Legal

Privacy notice

What we collect, why, for how long, and what you can do about it. The short version: account and billing details, request metering records, security logs — and, structurally, almost nothing about the content you store.

Draft — not yet in force

This document is a working draft published for transparency. It has not completed legal review, is not incorporated into any agreement, and creates no rights or obligations. The definitive version will be published before general availability. For terms you can rely on today, contact legal@PLACEHOLDER_DOMAIN.example.

Who we are

PLACEHOLDER_LEGAL_ENTITY, registered in PLACEHOLDER_COUNTRY_OF_INCORPORATION (company number PLACEHOLDER_COMPANY_NUMBER), PLACEHOLDER_REGISTERED_ADDRESS, is the controller for the data described below except where stated otherwise.

Data protection contact: privacy@PLACEHOLDER_DOMAIN.example.

What we process

Account & billing dataController: Tessera
Contact name, email address, billing address, payment instrument tokens held by our payment processor, and invoice history. Basis: performance of a contract. Retention: for the life of the account plus the statutory period applicable to financial records.
Credential identifiersController: Tessera
The public half of your ed25519 credential, which is also your account identifier, plus its state and caps. We do not retain the private half in any recoverable form. Retention: until revocation, then retained in revoked state to prevent reuse.
Request & usage recordsController: Tessera
Timestamps, endpoints, response codes, byte counts, and rate-limit counters, associated with a credential. Basis: performance of a contract for metering, and legitimate interest for abuse prevention and security. Retention: a rolling operational window, then aggregated.
Security & error logsController: Tessera
IP addresses, user agents, request identifiers, and stack traces. Basis: legitimate interest in securing the service. Retention: short, and no longer than needed for the purpose.
Customer contentProcessor: Tessera
Objects you store. We process these strictly on your instruction. Content is encrypted before it reaches us and we hold no filenames, paths, or content types. If your content contains personal data, you are the controller and we are the processor.
Website visitorsController: Tessera
Standard web server logs only. This website sets no cookies, embeds no third-party scripts, loads no external fonts, and runs no analytics or tracking of any kind.

Why we hold less than you might expect

Our data model has no field for a filename, directory path, content type, or plaintext object size. This is not a retention policy that could be changed by configuration — those columns do not exist. Content arrives already encrypted and is never assembled in our infrastructure. The practical consequence is that for most privacy questions about content, the honest answer is that we do not have the information.

We do hold placement metadata and per-slab encryption parameters, which is what allows us to repair your data without your involvement. This is described precisely on our security page.

Who we share it with

Only with the subprocessors we publish, for the purposes we publish. We do not sell personal data, do not share it for advertising, and do not use customer content to train anything.

Subprocessor list

International transfers

Where personal data leaves the EEA, transfers rely on Standard Contractual Clauses together with supplementary technical measures — principally that content is encrypted before transmission and no single jurisdiction holds a reconstructable copy. A transfer impact assessment is available on request.

Your rights

You may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interest. You may also lodge a complaint with your supervisory authority. We respond within one month.

Where a request concerns content you have stored, we will route it to you as controller and assist as processor — we cannot read the content and therefore cannot identify a data subject within it.

Breach notification

In the event of a personal data breach we notify the relevant supervisory authority within 72 hours of becoming aware of it, and affected customers without undue delay, with what we know at the time rather than after the investigation concludes.

Changes to this notice

Material changes will be announced before they take effect. This page will carry the effective date of the version in force.