Privacy Policy
Last updated: April 2, 2026
1. Information We Collect
Aquafire is designed with privacy in mind. We collect minimal information necessary to provide the Service:
- Wallet Address. Your Ethereum wallet address is used as your account identifier. We do not collect your name, email, or other personal data unless you voluntarily provide it (e.g., via the contact form).
- Document Data. Files and documents you upload are stored as cryptographic Aqua Protocol trees. The content is stored on our servers to provide the Service.
- Usage Data. We may collect anonymized usage statistics such as page views, feature usage, and performance metrics to improve the Service.
- Contact Information. If you contact us via our contact form, we collect the email address, subject, and message you provide.
2. How We Use Your Information
- To provide, maintain, and improve the Service.
- To authenticate your identity via SIWE (Sign-In with Ethereum).
- To process document signing, verification, and timestamping requests.
- To manage your subscription and billing (if applicable).
- To respond to your inquiries and support requests.
- To send transactional notifications (e.g., signing requests) when triggered by your actions or actions of other users involving your documents.
3. Data Storage and Security
Your data is stored using the Aqua Protocol's cryptographic tree structure, which provides built-in tamper detection through hash chains. Document data is stored on our servers using fjall, a high-performance embedded storage engine.
We implement industry-standard security measures to protect your data, including encrypted connections (TLS), secure session management, and access controls. However, no method of transmission over the Internet is 100% secure.
Your private keys are never transmitted to or stored on our servers. Authentication is performed entirely client-side via your wallet.
4. Cookies and Local Storage
Aquafire uses minimal browser storage:
- Session Nonce. A session identifier stored in your browser to maintain your authenticated session.
- Theme Preference. Your light/dark mode preference is stored in
localStorage.
We do not use third-party tracking cookies or advertising cookies.
5. Third-Party Services
We may use the following third-party services to operate the platform:
- SendGrid (Twilio) for transactional email delivery (signing requests, contact form).
- Twilio for SMS notifications.
- Ethereum Network for on-chain timestamping and verification.
- FreeTSA / RFC 3161 for trusted timestamping.
- NOWPayments for cryptocurrency payment processing (if applicable).
These services have their own privacy policies and we encourage you to review them.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. You may delete your data at any time through the Settings page. Upon account deletion:
- Your document trees and associated files will be permanently removed from our servers.
- Your session data will be invalidated.
- Subscription and billing records may be retained as required by law.
Because the Aqua Protocol is portable, you may export your data trees before deleting your account.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access. You may request a copy of the personal data we hold about you.
- Correction. You may request correction of inaccurate data.
- Deletion. You may request deletion of your data, subject to legal retention requirements.
- Portability. The Aqua Protocol natively supports data portability. You can export your trees at any time.
- Objection. You may object to certain processing activities.
To exercise any of these rights, please contact us using the information below.
8. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at: