Skip to content
Privacy Policy

Your data.
No one else's.

We built InfoPeak so that your digital life stays exactly that - yours. This page explains what we collect, what we don't, and how we keep it that way.

Last updated: August 2026 · Applies to infopeak.io, the InfoPeak Pass browser extension, and the InfoPeak Captcha widget

No Ads. Ever.

We don't track you to sell advertising. You are our member, not a product.

No AI Training.

Your private files, messages, and passwords are never used to train algorithms or AI models.

EU Hosting Only.

Your content lives on servers in the EU only, protected by GDPR - the world's strongest privacy law. Section 05 names the two things that do leave.

01 Our Philosophy

InfoPeak is built on the belief that a digital service should work for you, not harvest data from you. We practice what we call digital sovereignty - you own your data, you control access to it, and you can take it with you at any time.

Our encryption architecture is zero-knowledge: your master password is never sent to our servers. Every document, file, and saved password is encrypted on your device before it leaves it. Personal emails on @infopeak.me are zero-knowledge encrypted - we cannot read them even if compelled. This is not a marketing claim - it is a technical constraint baked into the architecture.

Exception - team custom domain mailboxes: One, Family, Business Standard and Business Premium customers who connect their own domain (e.g. @yourdomain.com) receive server-provisioned mailboxes. The credentials for these mailboxes are encrypted at rest using AES-256, but are not zero-knowledge - InfoPeak generates and can access the mailbox password in order to provision the account and deliver background mail sync. If this distinction matters to you, use your personal @infopeak.me address for sensitive correspondence.

02 What We Collect

Account information

Your name, email address, and username. Used to identify and manage your account.

Encrypted content

The ciphertext of your files, documents, calendar events, contacts, passwords, and personal emails. We store this, but we cannot read it - your keys never leave your device. Team custom domain mailboxes are encrypted at rest but not zero-knowledge (see architecture note above).

Technical logs

IP addresses and request timestamps, used solely to detect abuse and protect your account. Logs are retained for 30 days.

Sign-up record

When an account is created we store the IP address it was created from, together with the time. This is what enforces our limit of two accounts per network, and it is the only thing we use it for. Unlike the technical logs above it is not deleted after 30 days, because erasing it would reset the limit. It is a standalone list of addresses and times - not linked to your account, your activity, or your content. If you share an address with other people and find yourself blocked, write to support@infopeak.io and we will help you.

Approximate country

Derived once from your sign-up connection - country level only, never street address or precise location. Used for aggregate statistics and to show which countries InfoPeak has reached. It is not linked to your activity or content.

Payment data

Processed entirely by our payment provider. We never touch or store your full card details.

03 InfoPeak Pass - Browser Extension

The InfoPeak Pass browser extension uses the same zero-knowledge encryption as the web app: your passwords are encrypted on your device and never readable by us.

What the extension reads

The extension detects login forms on pages you visit in order to offer auto-fill. It reads only the page structure (input field types) - it does not read, store, or transmit page content, browsing history, or form values to our servers.

Authentication

The extension authenticates using a short-lived bearer token (15 minutes) issued when you visit infopeak.io while logged in. This token is stored only in browser session memory and is cleared when the browser closes.

Local storage

The extension stores your decrypted vault data only in browser session memory - memory that is cleared every time the browser closes. Nothing is written to persistent disk storage.

Permissions used

storage session memory · activeTab fill credentials in current tab · scripting inject fill code · alarms periodic cleanup · clipboardWrite copy passwords · tabs open infopeak.io for re-authentication

04 InfoPeak Captcha - Websites You Visit

InfoPeak Captcha is a bot-protection widget that our customers embed on their own websites. If you encounter it, we collect no personal data about you at all - no IP address, no cookie, no fingerprint, and no record that your visit took place.

How verification works

Your browser is asked to perform a short proof-of-work calculation - a small amount of arithmetic that is trivial for one visitor and expensive for a bot sending thousands of requests. There is no puzzle to solve and nothing to click. Whether you are human is inferred from the computation itself, never from your behaviour.

What we store

A challenge and its resulting token are held briefly in memory and are linked only to the customer's site key - never to you. We keep aggregate counts of how many verifications a site key has used, in order to enforce its plan limit. No per-visitor records are written to disk.

No tracking, no profiling

We set no cookies and use no device or browser fingerprinting. Because nothing identifies you, you cannot be recognised across the different websites that use InfoPeak Captcha, and we cannot build a profile of you. Rate limiting is applied per site key against total traffic, not per visitor.

If you operate a website using it

You are the controller for your own site. We process no personal data about your visitors on your behalf, so the widget adds no consent requirement of its own - though your wider cookie and privacy notices remain your responsibility. Your site key is bound to the domains you register, and the verification request travels between your server and ours without carrying visitor data.

05 Where Your Data Lives

Your content - mail, files, documents, calendars and contacts - is stored on servers in Germany, with the DNS resolver in Finland, and we do not move it out of the European Union. Every part of how we handle it is governed by the GDPR. What you send elsewhere yourself is a different matter: if you connect an outside tool, such as an AI assistant, it receives what you allow it to reach. Section 08 sets that out.

Two things do leave, and we would rather write them down than let you find them: your billing details go to Stripe, whose Irish company passes them to its American parent under Standard Contractual Clauses, and if you use InfoPeak Mail on Android with notifications on, the sender and subject line of an incoming mail go to Google so the notification can say who wrote and what about. Nothing else does. Section 08 sets out exactly who receives what, and how to switch the second one off.

06 Your Rights

As the owner of your digital life, you have the following rights under GDPR:

  • Access - Request a full export of all data associated with your account.
  • Correction - Request corrections to your personal information at any time.
  • Deletion - Permanently delete your account and all associated data. When you delete something at InfoPeak, it stays deleted - we run no "soft delete" backups visible to us.
  • Portability - Download your data in an open, portable format at any time.
  • Objection - Object to any processing of your data beyond what is strictly necessary to deliver the service.

07 Cookies

We use no advertising cookies, no cross-site tracking, and no third-party analytics. Every cookie we set is strictly necessary or functional, first-party, and listed here in full:

Cookie Purpose Duration Type
PHPSESSID Session management and authentication Browser session Strictly necessary
ipk_remember Keeps you signed in on this device 30 days Strictly necessary
ipk_device Recognises a device you have signed in from before, so a sign-in from a new one can raise a security alert 1 year Strictly necessary
ipk_pwa Identifies Progressive Web App (PWA) mode, which keeps the session alive between app launches 30 days Functional
ip_lang Remembers your language preference 1 year Functional
team_invite_token Carries a team invitation through the sign-up flow 10 minutes Functional

All cookies are first-party, HttpOnly, and served over HTTPS with SameSite=Lax. No data is shared with third parties. There is nothing here to consent to, because we set nothing that is not needed to run the product. Fonts and assets are self-hosted across our websites, including the sign-in and sign-up pages, so your browser makes no request to Google or any other third party.

08 Sub-Processors

InfoPeak uses the sub-processors below to deliver the Service. All of them are bound by a data processing agreement. The location column is where the data physically sits.

Sub-Processor Purpose Location
Contabo GmbH Application servers, database, mailboxes, VPN gateway, mail gateway, background workers Germany
Hetzner Online GmbH Object storage for files, photos and mail attachments Nuremberg, Germany
Hetzner Online GmbH DNS resolver (InfoPeak DNS) Helsinki, Finland
Stripe Payments Europe, Limited Payment processing and billing Ireland - onward transfer to Stripe, Inc. (United States) under Stripe's Standard Contractual Clauses
Google Ireland Limited / Google LLC Push notifications to the Android apps (Firebase Cloud Messaging) United States

What the push notification contains. For InfoPeak Mail on Android, the push message we hand to Google carries the sender's address and the subject line, so the notification can say who wrote and what about before the app has decrypted anything. It also carries the address of your own mailbox, so the app can tell your accounts apart. Message bodies, attachments and file contents are never included. If you would rather it said nothing, turn off Show sender and subject under Settings › Notifications: the push then says only that a message arrived, and neither the sender nor the subject leaves our servers. Browser push is different: the payload is encrypted to your browser under RFC 8291, so the push service passes it on without being able to read it.

Not sub-processors. Country lookup runs against a MaxMind database file stored on our own servers, so no request about you leaves them. Google and Microsoft appear only if you start an import from Gmail or Outlook yourself; the connection is made with your own authorisation and closes when the import finishes. Fonts and assets are self-hosted, so simply loading a page contacts nobody but us.

An AI assistant you connect. If you point Claude, ChatGPT or any other MCP tool at your account, it reaches your data because you authorised it - separately for mail, calendar, contacts and files, and separately for reading and for writing. It stops the moment you withdraw that, which you can do at any time. We run no AI of our own and we have no agreement with the one you choose: what it does with what it reads is governed by its terms and its privacy policy, not ours. So pick it the way you would pick anyone you hand a key to.

We will notify users at least 30 days in advance before adding new sub-processors. Objections can be raised by contacting support@infopeak.io.

09 Contact & Data Controller

The data controller responsible for processing your personal data is:

InfoPeak

Mergelsigvej 10
DK-7400 Herning
Denmark
CVR: 42161543

Questions about this policy or requests to exercise your rights can be sent to:

support@infopeak.io

We aim to respond within 48 hours. For formal GDPR requests, we will respond within 30 days as required by law.

10 Language and Governing Version

We publish this policy in sixteen languages so you can read it in your own. We prepare the translations carefully, but the governing version is the English one at infopeak.io/en/privacy: if a translation differs from it, the English text prevails. This is not meant to take anything away from you - it is to make sure sixteen versions cannot promise sixteen different things.