CipherDrive™ is designed to prevent ordinary server-side access to stored plaintext file contents, but the service still processes information needed to operate safely and reliably.
Ackaia may process information such as:
account identifier;
subscription plan and entitlement;
billing state;
account and security status.
Depending on the active client and product configuration, operationally visible information may include:
encrypted file size or object weight;
storage usage;
upload, update, download, or sharing timestamps;
object type, such as file or folder;
folder structure or parent-child relationships;
MIME category or generalized media category where required;
region-placement or replication records;
object identifiers.
Ackaia may know operational facts such as:
whether an object is shared;
whether a public link is active or disabled;
transfer usage;
download or access events;
records associated with recipient saved copies or provenance where applicable.
Ackaia may process:
IP addresses;
session identifiers;
browser and device information;
authentication events;
security logs;
suspicious-activity signals;
session revocation or account-recovery records.
Where applicable, Ackaia may also process or preserve:
pre-encryption risk signals;
blocked-upload records;
abuse reports;
malware or safety indicators;
policy-enforcement records;
legal-request records.
CipherDrive may encrypt selected metadata such as filenames where supported. If filename encryption is enabled for a given object, Ackaia is not expected to see the plaintext filename after encryption.
However, metadata encryption is selective and can depend on client version, feature support, migration state, or product configuration.
Without some operational metadata, a cloud drive could not reliably answer basic questions such as which account owns an object, how much storage it uses, where it belongs in a folder tree, whether a link is active, or whether a quota has been exceeded.
CipherDrive's privacy goal is not “zero metadata.” The goal is to minimize unnecessary exposure while preventing ordinary server-side access to stored plaintext file contents.