Erebrus legal
Privacy Policy
This policy covers Erebrus VPN, Erebrus Firewall, Erebrus Drop, and Erebrus AI, including wallet authentication, organization entitlements, VPN client management, firewall controls, local Drop Room transfers, optional IPFS storage, browser-side encryption, public shares, key recovery, local AI inference, LAN discovery, and shared model access.
Effective date: July 31, 2026
1. Scope
This Privacy Policy explains how NetSepio handles information for Erebrus VPN, Erebrus Firewall, Erebrus Drop, Erebrus AI, the Erebrus web application, mobile applications, dashboard, explorer, websites, support channels, and related services.
Erebrus VPN, Erebrus Firewall, Erebrus Drop, and Erebrus AI are different products with different data flows. This policy explains those differences.
2. Information We Collect
Information common to Erebrus services
- Wallet address, wallet network, signed authentication messages, and related wallet connection state.
- Organization membership, role, assigned seat tier, and organization plan data used to determine service access and storage quota.
- Cookies, local storage, authentication tokens, and session information needed to keep you signed in and secure.
- Device and browser metadata, such as user agent, operating system, app version, timestamps, IP address seen by our web servers, request logs, and diagnostics.
- Support messages, bug reports, survey responses, and feedback you choose to send us.
- Payment or transaction metadata when you purchase, subscribe, mint, or interact with payment processors or blockchains. NetSepio does not need your wallet seed phrase or private key.
Erebrus VPN information
- VPN client names or labels you create.
- Selected node, country or region preference, generated configuration metadata, and dashboard actions needed to manage VPN clients.
- Operational, security, and abuse-prevention logs related to authentication, API requests, node availability, subscription enforcement, and service reliability.
- Network metadata may be visible to VPN infrastructure as technically necessary to route traffic. For example, a VPN node may need to see connection endpoints to provide service.
Erebrus Firewall information
- Firewall service status, selected node, workspace, rule names, rule configuration, sync and restart actions, and administrator activity needed to provide firewall or DNS-filtering features.
- Firewall credentials and connection details where needed to let authorized workspace administrators access or configure protection services.
- Operational, security, and abuse-prevention logs related to firewall availability, configuration changes, rule enforcement, and service reliability.
Erebrus Drop information
- For local Drop Rooms, room identifiers, QR or browser link state, nearby-device connection details, transfer status, and local-network technical metadata may be generated or exchanged by participating devices to complete the transfer.
- Local-only Drop Room file contents are designed to move directly between nearby devices over Wi-Fi or hotspot and are not uploaded to NetSepio servers by default.
- For optional storage, file metadata such as filename, content type, byte size, selected node, storage scope, visibility, CID, upload state, and timestamps may be processed.
- Optional public stored file contents are sent as plaintext through the gateway to the selected Kubo/IPFS node.
- Optional private stored file contents are encrypted in your browser. The gateway and node receive ciphertext, authenticated encryption metadata, and a wrapped per-file key, but not the plaintext file key.
- An encrypted vault backup may be stored by the gateway. Your recovery secret and unwrapped vault key are not sent to the gateway and are not persisted by the web app.
- Upload, download, quota, node-health, audit, rate-limit, and security events needed to operate and protect the storage service.
Erebrus AI information
- Model catalog interactions, selected model identifiers, quantization preferences, download state, runtime settings, device capability signals, and app diagnostics needed to provide model discovery and local inference features.
- Personas, system prompts, conversation history, prompts, inputs, files, images, and outputs may be stored locally by the app when you choose to save them on your device.
- If you enable LAN discovery or shared inference, devices on the same network or trusted workspace may receive limited service discovery metadata, such as node availability, address, port, runtime status, and model capability information.
- If you send prompts, files, images, or other inputs to a shared model, workspace node, nearby device, gateway, support channel, or cloud-connected feature, the information needed to route, process, troubleshoot, secure, and return the request may be processed outside your device.
- Support messages, crash logs, diagnostics, or feedback may include AI prompts, outputs, model names, or local runtime details if you choose to send them to NetSepio.
3. Drop and AI Information We Do Not Collect by Default
- Your Drop recovery secret.
- Your plaintext account vault key.
- Plaintext per-file data keys.
- Plaintext private file contents.
- Prompts, outputs, personas, conversation history, local files, local images, or local model files used only with local-only Erebrus AI inference.
- Your wallet seed phrase or private key.
4. How We Use Information
- Provide, secure, maintain, and troubleshoot Erebrus VPN, Erebrus Firewall, Erebrus Drop, and Erebrus AI.
- Authenticate wallets and sessions.
- Create, manage, and revoke VPN clients, firewall rules, firewall credentials, and access credentials.
- Provide model catalog, local inference, shared-node discovery, workspace access, and AI diagnostics where you use those features.
- Apply organization membership, seat, plan, quota, and payment-related rules.
- Detect abuse, fraud, spam, malware, attacks, service misuse, and violations of our Terms.
- Respond to support requests and improve product reliability.
- Comply with legal obligations and enforce our rights.
5. How Erebrus Drop Works
Drop Rooms are the primary Drop flow: one device creates a local room, another joins by QR code or local browser link, and files, photos, or text move over Wi-Fi or hotspot between nearby devices.
When you choose optional storage, the web app sends file bytes through the Erebrus gateway to the Kubo node you select. The gateway controls authorization, quota, metadata, and managed pin lifecycle. Kubo stores content-addressed blocks and participates in IPFS.
Optional private stored files are encrypted and decrypted in your browser using a random per-file key wrapped by your in-memory account vault key. Keep the recovery secret secure: NetSepio cannot reset it or decrypt your files if it is lost.
Optional public IPFS content should be treated as public and potentially durable. Deleting a managed Drop file removes the gateway record and its managed pin when safe, but cannot guarantee removal from other IPFS nodes, caches, recipients, or independent pins.
6. How Erebrus AI Works
Erebrus AI is designed to run supported local models on your own device where available. In that local-only mode, prompts, inputs, personas, conversation history, outputs, and model files are not uploaded to NetSepio by default.
When you enable LAN discovery, a desktop or other device may advertise an Erebrus AI service, including limited technical metadata, to devices on the same local network. Only enable discovery on networks and devices you trust.
When you choose a shared model, workspace node, nearby device, remote gateway, support workflow, or future cloud-connected AI feature, the prompts, files, images, inputs, outputs, authorization data, and technical metadata needed for that feature may be processed outside your device.
Third-party models and model hubs may have their own licenses, terms, and privacy practices. Review them before downloading or using a model.
7. How We Share Information
We do not sell personal information. We do not share Erebrus Drop file contents with advertisers. We may share limited information in the following circumstances:
- Service providers that help with hosting, security, support, payment processing, wallet connectivity, infrastructure, model delivery or catalog operations, analytics for non-Drop and non-local-AI services where used, and app operations.
- Blockchain networks, wallet providers, RPC providers, payment processors, or app stores when you choose to use those features.
- VPN, Firewall, and Drop node operators or infrastructure providers as technically necessary to provide routing, network protection, local transfer support, and optional storage. Drop storage operators may see metadata and stored bytes; private stored bytes are ciphertext.
- AI workspace operators, shared-node providers, nearby devices, or infrastructure providers as technically necessary when you choose shared inference, LAN discovery, support, or remote AI features. Local-only AI inference is not sent to NetSepio by default.
- Legal, safety, or compliance recipients when we believe disclosure is required by law or necessary to protect rights, users, the Services, or the public.
- Business transfer recipients if NetSepio is involved in a merger, acquisition, financing, reorganization, or sale of assets.
- Other people or services when you intentionally publish or share a Drop file, disclose its CID, share AI outputs, export content, post publicly, or contact support.
8. Cookies and Local Storage
We use cookies, local storage, and similar technologies to support authentication, wallet connection state, security, preferences, and product functionality. You can control cookies through your browser, but some features may stop working if cookies or local storage are disabled.
The Drop vault key and recovery secret are not placed in localStorage or persisted app state. The raw vault key is held in memory only while unlocked and is cleared by refresh, navigation, or an explicit lock.
Erebrus AI may store model catalog cache, downloaded model state, personas, settings, conversation history, prompts, and outputs locally on your device if you choose to save or cache them. Clearing app or browser data may remove that local state.
9. Legal Bases for Processing
Where laws such as the GDPR apply, we process personal data under one or more legal bases:
- Contract: to provide Erebrus VPN, Erebrus Firewall, Erebrus Drop, Erebrus AI, account access, subscriptions, and support.
- Legitimate interests: to secure, debug, improve, and protect the Services and users.
- Consent: where we ask for optional permissions or communications consent.
- Legal obligation: to comply with applicable law, legal process, accounting, tax, fraud prevention, and compliance obligations.
10. Data Retention
- Wallet authentication, organization, plan, payment, support, and operational records are retained as long as needed to provide the Services, resolve disputes, enforce Terms, maintain security, and comply with law.
- VPN client metadata may be retained while your client, account, or organization service is active and for a reasonable period after deletion for security, backup, audit, or legal reasons.
- Firewall configuration, credential, status, and audit records may be retained while your account, node, or organization service is active and for a reasonable period after deletion for security, backup, audit, or legal reasons.
- Local-only Drop Room transfers are not retained by NetSepio by default. Managed Drop files and metadata remain until deleted, expired, or removed under applicable policy. Public IPFS copies may remain outside NetSepio's control; encrypted private blocks may also persist as unreadable ciphertext on independent nodes or backups.
- Local Erebrus AI model files, personas, prompts, conversation history, and outputs remain on your device until you delete them, clear app data, or uninstall the app. Shared-node, support, or remote AI request metadata may be retained as needed to provide the feature, maintain security, troubleshoot, enforce Terms, and comply with law.
- Security logs may be retained for a limited period to detect abuse, investigate incidents, and protect the Services.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information. These may include access controls, encryption in transit where appropriate, logging, monitoring, secure development practices, and vendor review.
No app, VPN, firewall, AI runtime, model file, blockchain, wallet, browser, local network, or transfer method can be guaranteed to be 100 percent secure. Keep your devices, wallets, operating systems, browsers, local networks, firewall credentials, received files, prompts, and AI outputs secure.
AI outputs can be inaccurate, unsafe, or unexpected. Review outputs before relying on them, sharing them, or using them in sensitive decisions.
12. Your Choices and Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal data. You may also have rights to appeal a privacy request decision or lodge a complaint with a regulator.
- You can disconnect wallets, clear browser cookies, lock the Drop vault, delete managed Drop files, delete local AI models, remove personas or conversation history, disable LAN discovery where available, or uninstall the app through your device controls.
- California residents may have rights to know, access, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and be free from discrimination for exercising privacy rights.
- European Economic Area, United Kingdom, and similar-region users may have GDPR-style rights, including access, rectification, erasure, restriction, objection, portability, and withdrawal of consent where processing is based on consent.
- To submit a request, contact support@netsepio.com. We may need to verify your request before acting on it.
13. International Transfers
NetSepio and service providers may process information in the United States and other countries. Those countries may have data protection laws different from your location. Where required, we use appropriate safeguards for international transfers.
14. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and delete it where required.
15. Third-party Links and Services
The Services may link to or integrate with wallets, blockchains, app stores, operating systems, browsers, payment providers, node operators, AI model publishers, model hubs, support tools, and other third parties. Their privacy practices are governed by their own policies, not this Privacy Policy.
16. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify users, such as updating this page or providing in-product notice. The updated policy applies when posted unless otherwise stated.
17. Contact
Questions or privacy requests can be sent to support@netsepio.com.
Postal contact, if required: NetSepio LLC, Georgia, Tbilisi, Krtsanisi District, Nino and Ilia Nakashidzeebi Str., N1, (formerly Avlev), Bl. N3, Apt. N3.
Account deletion
You can request deletion of your Erebrus account and the personal data associated with it. Read the account deletion page for what is deleted, what may be retained, and how to verify ownership.
If you can sign in, request deletion from your Profile. If you cannot sign in, use the contact form with the “Account deletion” category.