Legal
Privacy Policy
The short version: Enclave Auth is built for zero-knowledge authentication. Passwords, Account Manager Keys (AMK), and identity secret keys stay on the user's device. We store encrypted wraps and public metadata needed to operate login, sessions, and developer integrations — not plaintext credentials.
01
Overview
Enclave Technologies Inc. ("Enclave," "we," "us," or "our") operates Enclave Auth — drop-in post-quantum authentication available at auth.enclave.talk, through our web application, developer console, API, SDK, and related services (the "Service").
This Privacy Policy explains what information we collect, why we collect it, how we use it, and your rights regarding it. Enclave Auth is designed so that long-term identity secrets and account unlock material remain on the user's device. Our servers verify cryptographic proofs and mint sessions without routine access to passwords, AMK, or identity secret key seeds.
By using the Service, you agree to the collection and use of information in accordance with this policy.
02
Who This Policy Covers
This policy applies to end users who create an Enclave Auth account or sign in through an application that integrates Enclave Auth; and to developers, organizations, and businesses that configure applications, organizations, or billing in the Enclave Auth developer console or integrate through our SDK or API.
If you sign in to a third-party product that embeds Enclave Auth, that product operator may also process information about you under its own privacy policy. Enclave Auth provides the authentication layer; the integrating application controls its user experience and may collect additional data outside this Service.
03
Information We Collect
Account and profile information
- Email address and account identifiers
- Organization, workspace, application, and branch names configured in the developer console
- Billing contact details for paid plans
Authentication and session metadata
- Identity public keys associated with your account
- Encrypted AMK wraps, PIN verification hashes, and related unlock blobs supplied by the client
- Login challenge and verification event metadata (timestamps, success or failure, rate-limit counters)
- Session token identifiers, issuance times, and revocation status
- Optional device or client labels you provide for support
Developer integration data
- Application and OIDC client configuration
- Redirect URIs, branding settings, and published JWKS metadata
- API keys, webhook URLs, and integration logs where enabled
- End-user identifiers you supply when initiating auth flows through your application
Billing information
We use Stripe to process subscription and usage-based billing. We store Stripe customer and payment method reference IDs. Full payment card details are held by Stripe and governed by Stripe's Privacy Policy. We do not store your card number.
Technical information
- IP address and request logs for security, abuse prevention, and infrastructure operations
- Device and browser information necessary to operate the authentication application
04
What We Do Not Access
Enclave Auth does not store your password, AMK, identity secret key seed, BIP39 recovery phrase, or PIN in plaintext. The client derives keys locally and uploads only encrypted wraps and public cryptographic material required for verification.
We also do not:
- Sell personal information to data brokers or advertisers
- Use authentication data for behavioral advertising or cross-platform tracking
- Decrypt identity secret keys or AMK on our servers under normal operation
- Require integrating applications to receive more identity data than the configured auth flow permits
05
How We Use Information
We use the information we collect to:
- Create and manage Enclave Auth accounts and developer workspaces
- Issue login challenges, verify cryptographic responses, and mint sessions
- Operate OIDC flows, application configuration, and SDK integrations
- Process billing and enforce plan limits
- Prevent fraud, abuse, and unauthorized access
- Respond to support requests and legal obligations
- Improve the reliability and security of the Service
07
Authentication Architecture
Zero-knowledge by design. One post-quantum identity keypair per account is protected by an Account Manager Key (AMK) derived on the client. Servers store encrypted wraps and verify ML-DSA signatures during login — not plaintext secrets.
- Registration and unlock cryptography occur in the client SDK or application
- Optional PIN recovery uses independent verify and wrap derivations; the server may verify PIN guesses but cannot reconstruct wrap keys
- Sessions are bearer tokens validated cryptographically without exposing long-term secrets
- Integrating applications receive OIDC claims or session artifacts according to configured scopes
08
Data Retention
We retain account, session, integration, and billing records for as long as your account is active or as needed to provide the Service.
If you delete your account or request erasure:
- Profile and account data is deleted in accordance with our account erasure process
- Active sessions are revoked and encrypted wraps are removed according to applicable retention rules
- Security and billing logs may be retained for a limited period where required by law or for fraud prevention
- Stripe retains payment records under its own policies and legal obligations
09
Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, contact us at privacy@enclave.talk.
10
Your Rights and Choices
Depending on where you live, you may have the following rights regarding your personal information:
- Access — request a copy of the personal data we hold about you
- Correction — update inaccurate or incomplete information
- Deletion — request deletion of your account and personal data
- Portability — receive your data in a structured, machine-readable format
- Objection or restriction — object to or restrict certain processing
- Session revocation — sign out devices and invalidate active sessions through account settings where available
To exercise these rights, contact us at privacy@enclave.talk. We will respond within 30 days and may require identity verification before processing your request.
11
GDPR and CCPA
European users (GDPR)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation. Our legal bases for processing include contract performance, legitimate interests (security and fraud prevention), legal obligation, and consent where applicable.
You have the right to lodge a complaint with your local data protection authority. Data is primarily processed in the United States.
California residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect and disclose, to request deletion, and to opt out of any sale of personal information. We do not sell personal information and do not discriminate against you for exercising your privacy rights.
To submit a CCPA request, contact privacy@enclave.talk.
12
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page with an updated effective date and provide additional notice where required by law.
Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.
13
Contact
Privacy questions, data requests, and complaints should be directed to:
- Enclave Technologies Inc.
- Hattiesburg, MS 39401
- Privacy: privacy@enclave.talk
- Legal: legal@enclave.talk
- Support: support@enclave.talk
- Website: https://auth.enclave.talk