DEVELOPMENT PRIVACY NOTE
Clear about what goes where.
This note describes this static website and Aeterna’s development data boundaries. It is not a final production privacy policy. Operating jurisdictions, provider details and retention periods must be confirmed before launch. A public privacy contact is available on the contact page.
Last reviewed:
This website
The website is a static product introduction. It has no account creation, contact form, newsletter, advertising, analytics scripts, embedded third-party media or application cookies. The website uses system fonts and locally served visual assets.
A hosting server may process IP addresses and request metadata to serve pages and operate access logs. The production host, log configuration and retention period have not yet been finalized.
What stays on your device
Library contents—including account entries, notes, instructions, files, audio and video—are encrypted locally. The library contents, master password, emergency recovery code and plaintext library data key are not uploaded to the coordination service.
Encrypted backups remain under your control. The service does not keep a content copy and cannot reconstruct a library when all local copies are lost.
What the coordination service processes
The development implementation processes owner and contact email addresses, invitation and verification state, registered device identifiers and public keys, accepted activity, inactivity settings, constrained notification text, delivery records and recovery-claim audit data.
It also holds encrypted device-bound release material used in authorized delayed recovery. Service data alone is not sufficient to decrypt a local library. The service and email provider can read the addresses and rendered text necessary for email delivery.
Activity and notification data
Activity detection does not collect raw keystrokes, screen content, browsing history, application content, window titles or pointer positions. Accepted device signals support timing; they do not establish identity or physical presence.
An invitation is kept neutral until the recipient accepts and verifies. Do not place passwords, emergency recovery codes or other secrets into notification instructions.
Your choices and deletion
Owners configure timing, contacts and disclosure mode. Recipients can accept or decline a valid pending invitation. An accepted contact’s self-service withdrawal path is not yet available.
Account deletion and retention behavior must be finalized and verified before production launch. Removing service recovery material can permanently disable delayed recovery; it does not delete independent local library copies. No production retention period is asserted here.
Providers, operator and contact
AWS SES is the selected production email provider in ap-southeast-1. Production notification delivery, event configuration and provider validation remain pending. Other production hosting and processing details must be confirmed before launch.
Aeterna is an independent personal project. Product questions, privacy requests and unwanted-email reports can be sent to the public email address on the contact page. Applicable operating jurisdictions and production processing details still need to be confirmed before launch.