Ackaia Corporation General Privacy Policy#
Ackaia Corporation v1.00.00 July 24, 2026 1233 York Avenue, Apt. 301 New York, NY 10065 United States of America www.ackaia.com
Effective Date: July 24, 2026
Entity: Ackaia Corporation, 1233 York Avenue, Apt. 301, New York, NY 10065, United States
(“Ackaia”, “Ackaia Corp.”, “we”, “our”, “us”)
Applies To: Ackaia-operated websites, Ackaia ID, shared account and subscription services, customer-facing applications, APIs, support channels, and other products or services that link to this General Privacy Policy, except where a product-specific privacy policy provides more specific information.
Document Owner: Ackaia Corp. Privacy / Legal / Security
Primary Privacy Contact: privacy@ackaia.com
---
Revision History#
| Version | Changes | Date |
|---|---|---|
| 1.00.00 | Initial Publication | 07/24/2026 |
---
1. Purpose#
This General Privacy Policy explains how Ackaia collects, uses, stores, protects, shares, transfers, and otherwise processes personal information across the Ackaia ecosystem.
Ackaia builds privacy-first infrastructure. We seek to minimize unnecessary collection, limit access, use security and privacy by design, explain material processing clearly, and avoid business models based on selling personal information.
This Policy also explains the choices and privacy rights that may be available to you. Those rights vary by jurisdiction and may be subject to verification, exceptions, and limitations under applicable law.
2. Who We Are#
Ackaia Corporation is a company headquartered in New York, United States. Depending on the context and applicable law, Ackaia may act as a:
- controller or business that determines why and how personal information is processed;
- processor or service provider acting on documented instructions from a customer;
- joint or independent controller with another organization where responsibilities are shared or separately determined;
- operator of a Service that processes account, security, billing, and operational information.
Where Ackaia processes personal information for an organizational customer under a separate agreement, that customer’s privacy notice and instructions may also apply.
3. Scope#
This Policy applies to personal information processed through:
- Ackaia websites, dashboards, and public pages;
- Ackaia ID registration, authentication, account recovery, and security;
- shared subscriptions, entitlements, billing, offers, and account services;
- customer-facing Ackaia products and applications;
- Ackaia-operated APIs and developer services;
- support, feedback, legal, trust, safety, and security-reporting channels;
- communications from Ackaia;
- events, research, beta programs, and community participation where this Policy is presented;
- internal security, fraud-prevention, abuse-prevention, and service-reliability operations associated with those activities.
This Policy does not apply to:
- third-party services not controlled by Ackaia;
- employment or applicant information governed by a separate notice;
- information processed exclusively by an organizational customer for its own purposes;
- processing covered by a more specific notice to the extent that notice states different or additional practices.
4. Relationship to Product-Specific Privacy Policies#
Some Ackaia products process information in ways that require additional explanation. Their product-specific privacy policies supplement this Policy.
If a product-specific privacy policy conflicts with this Policy, the product-specific policy controls for that product and subject matter. This General Privacy Policy continues to apply to shared services such as Ackaia ID, corporate websites, account security, billing, legal compliance, and cross-service administration unless the product policy expressly states otherwise.
For example, CipherDrive™ has a separate Privacy Policy describing encrypted storage, file metadata, public sharing, local key storage, transfer accounting, and its Risk Assessment Engine.
5. Definitions#
“Personal Information” or “Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to an individual or household, as defined by applicable law.
“Processing” means collecting, using, storing, organizing, transmitting, disclosing, securing, deleting, or otherwise handling personal information.
“Service” or “Services” means an Ackaia-operated website, application, account system, product, API, interface, feature, or related service.
“Sensitive Personal Information” means categories given additional protection under applicable law, which may include authentication secrets, precise location, government identifiers, financial information, health information, biometric information, or information revealing certain protected characteristics.
“Service Provider” means a vendor, contractor, processor, or other organization that processes information to help Ackaia operate.
6. Categories of Information We Process#
The categories below describe information Ackaia may process. The actual categories depend on which Services you use, your settings, your location, your plan, and your interactions with Ackaia.
6.1 Account and Identity Information#
We may process:
- name and display name;
- email address and verified-contact status;
- Ackaia ID and other internal identifiers;
- username, profile information, and avatar;
- account creation date, status, type, and settings;
- organization, role, team, or membership information;
- age or eligibility confirmation where necessary;
- country, region, language, and time zone;
- information used for account recovery or verification.
6.2 Authentication and Security Information#
We may process:
- password hashes and passkey-related public information;
- multifactor-authentication configuration;
- session, token, and credential identifiers;
- login, logout, recovery, verification, and revocation events;
- IP addresses;
- approximate location inferred from an IP address;
- device, browser, operating-system, and user-agent information;
- failed-login and security-challenge records;
- suspicious-activity, fraud, abuse, and risk indicators;
- authorization decisions, policy evaluations, and security audit events;
- records associated with trusted or remembered devices.
Ackaia does not store plaintext passwords. Product-specific cryptographic secrets and local key material are handled as described in the applicable product documentation.
6.3 Subscription and Billing Information#
If you use a paid Service, trial, promotion, or offer, we may process:
- selected plan, billing interval, and entitlements;
- subscription, renewal, cancellation, and grace-period status;
- transaction, invoice, order, offer, and promotion identifiers;
- billing name, email, address, and tax information;
- payment status and fraud indicators;
- limited payment-method metadata provided by a processor, such as card brand, last digits, expiration information, or a processor token;
- credits, discounts, and redemption history.
Payment processors generally process full payment-card details directly. Ackaia does not intend to store full card numbers when a payment processor performs that function.
6.4 Government and Tax Identifiers#
Where required for billing, tax, compliance, identity, or account purposes, Ackaia may process a government or tax identifier supplied by you, such as a CPF, SSN, NIF, or equivalent identifier.
Unless a separate notice states otherwise, structural or mathematical validation does not mean Ackaia verified the identifier with a government agency or confirmed that it belongs to the person who supplied it.
6.5 Service and Usage Information#
We may process:
- Services and features accessed;
- page, screen, endpoint, or action events;
- request dates, timestamps, durations, and status codes;
- usage, quota, entitlement, and rate-limit records;
- feature preferences and configuration;
- API client, integration, and application identifiers;
- diagnostic, crash, reliability, and performance information;
- service region and routing information;
- records of administrative or organizational actions;
- non-content telemetry needed to operate and improve the Services.
6.6 Device, Network, and Website Information#
When you visit or use Ackaia websites and applications, we may process:
- IP address and approximate IP-derived region;
- browser, device type, and operating system;
- referring and destination pages;
- timestamps and navigation events;
- cookie, local-storage, session-storage, or similar identifiers;
- consent and preference records;
- security, bot-detection, and anti-fraud signals;
- performance and error telemetry.
6.7 Communications, Support, and Feedback#
If you communicate with Ackaia, we may process:
- your name, email address, and Account identifiers;
- the content and metadata of the communication;
- attachments, screenshots, logs, or files you choose to provide;
- support, complaint, appeal, and resolution history;
- survey responses and feedback;
- call or meeting information where notice and consent requirements are satisfied.
Do not send passwords, private keys, recovery phrases, illegal material, or unrelated sensitive information through ordinary support channels.
6.8 User Content#
Some Services allow you to submit, store, publish, transmit, or share User Content. Ackaia processes that content as necessary to provide the relevant Service and for the purposes described in applicable Product Terms.
Product architecture matters. For a supported zero-knowledge or end-to-end encrypted feature, Ackaia may store encrypted content without possessing the cryptographic material required to decrypt it. Other Services, support submissions, public pages, or communications may provide content to Ackaia in plaintext.
A general privacy statement does not override the specific technical boundaries described for a product.
6.9 Security, Trust, Safety, and Abuse Information#
We may process:
- authentication and authorization events;
- security alerts, audit logs, and incident records;
- fraud, spam, malware, phishing, or abuse indicators;
- public-link, endpoint, account, or integration risk signals;
- reports submitted by users, researchers, claimants, or authorities;
- vulnerability reports and remediation communications;
- hashes, fingerprints, or other technical indicators described in a Product Policy;
- enforcement, appeal, preservation, and legal-compliance records.
6.10 Information from Integrations and Third Parties#
We may receive information from:
- payment processors;
- identity, authentication, or verification providers you choose to use;
- organizational administrators;
- integrations you authorize;
- infrastructure, security, email, monitoring, or support providers;
- abuse reporters, copyright claimants, researchers, or law-enforcement authorities;
- public sources where collection and use are lawful;
- transaction, fraud-prevention, or sanctions-screening partners where applicable.
The categories received depend on the third party, your choices, and the purpose of the integration.
7. Sources of Personal Information#
Ackaia may collect personal information:
- directly from you;
- automatically from your device, browser, or use of a Service;
- from an organization or administrator that provides access to you;
- from Service Providers and integrations;
- from another user when they invite, share, or interact with you;
- from security researchers, abuse reporters, legal claimants, or authorities;
- from public sources where permitted by law;
- by deriving operational or security information from other data.
8. How We Use Personal Information#
8.1 Provide and Operate the Services#
We use information to:
- create and maintain Accounts;
- authenticate users and authorize actions;
- deliver product features and requested transactions;
- maintain settings, entitlements, quotas, and organization membership;
- route requests and operate infrastructure;
- provide support and resolve technical problems;
- enable integrations and exports you request.
8.2 Secure Accounts, Users, and Infrastructure#
We use information to:
- prevent unauthorized access and account takeover;
- detect suspicious activity, fraud, malware, abuse, and policy violations;
- enforce authentication, authorization, rate, and security controls;
- investigate and respond to incidents;
- protect cryptographic and key-management workflows;
- preserve service integrity and availability;
- maintain security and audit records.
8.3 Process Payments and Manage Entitlements#
We use information to:
- process transactions and renewals;
- issue invoices and receipts;
- apply plans, promotions, credits, and quotas;
- prevent payment fraud;
- manage cancellations, disputes, and refunds;
- meet accounting and tax obligations.
8.4 Communicate With You#
We use information to:
- send authentication, security, billing, and service notices;
- respond to support, privacy, legal, and security requests;
- provide policy and product updates;
- request feedback;
- send optional marketing communications where permitted.
8.5 Maintain, Analyze, and Improve#
We use operational information to:
- debug errors and investigate failures;
- measure reliability, performance, and capacity;
- understand feature adoption and usability;
- improve accessibility and localization;
- develop and evaluate Services;
- prevent outages and reduce operational risk.
Where feasible, Ackaia may aggregate, de-identify, minimize, or pseudonymize information used for these purposes.
8.6 Enforce Terms and Protect Rights#
We use information to:
- investigate suspected violations;
- prevent harm to users, victims, Ackaia, or third parties;
- enforce contracts, policies, and legal rights;
- manage complaints, appeals, and disputes;
- preserve evidence and establish, exercise, or defend legal claims.
8.7 Comply With Law#
We may use or disclose information to:
- comply with legal and regulatory obligations;
- respond to valid legal process;
- meet tax, accounting, consumer-protection, and data-protection requirements;
- report suspected child exploitation or other serious illegal activity where required or appropriate;
- respond to emergencies and credible threats of severe harm.
Our approach to legal process is described in the Ackaia Corporation Legal Request Response Policy.
9. Legal Bases for Processing#
Where law requires a legal basis, Ackaia may rely on:
9.1 Contract#
Processing necessary to enter into or perform a contract with you, such as creating an Account, authenticating you, providing a Service, processing a subscription, or responding to a support request.
9.2 Legitimate Interests#
Processing necessary for legitimate interests, including security, fraud and abuse prevention, service reliability, product improvement, customer support, business administration, legal claims, and protection of users, provided those interests are not overridden by applicable rights and freedoms.
9.3 Legal Obligation#
Processing necessary to comply with applicable law, legal process, tax, accounting, reporting, child-safety, consumer-protection, or data-protection obligations.
9.4 Consent#
Processing based on consent where required, including certain optional communications, cookies, integrations, or features. You may withdraw consent at any time, without affecting processing already lawfully performed.
9.5 Vital Interests and Public Interest#
Limited processing necessary to protect life, prevent serious harm, protect children or victims, respond to an emergency, or perform a task in the public interest where applicable law permits.
10. How We Disclose Personal Information#
Ackaia may disclose personal information in the following circumstances.
10.1 Service Providers#
We may engage providers for:
- cloud hosting and storage;
- network delivery and infrastructure;
- payment processing and billing;
- email and communications;
- security, logging, fraud prevention, and monitoring;
- customer support and ticketing;
- analytics and performance measurement;
- professional legal, accounting, insurance, and audit services;
- abuse prevention and child-safety functions;
- other operational services.
Providers are authorized to process information only for defined purposes and are subject to contractual, legal, and technical safeguards as appropriate to their role.
10.2 Organizational Customers and Administrators#
If an organization controls your Account or access, Ackaia may disclose relevant account, membership, administrative, security, entitlement, and usage information to authorized administrators, subject to the Service design and applicable agreements.
10.3 Integrations and Your Direction#
We disclose information when you direct us to do so, including when you:
- enable an integration;
- use a shared or public feature;
- invite another user;
- export information;
- request support involving a third party.
10.4 Security, Safety, and Legal Compliance#
We may disclose information to authorities, reporting bodies, child-protection organizations, security partners, affected organizations, or other appropriate recipients where reasonably necessary and legally permitted to:
- comply with law or valid legal process;
- prevent fraud, abuse, exploitation, malware, or severe harm;
- protect users, victims, Ackaia, or third parties;
- investigate or respond to a security incident;
- establish, exercise, or defend legal claims;
- enforce applicable agreements.
10.5 Business Transactions#
Information may be transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and appropriate confidentiality and privacy safeguards.
10.6 Public Information#
Information you intentionally publish through a public profile, repository, page, comment, link, or sharing feature may be visible to others and may be copied or redistributed outside Ackaia’s control.
11. Sale and Sharing of Personal Information#
Ackaia does not sell personal information for money.
Ackaia does not share personal information for cross-context behavioral advertising and does not use encrypted CipherDrive™ file contents for advertising.
If Ackaia introduces a practice treated as a “sale” or “sharing” under applicable law, we will update this Policy and provide required notices and opt-out mechanisms before or when the practice begins.
Disclosures to Service Providers, disclosures you direct, and disclosures for security or legal purposes are not treated as sales where applicable law excludes them from that definition.
12. Cookies and Similar Technologies#
Ackaia may use cookies, local storage, session storage, IndexedDB, and similar technologies for:
- authentication and session management;
- account and security controls;
- user preferences and accessibility;
- fraud and abuse prevention;
- performance, diagnostics, and basic usage measurement;
- consent and communication preferences;
- product-specific local cryptographic state as separately disclosed.
Where required, Ackaia will request consent for non-essential technologies. You can use browser or device settings to control these technologies, but disabling essential storage may prevent a Service from working.
13. International Data Transfers#
Ackaia is based in the United States and may use infrastructure and Service Providers in multiple countries. Personal information may therefore be processed outside the country where you live.
Where required, Ackaia uses recognized transfer mechanisms and safeguards, which may include:
- adequacy decisions;
- standard contractual clauses;
- contractual and organizational protections;
- transfer risk assessments;
- another mechanism permitted by applicable law.
Product-specific region placement or storage architecture may be described separately and does not necessarily mean all account, security, or support information remains in that region.
14. Data Retention#
Ackaia retains personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, protect security, meet legal obligations, resolve disputes, and enforce agreements.
Retention depends on factors such as:
- the Service and type of information;
- whether the Account or subscription remains active;
- user settings and deletion actions;
- security, fraud, abuse, and incident requirements;
- tax, accounting, contractual, and legal obligations;
- backup and disaster-recovery cycles;
- litigation holds and valid preservation requests;
- whether information can be safely aggregated or de-identified.
Deletion from active systems may not immediately remove information from encrypted backups, immutable security records, or legally required archives. Such information remains protected and is removed or overwritten according to applicable lifecycle processes.
15. Security#
Ackaia maintains technical, administrative, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.
Safeguards may include:
- access control and least privilege;
- multifactor authentication for sensitive access;
- encryption in transit and at rest where appropriate;
- secure development and change management;
- logging, monitoring, and incident response;
- vulnerability management and responsible disclosure;
- backups and continuity controls;
- personnel and provider safeguards;
- data minimization and retention controls.
Details are provided in the Ackaia Corporation Information Security Policy. No security program eliminates all risk, and you are responsible for protecting your credentials, devices, sessions, and recovery information.
16. Automated Systems#
Ackaia may use automated systems to:
- authenticate and authorize actions;
- detect account compromise, fraud, abuse, malware, or suspicious activity;
- enforce rate, quota, payment, and security controls;
- route support or operational events;
- generate product-specific risk signals described in applicable Product Policies.
Automated systems may block or restrict an action or Account. Where required by law and reasonably feasible, Ackaia provides a way to request review or appeal a significant automated enforcement action.
Ackaia does not intend to make solely automated decisions that produce legal or similarly significant effects about individuals unless the processing is permitted by law and appropriate notice and safeguards are provided.
17. Your Privacy Rights#
Depending on where you live and the context, you may have the right to:
- know whether Ackaia processes your personal information;
- access or receive a copy of personal information;
- correct inaccurate or incomplete information;
- delete information;
- restrict or object to processing;
- withdraw consent;
- receive portable information in a structured format;
- opt out of sale, sharing, targeted advertising, or certain profiling;
- limit certain uses of sensitive personal information;
- appeal a denied privacy request;
- lodge a complaint with a data-protection authority;
- receive equal service and not be discriminated against for exercising a right.
These rights are not absolute. Exceptions may apply for security, fraud prevention, legal obligations, freedom of expression, protection of others, contractual necessity, or legal claims.
18. Rights in the European Economic Area and European Union#
Where the General Data Protection Regulation applies, you may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority.
You may object to processing based on legitimate interests. Ackaia will stop the affected processing unless it demonstrates compelling legitimate grounds or the processing is needed for legal claims.
Where processing is based on consent, withdrawal does not affect the lawfulness of processing performed before withdrawal.
19. Rights in the United Kingdom#
Where the United Kingdom General Data Protection Regulation and Data Protection Act 2018 apply, you may have rights to be informed, access, rectification, erasure, restriction, portability, objection, and safeguards relating to automated decision-making.
You may complain to the UK Information Commissioner’s Office or another competent authority. Ackaia encourages you to contact privacy@ackaia.com first so we can try to resolve the concern.
20. Rights in Brazil#
Where the Lei Geral de Proteção de Dados Pessoais (“LGPD”) applies, you may have rights to:
- confirm processing;
- access personal data;
- correct incomplete, inaccurate, or outdated data;
- request anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data;
- request portability where regulated and applicable;
- obtain information about recipients and consequences of refusing consent;
- withdraw consent;
- request review of certain automated decisions;
- petition the Autoridade Nacional de Proteção de Dados or consumer-protection bodies.
For LGPD purposes, Ackaia may act as controlador or operador depending on the processing context.
21. Rights in California#
Where the California Consumer Privacy Act, as amended, applies, California residents may have rights to:
- know the categories and specific pieces of personal information collected;
- know the categories of sources, purposes, and recipients;
- request deletion;
- request correction;
- opt out of sale or sharing;
- limit certain uses or disclosures of sensitive personal information;
- receive non-discriminatory treatment for exercising a right.
Ackaia does not sell personal information or share it for cross-context behavioral advertising as described in Section 11.
You may use an authorized agent where permitted by law. Ackaia may verify your identity and the agent’s authority before completing a request.
22. Exercising Your Rights#
To submit a privacy request, contact privacy@ackaia.com or use privacy controls made available in the relevant Service.
Please identify:
- the right you wish to exercise;
- the relevant Ackaia Service;
- the Account or email involved;
- your jurisdiction, if relevant;
- sufficient detail for us to understand the request.
Ackaia may verify your identity and authority using information reasonably related to the request. We will not ask for more information than necessary. For sensitive or high-risk requests, additional verification may be required to protect the Account and other people.
If Ackaia cannot fulfill a request, we will explain the reason where required by law and describe any available appeal process.
23. Organizational Accounts#
If your Account is provided or controlled by an organization, the organization may be responsible for responding to requests concerning information it controls.
Ackaia may direct your request to that organization or assist it as a processor. Requests concerning Ackaia-controlled Account, billing, security, or corporate information may remain Ackaia’s responsibility.
24. Children’s Privacy#
The Services are not directed to children under 13, and Ackaia does not knowingly collect personal information from a child under 13 without authorization required by law.
Where local law establishes a higher age for independent consent, a parent or legal guardian may need to authorize processing. If you believe a child provided information contrary to this Policy, contact privacy@ackaia.com.
Ackaia may process limited information to assess age or eligibility where necessary and lawful. We seek to minimize that information and do not use it for unrelated advertising.
25. Data Breaches and Incident Notification#
Ackaia maintains incident-response processes designed to identify, contain, investigate, remediate, and learn from security incidents.
If an incident involving personal information triggers a legal notification obligation, Ackaia will notify affected individuals, customers, regulators, or other parties within the time and in the manner required by applicable law.
Notification may be delayed where authorized or required by law enforcement, necessary to avoid increasing harm, or otherwise permitted by applicable law.
26. De-Identified and Aggregated Information#
Ackaia may create and use aggregated or de-identified information for security, reliability, analytics, research, capacity planning, and product improvement.
Where information is maintained as de-identified, Ackaia will not attempt to re-identify it except where permitted to test the effectiveness of de-identification or required by law.
27. Do Not Track and Global Privacy Control#
Because there is no uniform industry standard for browser “Do Not Track” signals, Ackaia may not respond to those signals in a consistent manner.
Where applicable law requires recognition of a valid opt-out preference signal, such as Global Privacy Control, Ackaia will process the signal for the browser or device from which it is received. Because Ackaia does not currently sell personal information or share it for cross-context behavioral advertising, such a signal may not change current practices.
28. Changes to This Policy#
Ackaia may update this Policy to reflect changes in law, Services, technology, security, operations, or data practices.
The revision history and effective date identify the current version. For material changes, Ackaia will provide notice where reasonably required through email, an Account notice, the affected Service, or the Legal Repository.
If a change requires consent under applicable law, Ackaia will request consent before applying the change to the affected processing.
29. Complaints#
If you have a privacy concern, contact privacy@ackaia.com. We will review and respond within the period required by applicable law.
You may also submit a complaint to the competent privacy, data-protection, consumer-protection, or regulatory authority in your jurisdiction.
30. Contact#
Ackaia Corp. Privacy: privacy@ackaia.com
Legal: legal@ackaia.com
Security: security@ackaia.com
Abuse: abuse@ackaia.com
Website: www.ackaia.com
Address: 1233 York Avenue, Apt. 301, New York, NY 10065, United States of America
---
End of General Privacy Policy
