Legal

Privacy Policy

Enclave Technologies Inc.Effective: July 1, 2026Version 1.0

The short version: Enclave Auth is built for zero-knowledge authentication. Passwords, Account Manager Keys (AMK), and identity secret keys stay on the user's device. We store encrypted wraps and public metadata needed to operate login, sessions, and developer integrations — not plaintext credentials.

01

Overview

Enclave Technologies Inc. ("Enclave," "we," "us," or "our") operates Enclave Auth — drop-in post-quantum authentication available at auth.enclave.talk, through our web application, developer console, API, SDK, and related services (the "Service").

This Privacy Policy explains what information we collect, why we collect it, how we use it, and your rights regarding it. Enclave Auth is designed so that long-term identity secrets and account unlock material remain on the user's device. Our servers verify cryptographic proofs and mint sessions without routine access to passwords, AMK, or identity secret key seeds.

By using the Service, you agree to the collection and use of information in accordance with this policy.

02

Who This Policy Covers

This policy applies to end users who create an Enclave Auth account or sign in through an application that integrates Enclave Auth; and to developers, organizations, and businesses that configure applications, organizations, or billing in the Enclave Auth developer console or integrate through our SDK or API.

If you sign in to a third-party product that embeds Enclave Auth, that product operator may also process information about you under its own privacy policy. Enclave Auth provides the authentication layer; the integrating application controls its user experience and may collect additional data outside this Service.

03

Information We Collect

Account and profile information

  • Email address and account identifiers
  • Organization, workspace, application, and branch names configured in the developer console
  • Billing contact details for paid plans

Authentication and session metadata

  • Identity public keys associated with your account
  • Encrypted AMK wraps, PIN verification hashes, and related unlock blobs supplied by the client
  • Login challenge and verification event metadata (timestamps, success or failure, rate-limit counters)
  • Session token identifiers, issuance times, and revocation status
  • Optional device or client labels you provide for support

Developer integration data

  • Application and OIDC client configuration
  • Redirect URIs, branding settings, and published JWKS metadata
  • API keys, webhook URLs, and integration logs where enabled
  • End-user identifiers you supply when initiating auth flows through your application

Billing information

We use Stripe to process subscription and usage-based billing. We store Stripe customer and payment method reference IDs. Full payment card details are held by Stripe and governed by Stripe's Privacy Policy. We do not store your card number.

Technical information

  • IP address and request logs for security, abuse prevention, and infrastructure operations
  • Device and browser information necessary to operate the authentication application

04

What We Do Not Access

Enclave Auth does not store your password, AMK, identity secret key seed, BIP39 recovery phrase, or PIN in plaintext. The client derives keys locally and uploads only encrypted wraps and public cryptographic material required for verification.

We also do not:

  • Sell personal information to data brokers or advertisers
  • Use authentication data for behavioral advertising or cross-platform tracking
  • Decrypt identity secret keys or AMK on our servers under normal operation
  • Require integrating applications to receive more identity data than the configured auth flow permits

05

How We Use Information

We use the information we collect to:

  • Create and manage Enclave Auth accounts and developer workspaces
  • Issue login challenges, verify cryptographic responses, and mint sessions
  • Operate OIDC flows, application configuration, and SDK integrations
  • Process billing and enforce plan limits
  • Prevent fraud, abuse, and unauthorized access
  • Respond to support requests and legal obligations
  • Improve the reliability and security of the Service

06

How We Share Information

We do not sell personal information. We share information only in the following limited circumstances:

With integrating applications

When you authenticate through an application configured to use Enclave Auth, we share session and identity claims according to that application's OIDC or SDK configuration and your consent to sign in.

Service providers

  • Supabase — database, authentication infrastructure, and backend services
  • Stripe — payment processing and billing
  • Vercel and Cloudflare — hosting, CDN, and security
  • Email delivery providers — verification and account notices where enabled

Legal requirements

We may disclose information when required by law, valid legal process, or to protect the rights, property, or safety of Enclave Auth, our users, or the public. Because we do not hold AMK, passwords, or identity secret key seeds, we may be unable to produce credential material we never stored even when legally compelled.

Business transfers

In the event of a merger, acquisition, or sale of substantially all of our assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy where required by law.

07

Authentication Architecture

Zero-knowledge by design. One post-quantum identity keypair per account is protected by an Account Manager Key (AMK) derived on the client. Servers store encrypted wraps and verify ML-DSA signatures during login — not plaintext secrets.

  • Registration and unlock cryptography occur in the client SDK or application
  • Optional PIN recovery uses independent verify and wrap derivations; the server may verify PIN guesses but cannot reconstruct wrap keys
  • Sessions are bearer tokens validated cryptographically without exposing long-term secrets
  • Integrating applications receive OIDC claims or session artifacts according to configured scopes

08

Data Retention

We retain account, session, integration, and billing records for as long as your account is active or as needed to provide the Service.

If you delete your account or request erasure:

  • Profile and account data is deleted in accordance with our account erasure process
  • Active sessions are revoked and encrypted wraps are removed according to applicable retention rules
  • Security and billing logs may be retained for a limited period where required by law or for fraud prevention
  • Stripe retains payment records under its own policies and legal obligations

09

Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, contact us at privacy@enclave.talk.

10

Your Rights and Choices

Depending on where you live, you may have the following rights regarding your personal information:

  • Access — request a copy of the personal data we hold about you
  • Correction — update inaccurate or incomplete information
  • Deletion — request deletion of your account and personal data
  • Portability — receive your data in a structured, machine-readable format
  • Objection or restriction — object to or restrict certain processing
  • Session revocation — sign out devices and invalidate active sessions through account settings where available

To exercise these rights, contact us at privacy@enclave.talk. We will respond within 30 days and may require identity verification before processing your request.

11

GDPR and CCPA

European users (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation. Our legal bases for processing include contract performance, legitimate interests (security and fraud prevention), legal obligation, and consent where applicable.

You have the right to lodge a complaint with your local data protection authority. Data is primarily processed in the United States.

California residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect and disclose, to request deletion, and to opt out of any sale of personal information. We do not sell personal information and do not discriminate against you for exercising your privacy rights.

To submit a CCPA request, contact privacy@enclave.talk.

12

Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page with an updated effective date and provide additional notice where required by law.

Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.

13

Contact

Privacy questions, data requests, and complaints should be directed to:

  • Enclave Technologies Inc.
  • Hattiesburg, MS 39401
  • Privacy: privacy@enclave.talk
  • Legal: legal@enclave.talk
  • Support: support@enclave.talk
  • Website: https://auth.enclave.talk