No sale or ad use
Stored bytes are not sold, profiled for advertising, or used to train machine-learning models.
svc.nz is built to know less: no legal name is required, no advertising profile is built, and authentication capabilities are stored as hashes. This page also covers what the service still needs to know, including the current deletion limit you should understand before uploading.
Stored bytes are not sold, profiled for advertising, or used to train machine-learning models.
The box API does not require a name or email. Account records use an internal id, a label, and hashed API credentials.
With optional AES-256-GCM encryption, plaintext and the key stay in your client; svc.nz receives ciphertext and encryption metadata.
This policy covers the hosted svc.nz website, API, browser tools, and related support operated by Anphase Ltd in New Zealand. It does not automatically cover a self-hosted deployment operated by someone else; that operator is responsible for its own privacy practices.
For personal information svc.nz collects to run the service, Anphase Ltd is the responsible agency under New Zealand’s Privacy Act 2020. When you use a box to process personal information about other people, your own legal responsibilities continue to apply. The private trial does not currently offer a separate data-processing agreement and is not intended for regulated or high-risk personal information.
We store the content you upload and metadata needed to return it: box id, object name, version, size, content type, timestamps, hashes, ETags, expiry, and optional encryption metadata. Object names and content types are not encrypted by the client-side encryption feature.
Authentication capabilities and account keys are persisted as cryptographic hashes, not recoverable plaintext. We store scope, rotation, expiry, revocation, quota, second-factor, and access-control state needed to validate a request. A capability deliberately uploaded as content is treated as content.
Account records contain an internal id, a label chosen at creation, hashed API-key material, status, and timestamps. The hosted service is invite-only for creating accounts and boxes during the private trial, but it does not require an email address, legal name, postal address, or payment information in an account record.
A per-box audit chain records events such as creation, reads, writes, authentication failures, capability changes, webhook changes, and deletion, with operational metadata rather than stored bodies. A raw client address may be used transiently for rate limiting. The application stores a one-way hash derived from the client identifier and box context in an expiring rate-limit bucket rather than storing the raw address there.
Requests also pass through Cloudflare and AWS. Those providers may process IP addresses, request paths, timestamps, user-agent information, security signals, and error data in edge or infrastructure logs. The svc.nz Lambda log group is configured with one-week retention; provider security records may follow separate provider retention settings.
If you email us or submit a report, we receive the address, headers, message, attachments, and other information you provide. Abuse, copyright, privacy, and security reports may contain identity, contact, evidence, and complaint details required to assess and respond.
The site stores a theme preference in local storage. The local browser console also stores the most recently used box id and capability values so it can refill fields. The application does not use advertising cookies or third-party analytics. See Cookies and Local Storage for the precise inventory and clearing instructions.
We use information to:
We do not sell personal information or stored content. We do not use stored content for advertising, unrelated profiling, or machine-learning model training.
Where another privacy regime requires a stated legal basis, the basis will usually be performance of the service agreement, our legitimate interests in security and reliable operation, compliance with law, or consent where we specifically ask for it.
The primary hosted application, object storage, metadata, and service logs run in Amazon Web Services’ Sydney, Australia region (ap-southeast-2). Traffic passes through Cloudflare’s global network and may be processed at an edge location outside New Zealand or Australia before reaching the service. Support email may also pass through the sender’s and recipient’s email providers.
We use providers as service agents to operate the service and take reasonable steps to require appropriate safeguards. Where a transfer is a disclosure covered by New Zealand Information Privacy Principle 12, we will use an available lawful basis and comparable safeguards as required.
Deleting a version or box marks it deleted and removes access through the normal API at once. The stored bytes are removed separately. svc.nz runs a reference-aware collector that removes stored bytes only after every record referring to them has gone and a grace period of at least seventy-two hours has passed. That grace period exists so a deletion made in error can still be recovered, and so bytes belonging to an upload still in progress are never removed. Because content is addressed by its own hash, identical bytes uploaded to more than one box are stored once and shared, and they remain for as long as any box still refers to them. The collector runs automatically once a day, so in practice bytes are erased within a few days of the last reference to them going, and within thirty days at the outside.
Metadata, audit events, security records, and backup or non-current infrastructure versions may remain for operational, recovery, fraud-prevention, dispute, and legal purposes. Object storage keeps a non-current copy of anything it removes for seven days before discarding it, so bytes the collector removes persist in that form for up to a further seven days, which still leaves the whole sequence well inside thirty days.
Controls include TLS in transit, private S3 storage with encryption at rest, 256-bit random capabilities, hashing of persisted credentials, short-lived rotating access caps, scoped and attenuated caps, quota and rate controls, security headers, restricted browser asset serving, tamper-evident audit chaining, and optional client-side AES-256-GCM encryption.
No online service is perfectly secure. You are responsible for capability handling and for keeping another copy of important data. Client-side encryption protects stored plaintext only if you keep the encryption key separate from the content and capability.
If we become aware of a privacy breach that is likely to cause serious harm, we will notify the New Zealand Privacy Commissioner and affected people as required by the Privacy Act 2020. See the Security page to report a vulnerability.
You can choose not to upload personal information, use client-side encryption, use narrower capabilities, clear local browser storage, and delete box references with the applicable refresh capability. Remember that deleting through the API removes access immediately but not the stored bytes, which the daily collector erases after the grace period and only once nothing else refers to them.
You may ask for access to or correction of personal information Anphase Ltd holds about you, and may have rights to object, restrict processing, request deletion, or complain under applicable law. Capability-addressed content may not identify you, and an identity alone may be insufficient to locate it. We may need a box id, object URL, relevant timestamps, and evidence of authority. Do not send the live capability in your initial email.
We may decline or limit a request where law permits or where responding would expose another person’s data, compromise security, or require access we cannot verify. To make a request, email svc@anphase.co.nz with “Privacy request” in the subject.
svc.nz is a technical service not directed to children under 13, and we do not knowingly collect account information from them. People under 18 should use the service only with permission and supervision from a parent or legal guardian. If you believe a child has provided personal information inappropriately, contact us with enough non-sensitive detail to locate the issue.
We may update this policy as the service, providers, or law changes. The effective date above will change. For a material change, we will use a reasonable additional notice where an account contact channel exists. Because capability-only use may give us no way to identify or contact a user, check this page from time to time.
Anphase Ltd is based in New Zealand. Privacy requests and questions can be sent to svc@anphase.co.nz. You may also complain to the New Zealand Office of the Privacy Commissioner. Use the abuse process for harmful or illegal content reports.