Back to Home

Privacy Policy

Last updated: September 7, 2026

Quick Summary

  • ✓We never access, read, or sell your file contents.
  • ✓Client-side encryption means only you hold the keys.
  • ✓Zero-knowledge proofs verify membership without revealing identity.
  • ✓On-chain data is pseudonymous and never contains real-world identity.
  • ✓No advertising cookies, no cross-site tracking, no data brokers.
  • ✓You can delete your centralized account data at any time.

1. Privacy Overview

Aeterna is built on a foundational principle: your data belongs to you. Our architecture is designed to minimize what we know about you while maximizing what you can do with the platform. This Privacy Policy explains what limited information we collect, why we collect it, and how we protect it. It covers both our centralized services (authentication, metadata caching) and our integration with decentralized protocols (Arweave, IPFS, Ethereum L2). Key commitments: - We never access your file contents. - We never sell your personal information to third parties. - We use zero-knowledge cryptography to verify membership without revealing identity. - You can delete your centralized account data at any time.

2. Information We Collect

We collect different types of information depending on how you use the Service. Account Information (Free Tier only): - Email address or social login profile (name, profile picture) when you create an account via our authentication provider. - We do not require or collect legal names, phone numbers, or physical addresses. Wallet Information (Paid Tiers): - Your public wallet address (used as a pseudonymous identifier). - Transaction hashes related to your subscription and storage activity. - We never have access to your private keys or wallet seed phrase. Usage Data: - Pages visited, features used, and interaction patterns within the application. - Browser type, operating system, and device type (collected automatically). - IP address (used for rate limiting and abuse prevention; logged for no more than 30 days). Storage Metadata: - File names, sizes, content hashes (SHA-256), and storage backend (Arweave/IPFS). - Upload and access timestamps. - This metadata is used to provide the file management interface and does not include file contents. Zero-Knowledge Data: - Identity commitments and nullifiers derived from your cryptographic secret. - These are stored on-chain and in our indexer but reveal nothing about your real-world identity.

3. How We Use Your Information

We use collected information for the following purposes: Service Operations: - Authenticate your identity (via our auth provider for free tier, via wallet signature for paid tiers). - Process subscription payments through on-chain smart contracts. - Store file metadata to provide browsing, searching, and sharing features. - Index blockchain events to keep your dashboard in sync with on-chain state. Security & Abuse Prevention: - Rate-limit API requests to prevent abuse. - Detect and prevent fraudulent activity. - Verify zero-knowledge proofs for access control. Communication: - Send transactional emails (account verification, subscription confirmations). - Respond to support requests. - Notify you of material changes to the Service or these policies (we will never send marketing emails without explicit consent). Analytics: - Understand aggregate usage patterns to improve the Service. - We do not use your wallet address to build advertising profiles.

4. Information Sharing

We do not sell, trade, or rent your personal information to third parties. We share information only in the following limited circumstances: Service Providers: - Authentication provider (Privy) — verifies your email address or social account when you sign in. - Payment processor (Stripe) — processes subscription payments for users who pay via traditional payment methods. - Cloud infrastructure providers (Vercel, Railway) — host the application and backend services. - Storage pinning services (Pinata or equivalent) — pin files to IPFS on your behalf. Each service provider is contractually bound to use your data only for the purpose of providing their service to us. On-Chain Data: - Identity commitments, membership proofs, and archive receipts are stored on a public blockchain (Base L2). This data is inherently public and cannot be removed once written. - We design our on-chain data to be pseudonymous: it contains no real-world identity information. Legal Requirements: - We may disclose information if required by law, subpoena, or court order. - We may disclose information if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others. No Third-Party Advertising: - We do not share data with advertising networks, data brokers, or social media platforms for advertising purposes.

5. Encryption & Security

We employ multiple layers of security to protect your data: Client-Side Encryption: - When you enable encryption (optional), your files are encrypted in your browser using AES-256-GCM before leaving your device. - Encryption keys are derived from a passphrase you choose using PBKDF2 with a random salt. - We never see your passphrase or encryption keys. If you lose them, your encrypted files cannot be recovered. In Transit: - All communication between your browser and our servers is encrypted using TLS 1.3. - API requests to blockchain nodes and storage protocols also use encrypted connections. At Rest: - File metadata in our database is encrypted at rest using database-level encryption. - Temporary file data in our upload pipeline is stored in memory only and is not persisted to disk. Zero-Knowledge Architecture: - Our membership verification system uses zkSNARKs (zero-knowledge succinct non-interactive arguments of knowledge). - This means we can verify you are a member without learning anything about which member you are. - Your identity commitment is derived from a secret only you possess; it cannot be reversed to identify you. Smart Contract Security: - Our contracts are deployed using audited patterns from OpenZeppelin v5. - Access control is enforced at the contract level; no single point of failure.

6. Cookies & Tracking

Essential Cookies: - Session cookies for authentication (managed by our auth provider). - CSRF protection tokens. - These are strictly necessary for the Service to function and cannot be disabled. Analytics: - We use privacy-focused analytics (no third-party tracking cookies). - Analytics data is aggregated and does not identify individual users. Advertising Cookies: - We do not use advertising cookies or third-party tracking pixels. - We do not participate in cross-site tracking. You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent the Service from functioning correctly.

7. Data Retention

Account Data: - Retained while your account is active. You may delete your account at any time, which removes your email, profile data, and metadata cache within 30 days. On-Chain Data: - Identity commitments, membership tokens, and archive receipts are stored permanently on the blockchain and cannot be deleted. This is inherent to how decentralized protocols operate. IPFS Pinned Data: - Files pinned to IPFS remain available as long as the pinning service maintains them. If you cancel your subscription, pinned files may eventually be unpinned. Arweave Data: - Files stored on Arweave are permanent by design and cannot be deleted from the network. Your on-chain archive receipt remains indefinitely. Logs: - Server access logs are retained for 30 days for security purposes, then deleted. - Error logs containing no personal information may be retained longer for debugging.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data: Access — Request a copy of the personal data we hold about you. Rectification — Request correction of inaccurate personal data. Deletion — Request deletion of your centralized account data (this does not affect on-chain data). Portability — Request your data in a machine-readable format. Objection — Object to processing of your personal data for certain purposes. Restriction — Request restriction of processing in certain circumstances. Withdraw Consent — Withdraw consent for data processing where consent was the legal basis. To exercise any of these rights, contact us at team@aeternavault.cc. We will respond within 30 days. For users in the European Economic Area (EEA), these rights are provided under the General Data Protection Regulation (GDPR). For users in California, these rights are provided under the California Consumer Privacy Act (CCPA/CPRA). For users in other jurisdictions, we will honor applicable local data protection laws.

9. Children's Privacy

The Service is not intended for children under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information promptly. If you are a parent or guardian and believe your child has provided personal information to us, please contact us at team@aeternavault.cc.

10. International Data Transfers

Our servers are hosted in multiple regions to provide reliable service. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. By using the Service, you consent to such transfers. We ensure that appropriate safeguards are in place, including standard contractual clauses where required by applicable law. On-chain data is distributed across a global peer-to-peer network and is not subject to traditional data transfer restrictions.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated via: - Email notification to account holders. - A prominent banner on the application. - An updated "Last Updated" date at the top of this page. We encourage you to review this page periodically. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy. For material changes that affect how we process your data, we will seek your affirmative consent where required by law.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: Email: team@aeternavault.cc Website: https://aeternavault.cc Mailing Address: Aeterna Wilmington, DE 19801 United States

Questions about your privacy?

Contact our Data Protection Officer