Privacy
Last updated 19 July 2026
Umbra is a local-first tool. Your accounts, cookies, proxies and browsing live on your own computer. This page is about the small amount that doesn't.
What we store
Your account: email address, name if you gave one, and a hashed password. Never the password itself.
Your licence: plan, status and a hardware ID per activated machine, so a licence cannot be silently shared. The hardware ID is a derived identifier, not a hardware serial.
Card payments: handled by Stripe. We store their customer and subscription identifiers. We never see or store your card number.
Crypto payments: the transaction hash you give us, the plan and the amount, so a payment can be checked by hand and matched to your account. A transaction hash is already public on the blockchain. You never connect a wallet to us — you send from your own, and the hash is the only thing you hand over.
Support messages you choose to send from inside the app, and what you attach to them.
What we cannot read
Cloud sync is encrypted on your device. Every account and proxy is sealed on your computer before it is uploaded, with a key derived from a passphrase you set that is never transmitted. We hold ciphertext we cannot open — not the contents of your accounts or proxies.
What sync does reveal to us: each item's random identifier and how many you have, the size of each sealed record, the identifier and time of anything you delete, your licence key, and which of your devices synced when. Not names, not credentials, not proxy details. Because your synced workspace is tied to your licence, it is encrypted, not anonymous.
It is encrypted on your device, but it is not zero-knowledge: your passphrase is the only thing protecting the sealed copy, and anyone who obtained the stored data could test guesses against it offline. Choose a long, unguessable one. And if you lose it, we cannot recover your synced data for you — nobody can.
What never leaves your machine
Your browsing, cookies, logins, autofill data, card labels and the contents of every Account. Umbra does not route your traffic through our servers — it goes through whichever proxies you supply, directly.
Secrets stored locally are encrypted with your operating system's keystore where your system provides one. Where it does not, they are stored encoded rather than encrypted, and the app is explicit about that rather than pretending otherwise.
Third parties
Stripe for card payments, Resend for transactional email, and Vercel and Neon for hosting the site and its database. Each sees only what it needs to do its job. We do not sell data to anyone, and there is no advertising or analytics tracking on the desktop app.
Your rights
Email us and we will export or delete your account data. Deleting your account cancels any subscription and removes your licence and synced blob; what is on your own computer stays yours, and you can export it from the app at any time.
If you are in the UK or EU, the usual rights of access, correction, erasure and portability apply, and you can complain to your data protection authority.
Questions about any of this? Reach us through Contact support in the app, or the message form on your dashboard.