Trust CenterExplore products
Active

Product trust profile

CipherDrive™

Your files, encrypted before they leave your device.

CipherDrive is Ackaia's end-to-end encrypted personal cloud drive. Supported file content is encrypted in your browser before upload, while limited account, security, storage, and transfer metadata remains necessary to operate the service.

Visit product

Privacy labels

Understand the data relationship at a glance.

These labels summarize CipherDrive's practices. Open the detailed categories below for purpose, visibility, retention, and protection.

No Advertising Tracking

CipherDrive does not use encrypted file content for advertising or behavioral targeting, and does not sell encrypted file content.

Includes
  • Authentication & Security
  • Diagnostics & Service Activity

Data Linked to Your Account

Some operational data is associated with your Ackaia ID so the drive, subscription, sharing, and security features can work.

Includes
  • Account & Identity
  • Purchases & Billing
  • Storage Metadata
  • Transfer & Usage Data

Content Ackaia Cannot Read

Supported file content is encrypted before upload. In normal operation, Ackaia does not possess the keys required to decrypt stored files.

Includes
  • Encrypted File Content
  • Local Keys & Unlock State

Data journey

Follow each category from collection to protection.

Choose a category to see, in sequence, how its data enters CipherDrive, why it is used, how long it remains, and how it is protected.

Account & Identity

Information obtained from your Ackaia ID to provide and secure your account.

Linked to account
  1. 01
    How it enters the service

    Collection

    Received from your Ackaia ID and information you provide.

  2. 02
    Why it is used

    Purpose

    • Account access and authentication
    • Subscription and entitlement management
    • Security notices and essential communication
  3. 03
    How long it remains

    Retention

    Kept while the account is active and afterward when required for security, disputes, or legal obligations.

  4. 04
    How it is safeguarded

    Protection

    Protected in transit and at rest with access controls and auditability.

Data categories

What CipherDrive handles and why.

A file can be received as encrypted ciphertext without being readable by Ackaia. The categories below preserve that distinction.

Account & IdentityInformation obtained from your Ackaia ID to provide and secure your account.Linked to accountOpen details

Information in this category

  • Account identifier
  • Name and email address
  • Account type and status
  • Plan and subscription status
  • Security settings

Why it is used

  • Account access and authentication
  • Subscription and entitlement management
  • Security notices and essential communication
How it is obtained
Received from your Ackaia ID and information you provide.
Ackaia visibility
Accessible to authorized Ackaia systems and personnel when required for account operations.
Retention
Kept while the account is active and afterward when required for security, disputes, or legal obligations.
Protection
Protected in transit and at rest with access controls and auditability.
Authentication & SecuritySignals used to protect sessions, accounts, public links, and infrastructure.Linked to accountOpen details

Information in this category

  • IP address and approximate location
  • Browser, device, and user-agent data
  • Session identifiers and timestamps
  • Failed attempts and suspicious activity signals
  • Audit and account-recovery events

Why it is used

  • Prevent account takeover and unauthorized access
  • Detect abuse and enforce rate limits
  • Investigate and respond to security events
How it is obtained
Generated when you authenticate, access the service, or perform security-sensitive actions.
Ackaia visibility
Visible to authorized security systems and personnel on a need-to-know basis.
Retention
Security records are retained for a period proportionate to risk, investigation, and legal requirements.
Protection
Access-controlled, monitored, and handled separately from encrypted file content.
Purchases & BillingSubscription and payment metadata required for paid plans.Linked to accountOpen details

Information in this category

  • Selected plan and billing cycle
  • Subscription and payment status
  • Invoice and transaction identifiers
  • Billing contact and required tax data
  • Limited payment-method metadata

Why it is used

  • Process and manage subscriptions
  • Issue invoices and enforce plan limits
  • Prevent payment fraud and meet accounting duties
How it is obtained
Received during checkout and from the payment processor.
Ackaia visibility
Ackaia receives billing status and limited payment metadata, not full card numbers processed by the payment provider.
Retention
Kept for subscription administration and as required by tax, accounting, dispute, and fraud-prevention obligations.
Protection
Protected in transit and at rest; payment processing is separated from encrypted storage.
Storage MetadataOperational information needed to organize encrypted objects and run the drive.Linked to accountOpen details

Information in this category

  • Object identifiers and type
  • Encrypted size and storage usage
  • Upload, update, and deletion timestamps
  • Folder relationships and sharing status
  • Encrypted names, wrapped keys, and non-secret cryptographic parameters

Why it is used

  • Organize files and folders
  • Apply storage limits and sharing controls
  • Maintain reliable upload and download workflows
How it is obtained
Generated by storage actions and the encrypted client.
Ackaia visibility
Operational metadata is visible to Ackaia. Values encrypted by the client, such as supported filenames, are not readable in plaintext.
Retention
Maintained with the object and during deletion, backup, recovery, fraud-prevention, or dispute windows.
Protection
Protected in transit and at rest; sensitive supported metadata is encrypted client-side.
Encrypted File ContentYour file content, encrypted before it is uploaded.Encrypted before uploadOpen details

Information in this category

  • Encrypted file chunks
  • Encrypted file-key material
  • Authentication tags and non-secret parameters

Why it is used

  • Store and deliver the files you choose
  • Preserve confidentiality and integrity
How it is obtained
Encrypted in your browser before transmission, after applicable pre-encryption safety checks.
Ackaia visibility
Ackaia stores ciphertext but does not normally possess the keys required to read the plaintext file.
Retention
Stored until you delete the file or close the account, subject to deletion queues, backups, legal preservation, and safety obligations.
Protection
End-to-end encrypted for supported workflows and protected in transit. Decryption occurs on an authorized user device.
Local Keys & Unlock StateCryptographic material retained on your device to unlock the encrypted vault.Device onlyOpen details

Information in this category

  • Local wrapped key material
  • Vault unlock state
  • Device-trust information

Why it is used

  • Unlock and decrypt files on your device
  • Avoid requesting a vault secret on every visit
How it is obtained
Created and retained in browser or device storage where enabled.
Ackaia visibility
Not sent to Ackaia in plaintext during normal encrypted-storage operation.
Retention
Remains on the device until cleared, revoked, expired, or removed by the user or application.
Protection
Protected by the browser, device, vault secret, and applicable local wrapping controls.
Transfer & Usage DataCounters and events used for storage, bandwidth, and reliability limits.Linked to accountOpen details

Information in this category

  • Uploaded and downloaded bytes
  • Storage and transfer totals
  • Public and private transfer usage
  • Quota, throttling, and rate-limit events

Why it is used

  • Enforce plan and fair-use limits
  • Prevent abuse and maintain reliability
  • Plan capacity and troubleshoot transfers
How it is obtained
Generated when storage and transfer operations occur.
Ackaia visibility
Visible to operational systems and authorized personnel as needed.
Retention
Counters follow the account and plan lifecycle; event records may remain longer for security and disputes.
Protection
Protected in transit and at rest and kept separate from plaintext file content.
Diagnostics & Service ActivityLimited technical information used to keep CipherDrive reliable.Linked to accountOpen details

Information in this category

  • Pages and features used
  • Performance and error telemetry
  • Browser and operating-system category
  • Timestamps and approximate region

Why it is used

  • Debug errors and improve reliability
  • Measure performance and plan capacity
  • Understand basic feature usage
How it is obtained
Generated during use of the website, dashboard, and storage workflows.
Ackaia visibility
Ackaia may access limited diagnostics; encrypted file contents are not used for analytics or advertising.
Retention
Retained only as needed for reliability, debugging, security, and service improvement.
Protection
Minimized, access-controlled, and separated from encrypted file content.
Safety & Risk SignalsTechnical signals created before encryption for severe-abuse prevention.Linked to accountOpen details

Information in this category

  • Cryptographic or perceptual hashes
  • Media fingerprints and similarity indicators
  • Known-content match and risk signals
  • Blocked or rejected upload records
  • Related account, session, object, IP, and timestamp identifiers

Why it is used

  • Detect known child sexual abuse material and severe abuse
  • Prevent malware and prohibited uploads
  • Meet safety and legal obligations
How it is obtained
Generated before client-side encryption where the Risk Assessment Engine applies.
Ackaia visibility
Ackaia may process the resulting safety signal and associated event data. This does not provide a server-side key for decrypting stored files.
Retention
Retained according to severity, investigation, safety, preservation, and legal-reporting requirements.
Protection
Restricted to safety and security purposes; not intended for advertising or commercial profiling.

Ackaia ID access

CipherDrive uses only the account data it needs.

Authentication stays centralized through Ackaia ID. CipherDrive receives the account and entitlement information required to operate your encrypted drive.

Ackaia ID

An Ackaia ID is required to authenticate, connect your plan, enforce security controls, and associate your encrypted vault with your account.

Required

Ackaia ID data accessed

  • Account identifier
  • Name or display name
  • Email address
  • Account and subscription status
  • Plan and security settings

Plans and purchases

Free plan and optional paid subscriptions

Current regional prices, taxes, billing periods, and any promotional terms are shown before checkout.

Regional handling

See the context that applies to you.

Your current location only selects an initial view. It does not determine where your account data is stored or move your data between regions.

US

United States

Applicable framework
Applicable U.S. federal and state privacy, consumer-protection, safety, and legal-preservation requirements.
Data residency
CipherDrive does not currently promise exclusive in-country data residency. Encrypted content remains client-side encrypted regardless of processing location.
International processing
Operational data may be processed across jurisdictions when necessary to provide, secure, support, or legally operate the service.

Safeguards

  • Client-side encryption for supported file content
  • Access controls and auditability for operational data
  • Data minimization and purpose limitation

Providers and data recipients

Who supports CipherDrive in this region.

These companies provide infrastructure or payment capabilities for CipherDrive. Their involvement changes according to the selected operational region.

US · BR · PT

Amazon Web Services (AWS)

Cloud infrastructure and object storage used to operate supported Ackaia services.

Role
Processor
Provider visibility
May process encrypted objects and operational metadata. CipherDrive file content is encrypted before upload, and client-side decryption keys are not provided to AWS.
US

Equinix

Colocation facilities used to house Ackaia-operated servers in the United States.

Role
Physical infrastructure provider
Provider visibility
Does not have routine logical or application access to data on Ackaia-operated equipment and is not provided with CipherDrive client-side decryption keys. Physical access is limited to authorized facility and hardware operations.
US · PT

Stripe

Payment and subscription processing for CipherDrive customers outside Brazil.

Role
Processor + independent roles
Provider visibility
Receives payment and transaction information needed to complete and protect the purchase. It has no access to CipherDrive file content or client-side encryption keys.
Open full provider registry

Related documents

Read the source policies.

This profile is a readable summary. The legal repository remains the authoritative source for complete terms, policies, and technical disclosures.