ark256
Home About Pricing Security FAQ Open Vault
Home About Pricing Security FAQ Open Vault
Legal

Privacy Policy

Last updated: June 2026

Binary Leap OÜ ("ARK256", "we", "us", or "our"), registered in Estonia (Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia), operates the ARK256 zero-knowledge encrypted file storage service (the "Service"). This Privacy Policy explains what information we process and how. By using the Service you acknowledge the practices described here.

1. Information we collect

ARK256 is designed to collect as little about you as possible.

No account information. The Service has no accounts. We do not collect your name, email address, username, or password. Access is through a Vault ID and a secret key that you generate and control. We store only a cryptographic hash of your secret, never the secret itself.

Encrypted file content. Your files are encrypted on your device before they are uploaded. We store only the resulting encrypted data. Your encryption key never reaches our servers, so we cannot read, decrypt, or access the contents of your files.

File metadata. To operate your vault, we process limited metadata about your files, such as file names and sizes. This metadata is not encrypted in the same way your file contents are.

Technical data. We automatically process your IP address, request headers, and connection metadata when you access the Service, for rate limiting, abuse prevention, and security monitoring.

Payment information. Payments are processed entirely by Paddle.com Market Limited ("Paddle"), our Merchant of Record. We do not collect or store card numbers or bank details. We also do not store any billing identifier, customer ID, or email handled by Paddle. Your payment identity stays with Paddle and is not linked to your vault.

2. How we use your information

We use this information to: (a) provide and operate the Service; (b) authenticate access to your vault via your token; (c) process payments and manage subscriptions through Paddle; (d) enforce rate limits, detect abuse, and protect security; (e) comply with legal obligations. We do not use your information for advertising or profiling, and we do not sell it.

3. Legal basis for processing (GDPR)

For users in the European Economic Area, we process personal data under: performance of a contract (operating the Service you purchased); legitimate interests (security and abuse prevention); legal obligation (compliance with applicable law); and consent where required.

4. Zero-knowledge and Customer Data

The files you store are your Customer Data. We act only as a processor of that data, on your instructions, for the purpose of operating the Service. Because your files are encrypted on your device with a key we never receive, we cannot read your Customer Data. We process it only as ciphertext, to store it, relocate it during rotation, and return it to you on request.

5. Infrastructure and rotation

The Service runs on dedicated servers we operate through third-party data centre providers, across multiple regions: the European Union, the United States, and Asia-Pacific. Each vault is isolated at the database or virtual-machine level. As a core feature of the Service, your encrypted vault is automatically relocated ("rotated") between these regions on a recurring interval, by default approximately every six hours. Encrypted backups are stored on Amazon Web Services S3 in the EU (Frankfurt region).

6. International data transfers

Because rotation is automatic and spans regions in the United States and Asia-Pacific, your encrypted vault is regularly relocated outside the European Economic Area as part of normal operation. Only data that has already been encrypted on your device is ever transferred. Neither we nor the providers hosting these regions hold your encryption key, so your file contents cannot be read in any region, and no readable personal data leaves the EEA. The transferred data consists solely of encrypted blobs that we are unable to decrypt.

7. Sub-processors

We rely on the following sub-processors: third-party data centre providers for server hosting across our EU, US, and Asia-Pacific regions (these providers process only encrypted data and cannot access your file contents); Amazon Web Services for encrypted backup storage in the EU; and Paddle for payment processing, invoicing, and tax, as Merchant of Record (see paddle.com/privacy).

8. Data retention

Monthly plans: your encrypted vault is retained while your subscription is active. On cancellation, the vault and its data are destroyed at the end of the billing period.

One-time (30-day) plans: after the 30-day term, all servers, data, and copies are permanently destroyed.

Technical data (IP addresses and rate-limit records): retained for a maximum of 30 days for security purposes, then purged.

Because of the zero-knowledge design, destroyed vaults and lost credentials cannot be recovered.

9. Data security

(a) All connections to the Service are encrypted with TLS. (b) Files are encrypted on your device with AES-256 before upload. (c) We store only a hash of your secret, never the secret or your key. (d) Each vault is isolated at the database or virtual-machine level. (e) Backups are encrypted at rest. (f) Per-IP rate limiting and brute-force protection apply at the API and proxy layers. No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.

10. Your rights

If you are in the EEA, you have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Because the Service is token-only and zero-knowledge, our practical ability to act on some requests is limited: we cannot identify you, link a vault to your identity, or access your file contents without your credentials. To exercise your rights, contact us at bl@binaryleap.eu. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.

11. Cookies

The ARK256 marketing website (ark256.com) uses only essential cookies required for basic functionality. We do not use advertising or tracking cookies. The Service itself does not use cookies; access is performed via your token.

12. Children's privacy

The Service is not directed at individuals under 16. We do not knowingly collect personal information from children under 16.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated effective date. Continued use of the Service after the effective date constitutes acceptance.

14. Contact

Binary Leap OÜ, Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia. Email: bl@binaryleap.eu. Supervisory authority: Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia, info@aki.ee.

ARK256

Zero-knowledge encrypted file storage. Files are encrypted on your device and never stop moving.

Product
Home Pricing Security FAQ
Legal
Terms of Service Privacy Policy Refund Policy
ARK256 · Built by Binary Leap OÜ © 2026 ark256.com