Privacy & print access

The boundary,
stated precisely.

Noir Envelope is designed so cloud systems cannot read your photographs. Physical printing still requires a tightly restricted local release.

An important distinction

Noir protects print files while they are stored and transferred as ciphertext. When you submit an order, you authorize a dedicated production workstation to decrypt the final print-ready copy locally. An authorized operator may handle that copy only as needed to make, quality-check and pack your physical prints.

Operational disclosure · Version 1

What happens on your device

Your source photograph is selected and decoded inside your browser. Rotation, cropping, orientation, sRGB conversion, transparency flattening and JPEG rendering all happen locally. Re-rendering removes embedded metadata such as EXIF and GPS information. The source file itself is not uploaded by Noir Envelope.

What leaves your device

Your browser creates a unique 256-bit key for each final print-ready image. It encrypts the image in authenticated chunks and encrypts the file manifest. The image key is protected for the currently approved X-Wing production recipient. Uploads contain ciphertext, cryptographic integrity values, opaque identifiers and a wrapped key—not a readable photograph.

What cloud systems can and cannot know

Our infrastructure can know that an account or anonymous session exists, which print pack was selected, the number and approximate encrypted size of submitted images, order state, timestamps, IP/security telemetry, payment and delivery status. Shopify receives an opaque Noir print-session identifier and ordinary commerce information needed for checkout and delivery.

Cloud systems do not receive your source file, a readable print file, its encryption key, filename, photo preview, crop manifest, EXIF data or GPS location. They cannot create thumbnails, run image analysis or decrypt the stored ciphertext.

The trusted customer build pins an offline-signed production key set, which protects against a database or storage key substitution while that build is running. Like every web application, it cannot provide an absolute malicious-server guarantee if the entire deployed website itself is compromised and replaced. Deployment integrity, monitoring and independent review are therefore part of the security boundary.

Restricted local production access

The production recipient key is protected in the Windows workstation key store and is unsealed only inside the native host after authorization. USB A or B authenticates and unlocks the console; it does not carry the production recipient seed. The owner must also complete recent multi-factor authentication and receive a short-lived, single-use production grant. Decryption and image viewing happen locally on that workstation—not in a cloud admin panel.

A production operator can see the final print-ready copy after it is decrypted. This is necessary to print the physical product and may be necessary for a narrowly scoped quality check or approved reprint. Access and operational actions are audited. Staff cannot retrieve your original source file or an unreleased private-vault original.

Local handling and deletion

Temporary plaintext files are restricted to an encrypted, non-synced production workspace and scheduled for removal immediately after printing or within 24 hours, whichever occurs first. Print-spool behaviour and device cleanup are part of the production operating procedure. Once a file has been decrypted for authorized production, technical controls reduce—but cannot honestly make impossible—all human or compromised-device access.

Cloud retention

Future private vault

The future native Noir app is being built in a separate account, key and infrastructure domain for a local encrypted vault, optional encrypted backup and intentional sharing with other Noir users. Backup reuses the local immutable ciphertext while every share creates a freshly encrypted derivative. These capabilities remain disabled until their native, recovery, device-attestation and release gates pass independent review. Noir production equipment will not receive vault keys. Choosing “Print from Vault” will create a separate cropped production copy locally; the vault original remains encrypted.

Security limits

Noir cannot protect plaintext after an authorized device, user, recipient or print system intentionally opens it. Cloud systems can also observe opaque identifiers, ciphertext sizes, timing, routing and account or order relationships. Claims about post-quantum protection remain subject to independent review of the pinned implementation and wire protocol.

Questions or privacy requests

Contact privacy@noirenvelope.com. We will verify a request before discussing an order or account.

Choose your print pack