic keys or WebAuthn credentials.

This disclaimer supplements the limitation of liability in the Terms of Service.

5. Related policies

  • Security & Vulnerability Policy
  • Privacy Policy
  • Terms of Service
© 2026 InboxDays

Trust-first email for people and teams who live in their inbox.

Product

FeaturesHow it worksHelpInstall & downloadPricingSign upLog in

Legal & trust

PrivacyTermsBeta TermsCookiesSecuritySubprocessorsAll policies

Enterprise

Data Processing AddendumAI privacyZero-knowledge disclaimerAcceptable useCancel & refunds