Privacy policy
Last updated: 9 August 2026
This policy explains how Norum Send processes personal data when you create, send, or open a private message link.
Data controller
Adrian Isaksson Norum is the data controller. For privacy questions or requests, contact adrian@norum.se.
Data we process
- A random session identifier and timestamps used to operate and secure the service.
- Link identifiers, link settings, creation times, and message access or read events.
- In Ask, messages are encrypted in your browser. The server stores only ciphertext, the encrypted message key, encryption metadata, and the recipient's public key. The private key is not sent to the server.
- In Give, the message is stored as readable text on the server until it is deleted, consumed, or expires.
Message content can contain personal data if a user chooses to include it. Do not use Send for sensitive personal data or content you are not entitled to share.
Purpose
The data is processed to create and manage message links, deliver messages, enforce read limits, prevent misuse, and maintain the security and reliability of the service.
Cookie and local storage
Send uses one necessary cookie named send_session. It connects you to links you create so that you can manage them. It is HTTP-only, is not used for tracking, and expires after 30 days. Send uses no analytics, advertising, or third-party cookies.
In Ask, you may actively choose to save the private decryption key in your browser's local storage. The key otherwise stays only in the current tab. A saved key remains on that device until you delete the link through Send or clear the site's stored data in your browser.
Retention
Sessions expire after 30 days. Server-stored links, messages, encryption metadata, and access or read events are deleted after 30 days at the latest. They may be deleted earlier when a link is manually deleted, replaced, or consumed according to its read settings.
Recipients and international transfers
Data is not sold or used for advertising, profiling, or automated decision-making. It is available only to the controller and the hosting or infrastructure providers needed to operate the service. Hosting and data storage take place within the EU/EEA, and no intentional transfer outside the EU/EEA takes place.
Your rights
Depending on the circumstances, you may request access to, correction or deletion of your personal data, restriction of its use, object to processing based on legitimate interests, and request data portability where applicable. Some data may be difficult to identify without the relevant session or link identifier, especially encrypted Ask messages.
You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at imy.se.