Deck ← Back to home

Privacy Policy

Last updated: September 24, 2026

The short version. Your browser profiles — cookies, logins, history, everything inside them — live on your computer. We never see them. If you turn on sync, we store a copy that is encrypted on your device before it is uploaded; your passphrase itself is never sent to us. So that forgetting a passphrase does not cost you your profiles, we also keep a sealed backup copy of your account's encryption key, used only to carry out a password reset you ask for. What we hold besides that is what any account needs: your email, your plan, which computers have signed in (known to us only by one-way hashes of their hardware), for free accounts a keyed hash of the internet connection they use, and usage counters. We do not sell data and we do not run advertising trackers.

1. Who We Are

LoginDeck is operated by Balmer Island Media Inc., a corporation registered in Ontario, Canada ("LoginDeck", "we", "us", or "our"). This Privacy Policy explains how we collect, use, share, and protect personal information when you use the LoginDeck desktop application, the LoginDeck account and sync service, and our website (collectively, "the Software"). For purposes of the EU/UK General Data Protection Regulation, Balmer Island Media Inc. is the "controller" of the personal data described here. For purposes of the California Consumer Privacy Act as amended ("CCPA/CPRA"), Balmer Island Media Inc. is the "business".

2. What Stays on Your Computer

LoginDeck is local-first. The following are stored only on your device and are never transmitted to our servers, unless you enable sync (Section 4):

Web traffic from a profile goes from your computer to the website (directly or through the proxy you chose). We do not proxy, inspect, or log the traffic of your browser profiles.

3. Information We Collect

We collect the minimum information needed to operate an account and a paid plan:

4. Encrypted Sync

When you enable sync, profile settings, proxies, tags, folders, Flows, and — on plans that include it — a profile's cookies and local storage are encrypted on your device using keys derived from your passphrase, and only then uploaded. Our servers store ciphertext, a salt, and a copy of your vault key wrapped under your passphrase.

We also keep a second, sealed copy of that vault key (key escrow). It is encrypted under a master key held by our server, and it exists for one reason: so that a forgotten passphrase is a password-reset email rather than a permanently locked account. We use it only to complete a password reset that you start and confirm with a code emailed to your address, and to complete a "Continue with Google" sign-in on an account you have already set up. We do not use it to read, mine, or hand over your synced data, and your passphrase is never stored in any form that can be turned back into text.

You should understand the trade-off this creates, because we would rather state it than imply otherwise: because that sealed copy exists, our servers are technically capable of decrypting your synced data, and an attacker who obtained both our stored data and our master key could do the same. This is why sensitive sync content is limited to what the feature needs, and why we recommend you do not rely on sync as the only copy of anything you cannot afford to lose. Synced data is stored on our servers in Europe/North America and in Cloudflare R2 object storage (Section 6). Closing your account deletes your synced data, and its escrowed key, from our storage.

5. Features That Contact Our Servers or Third Parties

6. Data Sharing and Sub-processors

We do not sell your personal information. We share data only with the following categories of providers, and only as needed to operate LoginDeck:

7. How We Use Your Information; Lawful Basis

  • To provide, operate, and maintain the Software and your account.
  • To process payments and enforce plan limits.
  • To send transactional emails (receipts, account and security notices, important service updates).
  • To send product announcements, only if you opt in; you can opt out at any time.
  • To respond to support requests and improve the product.
  • To detect, prevent, and investigate fraud, abuse, and security incidents, including use that violates our Terms of Service.
  • To comply with legal obligations.

Where the GDPR applies, we rely on: (a) performance of a contract for account creation, billing, sync, and providing the Software; (b) our legitimate interests in operating, securing, and improving the Software and preventing abuse, where not overridden by your rights; (c) your consent for product emails, which you may withdraw at any time; and (d) compliance with legal obligations. We do not use your data to train AI models and we do not sell or rent personal information.

8. Data Retention and Security

Encrypted sync data is stored encrypted at rest and in transit (TLS). Account data is stored on secured servers. No security measure is perfect, and we cannot guarantee that personal data will never be subject to unauthorized access. Sync data is never stored in the clear, so access to our storage alone yields ciphertext; as explained in Section 4, an attacker who also obtained our escrow master key could decrypt it. The master key is held separately from backups and object storage for that reason.

Typical retention periods, subject to extension where required by law or to establish, exercise, or defend legal claims:

  • Account and encrypted sync data: for the life of your account. Closing your account deletes it; residual copies in backups are overwritten within 30 days.
  • Billing records: 7 years (Canadian and US tax retention norms), held by our payment processor and in our records.
  • Server and security logs, IP-check logs: up to 30 days.
  • Computer identifier hashes: kept with the account that first used that computer, and deleted with that account. The internet address a new account was created from: 30 days. The internet-connection hash of a free account: 7 days after that account last connected from it, and sooner if the account is deleted or moves to a paid plan.
  • Support correspondence: up to 3 years from the last interaction.
  • Unsubscribe lists: indefinitely, to honour your opt-out.

9. International Transfers

Our servers and providers are located in Canada, the United States, and the European Union. By using the Software you consent to the transfer of your information to these jurisdictions, which may have different data-protection laws than your country of residence. Where required, we rely on standard contractual clauses or equivalent safeguards with our providers.

10. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, export, restrict, or object to the processing of your personal data, and to withdraw consent. You can delete your synced data and close your account from inside the Software at any time, and export any profile your plan has open. For anything else, email support@logindeck.com from the address on your account. We will respond within 30 days (extendable where permitted by law for complex requests) and will not discriminate against you for exercising your rights.

EU/UK residents also have the right to lodge a complaint with a supervisory authority (in the UK, the Information Commissioner's Office; in the EU, your local data-protection authority). California residents have the right to know what personal information we collect and how it is used and shared, to delete it (subject to exceptions), to correct it, and to opt out of any "sale" or "sharing"; we do not sell or share personal information for cross-context behavioural advertising. An authorized agent may submit a request on your behalf with proof of authorization.

Synced data is stored encrypted, and reading, correcting, or exporting its contents is done by you inside the Software, where the data is already decrypted for you. We do not decrypt it on your behalf for access requests, because the Software gives you a faster and more complete route to the same result. We can delete it, and we will. If a profile is locked because your plan no longer covers it, you can still get a copy of your personal data in it: email support@logindeck.com from the address on your account, and we will make that profile available for you to export.

11. Cookies and Website

Our website does not use advertising or analytics cookies. It loads fonts from Google Fonts, which receives your IP address as part of serving them. The desktop application does not set tracking cookies. Our website does not respond to "Do Not Track" signals because no industry standard exists, but we do not track you across sites in any case.

12. Children

The Software is not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If a change is material, we will notify you by email or in-app notice before it takes effect. The date at the top shows the current version.

14. Contact

support@logindeck.com
Balmer Island Media Inc., 1020 Shaw Drive #1607, Mississauga, Ontario, Canada L5G 3Z5.