Privacy Policy
Last updated: August 14, 2026 · Plain English. No legalese trickery.
The short version. Cerberus is built so that we (Viemme) never see the contents of your files. Your data is encrypted and decrypted on your own PC, with a key derived from a master password only you know. Our server only stores metadata required to run the service: file/folder names, sizes, device events, IP, Wi-Fi name. Nothing more.
Who we are
Cerberus is operated by Viemme, contactable at info@viemme.co.uk. We are the data controller for personal data processed via this website and the dashboard.
What we DO NOT see
- The content of your protected files. Encryption and decryption happen entirely on your PC, locally, using AES-256-GCM with a key derived from your master password (Argon2id).
- Your master password. If you set it directly on the agent (recommended for sensitive use), our server never sees it. If you change it via the dashboard, it transits in HTTPS to be hashed and is never stored in plain text — only a bcrypt verification hash is kept.
- Your encrypted
.cerberusfiles. They live on your PC. We don't upload them, store them, or back them up. - Your decryption key. Without your master password, even we cannot decrypt your files. There is no backdoor.
What we collect, and why
From a website visitor
- Standard server logs (IP, user-agent, timestamps) — security and abuse prevention. Kept up to 30 days.
- If you fill in the contact form: your name, email, company (optional) and message — only to reply to you.
- If you opt in: anonymised Google Analytics data — to understand traffic. See the Cookie Policy.
When you create an account
- Email address and a hashed password (bcrypt). Your plain-text password is never stored.
- Last login timestamp.
- If you opt in: marketing email consent.
- One-time codes for two-factor flows (short-lived, deleted after use).
From the agent on your PC
- Heartbeat metadata: device ID, status, timestamp, agent version, IP address, Wi-Fi network name (SSID), file count, last scan time.
- List of folders configured for protection (paths, not contents) and their subfolders, so you can manage exclusions from the dashboard.
- List of detected file copies outside protected folders: file name, source path, copy path, size, partial fingerprint (a SHA-256 of 4 KB at the start + 4 KB at the end — not enough to reconstruct the file).
- Device events: heartbeat, alert, encrypt, wipe, errors — for your timeline.
Why we collect IP and Wi-Fi SSID. So that the dashboard can show you when a device suddenly appears from a different network — one of the early signs of theft. We do not geolocate or share this with anyone.
Legal basis (UK GDPR / EU GDPR)
- Performance of a contract — processing required to deliver the service you requested.
- Legitimate interest — abuse prevention, security logging, debugging.
- Consent — for analytics cookies and (separately) for marketing email.
How long we keep your data
- Account data: while your account exists, plus 30 days after deletion to allow recovery from accidental deletion.
- Device metadata: deleted automatically when you remove the device from the dashboard.
- Server logs: up to 30 days.
- Email content sent via Brevo: as per Brevo's retention (typically up to 30 days for delivery logs).
Who we share data with
- Brevo (EU-based) — sends transactional emails (one-time codes, alerts, password reset) on our behalf.
- Google — only if you opt into analytics. Anonymised IP, no advertising profile.
- Aruba (EU-based) — hosts our server.
We never sell your data. We never share it with advertisers.
Your rights
Under UK GDPR / EU GDPR you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your account and associated data (you can do this from the dashboard, or by emailing us).
- Restrict or object to processing.
- Portability — receive your data in a machine-readable format.
- Withdraw consent for analytics or marketing at any time.
- Lodge a complaint with the UK ICO (ico.org.uk) or your local data protection authority.
To exercise any right, email info@viemme.co.uk. We respond within 30 days.
Security
- All web traffic is HTTPS only.
- Passwords are stored hashed with bcrypt; master passwords with Argon2id.
- JWT tokens are signed and time-limited.
- Server-side configuration (secrets, API keys) is kept outside the web root.
- The agent stores its local configuration encrypted with Windows DPAPI.
Children
Cerberus is not directed at users under 16. We do not knowingly collect data from children.
Changes to this policy
If we make material changes we'll update the "Last updated" date and, for registered users, notify you by email before the change takes effect.
Contact
Questions, requests, or concerns? Email info@viemme.co.uk.