Privacy
PrivatArkiv stores account data and technical metadata in SQL. Private archive content is stored only as ciphertext and decrypted on the user device.
What this covers
This notice covers PrivatArkiv: the website, the installable app and the services that belong to them. It explains which information is processed, why, for how long, and what you can require.
It is written to be checked. Where something is a technical limit, it is stated as a limit and not as a promise.
Data controller
LexiCo AS is the controller for the information described here, and owns the technical proof origin in the Trust Standard Protocol.
Registration number: 937 155 344. Business address: Trolltorødveien 18, 3140 Nøtterøy.
Where a detail says it is not published yet, it has not been filled in for this installation. It has to be in place before the service is offered beyond this machine.
What we cannot read
Private archive content is zero-knowledge. Images, documents, descriptions, categories, prices, relations and travel details are encrypted on your own device before anything leaves it.
The server receives encrypted content, a hash and the metadata it needs to store and synchronise. The key is wrapped with your archive passphrase and never leaves your device in the clear.
That means we cannot read your content, cannot recover it for you if you lose the passphrase, and cannot hand it to anyone else in a readable form either. Image analysis happens on the device. Cloud processing is off by default and needs your explicit consent.
What we store about you
We store what running an account requires: your email address, your password in hashed form, your account and memberships, your chosen language, currency and mode, and which archives exist with which access.
We also store technical metadata about encrypted content: size, hash, revision number and time. That metadata says nothing about what the content is.
The basis is the agreement with you in order to provide the service, and legitimate interest for security and audit. Consent is used where it is named explicitly, such as any cloud processing.
We send email to confirm your address and to help you set a new password. Delivery goes through Resend, which is a processor for that purpose and receives your address and the message.
The confirmation link lasts 24 hours, the new-password link one hour. Both work once. We never confirm whether an address exists here, so the pages cannot be used to find out who has an account.
The delivery log shows status and any error. It never shows the message, the link or the token.
Proofs and timestamps
When you seal content, a hash is sent to a timestamping authority. The hash cannot be turned back into the content, and your content is not sent.
The proof documents that particular bytes existed at a point in time and that their integrity can be checked. It does not document truth, physical existence, identity, ownership or value.
Proofs are append-only. They cannot be changed or deleted, not even by us, because a proof that can be changed is not a proof.
Cookies and local storage
We use only the cookies the service needs to work: one for signing in, and a few that remember language, currency, mode and which account you are working in. We use no cookies for tracking, marketing or analytics.
The cookie that points at the active account is only a hint. Access is checked on the server on every request.
Your device also holds a local, decrypted index so the archive can be searched offline. It is cleared when you lock the archive or sign out.
Your rights
You can see, correct, export and erase the information about you. Export and erasure are under Privacy and data when you are signed in, and need no request to us.
The export holds the platform data the server has: account, membership, preferences, archive and sharing metadata, proof metadata and the audit events you triggered. It holds no images, descriptions, prices or keys, because the server cannot read them. The readable archive report is made on your own device.
If you believe the processing is unlawful, you can complain to the Norwegian Data Protection Authority, Datatilsynet.
Retention and erasure
Account data is kept for as long as the account exists. If you erase the account, the sign-in is removed, memberships are marked removed, shares are revoked and your key envelopes are removed.
Erasure is cryptographic. When no active member is left in an account, the recovery envelope goes too. The encrypted content can then not be opened again by anyone, not even by us.
Proof, sharing and membership events are append-only and are kept without naming you, because they document what happened. Other events about you are deleted. That is not the same as every row being physically removed, and the erasure flow says so.
Questions
Questions about privacy go to privat@lexico.no.
Data protection officer: not published yet.
Where a detail says it is not published yet, it has not been filled in for this installation. Both a point of contact and an assessment of whether a data protection officer is required must be in place before the service is offered externally.