Privacy policy

Last updated: 4 August 2026 · Effective: 4 August 2026

The short version Testament is a zero-knowledge encryption app. We never see your documents, your identity information, or your encryption keys. Your encrypted files are stored in your own Google Drive — not on our servers. The only data we process is what's needed to sign you in with Google, manage your subscription, and keep the app reliable (crash and performance diagnostics).

1. Who we are

Testament is operated by Piti Supanimitwasana, an individual developer based in Thailand. For privacy inquiries, contact us at support@testament-app.com.

2. What data we collect

Data we never collect, store, or transmit

Data typeWhat happens
Identity numbers (NID, passport, SSN, etc.)Used momentarily on your device for encryption key derivation, then immediately discarded. Never leaves your device.
Dates of birthSame as identity numbers — on-device only, discarded after use.
Secret phrasesSame as identity numbers — on-device only, discarded after use.
Document content (plaintext)Encrypted on your device before upload. We never see the original file.
Encryption keysDerived on your device, used once, zeroed from memory. Never transmitted.

Data we do process

Data typePurposeWhere storedRetention
Google account email and nameSign-in, account displayYour device (secure storage)Until you sign out
Google OAuth tokensAuthenticate with Google DriveYour device (OS keychain) + briefly on our auth proxy during token exchangeDevice: until sign out. Proxy: not stored (pass-through only)
Subscription statusDetermine your plan tier and featuresApple/Google/Stripe (payment provider)As long as subscription is active
Organization membership (Business plan)Link your account to your firm's orgCloudflare KV (email, role, join date only)Until removed from org
Client portal snapshots (Business plan)Render read-only document status page for clientsCloudflare KV (encrypted, with TTL expiry)Until link expires or is revoked
Crash & performance diagnostics; basic usage metrics (e.g. document/client counts)Diagnose crashes, keep the app reliable, and understand feature usageSentry (diagnostics) and our Cloudflare Worker (usage metrics), keyed to your emailSentry: up to ~90 days. Usage metrics: latest status only

Data stored on your device only

3. Your encrypted files

Your encrypted .testament files are stored in your own Google Drive account, inside a "Testament Vault" folder. We have no access to your Google Drive. The files are encrypted with AES-256-GCM before leaving your device — even Google cannot read them without the identity factors.

We do not backup, cache, index, or analyze your encrypted files. We do not have a server-side copy of any user's documents.

Google API Services User Data Policy (Limited Use)

Testament's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Testament requests the following Google OAuth scopes, each used only to provide the feature described:

Testament does not use Google user data for advertising, does not sell it, and does not allow humans to read it except with your explicit consent, for security purposes, or as required by law — consistent with the Limited Use requirements.

4. Our auth proxy

Testament uses a Cloudflare Worker as an authentication proxy. This proxy performs one function: exchanging Google OAuth authorization codes for access tokens, so that the app doesn't need to embed the OAuth client secret.

The proxy:

5. Organization data (Business plan)

If you use the Business plan, we store the following in Cloudflare KV to manage your organization:

This data contains no identity documents (NID, DOB, etc.), no encryption keys, and no document content. It is the minimum needed to manage team membership and billing.

6. Client portal snapshots (Business plan)

When an attorney generates a signed web link for a client, we store an encrypted snapshot in Cloudflare KV containing:

The snapshot is encrypted with AES-256-GCM at rest. It does not contain document content, identity information, or encryption keys. Snapshots are automatically deleted when they expire (based on the TTL set by the attorney) or when the attorney revokes the link.

7. Payment processing

We do not process credit cards or payment information directly. All payments are handled by:

Each payment provider has its own privacy policy. We receive only subscription status information (active/expired, plan tier, renewal date) — never card numbers, bank details, or billing addresses.

8. Diagnostics, analytics, and tracking

Testament uses Sentry to collect crash reports and basic performance data so we can find and fix bugs and keep the app reliable. Before any report is sent, identity data (ID numbers, dates of birth, secret phrases) is removed by an on-device scrubber; your email is attached to reports only so we can follow up on a support case. Sentry retains this data for approximately 90 days.

We also collect a small amount of first-party usage information — such as how many documents or clients you have — which is sent to our own Cloudflare Worker to operate your account and understand feature usage. This is not shared with any third-party analytics service.

We do not use advertising SDKs, do not track you across other apps or websites, do not build advertising profiles, do not sell your data, and do not display ads. None of the data above is used for "tracking" as defined by Apple's App Tracking Transparency framework.

9. Cookies

The Testament web app and landing pages do not use cookies. The client portal (signed web link) does not use cookies. No tracking cookies, no analytics cookies, no advertising cookies.

10. Children's privacy

Testament is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11. International data transfers

Our auth proxy and KV storage run on Cloudflare's global network. Data may be processed in any country where Cloudflare has infrastructure. Cloudflare maintains Standard Contractual Clauses (SCCs) for EU data transfers. Your encrypted documents remain in your Google Drive, subject to Google's data residency policies.

12. Data protection rights

For all users

You can:

PDPA (Thailand)

Under Thailand's Personal Data Protection Act, you have the right to access, correct, delete, restrict, and port your personal data. Since Testament stores virtually no personal data (identity information is never stored, documents are in your own Drive), most PDPA rights are satisfied by design. For any PDPA request, contact support@testament-app.com.

GDPR (European Union)

Under the General Data Protection Regulation, you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. Our legal basis for processing is legitimate interest (providing the service you signed up for) and contract performance. For any GDPR request, contact support@testament-app.com. We will respond within 30 days.

CCPA (California)

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. California residents have the right to know what data we collect (see Section 2 above), request deletion, and opt out of sale (not applicable — we don't sell data). Contact support@testament-app.com for any CCPA request.

13. Data breach notification

In the unlikely event of a data breach affecting personal data we hold (org membership data), we will notify affected users within 72 hours via email and update this page. Note that document content cannot be breached through us — we don't have it.

14. Changes to this policy

We may update this privacy policy to reflect changes in the app or legal requirements. Significant changes will be announced in the app and on this page. The "last updated" date at the top always reflects the most recent version.

15. Contact

For privacy questions, data requests, or concerns:

Email: support@testament-app.com
Location: Thailand
Response time: within 14 days (30 days for formal GDPR/PDPA requests)