This document is published in English and in Korean, and both versions state the same obligations in full — neither is a summary. If you live in Korea, the Korean version is the one that governs your agreement with us, and the law of Korea applies to it (section 17). For everyone else, English is the canonical text; where a term is unclear, the reading more favourable to you prevails; and the mandatory consumer law of the country where you live prevails over both versions. Section 19 has the whole rule.
Read this first
These five facts decide whether NMTS is right for you. They are explained in full below, and you will be shown them again inside the product before they can affect you.
- Your account code is the only key. If you lose it, your account and your files cannot be opened again — not by you, and not by us. There is no reset and no backup held by us. (Section 4)
- The product includes a wallet derived from that same code. If you lose the code, any coins held at that wallet's address are lost as well — not only your files. (Sections 2.7 and 4)
- Deleting a file destroys the key we hold, not the stored bytes. The encrypted bytes stay on the storage network until the term runs out — for storage you paid for from your own wallet, we cannot recall them, and for storage bought with credits we can and will if you ask. Backup copies of our database taken for disaster recovery can hold the wrapped key for a while longer; that key still needs your account code, which we do not have. (Section 8)
- Storage is prepaid and ends. When the term you paid for expires, the storage network deletes the data and we cannot stop it or get it back. Payments for storage cannot be reversed or refunded. (Section 7)
- This is a beta. Its version number is below 1.0, parts are unfinished, and an independent recovery tool that works without NMTS does not exist yet. (Section 5)
1. Who these terms are between
1.1 "We", "us" and "our" mean the individual who operates NMTS under the name needmoretruth. NMTS is run by one person, not by a company. The foot of the product's pages shows the longer form NeedMoreTruth Storage; that names the same one person and is not the name of a company. Where these terms say "the developer", that means the same individual.
1.2 "You" means the individual person using NMTS. The service is offered to individuals, for personal use. It is not offered to companies or other organisations.
1.3 "NMTS" is the name of this product and of the file format it uses. "The service" means the NMTS website and application at nmts.me.
1.4 "The storage network" means the Walrus storage network and the Sui blockchain. These are public, permissionless networks. We do not own, run or control them, and neither we nor you can choose which computers store your data. Your browser reaches them through a small number of gateway services that we did choose; those are named in the Privacy Policy, section 9.
1.5 "Your account code" is the 160-bit secret that is generated in your browser when you create an account. Every key your account uses is derived from it — including the key of the wallet described in section 2.7.
1.6 By creating an account you agree to these terms, and we record which version of these terms and of the Privacy Policy you accepted, and when. That record is written in the same step that creates your account, so an account that exists without it cannot happen (section 5.4). If you do not agree, do not create an account.
2. What the service is, and what it is not
2.1 NMTS is three things, and it helps to keep them apart:
- a file format — a published, documented way of encrypting and arranging data, which anyone can read and check;
- software — the application that runs in your browser. It encrypts your files, keeps an index of them, helps you send them to and fetch them from the storage network, and includes the wallet described in section 2.7; and
- a small coordination server that we operate. It holds only the records listed in the Privacy Policy — account records, encrypted file lists, share records, support messages, and, if you open a board profile, your nickname and what you wrote on the board. It never holds your files in readable form, your keys in usable form, or your money.
2.1a The board is part of the service and has its own terms. It is a public place inside NMTS where you can write and read, it is off until you open a board profile, and opening one asks you to accept the NMTS Board Terms — a separate document, put to you separately, which governs everything the board does. Where those terms and these ones differ, the Board Terms say so in their own first section rather than leaving you to find it. Nothing on the board changes what happens to your files, your credits or your wallet.
2.2 The service is not the storage. Your encrypted files are held by the storage network's nodes, which are run by other people all over the world.
2.3 We do not hold your money. Payments for storage go from the wallet you use to the storage network. They do not pass through us, and we are not a party to them: we cannot start a payment you have not authorised, and we cannot stop or reverse one. The one exception is an upload paid for with credits under section 10, which we pay for from our own funds and which our own key signs; for those uploads the storage object is registered at our address, and section 10.11 sets out what that means for you.
2.4 We never receive your account code or any key derived from it. They stay in your browser, and we cannot reconstruct them. If you import an outside wallet (section 2.7), the product wraps that wallet's private key in your browser, under a key derived from your account code, and keeps the wrapped result on that device only — it is never sent to us and we hold no copy of it, wrapped or otherwise. On a new device, or after signing out on the same device, you import the wallet again.
2.5 Nothing here is for sale. You cannot buy storage, credits or features from us, and there is no way to pay us for the service. The only money that can reach us is a voluntary gift under section 11, and a gift buys nothing.
2.6 We do not provide the service for use in situations where a failure would cause serious harm — for example medical treatment, emergency response, or the operation of vehicles, aircraft or industrial plant. Do not use it as the only copy of anything you cannot afford to lose.
2.7 The product includes a wallet. When you create an account, the software in your browser derives a Sui wallet from your account code. Its private key is produced and used inside your browser; we never receive it and it is not stored on our server. Every transaction — paying for storage, sending, exchanging, giving a gift — is signed on your device and sent from your browser to the network. We are not a party to any of them, we cannot start one you have not authorised, and we cannot stop or reverse one. The wallet's address holds real coins on a public network: it is money, and losing your account code loses it (section 4). You can export the wallet's private key at any time from the wallet screen and use it in any other Sui wallet, and you can import an outside wallet instead (section 2.4).
2.8 What the wallet can do. Four actions can move value, and no others: paying the storage network for a term; sending coins to an address you choose; exchanging one of the two coins for the other, in either direction, on a public market that runs on the chain — today the product offers two, DeepBook and Bluefin, shows you what each would give you, and lets you choose; neither is ours — DeepBook is maintained by the company that also builds the storage network's software, Bluefin is independent of it — and we take no fee of our own from either; and giving a gift under section 11. For each of them the same three facts hold: you sign it, your browser sends it, and we are not a party to it and cannot reverse it. We do not buy or sell any coin, we hold no coin inventory, and we are never the counterparty to an exchange. If you have armed auto-approval, section 7.7 governs how signing can happen without a further confirmation.
3. Your account
3.1 To create an account you must be at least 14 years old, and you must also be old enough, under the law where you live, to enter into an agreement like this on your own — in several countries that age is higher than 14.
3.2 We do not ask for your name, your email address, your phone number or your date of birth, and we do not hold them. We therefore cannot check your age. What we do instead is state the requirement in 3.1 on the screen where you create your account, at the point where you accept this document, so that you read it before you agree rather than after. We do not treat the act of creating an account as a statement by you about your age, and we keep neither your age nor your date of birth — what we keep is the record that you accepted this document (1.6).
3.3 If you are a minor under the law where you live, you or your legal representative may be entitled to cancel this agreement. Because we do not charge you for the service, there is nothing we have taken from you for it; cancelling ends your use of the service. A voluntary gift under section 11 is different: if a gift was made by someone who could not validly make it, write to nmts@nmts.me and section 11.5 says what we can do.
3.4 One account is one account code. Anyone who has the code has the account. Keep it to yourself.
3.5 If you live in the European Union or the European Economic Area, you can withdraw from this agreement within 14 days of creating your account, without giving a reason: write to nmts@nmts.me, use the model form at the end of this document, or simply delete your account in the product. Withdrawing costs you nothing and takes nothing from you. One thing it cannot undo: storage you already paid the network for is a blockchain transaction we were never a party to, and it cannot be refunded by us or by anyone (section 7.8).
4. Your account code — a statement of fact, not a shifting of blame
FACT NOTICE
If you lose your account code, your account and everything in it become unreadable, and this cannot be undone. The wallet in the product is derived from the same code — if the code is gone, any coins at that wallet's address are lost as well, and no one can move them again.
This is not a rule we have chosen to impose on you. It is what the design makes true. Your files are encrypted with keys derived from your account code. We do not have the code, we do not have a copy of it, and there is no reset path, no security-question path and no support path that can recover it. When the code is gone, the keys are gone, and the encrypted bytes cannot be turned back into files by us or by anyone else.
4.1 Because of the notice above, creating an account has two steps you cannot skip. You must type your account code back in to prove you have written it down, and you must confirm that you understand what the recovery map does and does not do. The recovery map is an encrypted index of your files that you can choose to place on the storage network; we neither build, open nor check it. It is not a backup of your account code, and it cannot recover an account whose code is lost.
4.2 The product also offers you a recovery kit — a small text file containing your account code in readable form, your public account id, your account fingerprint, and the storage address of your recovery map if you have made one. It is built in your browser and it is not uploaded to us. Store it somewhere safe and offline. You can produce it again at any time, but only while you still have your account code. Because the account code is also the root of the wallet in the product, the recovery kit is a financial record as well as a data record: it protects any coins at the wallet's address.
4.3 You are responsible for keeping your account code safe, in the ordinary sense that only you can do it. Section 14 sets out what we remain responsible for, and nothing in this section reduces that.
4.4 If someone else obtains your account code, they can read your files and spend from the wallet in the product. Tell us at nmts@nmts.me if you think that has happened. We can sign your other devices out, but we cannot re-encrypt or lock data — or freeze coins — that a person with your code can already reach.
5. Beta status
5.1 The service's version number is below 1.0, and the service is described as a beta. This document does not carry the exact number, because it changes with every release; the product shows it in two places: the build line at the foot of your account screen, and the update log, which anyone can read without signing in. That word is doing real work here, so we set out what it means in practice rather than disclaiming everything at once. We stop describing the service as a beta when its version number reaches 1.0, and not before.
5.2 Concretely, at the effective date of these terms:
- Parts of the product are still being built. Where that is true, the product says so on the screen where the feature would be.
- An independent recovery tool does not exist yet. Opening your files today means using NMTS. We intend to publish a tool that can decrypt your files without NMTS. Until that exists, your files can only be opened while NMTS itself is available.
- The service is operated by one person. There is no overnight support rota. An outage can last as long as it takes one person to notice and fix it.
- We add, change and remove features while the version number is below 1.0. Section 15 governs how we tell you, and 5.6 below governs what we may change and what your rights are when we do.
5.3 We do not disclaim everything by writing "as is". Instead: we tell you what is unfinished, we do not promise the service will be available without interruption, and section 14 sets out what we do remain responsible for.
5.4 Separate acceptance, and where it exists. Four things are put to you separately in the product, and you cannot get past them by scrolling. Creating an account makes you type your account code back in and tick that you have understood what the recovery map does and does not do (section 4.1). Arming auto-approval makes you re-enter your account code (section 7.7). Entering the preview build — if you choose to, and it is not always open — puts its own warning in front of you and records which version of that warning you agreed to. Opening a board profile puts the Board Terms in front of you as their own document with their own acceptance (2.1a), recorded by their own version; the board's two optional switches are separate again, each off until you turn it on and each recorded when you do. The other facts in this document — that storage ends when the term ends, and the beta limits listed in 5.2 — are shown on the screens where they apply and are not put to you as a second acceptance. Your acceptance of these terms is recorded by version: once when your account is created (section 1.6), and again each time we publish a new version and you accept it (section 15.5). We keep one record for each pair of versions you have accepted — recording the same pair again does not add another — earlier pairs are kept rather than overwritten, and they are all deleted with your account. The record names the Privacy Policy version too, because the two documents are published together; that part of the record shows which policy you were shown, and is not a consent to processing — the policy's own section 7.3 says why we do not ask for one for the service itself, and names the two board switches that are the exception.
5.5 If the service does not work as it should. Where the law where you live treats this agreement as the supply of a digital service — in the European Union it does — you are entitled to a service that works as this document says it does. If it does not, you can require us to put it right, and if we cannot or do not, you can end the agreement. For a problem that appears while we are supplying the service, it is for us to show the service was in conformity, not for you to show it was not. Nothing in this document reduces those rights.
5.6 What we may change, and your exit. We change the service only for these reasons: fixing faults and responding to security problems; following changes in the storage network's own formats, rules or prices; complying with a law; or adding and improving features during the beta. We announce any change that removes or reduces something you can do before it takes effect (section 15.3), on the notice board, which is public, dated and stays there for you to save or print. If a change makes the service worse for you in more than a minor way, you can end this agreement free of charge within 30 days of the later of the day the change happened and the day its notice first reached you, and section 16.2 — your files stay in your hands — applies as always; 15.6 says what ending the agreement does and does not do.
6. Encryption, and the limits of what we can say about it
6.1 Files are encrypted in your browser before any part of them leaves your device. File names and your folder structure are encrypted too, and they are held on our server only inside one encrypted blob per account that we do not have the key to. Where these terms call a record "encrypted", they mean encrypted in your browser with a key we do not have. The encryptions where we do hold a key are two, the same two the Privacy Policy names: the connection between your browser and us, and the backup of our database (8.6) — and every sentence about the backup says "backup" in the same breath.
6.2 We cannot decrypt the files that are already stored. The keys are derived from your account code, which we do not have.
6.3 The honest limit of that statement is this: we also write and distribute the software that does the encrypting. A statement about stored files is a statement about the past. It is not a promise that no future version of the software could behave differently, and you are relying on the code your browser actually runs. The encryption engine's source, the format specification and the conformance vectors are published — at github.com/needmoretruth/nmts-crypto, under the GNU Affero General Public License v3.0 — so that the format can be checked rather than believed. Reading them tells you what a browser should receive, not what yours received: we do not yet build the software so that anyone else could repeat the result byte for byte, and we publish no fingerprint of each release, so nothing there lets you verify the code your browser is running at this moment. Privacy Policy 4.3 says the same thing in the same words. The same limit applies to the wallet. We write the code that derives your wallet key and signs your transactions, and your browser runs the version we serve. We do not hold the key and we cannot sign in your place; but you are relying on the code we ship, and if you have armed auto-approval (section 7.7), that code can sign without asking you first. We publish the wallet's key-derivation format too, and you can export your key and use a different wallet at any time.
6.4 What our server does hold, and what it can therefore see, is listed in the Privacy Policy. It is not nothing: it includes how many files you have, how large each one is, and when each was created, changed or deleted.
7. Storage terms and expiry
7.1 Storage on the storage network is prepaid for a fixed term, measured in the network's own units of time ("epochs"). You choose the term when you upload — except on the credit rail, where the term is fixed (section 10.3a).
7.2 You pay for the term from the wallet in the product, or from an outside wallet you imported, in a transaction you sign yourself. The payment goes to the storage network. We are not a party to it: your wallet signs the order and your browser sends it — we supply the software.
7.3 When the term expires, the storage network deletes the data. We cannot prevent that, delay it or recover the data afterwards. Neither can you.
7.3a Storage bought with credits: two differences. Storage bought with credits is registered to us, not to you (section 10.11), and that has two consequences we would rather state than have you discover. First, we hold the storage object, so we are able to end it before its term runs out — the only occasions on which we do are listed in 8.2. Second, you cannot extend it, because extending is a transaction signed by whoever holds the object; and today we have built no way to extend it either, so when its term ends the storage network deletes the data. The product shows you the end date.
7.4 Extending a term is a new payment, signed by you, every time — for storage registered to your own wallet. Storage bought with credits cannot be extended, by you or by us (section 7.3a). We do not extend anything automatically, we never initiate a payment from your wallet ourselves, and the only way value leaves your wallet without a per-transaction confirmation is an auto-approval you armed under section 7.7.
7.5 The product warns you before a term ends — unless you have turned that warning off. You can set when it comes, and you can turn it off for good; turned off, no warning goes out. The warning appears inside the product only. We hold no email address or phone number for you, so if you do not open the product you will not see the warning. For storage bought with credits the warning is information and not something you can act on: see 7.3a.
7.6 The dates the product shows for an expiry are not exact. Epoch length is set by the storage network, not by us, so the exact moment can move. Where the product can only work out a floor, it shows the floor and says so — "at least N days left", "on that date at the earliest". A floor is not an estimate: the real end is that day or later, never earlier. Where a single date is shown without such a word, that date is an estimate, and the product says so there.
7.7 Auto-approval. You can choose to let the device you are using sign without asking you each time. There are two settings: storage only, which covers the per-signature confirmations of uploading files — the first payment approval of each upload, where the storage length and its cost are decided, is always asked — and everything, which also covers sending and exchanging. Everything means value can leave the wallet on that device with no further confirmation and with no amount limit, for as long as you set, up to 30 days. It is off unless you turn it on; arming it requires re-entering your account code; and you can turn it off at any time from the wallet screen, without your code. We never hold the authorisation — it is stored, encrypted, on your device. Turning it off removes the record from that device, and there is one thing it cannot reach: a copy of that record inside a backup of the device's own storage. Restoring such a backup before the period you set has run out brings the authorisation back with it. Gifts are in neither setting. Even with auto-approval on, you approve each gift separately (article 11).
7.8 Storage payments cannot be reversed or refunded. A payment for a storage term is a blockchain transaction. Once you have signed it and it has confirmed, it cannot be reversed by us, by you, or by the network, and there is no one to refund it: we were never a party to it, and the network has no refund mechanism. If you later lose your account code (section 4), or file records are removed under section 12, the term you paid for keeps running and the payment does not come back.
7.9 Asking which countries hold your data. You can ask us at any time which countries your stored information is in. The Privacy Policy, section 9.7, says exactly how we answer and what the limits of that answer are.
8. Deleting things
8.1 There are two different things people mean by "delete", and they have different effects. We use different names for them in the product and here.
8.2 Destroying the key. This is what happens when you delete a file in NMTS.
- The file moves to the trash. You can restore it from there.
- After 30 days in the trash, the record of the file and the wrapped key we hold are deleted from our database. The copy of the key inside your own encrypted file list is removed on the same 30-day schedule.
- You can also destroy the key immediately, without waiting 30 days, by erasing the file outright or emptying the trash.
- Once the key is gone, the encrypted bytes cannot be turned back into your file.
- The encrypted bytes stay on the storage network until the term runs out, and for a file you paid for from your own wallet we cannot recall them — that storage object belongs to your wallet, not to us. Storage bought with credits is different: we bought it, so the storage object is held at our address and is registered as the kind its owner can destroy early, and we are able to release those bytes before the term ends. We do that on three occasions and no others: when you ask us to; when a report under section 12 is made out against the file; and when a binding legal requirement addressed to us demands it. Where we can, we tell you first; otherwise we tell you afterwards, and section 12.5 says where we are able to put that notice. In every case the bytes cannot be read without the key.
- Backup (disaster-recovery) copies of our database made before the deletion can still contain the wrapped key for the period set out in the Privacy Policy, section 8. The wrapped key in those copies is no more openable than the one we deleted — it still needs your account code, which we do not have. The backup copy itself is a different matter: it is encrypted with a key we hold, because restoring the service is what it is for, and the Privacy Policy says what is inside it.
- If you had shared the file, a recipient whose device already unwrapped its key can still fetch and open the encrypted bytes until the term ends (section 9.5).
8.3 Removing the data from the storage network. Where the network's own rules allow it, the product can ask the network to release the storage you paid for. That is a transaction you sign yourself. It works only for storage registered to your own wallet, and where your file shares space with others it does not work either. Storage bought with credits is registered to us (section 10.11), so you cannot release it yourself — write to nmts@nmts.me naming the file and we release the storage object and confirm the transaction to you.
8.4 We do not describe a deleted file as gone for good, because while the encrypted bytes are still on the storage network that would not be true. The storage network is not ours. Walrus and Sui are public networks that we do not own or run, we hold no key to your files, and we hold your storage only where we bought it ourselves. So our power over stored bytes is not a matter of policy, it is a matter of who holds the storage object: where you paid from your own wallet it is yours and only your signature releases it; where credits paid, it is ours and we release it (8.2, 8.3). Beyond releasing the object there is no instruction either of us can send — nobody can require a storage node to discard a copy it has already taken, and we do not claim we can.
8.5 Deleting your account deletes the rows we hold for it: the account record, the file records, the encrypted file list, your encrypted device labels, your sessions, your shares, your credit ledger, the record of which version of these documents you accepted, your preview-channel record if you entered the preview build, any record that a free-trial application of yours was refused because the week was full, your board profile and everything you wrote on the board, your board terms acceptance and consent ledger, your notice box, your nickname history and the board's own counters for you, and any support inquiries linked to it. There is no condition attached and nothing we can point at to refuse it. One record is not deleted, and it is not about you: when we ourselves have done something to an account — granting credits, answering an inquiry — we keep our own note that we did it, because a record of what the operator did is not the operator's to erase. In the same step that deletes your account we strip your public code out of that note, so what is left says what was done and no longer says to whom. Deleting your account does not reach the storage network, and it does not reach the public blockchain record of transactions your wallet signed.
8.6 Backups are dealt with in the Privacy Policy. In short: our encrypted backup copies of the database — the disaster-recovery copies, encrypted with a key we hold (6.1) — may still contain data for longer than the periods above, and we do not promise otherwise.
9. Sharing
9.1 Every account has a public code. It is a short public value derived from your account. Giving it to someone lets them send you a file. On its own it does not open anything of yours.
9.2 When you share a file with someone, the product wraps that file's key so that only their account can unwrap it, and stores the wrapped key on our server against their account.
9.3 Our server therefore knows who shared which file with whom, and when. It does not know what the file is called, what it contains, or whether the recipient ever opened it — we keep no record of opening.
9.4 A recipient gets the file's size, the encrypted key material, and the sender's published sharing identity. They do not get your account code and they do not get your other files.
9.5 Either the sender or the recipient can undo a share. Doing so deletes the server-side record, and the recipient can no longer reach the file through NMTS. It does not reach a copy the recipient has already downloaded, and it does not take back the key material their device already received: anyone holding that key and the file's storage address can still fetch and open the encrypted bytes until the paid term ends, because the storage network serves its blobs to anyone who asks by identifier. Share only with people you would trust with the file itself.
9.6 What our server holds about shares is set out again in the Privacy Policy.
10. Free trial credits
10.1 While we run a free-trial programme, this section governs it. We may offer a limited number of free trial credits each week, and there may be weeks in which none are offered. Credits are a benefit we give away. They are not sold, and there is no way to buy them. If we ever start charging for credits, that will be a new version of these terms, announced under section 15, and the wording of this section will change with it.
10.2 Trials are handed out first-come, first-served in a fixed weekly batch. One account can win at most once per ISO week.
10.3 A trial is a fixed bundle of storage credits. The product shows the size of the current bundle before you apply, and the date the credits expire when they arrive (section 10.8).
10.3a What credits can and cannot do. Credits can pay for large files as well as small ones, within two ceilings that protect the funds that sign the payment: one file may cost at most 2,048 credits (about 2 GB at the fixed term), and one account may spend at most 4,096 credits a day (the day turns at midnight UTC). Where both a wallet and enough credits are available for a large file, the product asks you which one pays before anything starts. The product shows both ceilings before you confirm. A file that would cost more than the per-file ceiling is refused before anything is bought. The day's ceiling works differently: what your account has already spent today lives on our server and can move from another device, so your browser cannot know the remainder — a large file is paid for one piece at a time, and if the day's ceiling is reached partway, the pieces already paid for stay paid for and the upload waits; you can finish it after midnight UTC, or upload the file again from your own wallet. The storage term on this route is fixed at 28 days and you do not choose it, unlike an upload you pay for yourself; the exact end moment follows the storage network's own clock (7.6). And storage bought with credits cannot be extended — not by you, and today not by us either (section 7.3a): when its term ends, the storage network deletes the data. So if you need a file for longer than 28 days, pay for it from your own wallet from the start, with the term you actually need — the product says this again where you choose how to pay.
10.4 An upload paid for with credits is paid for by us: the transaction fees and the storage network's own charges for it are paid from our funds, not from your wallet.
10.5 Credits are non-transferable. You cannot give them to another person, sell them, or exchange them for money or for anything else, and there is nothing we or anyone else will give you in return for one. They can be used only inside NMTS. Two facts make that checkable. Credits are not a coin and are not recorded on any blockchain — they are a number on our own server. And the only thing a credit can ever be spent on is storage that we buy from the network on your behalf; there is nothing else to redeem them against, inside NMTS or outside it. What a credit costs us is not a secret — we buy real storage with real funds, and 10.4 says so — but that cost is ours. It is not a price you owe and not an amount you can claim.
10.6 A credit leaves your balance in exactly three ways and no others: you spend it, it expires (section 10.8), or we take it back on one of the grounds listed here. We do not take credits back for any other reason and not at our discretion:
- (a) you obtained them by breaking section 12 or by working around the one-win-per-week limit — for example by creating extra accounts;
- (b) they were issued by mistake, including a technical fault on our side;
- (c) a binding legal requirement addressed to us — a law, a court order or an order of a regulator — requires it.
10.7 If we take credits back under (b) we will tell you first where we can, and we will not disturb storage that has already been paid for with them. If we take them back under (a) or (c), we will tell you what ground we relied on. Section 12.5 says where we are able to put a message like that.
10.8 Unused credits expire. A trial bundle lasts 28 days. The product shows you the expiry date when the credits arrive, and your account screen shows the earliest expiry date among the credits you are holding; those are the two places the date appears, so check it there. Expiry is not a penalty and not a forfeiture of anything you paid for, because you paid nothing.
10.9 A trial gives you no priority, no different service level and no promise that trials will continue.
10.9a When we pause the programme. A free giveaway with no identity check is a target for someone creating accounts in bulk to sweep a week. We watch for it by counting how many separate accounts were turned away from a week that was already full; when that count runs far past what a real week produces, the programme pauses by itself and every application — including the following week's — is refused until a person has looked at it and restarted it. A pause is not a decision about you and is never recorded against you as a breach of section 12. What we keep from a refusal is that your account applied in that week and was turned away. We keep it for the ISO week in which it happened and for the eight complete weeks after that week: an hourly sweep removes it once its week is more than eight complete ISO weeks old, so one refusal record can stand for up to nine calendar weeks in all. It goes sooner when your account goes (section 8.5). The Privacy Policy says the rest.
10.10 We can also give credits outside the weekly trial — for example to put right a fault on our side, or as part of a programme we have announced. We do this on our own initiative; there is no way to ask for such a grant and no way to earn one. We choose how long such a grant lasts, in steps of two weeks and never more than 52 weeks, and your account screen shows the expiry date alongside the credits. We do not give credits in return for a gift under section 11 — in any amount, at any time.
10.11 Storage paid for with credits is registered to us, not to you. We pay the network from our own funds, our own key signs the transaction, and the storage object is held at our address. The public record of that transaction therefore shows our wallet, not yours. Two consequences follow, and we would rather you heard them here. First, we are able to destroy that storage before its term ends — it is registered in a releasable form on purpose, because storage that could never be reclaimed would tie up our funds forever. The occasions on which we do it are the three listed in 8.2, and no others. Second, you cannot release it yourself under section 8.3, because it is not registered to your wallet; write to nmts@nmts.me and we will release it. Everything else about the file is unchanged: it is encrypted with your keys and we cannot read it.
10.12 When a credit-paid upload does not go through. Spending credits happens in two steps: we take the credits, then we buy the storage from the network. If the purchase fails, the credits go back to you in full, automatically, and you can try again. If we ask the network to buy and never learn whether it did — the answer was lost, or did not arrive in time — we cannot tell whether your storage exists, and the credits go back to you in that case too. Returned credits keep the expiry date they already had, and if that date has passed by the time they come back — the attempt failed in the last minutes of a bundle's life — they are issued to you again as a fresh grant, so that what comes back is always visible in your balance and can be spent. You do not have to ask, you do not have to prove anything, and there is nothing for you to do except upload the file again. That outcome is a failure on our side, and carrying its cost is ours as well. Nothing in this section takes away any right you have under the law where you live to require us to supply what we agreed to supply, or to end this agreement if we do not.
11. Donations
11.1 You can send a voluntary gift to the developer. This is a gift, not a purchase.
11.2 Nothing is provided in return. No storage, no credits, no features, no priority, no badge, no listing. Anyone who gives nothing gets exactly the same service. We also do not exchange, convert or hold any coin on anyone's behalf.
11.3 Today there is one way to give: in SUI or WAL, from the wallet in the product, to the single address shown on the donation card. Both coins arrive at that same address; no other coin and no other address are offered. If we later publish addresses for other coins, each will carry its own receiving address and its own supported networks alongside it. A transfer sent to a wrong address, or on a network that address does not support, is lost, and we cannot recover it — check the coin, the address and the network before you sign. We are not the counterparty to any of these transfers; we publish an address, nothing more. We do not record donations in our database. Like every blockchain transfer, a donation is visible on the public ledger of the coin you used.
11.4 A gift is used at the developer's discretion. We make no promise about what it will be spent on, and nothing in the product converts a gift into storage, credits or any other benefit for you. Where the product shows a figure beside a gift, it is an illustration of scale, never an undertaking to spend it that way.
11.5 A blockchain transfer cannot be reversed once it is signed and confirmed — by us or by anyone else. Until you sign, you can simply change your mind. Where a law that you cannot contract out of gives you a claim about a gift — for example, a gift made by a minor — we can act on it only if you can identify the transaction: the transaction id from the product, or a signature from the sending address. We keep no record of who gave what, so we cannot find it for you. The product tells you this before you sign, and asks you to confirm.
11.6 A gift never pays for another person's storage as such. There is no way for you to pay into a fund on someone else's behalf: the donation card offers the developer and nobody else.
12. Acceptable use
12.1 Do not use the service to store, share or distribute:
- material that sexually exploits children — prohibited everywhere, always;
- material that infringes another person's rights;
- anything whose storage or distribution is a crime under the law where you are.
12.2 Do not attack the service: no attempts to break into other people's accounts, no automated flooding, no bypassing the human check or the rate limits, no probing for weaknesses without telling us first at nmts@nmts.me.
12.3 We cannot see what you store. That is the point of the design, and it is also the honest limit of enforcement here: we do not scan, we do not monitor, and we cannot detect prohibited content by ourselves. What we can do is act on reports.
12.4 Reports and notices. If you believe something stored or shared through NMTS infringes your rights or is unlawful, write to nmts@nmts.me. This address is also the point of contact for copyright takedown notices. Tell us:
- (a) what you are complaining about, precisely enough for us to identify it — normally the public code or the share involved;
- (b) why it infringes your rights or breaks the law, and on what basis you are entitled to complain;
- (c) how to reach you; and
- (d) a statement that you believe, in good faith, that what you have told us is accurate and complete.
12.5 What we will do, and how you hear about it. We confirm that we received your report. We look at every report we can identify, by hand — no automated system decides. Where a report is made out, the measures available to us are to remove the server-side records that let a file be reached through NMTS — the share record, or the file record; to release the storage object itself where the file was uploaded with credits and the storage is therefore ours (section 8.2); and to stop serving the account involved (16.3). We take them without undue delay, by hand, one at a time; no automated system performs any of them. When we decide, we tell both the person who reported and the person affected, promptly. We can write to the person who reported, because they gave us a way to reach them. For the person affected we hold no email address and no phone number, so the only places we can put it are the support inbox in the product, if a conversation is open there — where we also answer you — and, where the matter is not particular to one person, the notice board described in 15.3. We tell each of them:
- what we did, or declined to do, and its scope and duration;
- the facts and the ground we relied on — the law, or the clause of these terms;
- that no automated tool made the decision; and
- how to challenge it: reply to us, complain to a court where you live, or — where your country provides one — take it to an out-of-court dispute- settlement body.
Where we cannot tell whether a right has been infringed, or the two sides disagree, we do not act against the file while it is worked out. We have no way to hold one file back for a while and then put it back: the measures listed above are the only ones we hold, and each of them is permanent. So we would rather do nothing, and say that we are doing nothing, than remove something we may have to restore. We tell both sides where the matter stands, with the same information as above, and we look again as soon as either of them gives us something new.
If you tell us we acted wrongly and explain why, we look at it again and tell you what we decide. Two things we cannot do, and would rather write down than leave you to assume: a record we have deleted cannot be brought back, and a storage object we have released cannot be bought back. That is the reason we do nothing while we are unsure.
12.6 What we can and cannot do about stored bytes. We cannot read the file. What we can do about the bytes on the storage network depends on who the storage is registered to. Where it is registered to us — uploads paid for with credits (section 10.11) — we hold the storage object and we can ask the network to release it, and we do that on request or where a report is made out. Where it is registered to your own wallet, only you can do it, from inside the product: we can supply the software, not the signature. In either case releasing the object ends the storage we know of; we cannot prove that every node has discarded every copy it already holds, and we do not claim it. Removing our records only stops the file being reached through NMTS; it does not erase it from the world.
12.7 Where a law that applies to us requires us to keep material rather than delete it — for example where there is a preservation duty — we keep it and do not destroy it, unless following that demand would itself be unlawful under the law that protects you (for people in the European Union, a third country's order is only followed where an international agreement provides for it). When we act on a report we mark the item concerned, and a marked item is left out of the automatic deletion described in section 8 for as long as the mark stands. Reports reach us by email at nmts@nmts.me or through the support inbox. On the board there is a report button on every post and every comment, and the Board Terms describe what it does, who hears the outcome and in what time; a report about anything else still reaches us by email or through the support inbox.
12.8 Repeated infringement. We cannot find infringement ourselves; we act on reports. If reports show that an account is being used again and again to infringe other people's rights, we stop serving it (16.3).
12.9 If an authority orders us to act. What we can be made to hand over is what we hold: the records listed in the Privacy Policy, section 2 — account records, file sizes and timestamps, share records, and any support text still inside its 30 days. What we cannot produce, for anyone, is the content of your files, because we do not hold the keys — and their names, with one exception: names that you yourself attached to a support inquiry that is still inside its 30 days. We check that a demand actually binds us — for data you stored, that means a court order or a warrant issued by a judge — and we do not hand over records voluntarily to anyone, government or not. We keep a record of every disclosure, and we tell the affected person — in the places 12.5 lists, which are all we have — unless the law or the order itself forbids us from telling them. We do not publish a transparency report today; if that changes, section 15 governs how you hear about it.
13. Support
13.1 You can write to us through the support inbox in the product, or at nmts@nmts.me.
13.2 Text you write to us is stored in readable form in these places, and in no others: the support inbox in the product — both what you type and anything you choose to attach to it, such as a list of your file names; a report under section 12.4 if you send one; the board, where what you write is meant to be read and our server holds it in readable form for that purpose; and, if you email us, the mailbox that receives our email, which is run by our mailbox provider (named in the Privacy Policy). Whatever you write there, we can read. Do not paste your account code, and do not paste anything you would not want us to hold.
13.3 A support inquiry is held for 30 days and is then deleted from our live database, with any replies. You can withdraw an inquiry earlier, which deletes it straight away from that database. A backup copy taken before you withdrew it can still contain it; the Privacy Policy says for how long.
13.4 There is a length limit on inquiries and a limit on how often they can be sent. Both exist to keep this one plaintext surface small.
14. Our responsibility to you
14.1 Nothing in these terms excludes or limits any liability that the law where you live does not allow to be excluded or limited. If any part of this section conflicts with such a law, that law wins and the rest of this section still applies.
14.2 We are responsible to you for harm we cause intentionally or by gross negligence, and for death or personal injury caused by our negligence. We do not attempt to exclude any of that.
14.3 We are also responsible where we fail to do the things these terms say we will do and that failure causes you harm.
14.4 Subject always to 14.1 to 14.3, and except where the harm was caused or contributed to by our own breach of these terms or of the law, we are not responsible for:
- (a) loss of access caused by losing your account code (section 4);
- (b) the storage network deleting data you paid for from your own wallet when that term ends (section 7), and the ending of storage bought with credits at the end of its term — but not our releasing it early, which section 8.2 governs and which 14.2 and 14.3 reach in full;
- (c) what the operators of the storage network's nodes do or fail to do. We do not choose which nodes hold your data — though we did choose the network itself and the gateway services named in the Privacy Policy, and 14.2 and 14.3 apply in full to those choices. Distributed storage run by strangers is not a defect of the service; it is what the service is (sections 1.4 and 2.2);
- (d) the contents of the public blockchain record, which we cannot alter;
- (e) what someone does with a file after you have shared it with them;
- (f) transactions signed under an auto-approval you armed (section 7.7), except where 14.2 or 14.3 applies.
14.5 We do not set a monetary cap on our liability. We do not charge you, so a cap expressed as a share of what you paid us would be a cap of zero, and we do not think that is a fair term to ask you to accept.
14.6 If a court finds any part of these terms invalid, that part does not apply to you, and the rest continues to apply.
15. Changes to these terms
15.1 Each version of these terms has a version string in the form YYYY-MM-DD-vN and an effective date. Both appear at the top of the document. The date in the version's name is its effective date. Effect begins the moment that day's release goes live (UTC); the update log records the minute.
15.2 We do not edit a published version in place. A change means a new version with a new version string and a new effective date. We keep every version we have published and will send you any of them on request at nmts@nmts.me. The product displays the version in force; it does not yet display the earlier ones.
15.3 We announce every new version before it takes effect, on the notice board — at least seven days before it takes effect, and at least thirty days before, where the change is to your disadvantage. These two periods apply to every version published after this one. The notice board is where we put everything we say to you as a service: it is a page inside the product and on the website, readable without an account, every notice on it carries the date it was posted, and notices stay there — you can save or print what one says, and every notice carries a button that saves it as a dated file in both languages, so what you keep is a copy and not a link. When a notice — or the chain of notices it corrects and extends, which the board and the saved file keep together — announces a new version of these documents, that chain sets the passages that change side by side: what the words say now, and what they will say. It is not the update log, which is the list of what changed in each release. While a notice is current, a line above every signed-in screen points to it until you dismiss it; and where you have a support conversation open, we answer you there. We have no email address, no phone number and no postal address for you, so the board and that conversation are the whole of our reach.
15.3a The limit of the way we tell you. Because we hold no address of any kind for you, a notice cannot be sent to you personally; it waits on the board until you come, and the board is the whole of our reach. So the screen that asks for your acceptance (15.5) also offers the notice as a file made out for your account: it names the versions in force, the versions you last accepted, the date you saved it, and your right under 15.6, so that what you keep is a dated copy addressed to you and not a link. A change cannot start the 30 days in 15.6 before it has reached you.
15.4 Changes do not apply backwards. A dispute that has already arisen, and storage you have already paid for, are governed by the version that was in force at the time.
15.5 Continuing to use the service after a change is not, by itself, how you accept it. What the service does instead is refuse a short list of requests until your acceptance of the new version has been recorded: uploading a file, creating a share, publishing your sharing identity, and entering the preview build. The reason for refusing is a single one: each of those hands us, or takes on, something new, and a request like that has to happen under the version in force at the time — we must be able to show which version you had agreed to when you did it. Nothing you already hold is touched by this refusal. Anything we add later that changes something you hold or takes on something new joins the refused side by default — including, today, requests to features that are not switched on yet. The requests that are never refused are these, and this list is the whole of it: reading your drive, downloading your files, deleting a file, emptying the trash, restoring one from the trash, renaming and rearranging what you already hold (making a new folder is part of that), recording a storage extension your wallet has already paid for, applying for free credits, undoing a share, withdrawing a support inquiry, making or updating your recovery map and taking it with you, signing out of this device or other devices, writing to the support inbox, and deleting your account. Accepting is not the price of any of those. Nothing on that list is ever refused for want of your acceptance — including downloading everything you hold and taking your recovery map with you. (What a storage term does when it ends is a separate matter; sections 7.3 and 7.3a say it.) The refusal itself happens under this clause of the version you accepted: when a next version takes effect, this clause is what refuses the four requests from then on, and the rest of the new version does not apply to you until you accept it. A new version of the Privacy Policy alone has the same effect — the four requests wait until the acceptance record for the new pair (5.4) has been made.
The product asks for that acceptance on a screen. When you sign in after a change, that screen comes before the rest of the product. It names the version in force and the version you last accepted, links to the full text of both documents and to the notice board where we describe what changed (15.3), and takes your acceptance with two tick-boxes and a button. The first tick is your acceptance of these terms — that is the consent this screen asks for. The second confirms that you have read the Privacy Policy; it is a confirmation of what you were shown, not a consent to processing, and the policy's own section 7.3 says why we do not ask for one. Beside the button is one that puts the screen off — choosing it is how you reach your drive and your files without accepting — and taking it leaves a line above your screens that opens this screen again; the next time you open the product the screen comes first again. The screen never stands in front of the two documents themselves, the notice board, the support inbox, or the screens where you delete your account — you can reach all of those without accepting anything, and without putting it off first. If the change takes effect while you are signed in, we do not take away the screen you are working on, as a rule; where the product could not confirm your standing when you arrived, the acceptance screen may come first instead.
We do not summarise the change on that screen — what changed is written on the notice board (15.3), so that what you are asked to accept is the document itself and not our account of it. If the screen cannot take your acceptance — a browser holding an older build of the product will say so and ask you to reload — reload first; signing out and signing back in also fetches the current build. If neither fixes it, write to nmts@nmts.me: the fault is on our side, and we will put it right. While you have not accepted a new version, the version you last accepted remains the agreement between you and us — a new version does not apply to you until you accept it. For any storage term you had already paid for, the version you accepted when you paid keeps governing that term until it ends (15.4).
15.6 Why we may change these terms, and what you can do about it. We change them only for one of these reasons: to correct something that has stopped being true about the service; to follow a change in the law or in a ruling that binds us; to follow a change in the storage network's own rules, formats or prices; to describe a feature we have added, changed or removed under 5.6; or to make an obligation of ours clearer or stronger. We do not change them to take away a right you already have under the version you accepted. If a new version affects your use of the service in more than a minor way, you may end this agreement within 30 days of the later of the day it took effect and the day its notice first reached you, and we will not charge you anything for doing so. Whether the effect on you is more than minor is yours to judge — we do not refuse this right by judging otherwise — and the notice that announces a change says whether we think this right applies, so that you can weigh our view against your own. Two things we would rather you heard here than found out later. Ending this agreement is completed by deleting your account (16.1), and that step destroys the encrypted file list and the wrapped keys we hold (8.5); the encrypted bytes stay on the storage network until the term you paid for runs out, and no tool opens them without NMTS yet (5.2). Ending does not require deleting on the same day. Tell us at nmts@nmts.me that you are ending the agreement — we record that date — and delete your account when you have taken what you want to keep: until you delete it, section 16.2 keeps applying, so you can still download your files, take your recovery map, and ask for the copy of your records under Privacy Policy 10.2. So take those three things first, then delete. And a storage term you have already paid the network for is not given back (7.8): that term keeps running, and no version of these terms has ever refunded it. None of this narrows 16.1. You can delete your account and end this agreement at any time, free, with or without this section; and you can also do nothing — while you have not accepted the new version, the version you last accepted goes on being the agreement between you and us (15.5), and any storage term you have already paid for stays governed by the version you accepted when you paid (15.4).
16. Ending your use, and ending the service
16.1 You can stop using the service at any time and delete your account from inside the product. Deleting your account has the effects described in 8.5.
16.2 Your files stay in your hands. While NMTS is running, your paid term has not ended and we have not stopped serving your account (16.3), you can download any file with your own keys, so you do not need us to hand anything back to you. A tool that opens your files without NMTS does not exist yet — section 5.2 is honest about that, and 16.4 says what we do about it if the service ever closes.
16.3 If we stop serving your account. We will not describe a procedure we cannot carry out, so here is the plain shape of it. We have no process that closes an account on a timer. There is no closing state in the service: an account either works or is refused, and the refusal takes effect at once. So the one measure 12.5 and 12.8 give us is to stop serving the account — after that, signing in stops working. There is no 30-day wind-down, and we will not promise one we have not built.
Where we can put the reason is limited by what we hold about you: no email address, no phone number, no postal address, and no way for us to start a conversation. So we say why on the notice board (15.3) where the reason is not particular to one person, we write it into the support inbox where a conversation is already open, and we answer anyone who writes to nmts@nmts.me — including to tell you why and what you can still do. If no conversation is open, the first thing you may see is that signing in has stopped working.
Two things stay yours throughout. Deleting your account is something you do, not something we do to you: you can do it yourself at any time from the account screen, and it takes effect immediately (16.1, 8.5). That stays true even while we refuse to serve the account. Erasure does not pass through sign-in: the product has a separate door — reached from the sign-in screen — that takes your account code as the proof and does exactly one thing: delete the account and its records. Being refused service never closes it. If you have lost the account code itself, section 10.3 of the Privacy Policy says honestly what we can and cannot verify from outside; write to nmts@nmts.me and we will tell you where you stand. And your wallet's private key was never ours, so it is not something we can hand over or take away (section 2.7) — export it while you have access. This notice arrangement is the one agreed under this contract; where the law where you live prescribes a different route for a notice of this kind, that law applies instead.
16.4 If we shut the service down, we will announce it at least 30 days before the closing date — on the notice board (15.3), which is public and readable without an account — and we will tell you: what is closing and why; the closing date; that you can download your files before it, and how; that you should export your wallet's private key before the closing date if the wallet holds any balance, and how; that the records we hold will be deleted afterwards; and how to reach us. Before the closing date we will publish the decryption tool and format specification needed to open your downloaded files without NMTS, so that what you hold remains usable.
16.5 Shutting the service down does not delete your files from the storage network. Storage you have paid for runs to the end of its term, and the encrypted bytes stay there.
16.6 If something goes wrong. If we learn of a security incident, of user information being exposed, or of an unannounced interruption of ten minutes or more, we post a notice on the notice board (15.3) without undue delay, and we leave it up for at least 15 days. The board is readable without an account, which matters when the reason you cannot sign in is the incident. The notice says what happened, what caused it, what we have done, what you can do, and how to reach us. We cannot write to you individually — we hold no address for you — so the board, and the line above the screens of anyone signed in, are the whole of it, and the support inbox is where you can reach us back.
17. Governing law and disputes
17.1 We do not impose a choice of law or a choice of court on you. These terms do not name a single country's law and do not send disputes to one country's courts.
17.2 If you are a consumer, then because we have chosen no governing law, the law of the country where you normally live governs this agreement — all of it, not only its mandatory rules. In the European Union and in Korea, the law also guarantees that you can bring a claim in the courts of the place where you live; elsewhere, whether your home court will hear a claim is a question for that court, and we will not argue that this agreement sent the dispute somewhere else — it does not.
17.3 There is no arbitration clause in these terms and no waiver of your right to take part in a class or group action. We have not asked you to give up either.
17.4 Before starting a formal claim, please write to nmts@nmts.me and give us 30 days to try to sort it out. This is a request, not a condition, and it does not stop the clock on any deadline that applies to you.
17.5 Nothing here stops you from bringing a small-claims case, or from complaining to a regulator or a consumer body in your country.
18. Contact
18.1 Email: nmts@nmts.me
18.2 That address is our single point of contact — for you and for authorities. Messages sent to it are read by a person, not only by software. We can work in English and in Korean. It is also, formally, the designated recipient (수령인) for copyright takedown and restoration demands and other notices under section 12, and the contact for privacy matters, which are handled by the privacy team (개인정보 보호 담당 부서) described in the Privacy Policy.
18.3 If you disagree with something we did, write to the same address and say so. A person reads it, we answer with reasons, and section 12.5 sets out the further routes — including the courts where you live — if our answer does not satisfy you.
19. Language
19.1 These terms exist in English and in Korean. Each is a full version of the same obligations, not a summary, and each is equally binding on the person who accepted it. If you are a consumer habitually resident in Korea, the Korean version is the one that governs your agreement with us. For everyone else, English is the canonical text.
19.2 Where there is doubt about what a term means, and you are a consumer, the reading more favourable to you prevails; and the mandatory law of the country where you live prevails over both language versions. Subject to those rules, and to the Korean version's precedence for consumers resident in Korea, if the two versions genuinely conflict the English version is the reference text.
19.3 Important passages — section 4, section 7 and section 8 in particular — carry the same emphasis in both versions.
Annex — model withdrawal form (EU/EEA consumers, section 3.5)
To: needmoretruth, nmts@nmts.me
I hereby give notice that I withdraw from my contract for the NMTS service.
- Account created on: —
- Public account id (if you have it at hand): —
- Date: —
You do not have to use this form; an email in your own words, or deleting your account in the product, works just as well.