Privacy

The short version: your archive lives in a cloud account under your own name, not ours. We never see what’s inside it, and if we disappeared tomorrow it would keep running without us.

Why this reads the way it does

Most privacy policies are written to protect a company from the people using it. This one explains something we’re proud of, so we’ve written it the way we’d explain it to a friend. It is still the real policy. If there’s ever a disagreement about what we do with your information, this is the document that counts.

Visible Storage is made by Pickaxe LLC, a small company in New York. Every “we” below is us. It’s invite-only while we’re in alpha, so it’s a small group so far.

Your archive is yours, and we don’t look at it

When you join, we set up a private server in a cloud account under your own name. Your photos, your posts, your messages, every export you feed it, all of it lives there. Not in a shared pile alongside other people’s memories.

Your archive never travels to us. No upload path pointing our way, no copy on our servers, no cache, no thumbnails, no search index. We don’t see your file names. We don’t know how many photos you have or who is in them. This isn’t a screen we’ve chosen not to build. Your collection simply isn’t something we hold.

We do hold the cloud credentials needed to build your server and keep it healthy. We use them for that and nothing else.

If we disappear

Worth saying plainly, because it’s the reason we built it this way. If Pickaxe stops existing, your archive doesn’t. It runs in your cloud account, on infrastructure in your name, billed to you. There’s nothing here for us to switch off and no scramble to get your things out before the lights go off. You’d lose us, which we would mind, and keep everything we helped you gather.

What we store about you

Effectively your email address, plus plumbing.

  • Your email address. It’s how you sign in and how we reach you, and it’s the only personal information we ask for. No name, no phone number, no mailing address, no employer.
  • Your server’s details. The cloud account it runs in, whether setup finished, and how it’s doing.
  • Your address on the web. The subdomain you picked, or your own domain if you brought one, plus the certificate records that make HTTPS work.
  • Timestamps. When you were invited, when your record last changed, when you last signed in.

Signing in

Magic links. You type your email, we send a link, clicking it signs you in. There’s no password to remember and none to reset. The link lasts fifteen minutes and works once.

Your browser then holds a session token for thirty days, in its own storage rather than a cookie. Signing out clears it. We don’t set cookies at all.

What your server tells us

Your server sends occasional health notes so we can spot something breaking before you have to. A dashboard light, not a diary.

  • Which version of which app it’s running, and in which region.
  • How close it is to the cloud provider’s service limits.
  • Whether any part of its setup failed, and the error if it did.

Infrastructure, not content. We keep it ninety days, then it deletes itself. Installations also report which versions are running so we know what to keep supporting. That report carries a random id we hash before storing, and we only ever read it as totals.

What we don’t do

  • No analytics. No Google Analytics, no Mixpanel, no tracking pixel, no session recording. We don’t know what you clicked.
  • No advertising, and no selling or renting your information. You paying for your own storage is the business.
  • No AI training on your data. Nothing here trains a model, ours or anyone else’s.
  • No third-party anything on this site. Even the fonts come from our own domain.
  • No location tracking, no fingerprinting, no cross-site profiles.

Who else touches it

Three vendors, and here’s what each one does.

  • Mailgun sends our email, so they see your address and the message.
  • MongoDB Atlas stores everything on the list above.
  • Amazon Web Services runs all of it, including the account your archive lives in.

Anyone we add goes on this page.

Keeping it safe

Everything moves over HTTPS. What we store is encrypted at rest by the services holding it, and the secrets your server needs live in AWS’s encrypted parameter store rather than somewhere we’d stumble across them. Access to production is limited to the people who need it, through single sign-on rather than shared passwords. Our own systems run in the United States.

Deleting things

Ask and it’s done. Email team@pickaxe.nyc and we’ll delete your record and release the infrastructure behind it. We’re small enough that a person does this rather than a button, so give us a few days and we’ll confirm. Backups age out within thirty days.

None of that touches your archive. It lives in your own cloud account, so it stays yours to keep, move or delete on your own schedule, with us or without us.

Your rights over your information

Wherever you live, you can ask what we hold, ask us to correct it, ask for a copy, or ask us to delete it. Some places give you those rights by statute. We don’t much mind whether you’re legally entitled to them or just curious, because the answer is yes either way. There’s no compliance portal to navigate. There’s an email address and a person who reads it, and we’ll come back to you within thirty days, usually a lot sooner.

If someone comes asking

Faced with a subpoena or a government request, we’d have very little to hand over. An email address and some server records. Your archive isn’t ours to give. If we’re allowed to tell you about a request, we will.

If something goes wrong

If your information is ever exposed, we’ll tell you promptly and plainly. What happened, what was affected, what to do about it.

Money

Nobody’s charged yet, the alpha is free. When billing arrives we’ll use an established processor, your card number won’t touch our servers, and this page will change before any of that goes live.

Kids

Visible Storage isn’t built for anyone under thirteen, and we don’t knowingly collect their information. If you think a child has an account, tell us and we’ll remove it.

Waitlist emails

If you gave us your email to hear about launch, we use it to tell you about launch. No marketing sequence, no sharing, and one reply asking us to forget you is enough.

When this changes

We’re building early and in the open, so this page will change. If something materially affects how we handle your information, we’ll email you before it takes effect rather than quietly editing the date below.

Talking to us

team@pickaxe.nyc reaches actual humans. Questions, requests about your data, or the discovery that we’ve gotten something wrong here are all welcome, the last one especially. This policy is governed by the laws of the State of New York.

Last updated August 3, 2026