Privacy Policy
Effective 2026-08-01. This policy covers nemequene.ink and the Nemequene payments API, operated by Nemequene LLC (in formation) (Rhode Island, USA).
What we collect
- Account data: the email address you sign up with, and a salted Argon2id hash of your password. Passwords are never stored in readable form.
- API credentials: stored only as SHA-256 hashes. We cannot read your API key back; we can only rotate it.
- Usage metering: monthly counters of API calls and invoices per account, used for the published pricing and nothing else.
- Payment records: invoices, their bitcoin addresses, and payment events, kept in a tamper-evident append-only ledger. These are business records, not behavioural data.
- Server logs: standard access logs including IP addresses, kept for security and abuse prevention, on a short rotation.
What we deliberately do not collect
- No private keys, ever. The service is non-custodial by construction: you register a watch-only public key; nothing on our side can spend funds.
- No card numbers. No cardholder data enters the system.
- No trackers. No third-party analytics, ad pixels, or fingerprinting. The only cookie is the session cookie of the merchant portal (HttpOnly, Secure, SameSite=Strict).
What we do with it
We use your data to run the service, meter usage, and bill you. We do not sell or share personal data. There are no third-party data processors beyond the hosting of our own servers, which are located in the European Union.
Retention and deletion
Account data is deleted on request. Payment events live in an append-only ledger whose integrity our customers verify cryptographically; those entries are business records retained for financial-integrity and audit reasons, and they reference account identifiers, not personal details. Where erasure and ledger integrity meet, we remove or cryptographically sever the personal data while preserving the ledger's mathematical continuity.
Your rights
You may request access to, correction of, or deletion of your personal data at any time from your portal account. EU/UK visitors: we honour GDPR access, rectification and erasure requests as described above.
Changes
Changes to this policy will be posted here with a new effective date.