Privacy Policy
Last updated: June 2026
This policy explains what ChainAnchor (“we”, “us”) collects and how we handle it, across the ChainAnchor web app, API, and browser extension. ChainAnchor creates tamper-evident, blockchain-anchored proofs of files and web pages.
1. What we collect
- Account information — your email, username, optional name, plan tier, and a securely hashed password. If you enable two-factor authentication, an encrypted TOTP secret.
- Content you choose to anchor — for files, only the SHA-256 hash you submit (the file is hashed in your browser and is not uploaded). For web/extension captures: the page HTML, a screenshot, the URL and title you capture, and any folder/organization names you set.
- Security & operational data — IP address and browser user-agent (login history, rate limiting, abuse prevention), and error logs.
- Developer data — API keys (stored only as a hash) and any webhook URLs you configure.
- Organization data — membership, roles, invitations, and an activity/audit log of administrative actions.
- On-chain data — the hash (or Merkle root) and timestamp of each anchor are written to a public blockchain (Base). This is public and permanent by design and contains only the fingerprint — not your file contents or personal details.
We do not use third-party advertising or tracking cookies. The only cookie we set is a strictly-necessary authentication cookie that keeps you signed in.
2. How we use it
- To provide the service: create and store your proofs, render proof pages, run monitoring, and operate the API and extension.
- To send transactional email (verification, password reset, monitoring change alerts, organization invitations, and administrative notices).
- To secure and operate the service (authentication, rate limiting, diagnosing failures).
We do not sell your personal information.
3. Legal bases (EEA/UK)
Where the GDPR/UK GDPR applies, we process personal data to perform our contract with you (providing the service), for our legitimate interests (securing and improving the service), and to meet legal obligations. Transactional emails are part of providing the service.
4. Who we share it with (sub-processors)
We share data only with providers needed to run the service — see the Security & Trust page for the current sub-processor list. In summary: a cloud/VPS host, an email delivery provider, blockchain RPC providers, and the public Base blockchain. Webhooks you configure receive the event payloads you request.
5. Proof pages are shareable
Anyone with a proof URL can view that proof, including any web snapshot or screenshot it contains. Don’t anchor content you don’t want stored or shared. Captures behind a login are stored against your account and shown on their proof page.
6. Retention & your rights
- Access & portability: export all your anchors from your account at any time.
- Deletion: deleting your account removes your personal data and personal snapshots from our systems. Data already written to the public blockchain (hashes + timestamps) cannot be deleted, as it is outside anyone’s control.
- Rectification & objection: you can edit your details or contact us to exercise GDPR/UK GDPR or CCPA rights (access, deletion, correction, objection, and — for California residents — to know what we collect and that we do not sell it).
We keep account and proof data for as long as your account is active, and operational logs for a limited period for security.
7. Security
We use HTTPS, store passwords as bcrypt hashes and API keys as hashes, and offer optional two-factor authentication. See the Security & Trust page for details.
8. International transfers
Our providers may process data in other countries. Where required, transfers rely on appropriate safeguards (such as Standard Contractual Clauses).
9. Children
ChainAnchor is not directed to children under 16 and we do not knowingly collect their data.
10. Changes
We may update this policy; material changes will be reflected by the “Last updated” date above.
11. Who we are & contact
The data controller is [ChainAnchor legal entity], [registered in England and Wales]. Questions or requests (including data-subject rights): contact@chainanchor.io. UK/EEA users also have the right to lodge a complaint with their data-protection authority (in the UK, the ICO).