NullLink › Privacy Policy

Privacy Policy

Last revised: September 14, 2026

This Privacy Policy describes how NullLink, operated by Myrax Core GmbH ("Company", "we", "us", "our"), collects, uses, and protects your information when you use the service at nulllink.ch (the "Service"). NullLink is a zero-knowledge identity vault — our architecture is designed so that we cannot access your data.

1. Our Zero-Knowledge Promise

NullLink employs a zero-knowledge architecture. This means:

  • All encryption and decryption happens exclusively in your browser
  • Your passphrase never leaves your device
  • We store only encrypted blobs that are meaningless without your passphrase
  • We cannot read, access, or recover your stored credentials under any circumstances
  • Even if our servers were compromised, your data remains encrypted and secure

2. What We Collect

Data You Provide

  • Encrypted identity blobs — your vault data, stored in encrypted form that only you can decrypt
  • Public identifiers — your NL-ID (cryptographically derived) and optional @alias
  • Email address — if you choose to register one, used only for OTP login and account recovery notifications

Data We Do NOT Collect

  • Plaintext passwords, passphrases, or personal data
  • Names, physical addresses, or phone numbers
  • Tracking cookies, analytics scripts, or advertising identifiers
  • Records of which websites or services you use your NL-ID with
  • Contents of credentials you store in your vault

Automatically Collected Information

When you visit nulllink.ch, our server may process:

  • IP addresses — used for rate limiting and abuse prevention; not stored in logs
  • Basic request metadata — used for server operation and error diagnosis

We do not use third-party analytics, advertising networks, or tracking services.

3. Cryptographic Standards

NullLink uses industry-standard cryptographic algorithms:

  • Ed25519 — digital signatures
  • X25519 — key exchange for credential sharing
  • XSalsa20-Poly1305 — authenticated encryption
  • PBKDF2-SHA512 — key derivation with 100,000 rounds

4. How We Use Your Information

The limited information we have access to is used solely to:

  • Provide and maintain the identity vault service
  • Relay encrypted credential-sharing envelopes between authorized parties
  • Send OTP codes if you have registered an email address
  • Prevent abuse and maintain service security

5. Credential Sharing

When you share credentials with a third-party application or PeerDesk agent:

  • You explicitly approve each sharing request
  • Your browser encrypts the data end-to-end for the recipient
  • NullLink relays the sealed envelope — we cannot read its contents
  • An encrypted audit log entry is saved to your vault (only you can read it)

Once credentials are shared with a third party, that party becomes the data controller for the shared data. NullLink is not responsible for how third parties handle data you choose to share.

6. Data Storage & Security

  • Your encrypted data is stored on servers in Europe, subject to EU/GDPR standards
  • Migration to Swiss-hosted infrastructure is planned
  • All server communication uses TLS 1.3 encryption
  • Server access is restricted and monitored

7. Data Retention

Your encrypted vault data is retained as long as your account exists. You may delete your account and all associated data at any time from within the NullLink interface. Deletion is permanent and irreversible — we have no way to recover deleted data.

8. Your Rights

Under GDPR and Swiss data protection law, you have the right to:

  • Access — view all data associated with your NL-ID
  • Export — download an encrypted backup of your vault at any time
  • Delete — permanently remove your vault and all stored data
  • Lock — temporarily restrict access to your vault
  • Portability — export your data in a standard encrypted format

Since we cannot read your data, we inherently comply with data minimization principles.

9. Third-Party Services

NullLink does not integrate with third-party analytics, advertising, or tracking services. The only external resources loaded are:

  • Google Fonts — for typography (governed by Google's privacy policy)
  • TweetNaCl.js — cryptographic library loaded from CDN

10. Children's Privacy

NullLink is not intended for use by individuals under the age of 16. We do not knowingly collect or store data from children.

11. International Data Transfers

As your data is encrypted and unreadable to us, international data transfer concerns are inherently mitigated. Our servers are located in Europe, and we do not transfer data to jurisdictions outside the EEA/Switzerland.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the Service. Continued use constitutes acceptance of the revised policy.

13. Contact Us

For privacy-related questions or to exercise your data rights:

Myrax Core GmbH
Email: nulllink@myraxcore.com
Website: nulllink.ch

Home Help & FAQ Privacy Policy Terms of Use PeerDesk Platform

© 2026 NullLink · Operated by Myrax Core GmbH · nulllink@myraxcore.com