svc.nz
Policies
Data, without fog

Privacy policy

svc.nz is built to know less: no legal name is required, no advertising profile is built, and authentication capabilities are stored as hashes. This page also covers what the service still needs to know, including the current deletion limit you should understand before uploading.

Effective and last updated 28 August 2026
Content

No sale or ad use

Stored bytes are not sold, profiled for advertising, or used to train machine-learning models.

Identity

No email required

The box API does not require a name or email. Account records use an internal id, a label, and hashed API credentials.

Control

Encryption stays client-side

With optional AES-256-GCM encryption, plaintext and the key stay in your client; svc.nz receives ciphertext and encryption metadata.

Deletion is immediate; erasure completes within 30 days.

Deleting or expiring a box removes normal API access straight away. The underlying content-addressed bytes are then permanently erased by a routine reference-aware collection process, within thirty days, and only once nothing else refers to them. Identical bytes uploaded to another box are stored once and shared, so those bytes remain while that other box holds them; the thirty days run from the last box releasing them. Do not upload content that requires faster or independently verifiable erasure.

On this page
  1. Scope + operator
  2. What we collect
  3. How we use it
  4. When we share
  5. Where it goes
  6. Retention + deletion
  7. Security
  8. Your choices
  9. Children
  10. Changes
  11. Contact

1. Scope and operator

This policy covers the hosted svc.nz website, API, browser tools, and related support operated by Anphase Ltd in New Zealand. It does not automatically cover a self-hosted deployment operated by someone else; that operator is responsible for its own privacy practices.

For personal information svc.nz collects to run the service, Anphase Ltd is the responsible agency under New Zealand’s Privacy Act 2020. When you use a box to process personal information about other people, your own legal responsibilities continue to apply. The private trial does not currently offer a separate data-processing agreement and is not intended for regulated or high-risk personal information.

2. What we collect

Bytes and version metadata

We store the content you upload and metadata needed to return it: box id, object name, version, size, content type, timestamps, hashes, ETags, expiry, and optional encryption metadata. Object names and content types are not encrypted by the client-side encryption feature.

Credentials and access state

Authentication capabilities and account keys are persisted as cryptographic hashes, not recoverable plaintext. We store scope, rotation, expiry, revocation, quota, second-factor, and access-control state needed to validate a request. A capability deliberately uploaded as content is treated as content.

Accounts

Account records contain an internal id, a label chosen at creation, hashed API-key material, status, and timestamps. The hosted service is invite-only for creating accounts and boxes during the private trial, but it does not require an email address, legal name, postal address, or payment information in an account record.

Operational and audit data

A per-box audit chain records events such as creation, reads, writes, authentication failures, capability changes, webhook changes, and deletion, with operational metadata rather than stored bodies. A raw client address may be used transiently for rate limiting. The application stores a one-way hash derived from the client identifier and box context in an expiring rate-limit bucket rather than storing the raw address there.

Requests also pass through Cloudflare and AWS. Those providers may process IP addresses, request paths, timestamps, user-agent information, security signals, and error data in edge or infrastructure logs. The svc.nz Lambda log group is configured with one-week retention; provider security records may follow separate provider retention settings.

Contact and support

If you email us or submit a report, we receive the address, headers, message, attachments, and other information you provide. Abuse, copyright, privacy, and security reports may contain identity, contact, evidence, and complaint details required to assess and respond.

Your browser

The site stores a theme preference in local storage. The local browser console also stores the most recently used box id and capability values so it can refill fields. The application does not use advertising cookies or third-party analytics. See Cookies and Local Storage for the precise inventory and clearing instructions.

3. How we use information

We use information to:

  • store, version, retrieve, return, and otherwise process content to provide the service;
  • authenticate capability holders, rotate credentials, enforce quotas, and prevent abuse;
  • operate webhooks and other features you configure;
  • maintain, diagnose, secure, and improve reliability;
  • respond to support, privacy, abuse, copyright, and security requests;
  • enforce the Terms and protect people, rights, and infrastructure; and
  • meet legal obligations and establish, exercise, or defend legal claims.

We do not sell personal information or stored content. We do not use stored content for advertising, unrelated profiling, or machine-learning model training.

Where another privacy regime requires a stated legal basis, the basis will usually be performance of the service agreement, our legitimate interests in security and reliable operation, compliance with law, or consent where we specifically ask for it.

4. When information is shared

Information may be made available:

  • to capability holders: content and metadata are returned to anyone presenting a valid capability with the required permissions;
  • to infrastructure providers: the providers listed on the Subprocessors page process data to host, protect, and deliver svc.nz;
  • at your direction: for example, metadata sent to a webhook URL you configure;
  • for safety and enforcement: where reasonably needed to investigate abuse, protect rights or security, or enforce the Terms;
  • for legal reasons: where required or permitted by law, court order, or a valid government request; and
  • in a business transfer: to advisers and a genuine successor involved in a merger, financing, reorganisation, or sale, subject to appropriate confidentiality and continued protection.

Because capabilities are bearer credentials, sharing a capability is a disclosure you control. Use a narrow read-only or time-limited capability wherever possible, and never put live credentials in ordinary support email.

5. Where information is processed

The primary hosted application, object storage, metadata, and service logs run in Amazon Web Services’ Sydney, Australia region (ap-southeast-2). Traffic passes through Cloudflare’s global network and may be processed at an edge location outside New Zealand or Australia before reaching the service. Support email may also pass through the sender’s and recipient’s email providers.

We use providers as service agents to operate the service and take reasonable steps to require appropriate safeguards. Where a transfer is a disclosure covered by New Zealand Information Privacy Principle 12, we will use an available lawful basis and comparable safeguards as required.

6. Retention and deletion

Anonymous boxes
Normal access expires seven days after the latest successful write.
Account boxes
Persist until deleted or removed under the policies; no automatic default expiry.
Service logs
The AWS Lambda log group is configured for one week.
Support records
Kept as reasonably needed to resolve the matter and meet legal obligations.

Deleting a version or box marks it deleted and removes access through the normal API at once. The stored bytes are removed separately. svc.nz runs a reference-aware collector that removes stored bytes only after every record referring to them has gone and a grace period of at least seventy-two hours has passed. That grace period exists so a deletion made in error can still be recovered, and so bytes belonging to an upload still in progress are never removed. Because content is addressed by its own hash, identical bytes uploaded to more than one box are stored once and shared, and they remain for as long as any box still refers to them. The collector runs automatically once a day, so in practice bytes are erased within a few days of the last reference to them going, and within thirty days at the outside.

Metadata, audit events, security records, and backup or non-current infrastructure versions may remain for operational, recovery, fraud-prevention, dispute, and legal purposes. Object storage keeps a non-current copy of anything it removes for seven days before discarding it, so bytes the collector removes persist in that form for up to a further seven days, which still leaves the whole sequence well inside thirty days.

7. How information is protected

Controls include TLS in transit, private S3 storage with encryption at rest, 256-bit random capabilities, hashing of persisted credentials, short-lived rotating access caps, scoped and attenuated caps, quota and rate controls, security headers, restricted browser asset serving, tamper-evident audit chaining, and optional client-side AES-256-GCM encryption.

No online service is perfectly secure. You are responsible for capability handling and for keeping another copy of important data. Client-side encryption protects stored plaintext only if you keep the encryption key separate from the content and capability.

If we become aware of a privacy breach that is likely to cause serious harm, we will notify the New Zealand Privacy Commissioner and affected people as required by the Privacy Act 2020. See the Security page to report a vulnerability.

8. Your choices and rights

You can choose not to upload personal information, use client-side encryption, use narrower capabilities, clear local browser storage, and delete box references with the applicable refresh capability. Remember that deleting through the API removes access immediately but not the stored bytes, which the daily collector erases after the grace period and only once nothing else refers to them.

You may ask for access to or correction of personal information Anphase Ltd holds about you, and may have rights to object, restrict processing, request deletion, or complain under applicable law. Capability-addressed content may not identify you, and an identity alone may be insufficient to locate it. We may need a box id, object URL, relevant timestamps, and evidence of authority. Do not send the live capability in your initial email.

We may decline or limit a request where law permits or where responding would expose another person’s data, compromise security, or require access we cannot verify. To make a request, email svc@anphase.co.nz with “Privacy request” in the subject.

9. Children

svc.nz is a technical service not directed to children under 13, and we do not knowingly collect account information from them. People under 18 should use the service only with permission and supervision from a parent or legal guardian. If you believe a child has provided personal information inappropriately, contact us with enough non-sensitive detail to locate the issue.

10. Changes to this policy

We may update this policy as the service, providers, or law changes. The effective date above will change. For a material change, we will use a reasonable additional notice where an account contact channel exists. Because capability-only use may give us no way to identify or contact a user, check this page from time to time.

11. Contact and complaints

Anphase Ltd is based in New Zealand. Privacy requests and questions can be sent to svc@anphase.co.nz. You may also complain to the New Zealand Office of the Privacy Commissioner. Use the abuse process for harmful or illegal content reports.

svc.nzPrivacy for the private trial.Operated by Anphase Ltd in Aotearoa New Zealand.
Policy centreTermsPrivacyAcceptable useAbuseSecurityCopyrightCookiesSubprocessors