Privacy Policy
Last updated: September 7, 2026
Quick Summary
- ✓We never access, read, or sell your file contents.
- ✓Client-side encryption means only you hold the keys.
- ✓Zero-knowledge proofs verify membership without revealing identity.
- ✓On-chain data is pseudonymous and never contains real-world identity.
- ✓No advertising cookies, no cross-site tracking, no data brokers.
- ✓You can delete your centralized account data at any time.
Table of Contents
1. Privacy Overview
Aeterna is built on a foundational principle: your data belongs to you. Our architecture is designed to minimize what we know about you while maximizing what you can do with the platform.
This Privacy Policy explains what limited information we collect, why we collect it, and how we protect it. It covers both our centralized services (authentication, metadata caching) and our integration with decentralized protocols (Arweave, IPFS, Ethereum L2).
Key commitments:
- We never access your file contents.
- We never sell your personal information to third parties.
- We use zero-knowledge cryptography to verify membership without revealing identity.
- You can delete your centralized account data at any time.
2. Information We Collect
We collect different types of information depending on how you use the Service.
Account Information (Free Tier only):
- Email address or social login profile (name, profile picture) when you create an account via our authentication provider.
- We do not require or collect legal names, phone numbers, or physical addresses.
Wallet Information (Paid Tiers):
- Your public wallet address (used as a pseudonymous identifier).
- Transaction hashes related to your subscription and storage activity.
- We never have access to your private keys or wallet seed phrase.
Usage Data:
- Pages visited, features used, and interaction patterns within the application.
- Browser type, operating system, and device type (collected automatically).
- IP address (used for rate limiting and abuse prevention; logged for no more than 30 days).
Storage Metadata:
- File names, sizes, content hashes (SHA-256), and storage backend (Arweave/IPFS).
- Upload and access timestamps.
- This metadata is used to provide the file management interface and does not include file contents.
Zero-Knowledge Data:
- Identity commitments and nullifiers derived from your cryptographic secret.
- These are stored on-chain and in our indexer but reveal nothing about your real-world identity.
3. How We Use Your Information
We use collected information for the following purposes:
Service Operations:
- Authenticate your identity (via our auth provider for free tier, via wallet signature for paid tiers).
- Process subscription payments through on-chain smart contracts.
- Store file metadata to provide browsing, searching, and sharing features.
- Index blockchain events to keep your dashboard in sync with on-chain state.
Security & Abuse Prevention:
- Rate-limit API requests to prevent abuse.
- Detect and prevent fraudulent activity.
- Verify zero-knowledge proofs for access control.
Communication:
- Send transactional emails (account verification, subscription confirmations).
- Respond to support requests.
- Notify you of material changes to the Service or these policies (we will never send marketing emails without explicit consent).
Analytics:
- Understand aggregate usage patterns to improve the Service.
- We do not use your wallet address to build advertising profiles.
5. Encryption & Security
We employ multiple layers of security to protect your data:
Client-Side Encryption:
- When you enable encryption (optional), your files are encrypted in your browser using AES-256-GCM before leaving your device.
- Encryption keys are derived from a passphrase you choose using PBKDF2 with a random salt.
- We never see your passphrase or encryption keys. If you lose them, your encrypted files cannot be recovered.
In Transit:
- All communication between your browser and our servers is encrypted using TLS 1.3.
- API requests to blockchain nodes and storage protocols also use encrypted connections.
At Rest:
- File metadata in our database is encrypted at rest using database-level encryption.
- Temporary file data in our upload pipeline is stored in memory only and is not persisted to disk.
Zero-Knowledge Architecture:
- Our membership verification system uses zkSNARKs (zero-knowledge succinct non-interactive arguments of knowledge).
- This means we can verify you are a member without learning anything about which member you are.
- Your identity commitment is derived from a secret only you possess; it cannot be reversed to identify you.
Smart Contract Security:
- Our contracts are deployed using audited patterns from OpenZeppelin v5.
- Access control is enforced at the contract level; no single point of failure.
7. Data Retention
Account Data:
- Retained while your account is active. You may delete your account at any time, which removes your email, profile data, and metadata cache within 30 days.
On-Chain Data:
- Identity commitments, membership tokens, and archive receipts are stored permanently on the blockchain and cannot be deleted. This is inherent to how decentralized protocols operate.
IPFS Pinned Data:
- Files pinned to IPFS remain available as long as the pinning service maintains them. If you cancel your subscription, pinned files may eventually be unpinned.
Arweave Data:
- Files stored on Arweave are permanent by design and cannot be deleted from the network. Your on-chain archive receipt remains indefinitely.
Logs:
- Server access logs are retained for 30 days for security purposes, then deleted.
- Error logs containing no personal information may be retained longer for debugging.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Access — Request a copy of the personal data we hold about you.
Rectification — Request correction of inaccurate personal data.
Deletion — Request deletion of your centralized account data (this does not affect on-chain data).
Portability — Request your data in a machine-readable format.
Objection — Object to processing of your personal data for certain purposes.
Restriction — Request restriction of processing in certain circumstances.
Withdraw Consent — Withdraw consent for data processing where consent was the legal basis.
To exercise any of these rights, contact us at team@aeternavault.cc. We will respond within 30 days.
For users in the European Economic Area (EEA), these rights are provided under the General Data Protection Regulation (GDPR).
For users in California, these rights are provided under the California Consumer Privacy Act (CCPA/CPRA).
For users in other jurisdictions, we will honor applicable local data protection laws.
9. Children's Privacy
The Service is not intended for children under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information promptly.
If you are a parent or guardian and believe your child has provided personal information to us, please contact us at team@aeternavault.cc.
10. International Data Transfers
Our servers are hosted in multiple regions to provide reliable service. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
By using the Service, you consent to such transfers. We ensure that appropriate safeguards are in place, including standard contractual clauses where required by applicable law.
On-chain data is distributed across a global peer-to-peer network and is not subject to traditional data transfer restrictions.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated via:
- Email notification to account holders.
- A prominent banner on the application.
- An updated "Last Updated" date at the top of this page.
We encourage you to review this page periodically. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
For material changes that affect how we process your data, we will seek your affirmative consent where required by law.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: team@aeternavault.cc
Website: https://aeternavault.cc
Mailing Address:
Aeterna
Wilmington, DE 19801
United States
Questions about your privacy?
Contact our Data Protection Officer