Entropa_

Privacy Policy

Last updated 2026-08-27

Entropa is data-minimal by design: we never receive, see, or store the underlying data you're attesting to — only a hash, a signature, and a timestamp. The main thing to understand isn't "what do we do with your data" — it's "everything you submit lives in your own permanent, readable log while your account is active." See Section 3.

1. Information we collect

From you, directly: name/company and email at signup or onboarding; billing information (collected and stored by Stripe, Inc. — we never see raw card data); any message sent via a contact or support form.

From your submissions: the payload you submit (typically a hash), an optional label, your authenticated partner identity, and the real timestamp of submission.

Automatically: standard Cloud Run web server logs (IP, timestamp, request path), retained per Google Cloud's default retention, used only operationally.

We do not receive the raw data behind your hash — that's the entire design point.

2. What we don't collect

No cookies or tracking pixels. No passwords (API-key based access). No payment card data. No underlying business data behind a submitted hash — we structurally cannot see it.

3. How your submissions are stored, and what "permanent" means

Each customer has their own append-only Merkle log, structurally separate from every other customer's. Read access to your own log is unauthenticated by design — a transparency-log receipt has to be independently verifiable by anyone who has it, without logging in to Entropa's servers. This is not the same as being publicly indexed: the Scryon explorer is a static demo using synthetic data, not a live view of any real customer's log.

While your account is active, there is no way to selectively delete an individual record. If you cancel, your entire log and account record are deleted in full, immediately — all-or-nothing, and it cannot be undone.

Practical implication: a properly-computed hash reveals nothing about your original data, but whatever you put in payload or label is genuinely readable by anyone who has your account identifier, for as long as your account remains active.

4. How we use what we collect

To operate the Service, secure it against abuse, communicate with you about your account or material changes, and comply with legal obligations.

5. How we share information

We do not sell your personal data. We share information only with Stripe (billing), Google Cloud Platform (our infrastructure provider), and law enforcement/regulators if required by valid legal process.

6. International data transfers

Our infrastructure runs on Google Cloud Platform, which may process data in multiple regions as part of its standard operation, under Google's own compliance safeguards.

7. Data retention

Log data is retained permanently while your account is active. Canceling deletes your entire log and account record (name, email, API key, billing linkage) in full, immediately. Download your full history from your dashboard first — we cannot recover it afterward. Server logs follow Google Cloud's default retention.

8. Your rights

You may have rights to access, correct, port, or request deletion of your personal data, and to object to certain processing, depending on your jurisdiction (including GDPR, UK GDPR, or CCPA/CPRA rights where applicable). Email aimozart@entropa.space, or cancel your account directly from your dashboard for immediate deletion.

9. Security

Submissions are transmitted over HTTPS/TLS. Write access is gated by per-partner API keys. The log itself is cryptographically signed (ML-DSA / NIST FIPS-204), so tampering is detectable. In the event of a breach affecting your personal information, we will notify you without undue delay.

10. Children's privacy

Entropa is a B2B/developer infrastructure product, not directed at children, and we do not knowingly collect data from anyone under 18.

11. Changes to this policy

Material changes will be communicated to active partners directly, with reasonable advance notice where practical.

12. Contact

Questions, or to exercise your data rights: aimozart@entropa.space, or via entropa.space/hire.