SpamKill checks every submission at the moment it arrives. The ones we block are sealed with your key before they're stored — and from then on, only your passphrase can open them. Decrypted in your browser. Gone after 31 days.
This page covers blocked leads. The check itself reads the submission — a filter can't judge what it can't see. Submissions that pass are delivered to your CRM in the original format, with pipeline stage, UTMs and hidden fields intact, and are not retained by us. What we store is what we blocked.
If the encryption passphrase is lost, so is the data — like a good backup password. You create it during setup, and we never keep a copy. Write it down or save it in your password manager before you finish: what you keep is the only way back in.
This is not your account login password. Your login password works the way every login password does, and you can reset it yourself at any time. The encryption passphrase is a separate secret that never reaches us — which is exactly why we can reset the one and not the other.