← whym

Privacy policy

Zásady ochrany osobních údajů · Last updated 19 August 2026

Draft. Prepared from public register data and general knowledge of the GDPR and Czech implementing law. Not legal advice, and not reviewed by a lawyer. Have it checked before the service is opened to the public.

The short version

Your vault is encrypted in your browser before it reaches us. We hold an email address, some timestamps, and a block of ciphertext we cannot read. There are no trackers, no analytics, and no advertising. Nothing is sold or shared.

Who is responsible

The controller of your personal data is OmNexis s.r.o., IČO 02800888, Pražská 69/17, 273 43 Buštěhrad, Czech Republic, registered at Městský soud v Praze, oddíl C, vložka 223765.

For any question about your data, or to exercise any right below, write to rharms@omnexis.com.

No Data Protection Officer has been appointed. The service does not carry out large-scale monitoring or large-scale processing of special categories of data, so Article 37 GDPR does not require one.

What we hold

DataWhyLawful basis
Email address Identifies your account, receives the sign-up link and security notices Art. 6(1)(b) — performance of a contract
Verifier derived from your master password Proves you know your password without us holding it. It is the output of a key-derivation function run in your browser, hashed again on our side, and cannot be used to decrypt anything Art. 6(1)(b)
Your vault, encrypted The service itself. To us it is an opaque block of bytes — we do not know what any card is called, which services you use, or what is in them Art. 6(1)(b)
Timestamps — created, changed, last opened Shown on your cards, and let you notice access you did not make Art. 6(1)(b)
Two-factor secret Verifies your authenticator codes. Encrypted at rest Art. 6(1)(b)
Security log — IP address, browser user agent, event, time Detecting and blocking password guessing, and showing you your own account activity Art. 6(1)(f) — legitimate interest in keeping the service secure

Your IP address and browser user agent are personal data, and they are the only items above we keep for a reason other than running your account. You can object to this processing under Article 21; note that we cannot operate brute-force protection without it, so an objection may mean we cannot continue to provide the service.

What we deliberately do not collect

Icon lookups

When you ask whym to find an icon for a card, the site address you supply is sent to our server, which fetches the icon on your behalf. This is deliberate: doing it in your browser would tell a third-party icon service which sites you hold accounts with. Those requests are not logged.

Breached-password checks

When you choose a master password, the first five characters of its SHA-1 hash are sent through our server to the Have I Been Pwned service to check whether it appears in a known breach. Your password never leaves your device, and the five characters match many hundreds of thousands of possible passwords, so nothing about yours is revealed. This is the k-anonymity model published by that service.

Cookies

One cookie, named whym_session. It holds a random session identifier, is marked HttpOnly, Secure and SameSite=Strict, and exists only to keep you signed in. It is strictly necessary for a service you have requested, so under §89(3) of Act No. 127/2005 Coll. and the ePrivacy Directive no consent banner is required, and none is shown. We use no other cookies and no local storage for tracking.

How long we keep it

ItemRetention
Account and vaultUntil you delete the account, then removed
Deleted cards ("trash")30 days, then permanently erased
Security log90 days
Encrypted backups30 days on a rolling basis
Sign-up links and sign-in ticketsMinutes to hours; deleted once used or expired

Because backups are kept for 30 days, deleted data may persist in them for up to that period before ageing out.

Who else sees it

We do not sell, rent or share your data. It is processed on our behalf only by:

All processing takes place within the European Union. There are no transfers to third countries. We disclose data to public authorities only where legally compelled — and note that for the contents of your vault we are technically unable to comply, because we cannot decrypt it.

Security

Your master password is turned into an encryption key in your browser using Argon2id, and everything you store is encrypted with AES-256-GCM before it is transmitted. The key never leaves your device. Our server stores ciphertext.

This has a consequence you should understand: if you forget your master password and lose your recovery kit, your data cannot be recovered by anyone, including us. That is not a limitation we could remove — a reset we could perform would be a reset an attacker could perform.

Two-factor authentication is required on every account. Traffic is encrypted with TLS. Sign-in attempts are rate-limited and locked out after repeated failures.

In the event of a personal data breach likely to result in a risk to your rights, we will notify ÚOOÚ within 72 hours and inform you without undue delay where the risk is high, as required by Articles 33 and 34 GDPR.

Your rights

Under the GDPR you may:

Write to rharms@omnexis.com. We answer within one month. There is no charge unless a request is manifestly unfounded or excessive.

Note that we can only ever return your vault in encrypted form. We have no means of decrypting it, so an access request cannot produce readable card contents from us — only you can produce those, using the app.

Children

The service is not intended for children under 15, the age of digital consent set by §7 of Act No. 110/2019 Coll. We do not knowingly create accounts for them.

Changes

If this policy changes materially we will say so on this page and, where the change affects you, by email. The date at the top always reflects the current version.

whym Terms Provider information