Legal
Privacy Policy
What we collect, why, who processes it, how long we keep it, and how to get it removed. Because we compute reputation from public profiles, this page is deliberately explicit.
Last updated: set publication date
Draft — review with counsel before relying on it
1. Who is responsible
Legal entity, jurisdiction("Proof of Audits") is the controller of personal data processed through the Services. Contact: privacy@proofofaudits.com (confirm this inbox is monitored before publishing).
2. The data we process
| Category | Examples | Source |
|---|---|---|
| Public auditor data | Contest results, accepted findings, severities, placements, payouts, public handle & bio | Public profiles (Code4rena, Sherlock, Cantina, Immunefi, CodeHawks) |
| Verification data | One-time bio code, confirmation that the code appeared in your public bio | You (via your public profile) |
| Account data | Email, account role, notification preferences | You |
| Wallet / on-chain data | Connected wallet address, agreement-signature record, timestamp | You (wallet connection) |
| Protocol submissions | Repository scope, chain details, review evidence | Protocol teams |
| Usage & device data | Consent choice, page and session activity, Web Vitals, coarse attribution, and security/anti-Sybil device signals | Automatically, after analytics consent where required |
On public data
3. Why we process it (purposes & lawful basis)
- Provide the Services: compute reputation, verify profile ownership, route engagements, publish passports you've agreed to publish.
- Security & integrity: prevent fraud, Sybil attacks, and abuse.
- Communication: respond to requests and send opt-in notifications.
- Legal compliance and enforcing our Terms.
Where GDPR applies, our lawful bases are typically legitimate interests (aggregating public professional reputation, security), consent (opt-in notifications), and contract (delivering an engagement). Confirm bases with counsel.
4. Wallet & on-chain data
Connecting a wallet exposes your public address. If you sign our engagement agreement, we record the address, signature, and timestamp as proof of acceptance. We never request a signature that moves funds, a token approval, a seed phrase, or a private key. On-chain attestations are, by nature, public and permanent — we cannot delete data written to a public blockchain.
5. Sharing & processors
We do not sell personal data. We share it only with:
- Service providers who process data on our behalf (e.g. hosting, email, and scraping/enrichment infrastructure) under contract. List actual processors — e.g. hosting, email, Firecrawl.
- Counterparties to an engagement you enter, to the extent needed to deliver it.
- Authorities where required by law.
6. Retention
We keep personal data only as long as needed for the purposes above or as required by law, then delete or anonymize it. State concrete retention periods once decided.
7. Your rights & how to exercise them
You can access, correct, or delete your data, object to or restrict processing, and request a copy of it.
- Correction / dispute a score: contact us and we'll review and re-score.
- Deletion: request removal of your profile and associated data; we'll action it (except immutable on-chain records and data we must retain by law).
- Opt out: notifications are opt-in and you can unsubscribe anytime.
Make a request
8. Cookies, transfers & changes
- We use necessary cookies/local storage for sessions and security. If you allow analytics, Amplitude records page, session, Web Vital, and defined product events. We do not send raw wallet addresses, private source, report contents, credentials, signatures, or security findings to Amplitude. Production Session Replay is disabled pending privacy review.
- Data may be processed in regions/countries; where required we use appropriate safeguards for international transfers.
- We may update this policy; material changes are posted here with a new "last updated" date.