Legal
Privacy
Effective August 13, 2026
What we store
If you use Google sign-in, we receive your Google account's stable identifier and verified email address. We do not receive your Google password and do not request access to Gmail, Drive, contacts or other Google services. If you use wallet sign-in, we process the public wallet address and signature needed to verify control. We also process account settings, submission and payment metadata, verification results and reward destinations you provide.
Technical data and cookies
Our infrastructure may record IP address, user agent, request time, requested path, response status and security or reliability events. Session and CSRF cookies keep you signed in and protect account actions. They are functional cookies, not advertising cookies.
How we use information
We use information to authenticate you, link sign-in methods only when you explicitly request it, operate and secure the verifier, attribute submissions, process payments and rewards, prevent abuse, diagnose failures, comply with law and communicate about your account or submissions. We do not sell personal information or use Google account data for advertising.
Sharing and public records
We share information only with service providers that host, secure, monitor or deliver the service; when you direct us to; or when legally required. Public wallet addresses, signed public-credit details, verification results and blockchain transactions may be visible publicly. Blockchain records and third-party archives may be permanent even if information is later removed from our own systems.
Retention and security
We keep account and transaction records for as long as needed to operate the service, protect it, resolve disputes and meet legal obligations. Expired sign-in challenges and sessions are retained only as operationally necessary. We use access controls, cryptographic verification, limited OAuth scopes and server-side session revocation, but no online system can promise absolute security.
Your choices
You can sign out at any time and may ask us to access, correct or delete personal data we control, subject to security, fraud-prevention, transaction-record and legal exceptions. Public or on-chain records may not be erasable. To make a request or ask a privacy question, email [email protected].
Changes
We may update this policy as the service develops. The effective date above identifies the current version; material changes will be posted here.