PRIVACY POLICY
LAST UPDATED: AUGUST 3, 2026
Noira cannot read your contracts, so Noira cannot leak them. Every agreement is encrypted in your browser before it leaves your device, and only ciphertext is written to the Internet Computer — decrypted by a threshold quorum of independent subnet replicas, never by a single party. This page describes what little data we do hold, where it lives, and the rights you keep.
1. WHAT DATA DOES NOIRA COLLECT?
The minimum required to operate an on-chain signing platform, and nothing more. Noira stores your Internet Identity principal (the anonymous identifier issued by the identity canister), your account's consent state (which agreements you have agreed to and when), and audit-log metadata for each signing event — timestamps, principal references, and the on-chain action taken. This metadata is what makes a Noira signature independently verifiable; it is not personal content, and it is not correlated to your off-chain identity.
2. WHAT DOES NOIRA NOT COLLECT — OR CANNOT READ?
Noira cannot read the contents of your contracts. Contract plaintext is encrypted in your browser before it ever leaves your device, and only ciphertext is written to the Internet Computer. Decryption requires a threshold quorum of independent subnet replicas acting through VetKeys threshold cryptography — no single party, including Noira, holds a key that can decrypt a stored document. We do not collect browsing history, search queries, location data, device fingerprints, or any analytics telemetry. There are no advertising trackers loaded on this site.
3. WHERE DOES MY DATA LIVE?
In two places, both under your control. Encrypted contract ciphertext and the audit-log metadata that anchors it live in an Internet Computer canister — a tamper-proof, replicated on-chain store governed by protocol-level consensus. In-progress Guided drafts that you have not yet finalized are held locally in your browser's localStorage, so an unfinished agreement never touches the network until you choose to publish it. There is no intermediate Noira-operated database in the path.
4. WHAT DOES 'WHAT WE CANNOT READ, WE CANNOT LEAK' MEAN?
It is the structural guarantee that underpins the rest of this policy. A breach can only expose data that exists in a readable form somewhere. Because Noira never possesses contract plaintext — only ciphertext that no single party can decrypt — a compromise of Noira's infrastructure cannot expose the contents of your agreements. The threat model is shifted from trusting the operator to trusting the cryptography, and the cryptography is verifiable on-chain.
5. DOES NOIRA SHARE DATA WITH THIRD PARTIES?
No. Noira does not sell, rent, share, or disclose user data to any third party. There are no analytics vendors, no advertising networks, no marketing pixels, and no data brokers integrated into this application. The only external calls the application makes are to the Internet Computer protocol itself, which is the network that stores your encrypted data — not a counterparty that can read it.
6. WHAT RIGHTS DO I HAVE OVER MY DATA?
You retain access to everything that is yours. You can read your own contracts and audit metadata at any time by signing in with the Internet Identity principal that owns them. You can delete your account and the data associated with it from the danger zone in Settings, which removes your profile and triggers the on-chain lifecycle for the records you own. Because your data lives on a public protocol rather than a private server, deletion is an on-chain action — verifiable, not a promise.

