Pluvira
Privacy by Design

Privacy Policy

Last Updated: September 2026 • Strict Zero-PII Architecture

1. Zero-PII Architecture & Identity

Pluvira is engineered from the ground up to operate without collecting or storing Personally Identifiable Information (PII). We do not store plaintext email addresses, names, or physical locations in our database.

  • Blind Provider Hashing: User authentications via biometric Passkeys (FIDO2) or social OAuth are transformed into deterministic HMAC-SHA256 blind indices using an immutable server pepper.
  • Crockford Base32 Identity: Users are identified exclusively through a randomly generated 12-character Crockford Base32 User ID (XXXX-XXXX-XXXX).

2. Zero-Knowledge E2EE Cloud Backups

Configuration snapshots uploaded to Pluvira Cloud Vault are encrypted client-side using AES-256-GCM with encryption keys derived via PBKDF2-HMAC-SHA256 (600,000 iterations) from a user-chosen passphrase.

The passphrase and encryption keys never leave your local environment. Pluvira Cloud stores only opaque binary blobs and SHA-256 checksums, with zero mathematical capability to inspect or decrypt backup data.

3. Zero-Knowledge IP Lease Tracking

Concurrent seat limits are enforced in volatile memory (Redis) using irreversible blind IP hashes:
blind_ip_hash = HMAC-SHA256(client_ip || license_key, PEPPER).

Raw client IP addresses are never logged or stored in persistent database tables.

4. k-Anonymity Stream Telemetry (k ≥ 50)

Anonymous stream reliability metrics reported to Pluvira Cloud strictly strip all authentication tokens, query parameters, and user credentials.

Under our mathematical k ≥ 50 invariant, reliability data is only aggregated and queryable when at least 50 distinct, anonymous client nodes report the identical stream hash within a rolling time window. Niche or private streams remain 100% masked.

5. Zero Tracking Cookies & Third-Party Analytics

Pluvira websites and portals contain zero third-party tracking scripts, zero advertising pixels, and zero Google Analytics. Authentication tokens are persisted strictly in local browser storage.