Privacy notice · updated 2026-09-30
Temporary ciphertext, minimal metadata.
The initial Beta is an English Developer service operated from Japan without country-specific advertising, sales or regional offers. Public availability is not a representation that Dermoptera targets or has completed a regulatory launch in every jurisdiction.
Operator and contact
Dermoptera Handoff is operated from Japan by an individual using the Dermoptera brand. The individual's legal name and serviceable address are held in a private legal record and supplied without delay after a verified request to legal@dermoptera.work. They are not routinely published in the repository, npm package or Developer site. Use that address for operator-information, privacy, complaint and data-rights requests; use security@dermoptera.work only for security reports. No private email address, personal telephone number or home address is used as a public contact unless a specific legal obligation requires it.
Transferred state
Your app encrypts state in the sender's browser with AES-256-GCM. The service temporarily stores ciphertext, IV, hashed claim material, Project association, size and expiry metadata. The AES key stays in the continuation URL fragment and is not intentionally sent to the backend. Default TTL is ten minutes and permitted TTL is one to thirty minutes. One successful claim makes replay unavailable. Ciphertext is normally deleted after claim; best-effort deletion failures and unclaimed ciphertext are removed after expiry cleanup.
Encryption limits backend access but does not protect a compromised app, browser, device, extension, screenshot or copied URL. Developers remain responsible for the state they choose and for end-user notice.
Developer data
We process email, authentication subject, account and Project IDs/status/timestamps, Project names, Allowed Origins, credential hashes and non-secret prefixes, quota and aggregate create/claim/expiry/error counters. Raw Project keys are not retained after display. Hashed deletion tombstones last 30 days. Project usage is deleted with its Project.
Providers, cookies and logs
Clerk provides email-code authentication, sessions and bot protection. Cloudflare provides DNS/CDN security, Workers execution and D1 storage. They may process data outside Japan under their published terms and subprocessors. Strictly necessary Clerk browser storage/cookies support sign-in and logout. We do not use advertising cookies or Google Analytics in the initial Beta. Application code is designed not to log plaintext state, AES keys, complete claim tokens, fragments or request bodies; Cloudflare may process ordinary platform request/security metadata under its settings and terms.
Your requests
Use Dashboard deletion where available, or email legal from the account address for access, correction, addition, deletion, suspension, erasure, suspension of third-party provision or a complaint. Identify the account/Project but never send credentials or transferred state. We may verify through the signed-in account or fresh email verification. The Free Beta charges no request fee. Requests may be limited where law permits, with reasons where required.
Retention and change
Transfer, replay, rate-limit and auth records follow the short periods above; account/Project records remain until self-service deletion subject to technical completion and required legal records. Material notice changes are dated. This notice does not limit non-waivable rights.