Last updated: 21 July 2026
The short version: this website collects nothing, and the software is designed so that we cannot see your data even if we wanted to. This page exists to say that precisely.
apertomemory.org is a static page. It sets no cookies, runs no analytics, no trackers, no fingerprinting, and has no accounts, forms or comment boxes. We do not know who you are and have no way to find out.
The site is served through a content delivery network (Amazon CloudFront), which - like any web server on the internet - processes your IP address transiently to deliver the page. We have not enabled access logging. Fonts are loaded from Google Fonts, which receives the request for the font files; if you prefer to avoid that, the site remains readable with fonts blocked.
The apertomemory packages (PyPI and npm) run entirely on your machine. They make no network calls, send no telemetry, and phone nowhere home. Your vault is a local, encrypted file; your passphrase never leaves your device. There is no server component operated by this project - which is why there is no data we could collect, store, sell or lose.
If you store or sync your exported .amem files through a third-party service of your choice, that service sees only ciphertext, opaque identifiers, object sizes and timing - as documented honestly in the specification.
If you visit our repositories on GitHub, install packages from PyPI or npm, or write to the IETF mailing lists, those platforms process your data under their own privacy policies. That is between you and them.
If you email a security report to irn@irn3.com, we use your address only to coordinate the disclosure, as described in the security policy.
If this policy ever changes, the new version will be published here with an updated date. Questions: irn@irn3.com.