Privacy Policy (GDPR)
Version 2026-09-05
Registration uses Cloudflare Turnstile. We send the verification token and IP address to Cloudflare for validation. Confirmation emails are sent through our configured email provider. Pending registration details expire after 30 minutes and are removed by scheduled cleanup or a later registration. No account is created before email confirmation.
The account service stores the minimum profile data required for authentication: email address, password hash, account status, consent versions, consent timestamp, and account timestamps.
Authentication sessions and password-reset records use random tokens stored only as cryptographic hashes. Reset tokens expire after 15 minutes. Expired sessions, reset records, and rate-limit metadata are removed automatically.
Account settings let you export your profile, preferences, followed projects and saved conversation messages as JSON. You can also permanently delete your account after confirming your password. Deletion removes the user record, active sessions, password-reset records, preferences, followed projects and saved conversations.
Free chats are not stored. Premium chat storage is limited to 100 chats, 1 MB or 200 questions per chat and 20 MB per account. Full chats remain readable; users delete chats to free space. Ending Premium deletes saved chats. To enforce the rolling 24-hour free quota, keyed hashes of account, email, network and request identifiers and timestamps expire after 24 hours, including after account deletion. They contain no question or answer text. Expired records are removed by scheduled cleanup or a later Core request.
We record the time of your last successful password sign-in to count active email-confirmed accounts. Public statistics contain only totals; positive activity totals below ten are suppressed. The timestamp is replaced at the next successful sign-in and deleted when the account is deleted.
Contact and support
Contact us at contact@trustdepin.com for account, support or privacy enquiries. The contact form sends your email address, selected subject and message to this mailbox so that TrustDePIN can handle your enquiry and reply. Do not send passwords or sensitive personal information.
The website does not store contact-message content or contact-form drafts in its database or browser storage. To prevent duplicate delivery, it temporarily stores a keyed hash of the request and content, its delivery state and a timestamp. These records expire after 48 hours and are removed by the scheduled cleanup or a subsequent submission. Sent email is processed by the configured email provider. Deleting an account does not remove previously sent support email; contact us about that correspondence.
Production operation still requires TrustDePIN's controller identity, contact details, lawful-basis wording, processor/subprocessor disclosures, and jurisdiction-specific retention statements to be reviewed and published as applicable.