Hush by Umikflow

Privacy Policy

Last updated: September 26, 2026

Hush is built and operated by the Umikflow team. This Privacy Policy explains how Hush handles information.

Your Data

Encrypted Secrets

Hush is designed so that secret contents are encrypted locally in your browser before they are sent to our servers. Hush does not receive or store the decryption key.

Limited Metadata

Hush temporarily stores encrypted envelope fields, including ciphertext, IV, and—where applicable—a salt and wrapped key. We also store an opaque secret ID, an expiry timestamp, and a hashed finalization token for passphrase-protected secrets.

Anti-Abuse Data

To prevent abuse, Hush uses HMAC-hashed IP identifiers for rate limiting. These identifiers are retained only within the applicable 15-minute and 24-hour rate-limit windows. Raw IP addresses are not stored in Hush's application database.

Deletion Guarantees & Limits

One-Time Mode vs Passphrase Mode

For normal secrets, after a recipient deliberately clicks Reveal, the encrypted envelope is consumed and erased in a single database transaction. A later request for the same secret is unavailable.

Passphrase mode works differently. An incorrect passphrase can be retried. The encrypted envelope remains available until the recipient successfully decrypts it and the official client completes finalization, or until the secret expires. This is best-effort finalization rather than the same server-enforced one-time mechanism used by normal secrets.

Expiry and Cleanup

Expired secrets are denied access immediately based on their expiry timestamp. A scheduled cleanup process deletes expired records from the live database.

Deletion from the live database does not necessarily mean immediate removal from all infrastructure backups. We rely on cloud providers for infrastructure and do not claim that provider backups are instantly purged after a record is deleted.

Service Providers

We rely on the following infrastructure providers to operate Hush:

These providers may process limited technical connection data under their own privacy policies.

Contact

For privacy questions or requests, contact support@umikflow.com.