Locknote by Scorchsoft
Privacy notice
Version 2 October 2026 · Operational notice; provider retention details pending confirmation
Who is responsible
Scorchsoft Ltd (07246693), 13 Portland Road, Edgbaston, Birmingham, B16 9HN, is responsible for account and operational data. Contact www.scorchsoft.com/contact-scorchsoft and mark your enquiry ‘Locknote privacy’. Where we handle encrypted content on a client's instructions, the parties should agree any required processor terms. Encryption does not remove UK GDPR duties.
Information and sources
The service handles sender email addresses when supplied and verified after creation, and recipient email addresses while sending verification messages; it stores keyed email lookups rather than the addresses in note records. It also stores optional unencrypted titles, encrypted note payloads and protected keys, creation/expiry/deletion times, terms acceptance, short-lived verification and session records, and rate-limit counters derived from email and IP address. MailerSend handles delivery addresses and verification links. Hosting and mail provider logs may contain technical information such as IP addresses and URLs. The server is designed not to receive readable note contents or sharing passwords. Older note links have a fragment secret that stays in the browser. New recipient verification links carry a short-lived, server-encrypted email claim to resume the note in another tab.
Why we use it
We use the information to operate temporary notes, verify access, manage deletion, prevent abuse and meet legal duties. Potential lawful bases include legitimate interests in secure business communication and service protection, contract where necessary, and legal obligation where applicable. These bases and any legitimate-interests assessment should be reviewed before wider launch. Agreeing to the Terms is not GDPR consent.
Who receives it and international transfers
The service runs on ChatGPT Sites and underlying infrastructure and uses MailerSend for fixed verification messages. Authorised Scorchsoft personnel can access operational metadata. Mail delivery receives the destination address and verification message, not the contents, title, sharing password or original private link. Hosting subprocessors, processing locations and UK transfer safeguards require confirmation before a wider launch.
Retention and deletion
New access stops immediately at expiry or sender deletion. Verified senders can delete their notes, which removes the active encrypted payload, title and recipient keys immediately. A creator can optionally link a note to their email within 24 hours, while it remains active, to manage and delete it. Unlinked notes cannot be deleted early by their creator. When optional self-destruct is enabled, the first successful password unlock deletes the active note record, title, recipient keys, access grants and associated verification records immediately. This applies to all recipients; saved copies cannot be recalled. Otherwise notes remain available until expiry unless Scorchsoft intervenes for security or legal reasons. A daily task and throttled visit checks purge expired active records, normally within a further 24 hours; failures or backlogs can take longer. A minimal terminal status without title or recipient identity may remain for 30 days. Expired verification records, sessions and rate-limit counters are cleaned in bounded batches. Provider logs, email records and backups have separate retention periods that still require confirmation; expiry is not a guarantee of erasure from every backup.
Browser storage and cookies
Readable notes and sharing passwords stay in an open tab's memory; older notes also keep their private link secrets there; the app does not write them to localStorage, sessionStorage or IndexedDB. Necessary secure, HttpOnly cookies hold random sender and recipient session tokens (seven days and 15 minutes respectively). No advertising cookies or session-replay analytics are used by the note app. Browser memory erasure cannot be guaranteed; copies, screenshots, clipboard history and extensions are controlled by your device.
Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction or portability of your personal information. You may object to processing based on legitimate interests. Contact Scorchsoft using the details above; we may need proportionate identity verification. You can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. These rights are subject to applicable conditions and exceptions. Required email and security information enables the access checks; without it we cannot provide access. The title is optional. No automated decisions with legal or similarly significant effects are planned.
Recipients who did not request a note
A sender may have supplied your email address before you use the tool. A verification email is sent only after someone enters that address on a specific note link. If you did not request it, do not click the link. The email explains its purpose and does not include note contents or the sharing password. For new notes, its one-time verification link can take the approved recipient to the password screen. Contact Scorchsoft about misuse of your address.