Privacy Policy
What stays on your devices and what our cloud service handles.
Policy version: 2026-10-02
Effective Date: TBD
DRAFT
1. Our service and your content
Aperture Robotics, LLC operates Spacewave. Your Space content is encrypted on your devices before it reaches cloud storage or travels between devices. We do not hold the keys needed to read it. Local content stays under your control unless you choose to share or back it up. The Spacewave client is open source and sends us no tracking or telemetry. Local diagnostic views stay on your device.
Our cloud services handle operational information to provide the service, secure accounts, maintain service quality, and calculate charges. Account and service communications, support requests, copyright notices, and payment records are separate from encrypted Space content and can contain readable personal information. This policy explains those flows. The current service has no Aperture-operated AI features and does not use Space content to train models.
2. Information we handle
Account and authentication records include email addresses, public keys and credential records, optional authentication-provider identifiers, account and session identifiers, device information, authorization relationships, and activity timestamps such as last connection. For email/password authentication, password processing happens on your device; we receive the public-key material needed for authentication, not your password or Space decryption keys.
Billing records include billing-account and customer identifiers, accepted subscription terms and consent, selected spending limits, subscription and invoice status, transaction references, storage totals, operation counts, reservations, and billing-period dates. Stripe processes payment credentials. We do not store full payment-card details, but receive the billing information and payment outcomes needed to administer service and resolve charges.
Connection and security information can include IP addresses, user agents, request and connection timestamps, error information, and security events. Cloud service counters measure aggregate requests, operations, latency, and service success. Necessary billing usage remains attributable to its billing account. We do not use these records for advertising attribution, personal browsing journeys, engagement profiling, or data brokerage.
Service-email records include recipient and sender addresses, subject, queue and provider-acceptance times, retry status, and bounded failure information. Message bodies remain while delivery is pending and are removed when delivery is accepted by the provider or permanently fails. Email content can include verification links, billing terms, account warnings, and copyright-notice details. Support and legal correspondence contains the information you or another correspondent supplies.
We do not collect keystrokes, in-app browsing histories, advertising identifiers, precise location, or interaction telemetry from the Spacewave client. Necessary account, device, and session identifiers are described above. Cloudflare Turnstile can process browser and interaction signals for bot protection; that provider's processing is distinct from Spacewave client analytics.
3. Purposes and roles
We use operational information to authenticate users, apply permissions, store and transmit encrypted content as instructed, calculate and collect charges, send service communications, diagnose faults, prevent abuse, respond to support requests, and meet legal obligations. We do not sell personal information, share it for cross-context behavioral advertising, or send it to data brokers. We do not use advertising trackers or tracking pixels. Essential cookies and local storage support authentication, settings, and service operation.
Aperture acts as controller for account, billing, security, support, and legal operations. Where applicable data-protection law governs business customer content that we process on the customer's instructions, the customer determines its purposes and Aperture acts as processor under the Business Data Processing Addendum attached to our Terms of Service. Encryption does not remove the need to assess those roles.
Where GDPR or UK GDPR applies to our controller activities, our legal bases are performance of the requested service, compliance with legal obligations, and legitimate interests in security, abuse prevention, and reliable operations, subject to the required balancing of individual rights. We seek consent where law requires it and explain the particular purpose. We do not make decisions based solely on automated profiling that produce legal or similarly significant effects.
4. Recipients
Cloudflare operates the cloud service, including encrypted storage, request processing, databases, connection infrastructure, and security controls. It receives the encrypted content and operational information needed for those functions. Cloudflare Turnstile supplies bot protection. See Cloudflare's privacy policy and Turnstile's privacy policy.
The default peer connection configuration contacts Google’s public STUN service to discover a device’s public network address. That service receives connection metadata such as the source IP address and port, not Space content or its decryption keys. See Google’s privacy policy. Configured network and relay services may receive the connection metadata needed to establish a link.
Stripe processes payments, subscriptions, invoices, and usage charges and receives necessary account, billing, and transaction information. See Stripe's privacy policy. Resend delivers transactional email and receives recipient addresses and service-message content. See Resend's privacy policy.
If you choose an external sign-in provider, that provider receives the authentication request and supplies the identity information authorized by the sign-in flow under its own privacy terms. Collaborators you authorize receive the content and permissions you share with them. Authorized devices can communicate directly or through connection infrastructure; transmitted Space content remains encrypted.
Copyright complainants and subscribers receive relevant notice or counter-notice details as required by the DMCA process, including contact information and statements needed to identify and resolve the claim. Do not include unrelated sensitive information in a notice. We may disclose information for valid legal process, to protect people or the service where law permits, or as required by law. We notify affected users when legally permitted. A business transfer can involve necessary records, subject to applicable law and continued protection of the information.
5. Security
We use encryption for Space content on devices and during transmission, access controls, authentication, and infrastructure security measures. Authorized infrastructure personnel may process service records under confidentiality and access restrictions; Space decryption keys are not supplied to them. Encryption does not prevent loss of credentials, compromise of your device, or every operational failure. Keep recovery information and independent backups secure.
If a personal-data breach requires notification, we notify affected people and authorities within the applicable legal timeframes. For business content processed on a customer's behalf, we notify that customer without undue delay after becoming aware of a personal-data breach and assist its response.
6. Retention and deletion
Account and operational records are retained while needed to provide the account, administer funding and permissions, maintain security, and resolve outstanding obligations. Ending a subscription does not itself close the account. After paid coverage ends, the affected cloud resources have thirty days of read-only recovery and export, unless a separate account-deletion request or lawful restriction applies. At the end of recovery, access ends and cleanup is queued.
Confirmed voluntary account deletion starts a twenty-four-hour read-only hold with an undo option. After the hold, primary account access ends and queued cleanup removes affected data. Physical deletion is asynchronous and retries failures. Separately funded resources, copies held by collaborators, and local device copies have their own authority and lifetime; deleting your account does not promise to erase those copies.
Subscription-consent and material-offer-change evidence is retained with restricted access for at least three years from the recorded agreement or change, or one year after termination, whichever is longer, and is then expired by the billing lifecycle unless a lawful preservation requirement applies. Transaction, tax, dispute, and legal records remain for the applicable statutory period or while a specific unresolved claim or legal hold requires them. Such retention does not permit continued ordinary use of a deleted account or indefinite retention for unspecified future purposes.
The service-email log keeps recipient, sender, subject, status, and delivery-attempt metadata for ninety days after provider acceptance or permanent failure. The delivery queue deletes the body at that transition. Copies delivered to recipients, provider records retained under the provider's applicable obligations, and separately retained support or legal case records have their own purposes and retention requirements.
Security and diagnostic information is retained only as needed for investigation, service operation, or a legal obligation. Encrypted caches and temporary infrastructure copies are removed through cleanup or ordinary expiry. We do not promise an unverified fixed backup-erasure interval. Records retained solely for restoration or preservation remain restricted and are removed when their applicable purpose or retention obligation ends. Contact [email protected] for the retention criteria relevant to a particular request.
7. Access, correction, and other rights
Contact [email protected] to request access, correction, deletion, or an explanation of how we handle your personal information. You can export content and manage your account through the service while you have access. We reasonably verify identity and authority, use the request information for handling the request, and respond within the period required by applicable law. We explain a refusal or lawful exception and available review or complaint options. We do not discriminate against people for exercising privacy rights.
Where California privacy law applies, rights can include knowing the categories and specific information collected or disclosed, correction, deletion, and limits on certain sensitive-information use. We do not sell or share information for cross-context behavioral advertising. Our categories include identifiers, account and commercial records, device and network information, and correspondence, from you, service operation, selected providers, and legal correspondents for the purposes and recipients described above. An authorized agent may submit a request with appropriate proof of authority.
Where GDPR or UK GDPR applies, rights can also include portability, restriction, objection to legitimate-interest processing, withdrawal of consent for consent-based processing, and complaint to a competent supervisory authority. Withdrawal does not invalidate processing already lawfully performed. Where we process business content for a customer, we refer the request to that customer and assist it as required.
8. International processing
9. Children and changes
Spacewave is not directed to children under sixteen. If we learn that an account belongs to a child under sixteen, we take steps to remove the account and personal information subject to lawful retention obligations. Contact [email protected] with a concern.
We give thirty days' advance email notice of ordinary material policy changes. A narrowly necessary urgent legal or security change may take effect sooner with notice as soon as reasonably possible. We obtain new consent where required. A privacy-policy update alone does not authorize a new incompatible processing purpose.