SPHERING³ — PRIVACY POLICY
Version 5.0 · Effective September 16, 2026
PLEASE READ THIS FIRST
Two things about this service are unusual, and both concern your privacy.
First: we do not keep your personal information on our servers. Your account is authenticated by Google; the artifacts you prepare live in a vault on your own device; payment is taken by a payment processor, not by us. What our servers retain is our own accounting ledger, and that ledger does not contain your name, your email, your artifacts or their contents.
Second: when you mint an artifact, the record is permanent. It is written to a public, decentralized network operated by third parties. That network provides no deletion mechanism to anyone — not to you, not to SPHERING³ LLC, not to a court. Whatever you choose to put in that record — including your name as creator and any comments you add — stays there. This policy tells you exactly which information ends up in a permanent record so that you can decide what to include before you mint.
1 · Who we are
This policy is published by SPHERING³ LLC, a Florida limited liability company, 6000 Peninsular Avenue T37, Key West, Florida 33040, United States (“we”, “us”). We are the controller of the personal information described in this policy. We do not process personal information on behalf of any other controller.
Contact for privacy matters: legal@sphering3.com, marked “Privacy”.
2 · Scope
This policy applies to the Services as defined in our General Terms and Conditions — our websites, applications, interfaces, and the minting and archival services we provide through them. It does not apply to third-party services you reach through ours, including Google sign-in, payment processors, and the permanent networks on which artifacts are recorded; each has its own privacy terms.
Where this policy and our Terms of Service or General Terms and Conditions address the same subject in relation to personal information, this policy governs.
3 · What we collect, and where it lives
| information | where it lives | on our servers? |
|---|---|---|
| Sign-in identity — the Google account you authenticate with | Google, and a session token on your device | No. We receive a sign-in assertion from Google and do not store your name or email. |
| Your artifacts and their contents | the vault on your device until you mint; the permanent network after you mint | No. |
| Payment details — card number, billing address | your payment processor | No. Card data is handled entirely by the processor. |
| Transaction ledger — amount, timestamp, size class, survivability level, artifact identifier, payment-processor reference | our accounting system | Yes. This is our own financial record. It contains no name, email, address or artifact content. |
| Technical logs — IP address, browser type, request timing, error records | our web servers, briefly | Yes, briefly — see Section 8. |
| Support correspondence — what you send us when you write to us | our mailbox | Yes, for as long as the matter is open and as Section 8 describes. |
We do not collect government-issued identification, proof of address, identity photographs, tax identification numbers, or biometric information. We do not perform identity verification beyond Google sign-in.
We do not use cookies for advertising or cross-site tracking. We use a session cookie to keep you signed in and a preference cookie if you choose a display setting. That is all.
4 · What goes into a permanent record
When you mint, a Certificate of Authenticity (CoFA) and a core manifest are written to a permanent public network. Depending on what you choose to include, that record may contain:
- the artifact’s cryptographic hash and size;
- the artifact identifier and mint timestamp;
- your name or chosen creator identity, if you elect to be named as creator;
- any description or comments you add;
- the survivability level and the CoFA’s stated value.
Everything in that record is public, permanent, indexable and copyable. It is not held on our servers, and the network that holds it offers no removal mechanism to any party. Do not include anything in a description, comment or creator field that you would not want permanently public. We show you the record before you confirm the mint, and confirming it is your decision.
5 · How we use information
We use the information in Section 3 to:
- authenticate you and keep your session working;
- complete the transaction you requested and maintain our accounting records;
- secure the Services, detect abuse and fraud, and keep the systems running;
- respond when you contact us;
- comply with law, respond to lawful process, and establish or defend legal claims.
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use your artifacts or their contents for any purpose other than providing the service you asked for.
6 · Legal bases (where the law requires one)
For people in the European Economic Area, the United Kingdom, or elsewhere where a legal basis is required: we process sign-in and transaction information to perform our contract with you; technical logs and abuse prevention on our legitimate interest in running a secure service; support correspondence to perform our contract and on our legitimate interest in answering you; and retention for legal, tax and accounting purposes to comply with legal obligations.
7 · Who we disclose information to
- Google, for sign-in, under Google’s terms.
- Our payment processor, which receives your payment details directly and returns a reference to us.
- Service providers who host our systems, under contracts limiting their use of information to our instructions.
- The permanent network, which receives the record described in Section 4 — this is a publication, not a disclosure to a recipient, and it is initiated by you.
- Authorities and courts, where required by law or valid legal process, and professional advisers as needed to establish or defend claims.
- A successor, if we are acquired or reorganized, on the same terms as this policy.
8 · How long we keep information
| information | retention |
|---|---|
| Session token | until you sign out or the session expires |
| Transaction ledger | the period required by tax and accounting law — seven years — and then deleted |
| Technical logs | thirty days, then deleted, unless preserved for a specific security investigation or legal hold |
| Support correspondence | until the matter is closed, then twelve months, then deleted |
| Permanent records (Section 4) | indefinitely. These live on a network that provides no alteration mechanism to any party. This retention is not set by us and is not ours to change. |
9 · Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to restrict or object to processing, and to withdraw consent.
You can exercise these rights by writing to legal@sphering3.com. We will verify that the request comes from the account holder by asking you to confirm through the Google account you used to sign in, and we will respond within the period the applicable law allows — thirty days for most, forty-five days under California law.
Privacy questions that are not a rights request — how this policy works, what we hold, or anything you want explained before you decide — go to support@sphering3.com. Correspondence addressed to a data protection officer reaches the same mailbox.
Two limits, stated honestly:
- We hold very little to give you or delete. Most of what you might expect us to hold, we do not hold — see Section 3.
- A permanent record is beyond the reach of an erasure request. The network that holds it gives SPHERING³ LLC no more ability to alter it than it gives you. A request to erase information you chose to include in a minted record is a request no party is positioned to fulfil. We tell you this before you mint.
You will not be discriminated against for exercising any right.
9.1 California residents
Under the California Consumer Privacy Act as amended, you have the right to know what personal information we collect, use and disclose; to delete it; to correct it; to opt out of sale or sharing; and to limit use of sensitive personal information. We do not sell or share personal information and we do not collect sensitive personal information as defined by that law. Categories collected in the preceding twelve months are those in Section 3; sources are you, Google and our payment processor; purposes are those in Section 5; recipients are those in Section 7. You may designate an authorized agent to make a request on your behalf.
9.2 Florida residents
We are established in Florida. Florida residents have rights under the Florida Digital Bill of Rights to the extent it applies. We honour the rights described above for all Florida residents regardless of applicability thresholds.
9.3 Other United States states
Residents of other states with comprehensive privacy laws have substantially the same rights described in this Section and may exercise them the same way.
9.4 European Economic Area and United Kingdom
You have the rights described above together with the right to lodge a complaint with your supervisory authority. Our legal bases are in Section 6. Information may be transferred to the United States; where required, we rely on standard contractual clauses or another lawful transfer mechanism.
10 · Children
The Services are for adults. You must be at least 18, or the age of majority where you live, whichever is higher. We do not knowingly collect information from anyone under that age; if we learn that we have, we will close the account.
11 · Security
We protect the information we hold with access controls, encryption in transit, and logging. Because we hold so little, the most important security decision is yours: the vault on your device is protected by your device and your passkey, and a permanent record is protected by the network it lives on. If you believe your account has been compromised, write to legal@sphering3.com marked “Security”.
12 · International transfers
We operate from the United States. Information we hold is processed in the United States and, through our service providers, may be processed in other countries. Section 9.4 describes the safeguards that apply.
13 · Data protection officer and representatives
We have not appointed a data protection officer and have not designated a representative in the European Union or the United Kingdom. Our activities do not, at present, require either. If that changes, this section will be updated before the change takes effect. Privacy correspondence goes to legal@sphering3.com.
14 · Changes
We may update this policy. The version and effective date at the top of this page are authoritative. Material changes are posted before they take effect, and where the law requires it, we will notify you.
15 · Contact
SPHERING³ LLC · 6000 Peninsular Avenue T37 · Key West, Florida 33040 · United States legal@sphering3.com — mark your message “Privacy”, “Security” or “Rights request” so it reaches the right hands.