AnoniCloud

Privacy policy




<ul> <li> Perché AnoniCloud </li> <li> Filosofia </li> <li> Download </li> <li> Aiutaci </li> <li> FAQ </li> <li> Blog </li> <li> Ita Deutsch English Italiano Português Română </li> </ul> Privacy policy and technical details <p>Rev. 12 June 2020</p> Purpose of the service <p>AnoniCloud is a service aiming to store user's document in the best confidential way, using zero-knowledge encryption, state of art encryption algorithm avoiding decryption of data also with quantum computers.</p> Service stage <p>AnoniCloud is <em>actually</em> in public beta stage. Before going on production stage, all security assessment on machines and protocol has to be performed by AnoniCloud team and / or its consultants.<br> User's are kindly invited to use the service, provide a feedback on their experience and don't store any sensitive data.</p> <p> <em>At this stage we decline any responsibility for sensitive data disclosure.</em> </p> Service philosophy <p>AnoniCloud is a software conceived sittings on three <em>technical</em> pillars:</p> <ul> <li>1. Anonymity</li> <ul> <li>The user is not required to provide any personal data, like email, telephone number, real name and surname, to access the service;</li> <li>user's identity is determined by the system by means of a "username" that is a string of ASCII printable characters, maximum 255 character long and a "password" a string of ASCII printable characters, maximum 255 character long;</li> <li>Over the "username" a user's UUID is generated and used internally by the server system to link user's account and user's data. the "username" is the only data stored as-is into our system;</li> <li>The "password" is never sent over the net: Before leaving the user's device, the password, by means of SRP-6a (Secure Remote Password protocol), is used to generate two data (a SALT and a VERIFIER) both stored on the server. by means of them, is actually impossible to revert the original password.</li> </ul> <li>2. Inviolability</li> <ul> <li>User's documents are divided in chunks and encrypted by means of a document encryption key before leaving the user's device. the encryption algorithm used is AES-256-CBC. to perform encryption and decryption operation the password is temporarily stored on user's device and is used to encrypt and decrypt the document key. once again the original user's password is not known by AnoniCloud and we're not able to recover's original user's documents content;</li> <li>Informations over the network are two-layers encrypted: first layer, chunk level encryption and second layer, https traffic encryption;</li> <li>All communications between client and server are signed with an ephemeral key, valid and rotated every five minutes. at the expiration, a new key is negotiated. the signing key is never sent over the net.</li> </ul> <li>3. Integrity</li> <ul> <li>The checksum (technically a SHA256-treehash) of each document is stored on document's metadata. the metadata are encrypted in the same way of the user's document. because of this, they are not readable by us. comparing the stored checksum with the locally calculated when retrieving the document, any alteration in content respect to the original is promptly underlined.</li> </ul> </ul> <p>Considering the three points above, AnoniCloud team is not able to access any user's data.</p> Data storage location <p>All data are stored in Switzerland.</p> What data are stored <ol> <li>User's encrypted document - See "Service philosophy" - Not accessible by AnoniCloud team;</li> <li>User's access data - Scrambled by SRP-6a - Not accessible by AnoniCloud team;</li> <li>Limiting to the public beta phase, all user's source IPs and server diagnostic are stored in clear and accessible by AnoniCloud team;</li> <li>User's feedback, support requests email are stored in clear and are used to provide requested support to user and improve our service. these data will be not sent outside AnoniCloud team.</li> </ol> Data Processed by Third Parties <p>No user's data are processed by third parties.</p> Data erasure <p>The user has the full right to erase partly or all his data. as "erasure" we intend the complete data removal without the technical possibility to recover them once deleted. On AnoniCloud app a "Document delete" function and a "Delete user's profile" are available to wipe out partly or all user's data from AnoniCloud server.</p> About our website <p>No tracking cookies are stored on user's browser starting from our website.</p> <p>Website is split in two parts:</p> <ol> <li>Presentation, corporate informations;</li> <li>Blog.</li> </ol> <p> <strong>Presentation and corporate informations</strong> don't store any cookie. Is a static tailor made website based on Bootstrap 4 and is built to avoid any informations loading from external CDN (Content Delivery Network). Anonymized IP address (last three digit hidden) is stored on our <em>Open Web Analytics</em> (<em>OWA</em> for short) database for statistical purposes. OWA runs on our webserver.</p> <p>More informations on OWA: Open Web Analytics official website.</p> <p> <strong>Blog</strong> run under WordPress with security and statistical plugins. anonymized (hashed) IP addresses are collected for statistical purposes. Language preferences cookie and session cookies are installed on user's browser. data stored on cookies are scrambled directly by WordPress engine.</p> Questions and feedback reference <p>Questions and feedback from users are welcome and can be addressed at: contact@anonicloud.ch.</p> <p>Responsible body and direct contact for data protection topics:</p> <p> Francesco Piraneo Giuliano<br> Pusgiort 20<br> 6835 Breggia<br> Switzerland </p> Amendment of the privacy policy <p>We reserve the right to change this Privacy Policy from time to time in order to comply with changed legal requirements or to reflect new functionalities of the app. The current Privacy Policy is always available for consultation from within AnoniCloud website.</p> <p> 6835 Morbio Superiore<br> Switzerland </p> <p> <strong>Scriveteci!</strong> <br> contact@anonicloud.ch<br> ...oppure usa <strong>Threema</strong>! </p> <p>Il mondo di AnoniCloud:</p> Perché AnoniCloud Aiutaci Filosofia FAQ Download Privacy policy Blog Credits <p>I nostri social</p>





Comments:
No comments found