← Back to Inaya NetworkLEGAL

Privacy Policy

Last updated: August 2026

1. What Inaya Network is architected to never see

Files uploaded through the Sovereign Vault are encrypted (AES-256-GCM) and sharded entirely inside your own browser or device, using a key derived from your own passkey (PBKDF2), before anything ever reaches our servers or the storage network. Inaya Network does not hold your passkey, cannot recover it if lost, and cannot decrypt a complete copy of your file — this is an architectural guarantee, not a policy promise.

2. Information we do collect

  • Wallet address, once you connect a wallet — used as your identity for on-chain features (staking, referrals, Genesis Airdrop, node registration).
  • Identity verification data submitted during KYC, processed by our third-party verification provider, Didit — used to activate referral rewards and prevent Sybil abuse of reward programs.
  • Email address, for Business Workspace accounts (magic-link sign-in or Google Sign-In), referral program activation, and Investor Data Room access requests.
  • Encrypted file metadata (filename, size, shard locations, timestamps) — never the decrypted file contents.
  • Payment information, processed entirely by Stripe for Business Workspace subscriptions and Corporate Reserve storage plans — Inaya Network never receives or stores your card details directly.
  • Basic usage and performance data via Vercel Analytics and Speed Insights — page views, load performance, and general usage patterns, not tied to file contents.

3. How we use it

To operate the features you use directly — wallet-based rewards, KYC-gated referral payouts, Business Workspace accounts and billing, and Investor Data Room access control — and to monitor and improve the reliability of the app. We do not sell personal data to third parties.

4. Where data is stored

Application data (accounts, referral records, KYC verification status, document metadata) is stored in MongoDB. Encrypted file shards are stored on Pinata's IPFS pinning service — as ciphertext, not plaintext. On-chain data (wallet addresses, transaction history, staking positions) is public by the nature of a blockchain and not something Inaya Network controls or can delete.

5. Third-party processors

  • Didit — identity verification (KYC) for referral program activation.
  • Stripe — payment processing for Business Workspace and Corporate Reserve purchases.
  • Google — OAuth sign-in for Business Workspace accounts (optional; magic-link email sign-in is always available as an alternative).
  • Pinata (IPFS) — encrypted file storage.
  • Vercel — application hosting, analytics, and performance monitoring.
  • MongoDB Atlas — application database hosting.

6. Your rights

You can request a copy of the personal data we hold about you, request its deletion (where it doesn't conflict with an immutable on-chain record or an active legal/financial obligation), and withdraw consent for optional features like KYC or Google Sign-In at any time. Contact us using the details below to exercise any of these.

7. Testnet status

Inaya Network is currently deployed on BNB Chain Testnet. No real funds are at risk from on-chain interactions during this phase, but the off-chain data practices described above (KYC, account data, payment processing for real products like Business Workspace) already apply in full.

8. Changes to this policy

We'll update this page as the product evolves, and material changes will be reflected in the "last updated" date below. Continued use of Inaya Network after an update constitutes acceptance of the revised policy.

9. Contact

Questions about this policy or your data: contact@inayanetwork.com. Support: support@inayanetwork.com.

See also our Terms of Service.