1. Introduction
BlastChamber LLC ("BlastChamber," "we," "us," or "our") operates a commercial encrypted cloud storage service accessible at cloud.blastchamber.net (the "Service"). We provide secure, private file storage and backup to individuals and businesses, hosted entirely on physical servers we own and control in Rockford, Illinois.
This Privacy Policy ("Policy") explains what information we collect, how we use it, how we protect it, and the choices available to you. This Policy applies to all clients ("you" or "Client") who use the Service, including during the 14-day free trial period.
We designed this Service around a simple principle: your data belongs to you. We do not mine your files, scan them for advertising, sell your information, or share it with third parties for commercial purposes. Our business model is straightforward — you pay us for storage, and we protect your data. That's it.
By creating an account or using the Service, you acknowledge that you have read and understood this Policy and agree to the practices described herein.
2. Information We Collect
We collect only the information necessary to operate your account, process payments, maintain security, and provide support. We deliberately minimize the data we collect.
2.1 Account Information
When you register for an account, we collect:
- Full name — to identify the account holder and for KYC verification (see Section 8).
- Email address — for account communication, support, and password recovery.
- Password — stored as a salted hash; we never store passwords in plaintext.
- Business name (if applicable) — for commercial accounts and invoicing.
2.2 Payment Information
We process all payments through Stripe, Inc., a PCI-DSS compliant payment processor. BlastChamber does not receive, store, or transmit your full credit card number, CVV, or other sensitive cardholder data. Stripe provides us with a tokenized reference and the last four digits of your card for display purposes. For details on how Stripe handles your payment data, see Stripe's Privacy Policy.
2.3 Usage Information
We collect limited operational data necessary to manage your account:
- Storage used — the amount of storage space your account consumes, for billing and capacity management.
- Last login timestamp — to detect unauthorized access and manage inactive accounts.
- Account status — active, trial, suspended, or cancelled.
- Plan and billing history — your subscription tier and payment records (processed via Stripe).
2.4 Technical and Security Information
We collect minimal technical data strictly for security and abuse prevention:
- IP address — logged at login for security monitoring, fraud detection, and abuse prevention. We do not track or log IP addresses during routine file operations.
- Login timestamps — for security auditing and unauthorized access detection.
- Server-side error logs — technical logs that may contain non-content metadata (e.g., timestamps, operation types) but do not include file contents or file names.
2.5 What We Do NOT Collect
- File contents (in the E2EE premium tier — see Section 5).
- Browsing history, location tracking, or behavioral profiles.
- Device fingerprints or cross-site tracking identifiers.
- Biometric data.
- Information about your contacts or third parties.
3. How We Use Your Information
We use the information we collect for the following specific, limited purposes:
3.1 Account Management
- To create, maintain, and administer your account.
- To authenticate your identity at login.
- To communicate with you about your account, including service notifications and policy updates.
3.2 Billing and Payments
- To process subscription payments through Stripe.
- To manage your 14-day free trial and subscription renewals.
- To issue invoices and maintain billing records as required for tax and accounting purposes.
3.3 Security and Abuse Prevention
- To detect, investigate, and prevent unauthorized access, fraud, and abuse.
- To log IP addresses at login for security auditing.
- To monitor account activity for signs of compromise.
3.4 Client Support
- To respond to your support requests and provide technical assistance.
- To troubleshoot and resolve issues you report to us.
3.5 Legal Compliance
- To comply with applicable laws, court orders, and lawful government requests as described in Section 7.
We do not use your information for any purpose beyond those listed above. We do not use your data to build profiles, train machine learning models, or develop advertising products.
4. What We Do NOT Do
We believe transparency about what we don't do is just as important as what we do. The following is an explicit list of practices BlastChamber will never engage in:
- No data mining. We do not analyze your stored files, metadata, or usage patterns to extract insights, build profiles, or generate business intelligence.
- No advertising. We do not display advertisements in the Service, and we do not use your data to serve ads on other platforms.
- No ad targeting. We do not share data with advertising networks, data brokers, or marketing platforms.
- No selling of data. We do not sell, rent, or license your personal information or file data to any third party — ever. This is not a policy we will change.
- No file scanning for advertising. We do not scan, index, or inspect the contents of your stored files for the purpose of advertising, profiling, or any commercial purpose other than operating the Service itself.
- No third-party trackers. We do not embed third-party analytics, advertising pixels, or tracking SDKs in the Service interface. Our site uses Cloudflare Web Analytics on public marketing pages — a cookie-free, aggregated service that does not track users inside the storage application.
- No behavioral profiling. We do not track your activity across other websites or services.
Our revenue comes entirely from subscription fees paid by our clients. We have no incentive to monetize your data because our business depends on protecting it.
5. Data Storage and Encryption
Protecting your data is the core of our Service. We employ multiple layers of encryption and security.
5.1 Encryption at Rest
All stored data is encrypted at rest using ZFS native encryption on our physical storage servers. This means your files are encrypted on the underlying storage media and cannot be read by directly accessing the disks. Encryption keys are managed by BlastChamber and stored separately from the encrypted data.
5.2 Encryption in Transit
All data transmitted between your devices and our servers is protected by Transport Layer Security (TLS 1.2 or higher). This prevents interception or tampering of your data while it travels over the network. We enforce HTTPS for all connections to the Service.
5.3 End-to-End Encryption (E2EE) — Premium Tier
Clients who subscribe to the E2EE premium tier receive end-to-end encryption, which provides the maximum level of privacy available on our Service:
- Files are encrypted on the client's device before they are uploaded to BlastChamber servers.
- The encryption keys are generated and held by the client. BlastChamber never receives, stores, or has access to these keys.
- As a result, BlastChamber cannot decrypt, read, or access the contents of E2EE client files — even if compelled by law enforcement, we could only produce encrypted ciphertext that we cannot decrypt.
- In the E2EE tier, BlastChamber can see only file size, upload timestamp, and the fact that a file exists. We cannot see file names (if encrypted client-side), file contents, or file types.
Important: In the E2EE tier, if you lose your encryption key, BlastChamber cannot recover your data. There is no backdoor. You are solely responsible for safeguarding your keys. We recommend secure key backup using a password manager or offline storage.
5.4 Infrastructure
- The Service is hosted on BlastChamber's own physical servers located in Rockford, Illinois. We do not use third-party cloud providers (e.g., AWS, Google Cloud, Azure) in the storage or processing chain.
- Backups are replicated to a separate physical server (TrueNAS on host BN4) at a different physical location, ensuring geographic separation of primary and backup data.
- No element of your stored data passes through or resides on third-party cloud infrastructure.
6. Data Retention
6.1 Active Accounts
We retain your data for as long as your account is active and your subscription is in good standing. You may delete individual files at any time through the Service interface. Deleted files are permanently removed from active storage and from backups according to our backup rotation schedule.
6.2 Account Cancellation
If you cancel your account — whether by choice, non-payment, or the conclusion of a free trial without conversion — the following retention schedule applies:
- Grace period: Your data is retained for 30 days after account cancellation. During this period, you may contact us to reactivate your account and recover your data.
- Permanent deletion: After the 30-day grace period, your data is permanently and irreversibly deleted from all primary storage and backup systems. This deletion is not recoverable by any party, including BlastChamber.
- Account records: Basic account records (name, email, billing history) may be retained for a longer period as required for tax, accounting, and legal compliance under applicable law, but your stored files and file metadata are deleted as described above.
6.3 E2EE Tier
In the E2EE premium tier, your encrypted files are subject to the same retention schedule. Since BlastChamber cannot decrypt these files, deletion of the encrypted ciphertext constitutes permanent, unrecoverable deletion.
7. Data Sharing
7.1 We Do Not Sell or Share Your Data Commercially
BlastChamber will never sell, rent, lease, or license your personal information or stored data to any third party for commercial purposes. We do not share your data with advertisers, data brokers, or marketing companies.
7.2 When We May Be Required to Disclose Information
We may disclose your information only in the following limited circumstances:
- Legal compliance: When required to comply with applicable federal, state, or local law.
- Court order or subpoena: When we receive a valid court order, subpoena, or other lawful legal process. We will make reasonable efforts to notify you of such requests unless prohibited by law.
- Law enforcement: In response to lawful requests from law enforcement agencies, where we are legally compelled to comply.
- Your consent: When you explicitly consent to the disclosure.
- Service providers: We share limited data with Stripe for payment processing, as described in Section 2.2. Stripe is contractually and legally bound to handle your payment data securely and does not use it for BlastChamber's purposes beyond payment processing.
7.3 What We Can and Cannot Disclose
- Standard tier: In response to a valid legal order, we may be compelled to disclose account information (name, email, billing records) and, if technically possible, the contents of stored files (which are encrypted at rest but which BlastChamber can decrypt with its own keys).
- E2EE premium tier: In response to a valid legal order, we can disclose account metadata (name, email, billing records, file sizes, timestamps) but cannot disclose the contents of your encrypted files, because we do not possess the decryption keys. We can only produce encrypted ciphertext that we cannot read.
7.4 No Voluntary Disclosure
We do not voluntarily provide your data to any government agency, law enforcement body, or third party except as described in this section. We do not participate in voluntary data-sharing programs.
8. Client Vetting and Identity Verification (KYC)
8.1 Why We Verify Identity
BlastChamber is a commercial service provider. To protect the integrity of our platform, prevent fraud and abuse, and comply with applicable regulations, we require identity verification before provisioning a storage account. This process is commonly referred to as "Know Your Customer" (KYC).
8.2 What We Collect for Verification
Before your account is fully provisioned, we may collect and verify:
- Government-issued photo identification — to confirm your identity (e.g., driver's license, passport, state ID). We verify the document and then delete the image, retaining only a record that verification was completed.
- Business verification (for commercial accounts) — business name, registration documents, or relevant licensing, to confirm the business is legitimate.
- Contact verification — confirmation that the email address and phone number (if provided) belong to you.
8.3 How We Use Verification Data
- To confirm you are who you claim to be.
- To prevent fraudulent accounts, abuse, and use of the Service for illegal purposes.
- To comply with applicable laws and regulations.
8.4 Retention of Verification Records
We retain a record that identity verification was completed, but we delete the actual images of your identification documents after verification is confirmed, unless retention is required by law. We do not maintain a database of client IDs.
9. Cookies and Tracking
9.1 Session Cookies Only
The Service uses a single session cookie to maintain your authenticated login session. This cookie:
- Is necessary for the Service to function — without it, you cannot stay logged in.
- Is destroyed when you log out or close your browser session.
- Does not track you across other websites.
- Does not contain personally identifiable information (it is a random session token).
9.2 What We Do NOT Use
- No analytics cookies. We do not use Google Analytics, Adobe Analytics, or any other web analytics platform.
- No tracking cookies. We do not place cookies that persist after your session ends.
- No third-party cookies. We do not allow third-party services to set cookies in our Service.
- No advertising cookies. We do not use cookies for advertising or ad targeting.
- No fingerprinting. We do not use browser fingerprinting or device identification techniques.
9.3 Browser Configuration
Because we use only a necessary session cookie, there are no optional cookies to manage or decline. If you disable all cookies in your browser, the Service will not be able to maintain your login session.
10. Data Security Measures
We take a defense-in-depth approach to security. The following measures are in place:
10.1 Physical Security
- Servers are housed in a physically secured facility in Rockford, Illinois, with restricted physical access.
- Only authorized BlastChamber personnel have physical access to server hardware.
- No third party has physical access to our servers.
10.2 Encryption
- At rest: All data is encrypted using ZFS native encryption (see Section 5.1).
- In transit: All network traffic is encrypted with TLS 1.2+ (see Section 5.2).
- E2EE tier: Client-side encryption ensures BlastChamber cannot access file contents (see Section 5.3).
10.3 Access Controls
- Access to server administration is restricted to authorized BlastChamber personnel.
- Administrative access is authenticated and logged.
- We follow the principle of least privilege — personnel access only what is necessary to operate the Service.
- No employee or contractor has routine access to client file contents. Access to the storage layer requires specific administrative authorization and is logged.
10.4 Backups
- Data is backed up to a separate physical server (TrueNAS on host BN4) at a different physical location.
- Backups are encrypted using the same ZFS native encryption as primary storage.
- Backup integrity is verified on a regular schedule.
- In the E2EE tier, backups contain only encrypted ciphertext, which BlastChamber cannot decrypt.
10.5 No Third-Party Cloud
- The entire storage and processing chain runs on BlastChamber-owned infrastructure. No element of your data is stored on or processed by third-party cloud providers such as Amazon Web Services, Google Cloud, or Microsoft Azure.
10.6 Security Incidents
In the event of a confirmed data breach affecting client data, BlastChamber will:
- Take immediate steps to contain and remediate the breach.
- Notify affected clients within a reasonable timeframe (and in any case within 72 hours of confirmation).
- Provide details of the breach, the data affected, and the steps we are taking in response.
- Notify applicable authorities as required by law.
11. Your Rights
As a BlastChamber client, you have the following rights regarding your data:
11.1 Access
You may request a copy of the personal information we hold about you (account information, usage data, billing records). We will provide this within 30 days of your request.
11.2 Download and Export
You may download your stored files at any time through the Service interface. You may also request an export of your account data (excluding file contents) in a portable format.
11.3 Correction
You may update your account information (name, email, business name) at any time through the Service interface or by contacting support.
11.4 Deletion
You may delete individual files at any time. You may also request permanent deletion of your entire account and all associated data. Upon such request, your data will be permanently deleted within 30 days, as described in Section 6.
11.5 Withdrawal of Consent
If we are processing your data based on your consent, you may withdraw that consent at any time by contacting us. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
11.6 How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected]. We will verify your identity before processing requests involving personal data.
12. Children's Privacy
The Service is not directed to children and is not intended for use by anyone under the age of 18. We do not knowingly collect information from individuals under 18. If you believe a minor has provided us with personal information, please contact us at [email protected] and we will take steps to delete that information.
By using the Service, you represent and warrant that you are at least 18 years of age and, if registering a commercial account, that you are authorized to act on behalf of your business.
13. International Users
13.1 Data Location
The Service is hosted entirely on physical servers located in Rockford, Illinois, United States. All client data — including account information and stored files — is processed and stored in the United States. We do not transfer client data to servers in other countries.
13.2 Governing Law
This Privacy Policy and your use of the Service are governed by the laws of the State of Illinois and applicable United States federal law, without regard to conflict-of-law principles. Any disputes arising under this Policy shall be resolved in the courts located in Winnebago County, Illinois, or the United States District Court for the Northern District of Illinois, as applicable.
13.3 International Data Protection Laws
If you are accessing the Service from outside the United States, please be aware that your data will be processed in the United States, which may have different data protection laws than your jurisdiction. By using the Service, you acknowledge and consent to the transfer and processing of your data in the United States. We will nonetheless strive to honor the rights described in Section 11 regardless of your location.
14. Changes to This Policy
14.1 Notification of Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Service features. When we make material changes, we will:
- Update the "Effective Date" at the top of this document.
- Notify active clients by email at least 30 days before the changes take effect.
- Maintain the previous version of the Policy available upon request.
14.2 Continued Use
If you continue to use the Service after the effective date of any changes, you are deemed to have accepted the updated Policy. If you do not agree with the changes, you may cancel your account as described in Section 6 before the changes take effect.
14.3 Core Commitments
Certain commitments in this Policy are fundamental to our Service and will not change:
- We will never sell your personal data.
- We will never use your data for advertising.
- We will never scan your files for commercial profiling.
- We will never use third-party cloud providers in the storage chain.
15. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:
We are committed to responding to all legitimate inquiries within a reasonable timeframe, typically within 5 business days.
Appendix A: Summary of Key Commitments
| Commitment |
Detail |
| We sell your data |
Never. |
| We mine your files |
Never. |
| We show ads |
Never. |
| We use third-party cloud |
Never. Our servers, our rules. |
| We track you |
No. Session cookie only. |
| Encryption at rest |
Yes — ZFS native encryption. |
| Encryption in transit |
Yes — TLS 1.2+. |
| End-to-end encryption |
Available in E2EE premium tier. |
| Data retention after cancellation |
30 days, then permanent deletion. |
| Free trial |
14 days, no credit card required for trial. |
| Where your data lives |
Rockford, Illinois, USA. |
| Governing law |
State of Illinois, USA. |