Privacy Policy
Effective Date: August 3, 2026
Axamoon ("we", "our", or "us") is dedicated to protecting your personal privacy. Axamoon is built from the ground up as a zero-knowledge end-to-end encrypted (E2EE) photo sharing application.
1. Zero-Knowledge Cryptographic Architecture
Your photos are encrypted on your local device (using Apple CryptoKit Curve25519 ECC + 256-bit AES-GCM) BEFORE being uploaded to our cloud infrastructure. Only designated album keyholders hold the private decryption keys. We, our cloud providers, and third parties cannot decrypt or read your photos under any circumstances.
2. Data Collection & Hashing
- Phone Numbers: Used solely for account authentication via Firebase Auth. Phone numbers are hashed on-device using SHA-256 before key lookup.
- No Third-Party Ad Trackers: Axamoon contains 0 third-party advertising trackers or data-mining SDKs.
- No Plaintext Photo Access: We do not collect, view, or process plaintext photo data on our servers.
3. Ephemeral Vault Lifespan
Photos and albums automatically self-destruct from cloud servers based on your active tier (7, 30, 60, or 90 days), eliminating long-term digital footprints.
4. Account Deletion
You can delete your account and associated encrypted key records at any time directly within the app settings under Account → Delete Account.
5. Contact Us
If you have any questions about this Privacy Policy, please contact us at privacy@axamoon.app.