XVALID Privacy Policy

Last Updated: April 15, 2025

Introduction

Welcome to XVALID! We are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how XVALID ("XVALID", "we", "us", or "our") collects, uses, stores, and shares information when you use our Web3 platform and related services (collectively, the "Services"). By accessing or using XVALID (including our website xvalid.io and any decentralized application interfaces), you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the terms, please discontinue use of our Services.

Scope

This Privacy Policy applies to all users of XVALID worldwide. We adhere to global data protection standards, including the EU GDPR, California CCPA, Singapore PDPA, and other applicable laws. We design our platform with privacy in mind – we minimize personal data collection and never require identity verification (No KYC) for you to use XVALID. Below we outline what data we do collect, how we handle it, and your rights regarding that information.

Data We Collect

We strive to collect as little personal data as possible. The following are the categories of data we may collect and process when you use XVALID:

Wallet Addresses

When you connect a blockchain wallet to XVALID or perform on-chain transactions via our platform, we collect your public wallet address. This is used to authenticate you (as your "login" to our Web3 Services) and to link any content or actions you perform to your address. Wallet addresses are considered public information on the blockchain; however, we treat them as personal data where required by law.

Email Address (Optional)

We do not require any email to use the core Services. If you choose to provide an email (for example, by contacting support, subscribing to updates, or creating an optional user profile), we will collect your email address. This may be used for communication purposes (such as responding to inquiries or sending newsletters if you have opted in). You can always choose not to provide an email, but then you might not receive certain notifications or support responses.

Content Hashes and Metadata

XVALID allows users to submit or store content through our platform. Rather than storing the content itself on our servers, we store a content identifier (hash) of any user-submitted content. This hash is a cryptographic representation of the content and by itself does not reveal the content's plain form. We may also store basic metadata about the content (for example, timestamps, content type, or tags) necessary for the Service's functionality. The actual user content is stored on a decentralized storage network (as explained below in Data Storage).

User-Generated Content

Any content you publish or validate via XVALID (such as text, files, or other media) is not stored by us in a way that we can read, but it becomes available on the public IPFS network via its hash. Important: Do not include sensitive personal information in any content you submit on XVALID, as content on public blockchains or IPFS can be accessed by anyone with the hash or address. We do not proactively collect personal data within your content, and any such inclusion is at your discretion and risk.

Usage Data (Analytics Information)

Like most online platforms, we may automatically collect limited information about how you interact with our website or app. This may include technical data such as your IP address, browser type, device information, locale, and usage statistics (e.g. pages or screens viewed, clicks, and time spent). We collect this data through third-party analytics tools or cookies (see Cookies and Analytics below). This data does not identify you by name and is used only to analyze and improve our Services. Where required, we will treat IP addresses and similar identifiers as personal data, though we seek to anonymize or pseudonymize this data wherever feasible.

No Sensitive Personal Data

We do not collect any sensitive personal information such as your real name, physical address, phone number, government ID numbers, date of birth, financial account information, or biometric data. XVALID does not perform any KYC (Know Your Customer) identity verification. We also do not intentionally collect any information about your racial or ethnic origin, political opinions, religious beliefs, health, or other special categories of data. Please do not send us such data through any means.

How We Use Your Data

XVALID collects and uses the limited data outlined above solely for legitimate purposes of operating and improving our platform. Specifically, we use your data for the following purposes:

Providing the Core Service

Your wallet address and content hashes are used to operate the core features of XVALID. For example, we use your wallet address to authenticate your interactions (so you can publish or validate content) and to attribute content or actions to you on the platform. Content hashes allow us to reference and retrieve the content you submitted from decentralized storage. This processing is necessary to perform the services you request (i.e. it is needed to fulfill our contract with you when you use our platform).

Content Moderation and Safety

We are committed to maintaining a safe and legal platform. To achieve this, we utilize automated content moderation tools, including third-party artificial intelligence services, to scan or review content that users submit. For example, we use the OpenAI API (and similar AI moderation services) to analyze content for compliance with our Terms of Service and safety policies. This means that user content may be transmitted to an AI moderation service to detect prohibited material (such as hate speech, explicit imagery, personal data, or other content that violates our rules). The moderation process is used only to flag or filter out content that violates our policies or the law – we do not use it for advertising or profiling. Any third-party AI service we use is bound to only use the data for providing moderation analysis and not for their own purposes.

Communication

If you provided an email address or contact info, we use it to communicate with you. This includes responding to support requests or inquiries you send us, sending service-related announcements (e.g. updates to our terms or privacy policy, security alerts), and sending newsletters or project updates if and only if you subscribed to them. We will not send you marketing emails without your consent, and you can opt-out at any time (each non-essential email will contain an unsubscribe link or instructions).

Analytics and Improvement

We use usage data (like IP address, device and browsing info, and on-site interactions) to understand how our Services are used and to improve user experience. For instance, analytics help us detect site traffic patterns, debug performance issues, and decide on new features or enhancements. This analysis is typically done in aggregate form (overall trends rather than examining individual user behavior) and is carried out using third-party analytics providers. Where required by law or if feasible, we will obtain your consent for analytics cookies or use only anonymized data. We do not use your data for behavioral advertising or sell your data to advertisers.

Ensuring Security and Preventing Misuse

We may process data (including wallet addresses and technical usage logs) to monitor for fraudulent, suspicious, or malicious activity on the platform. This helps protect XVALID and its users from abuse such as spam, hacking attempts, or other violations of our Terms of Service. For example, if multiple content submissions from a single wallet are flagged for violating rules, we may investigate that wallet address. We also may use IP address or device information to implement security measures (like rate limiting or blocking suspicious network traffic). This processing is based on our legitimate interest in keeping the Service secure and fair, and in some cases to comply with legal obligations.

Compliance with Law

We will use or disclose data as necessary to comply with any applicable laws, regulations, legal processes, or governmental requests. For example, if we receive a valid subpoena or order relating to a particular wallet address or content hash (perhaps in an investigation of illegal content), we may be obligated to provide any information we have (which is minimal). We will only disclose what is legally required and will notify users of such requests when permissible.

We will not use your personal data for purposes that are incompatible with the above, unless we obtain your consent or are required by law. We do not engage in any form of selling or renting of your personal data to third parties for their own marketing or commercial purposes.

How We Store and Protect Your Data

XVALID takes data security seriously and implements industry-standard practices to protect the information we hold. Here is how and where we store data, and the measures in place to safeguard it:

Decentralized Content Storage (IPFS)

User-generated content (the actual files or data you upload) is stored on the InterPlanetary File System (IPFS), a decentralized storage network. When you submit content, it is distributed across the IPFS network rather than being stored on a centralized server controlled by XVALID. We (or our chosen IPFS pinning service) may "pin" your content to ensure it remains available on the network, but XVALID does not centrally hold the raw content data. Instead, we store only the content's hash (identifier) in our database. Please note: Content on IPFS is by design publicly accessible to anyone who has the content hash. While this enhances censorship resistance, it means we cannot guarantee the confidentiality of content you choose to put on IPFS via our platform. Do not upload any private or sensitive personal data that you would not want to be public. If you later request deletion of content, we can remove the reference from our platform and stop pinning it, but we cannot retroactively remove content from all third-party nodes on the IPFS network.

Database Storage

Data such as content hashes, wallet addresses, and any account-related information (like optional email or settings) are stored in our secure database. We utilize a reputable cloud database provider (for example, MongoDB Atlas or an equivalent managed database service) to host our data. This database is protected by access controls, encryption at rest, and encryption in transit. Only authorized XVALID team members or service processes can access the database, and only for permitted purposes. We do not store plaintext passwords (in fact, XVALID uses crypto wallets for login, so no password is needed for that; any other authentication tokens are handled securely). We regularly backup the database to prevent data loss, and those backups are similarly secured.

OpenAI and Other Subprocessors

When we use the OpenAI API for content moderation (or any similar AI service), the content data is sent securely via encrypted connection to OpenAI's systems. We do not permanently store the content of these moderation checks on our own servers beyond perhaps a flag or score indicating if content was approved or rejected. OpenAI might temporarily retain the data we send for abuse monitoring (per their policies), but they will not use it to train their models or for other purposes without our instruction. All subprocessors we use are carefully vetted and contractually obligated to protect your data.

Third-Party Analytics Storage

Analytics providers may store usage data (page views, IP, etc.) on their servers. We ensure that any analytics partner either does not receive personal data or, if they do (like an IP address), they handle it in compliance with privacy laws (for example, by truncating/anonymizing IPs in the EU). We currently use third-party tools only to gather insights on a general level. We do not collect device advertising IDs or precise geolocation data.

Security Measures

We employ organizational and technical measures to secure your data. This includes using encryption (HTTPS/TLS) for all data in transit between your browser/wallet and our platform, encryption at rest for stored data, firewalls and network security to prevent unauthorized access, and continuous monitoring for potential vulnerabilities or attacks. Our team follows security best practices in software development to minimize bugs and conducts audits of smart contracts and backend systems where applicable. In addition, by limiting the personal data we collect, we inherently reduce the risk to your privacy in the event of any security incident.

Access Controls

Internal access to user data is strictly limited. XVALID team members access the minimal data necessary to perform their job (for example, support staff can see the email you provided to respond to you, but they cannot see data you didn't provide). Wallet addresses and content hashes are generally public information, but any link to an email or any non-public info is kept confidential internally. We also ensure that our service providers (database hosting, etc.) implement strong access control on their side.

Data Breach Response

While we strive to prevent any breach, we have a response plan in place if an incident occurs that affects personal data. In the unlikely event of a data breach, we will notify affected users and relevant authorities as required by law (for example, under GDPR we would notify the supervisory authority and users of serious breaches within the mandated timeframe). We would also take immediate steps to contain and remedy the breach.

Data Localization and Transfers

Our servers and service providers may be located in various countries (for example, our database may be hosted in the United States or European Union datacenters, and our team operates globally). This means your data may be transferred to or accessed from outside your home jurisdiction. International data transfers are addressed in detail below, but in short, we implement appropriate safeguards (such as Standard Contractual Clauses for EU data or ensuring providers are certified under frameworks like those between EU-US or meet PDPA requirements) when transferring data internationally.

Third-Party Service Providers (Subprocessors)

To provide the XVALID Services, we rely on certain trusted third-party partners – essentially extensions of our team – who process data on our behalf. We do not share your data with unrelated third parties for their own use, but we do use service providers in the following categories:

Cloud Database and Hosting Providers

We use third-party cloud infrastructure to host our website, database, and Services. For example, our content hash and user data may be stored in a cloud database service (such as MongoDB Atlas or a similar database-as-a-service platform), and our servers may run on cloud providers like AWS, Azure, or others. These providers store and process data only to the extent needed to keep our Service running (e.g., storing data, performing backups, etc.). They are not permitted to access or use your data for any other purposes. We have agreements in place (including Data Processing Addendums where applicable) to ensure they protect your data under strict confidentiality and security standards.

Decentralized Storage Networks

As noted, XVALID uses IPFS for content storage. We may engage IPFS pinning services or gateways (third-party services that help store and retrieve IPFS content) to ensure content availability. Examples could include Infura, Pinata, or others. These services will handle the content (which might include personal data if you included any in the content) for storage and retrieval on the IPFS network. However, they do not interpret the data – they simply ensure it's stored across the network. All such services are chosen for reliability and their commitment to privacy (many IPFS providers have their own privacy practices which align with decentralized principles).

AI and Moderation Services

We integrate external AI services to help moderate and filter user content. The primary example is OpenAI's API for content moderation (checking text against safety policies). When content moderation is performed, the content is sent to these third-party AI systems, which then return an analysis (for instance, whether the content is safe or violates certain rules). These AI service providers act as our processors for this data. They are not allowed to use your content for any purpose other than providing us the moderation results. We ensure this via our contract or via the provider's terms (OpenAI, for example, commits not to use API-submitted data to train models without permission and to maintain confidentiality).

Analytics and Tracking Tools

We use third-party analytics tools (which may involve cookies or similar technologies) to gather usage statistics. These may include, for instance, Google Analytics, or other web analytics services. Such tools may automatically receive certain technical information from your device (as described under Usage Data). We configure these tools to respect privacy: for example, where possible, we enable IP anonymization and do not allow them to use data for their own advertising purposes. Analytics providers act as data processors for us – meaning they only process your information per our instructions (to provide aggregate stats, etc.). We do not share any directly identifying information (like names or emails) with our analytics partners. You have choices to limit this data collection (see Cookies and Your Choices).

Email and Communication Providers

If we send emails or transactional messages, we may use an email delivery service (for example, SendGrid, Mailchimp, or similar) to manage our mailing lists and send messages. These providers would handle your email address and the content of the messages on our behalf. They are only permitted to use that information to send communications as we direct, and not for anything else. We likewise ensure any such provider has strong security and privacy commitments.

Other Service Providers

We may use additional services for things like application performance monitoring, customer support ticketing, or community forums. If any personal data is processed by such services, it will be only what's necessary. For instance, if you engage with our community forum or social media via links on our site, any data you provide there is subject to those platforms' privacy policies (we do not automatically ingest that data into XVALID systems). We will always endeavor to list the categories of our subprocessors here and keep this section up to date as our service ecosystem evolves.

No Selling or Unauthorized Sharing

We want to emphasize that we do not sell your personal data to any third party. We also do not share it with third parties for their own marketing or advertising. Any third parties who process user data are doing so to support XVALID's operations as described, under contractual obligations to preserve your privacy.

Legal Requirements and Asset Transfers

In addition to the above service providers, there are a couple of special circumstances where we might share data:

  • If required by law or governmental authority, we may share data pursuant to a legal request (as detailed in How We Use Your Data – Compliance with Law). We will verify any request and only provide information that is necessary and proportionate.
  • If XVALID undergoes a business transition, such as a merger, acquisition, or financing, your data (to the limited extent we have any personal data) may be transferred to a successor or affiliate as part of that process. If such a transfer occurs, we will ensure the recipient commits to respect this Privacy Policy or provide notice and possibly request your consent if required by law.

Cookies and Analytics

Cookies are small text files placed on your device to store information, which are commonly used to make websites work or to work more efficiently, as well as to provide reporting information. When you visit XVALID's website or use our web app, we may use cookies and similar tracking technologies (like web beacons or local storage) to enhance your experience and collect usage data.

Functional Cookies

Some cookies are necessary for the site to function – for example, to remember your preferences or keep you logged in during a session (if applicable). Because XVALID uses crypto wallets for authentication, we may not use traditional login cookies, but we might use local storage or session storage to remember that you've connected your wallet or to store a session identifier for your visit. These functional cookies do not identify you personally and are typically exempt from consent requirements.

Analytics Cookies

We use analytics cookies (or similar trackers) to collect information about how users interact with our site. This information helps us count visitors, see which features are popular, and understand user pathways through our application. For instance, we might use Google Analytics which sets cookies to distinguish users and throttle request rates. The data collected may include your IP address and usage information as described earlier. We configure analytics to avoid collecting any more data than necessary – often we anonymize the last digits of IP addresses and we do not allow cross-site tracking.

Third-Party Tools

In addition to pure analytics, if we embed content or integrate with other platforms, those third parties might set cookies. For example, if in the future we integrate an optional chat support widget, that service might use cookies. We will endeavor to list any significant third-party cookie usage here and ensure you have notice of it. As of the latest update, our primary third-party cookies relate to analytics and performance (e.g., Cloudflare may set a cookie for security or caching reasons, which does not track personal data).

Your Choices for Cookies

When you first visit our site from certain jurisdictions, you may see a cookie banner or notice that invites you to consent to or manage cookies. We will not set non-essential cookies (like analytics) without your consent where required by law (such as in the EU/EEA). You can always choose to block or delete cookies through your browser settings. Most browsers allow you to refuse new cookies, see when you receive a cookie, or delete existing cookies. However, please note that some features of our Service might not function properly without cookies (for example, you may need to reconnect your wallet each time if the session cookie is blocked).

Do Not Track

Some browsers offer a "Do Not Track" (DNT) signal that allows you to indicate your preference regarding tracking. Currently, there is no universal standard for how to interpret DNT signals. While we respect the intent of DNT, our site may not respond differently to a browser with a DNT signal. Instead, we provide the privacy controls described (consent for analytics in certain regions, and the ability for you to opt-out manually). We will update this policy if our practice changes in the future.

Analytics Opt-Out

If we use Google Analytics, you can opt out of Google Analytics data collection for this site and others by installing the Google Analytics Opt-out Browser Add-on, which prevents your browser from sending data to Google Analytics. Other analytics tools may have similar opt-out mechanisms. Additionally, you can contact us (see Contact Us section) to inquire if we currently use any analytics that support a manual opt-out, and we will provide guidance.

By using our site without opting out or blocking cookies, you consent to our use of cookies and trackers as described. We do not use cookies for advertising or cross-site tracking of your behavior.

Privacy by Design: No KYC & No Investor Data

XVALID is built with a privacy-first and compliance-first design philosophy. A core principle is data minimization – collecting only what we truly need and avoiding any collection of sensitive personal information. Two major ways we implement this are:

No KYC or Identity Verification

We do not require users to undergo any Know-Your-Customer (KYC) checks or identity verification process to use XVALID. Unlike some platforms (especially in the crypto space) that might require uploading an ID or personal documents, XVALID requires none of that. You access our Services simply by connecting a blockchain wallet. All interactions (such as posting or validating content) are tied to your wallet address. This means we never collect your legal name, address, date of birth, identification number, or other personal identifiers. By avoiding KYC, we not only protect your privacy but also eliminate large databases of sensitive data that could be targets for breaches.

Important: While we do not ask for KYC, users are responsible for ensuring they comply with any laws applicable to them. If you choose to provide personal information to us in any way, we will treat it according to this Policy, but you should refrain from doing so unless necessary (for example, only provide an email if you want us to contact you; otherwise, remain pseudonymous).

No Investor Token Sale (No Private or Public ICO)

XVALID's token distribution is structured to avoid the need for gathering investor information. We did not conduct any private sale, public ICO, or token pre-sale that would involve selling tokens to investors in exchange for funds. Many token projects that raise capital from investors are required to collect personal data for legal or regulatory reasons (such as KYC/AML for token sale participants, or maintaining a list of shareholders). XVALID deliberately avoided this model. Our token (the XVALID token) has been distributed through alternative means (for example, community rewards, on-chain emissions, or other non-investment mechanisms) that did not require us to collect anyone's personal identity or payment information. By not having outside investors or a token sale, we mitigate legal risks and ensure that we are not holding personal data related to such activities. This approach keeps the platform more compliant with securities laws and, from a privacy perspective, means there's no database of investor names, credit card details, or contribution records. All token transactions occur on-chain, and your wallet address is the only identifier involved.

By adhering to these principles, XVALID significantly reduces the privacy impact on our users. We want you to use the platform with confidence that we aren't secretly accumulating a trove of personal information. Our business model and platform governance are structured in a way that we can provide utility without intruding on your privacy.

User Obligations and Usage Guidelines

While we at XVALID do our part to protect your data and privacy, users also have certain responsibilities when using the platform. We ask you to adhere to the following guidelines to help maintain a trustworthy environment:

Do Not Share Personal Data in Public Content

XVALID is a public platform, and content you publish (stored via IPFS and linked to your blockchain address) can be accessed globally. Avoid submitting personal data (yours or anyone else's) as content. This includes things like real names, contact details, private images, or any personally identifiable information. Our platform is not intended for sharing private information, and if you post such data it could become permanently part of a public blockchain or IPFS record that we cannot fully erase. We are not responsible for personal information you or others disseminate through the use of our Services.

Content Compliance

You must ensure that any content you upload or actions you take on XVALID comply with our Terms of Service and all applicable laws. Do not use XVALID to publish illegal material, harassing or hateful content, or anything that violates the rights of others (such as copyright or privacy rights). Remember that we employ content moderation – content that violates rules may be removed and could be reported to authorities if it's unlawful. As a user, you are obligated to use the Service for its intended purpose and not to misuse it.

Account Security

Although XVALID does not use traditional accounts (your "account" is essentially your wallet connection), you are responsible for the security of your blockchain wallet and private keys. Never share your private keys or seed phrases with anyone, including us – XVALID will never ask for them. If you lose control of your wallet, an attacker could impersonate you on our platform (since they would control your address). We recommend using secure wallet practices and enabling additional protections (like hardware wallets) to keep your credentials safe.

Accuracy of Information

If you do choose to provide us with any information (such as an email for contact or any optional profile info), you agree that such information is accurate and belongs to you. Do not provide an email or contact that is not yours or that you are not authorized to use. If we discover information that appears fraudulent or misappropriated, we may delete it and, if necessary, restrict your use of the platform.

Respect Others' Privacy

If as a user you happen to collect or learn personal information about other XVALID users (for example, through their content or interactions), you agree to treat that information with care. You should not harvest data from the platform for unwarranted purposes, and you must not misuse any other user's information. Also, if you refer friends or share content, do not expose others' personal data without consent.

Opt-Out Choices

You have the choice of how you use XVALID. If you disagree with this Privacy Policy or the Terms, you should discontinue use of the Service. You may also use privacy tools (like VPNs or privacy browsers) if you wish, though note that interacting with the blockchain will always expose your wallet address by design. If you want to limit data collection, you can adjust your browser settings to block cookies or tracking (with the understanding that it may degrade functionality as mentioned). For any optional features like email newsletters or community forums, participation is voluntary – you can opt out or refrain from those features if you want to remain as anonymous as possible. We provide ways to unsubscribe or opt out wherever we offer such options, and you can always contact us to assist with any opt-out request.

By following these guidelines, you not only protect yourself but also contribute to the overall integrity and privacy-respectful culture of the XVALID ecosystem. We reserve the right to take appropriate action for violations of these obligations, as described in our Terms of Service.

International Compliance and Data Transfers

XVALID is a global platform. We are committed to handling personal data in compliance with the stringent privacy regulations around the world, including but not limited to the European Union's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) (as amended by the CPRA), Singapore's Personal Data Protection Act (PDPA), and other applicable laws in jurisdictions where we operate or have users. Below is how we address key international requirements:

EU/EEA (GDPR) Compliance

For users in the European Union, European Economic Area, or United Kingdom (which follows similar laws post-Brexit), we operate as a "Data Controller" of the limited personal data we handle (e.g., wallet addresses, emails, usage data). We ensure that we have a valid legal basis for all processing:

  • Our legal bases typically include performance of a contract (providing you the Service you request when you use our platform), legitimate interests (for securing and improving the platform – we balance these interests against your rights and expect minimal privacy impact due to data minimization), and in some cases consent (for example, for optional analytics cookies or for sending you a newsletter if you signed up).
  • We uphold the GDPR principles of data minimization, purpose limitation, and storage limitation. We only collect what is necessary, use it as described, and retain it no longer than needed.
  • If we transfer personal data from the EU to outside countries (e.g., to the U.S. where some of our infrastructure or subprocessors may be), we rely on appropriate safeguards. Typically, this means we have Standard Contractual Clauses (SCCs) in place with our service providers, or the provider is certified under an approved framework if one exists.
  • GDPR grants individuals certain rights (detailed in Your Rights and Choices below) such as access, deletion, correction, and objection rights. We extend those to you and provide mechanisms to exercise them.

United States and CCPA (California)

For U.S. users, privacy laws can vary by state. We strive to comply with all applicable laws, including the California Consumer Privacy Act (CCPA) for California residents:

  • Under CCPA, California residents have rights to know what personal information we collect, how we use it, and to request access or deletion of that information.
  • No Sale of Personal Information: We do not and will not "sell" personal information as defined by the CCPA. We also do not share your personal information for cross-context behavioral advertising.
  • California residents have the right to request deletion of their personal information that we have collected (with some exceptions under CCPA).
  • Non-Discrimination: We will never discriminate against someone for exercising their privacy rights under CCPA (or any law).

Singapore (PDPA) and Other Countries

For users in Singapore, we comply with the Personal Data Protection Act (PDPA) and its data protection obligations:

  • We collect, use, and disclose personal data with your consent or as permitted by law.
  • We take reasonable steps to protect personal data from unauthorized access or misuse and to ensure accuracy and completeness.
  • Singapore individuals have rights to access and correct their personal data held by us.
  • We will cease to retain personal data or remove identifying factors when it is no longer necessary for legal or business purposes.

International Data Transfers

Your data may be transferred to and processed in countries other than your own. These countries may have data protection laws different from the laws of your jurisdiction. Wherever your data is transferred, we ensure there are adequate protections:

  • For data originating from the EU/EEA, UK, or Switzerland, we typically rely on Standard Contractual Clauses (SCCs) with any processor in a country not deemed to have adequate laws by the EU.
  • We also may rely on your consent for certain cross-border transfers when you use our Services.
  • Our requirement for our service providers is to comply with this Privacy Policy and all applicable privacy laws in handling your data.

Your Rights and Choices

You have significant control over your personal data and how it's used by XVALID. We want to empower you with the ability to access, correct, or delete information as well as to make choices about your privacy. Below is a summary of your rights and how to exercise them:

Right to Access

You have the right to request confirmation if we are processing your personal data, and to request a copy of the data we hold about you. This is sometimes called a Data Subject Access Request. Given the minimal data we collect, this would likely include things like any email you provided, your wallet address (which you likely know already), content hashes associated with your address, and any usage logs that are considered personal data (like IP addresses in logs, if not anonymized). We will provide this information in a concise, transparent format, usually within 30 days as required by GDPR (or 45 days under CCPA, which can be extended by another 45 days with notice if necessary).

Right to Rectification (Correction)

If you believe any personal data we have about you is inaccurate or incomplete, you have the right to request that we correct or update it. For example, if you provided an email and you want to update it or you think we logged something incorrectly, let us know. We will rectify incorrect data promptly. (Note: Most data we have comes directly from you or the blockchain, so mismatches are uncommon, but the right stands.)

Right to Deletion (Erasure)

You may request that we delete personal data we hold about you. This is sometimes called the "Right to be Forgotten". You can ask us to delete information like your email, any account profile data, and so on. We will honor such requests to the extent required by law:

  • If you have an account or profile on XVALID, we can delete your account information and any personal data attached to it.
  • We can remove references to content you've posted from our databases.
  • However, we cannot delete data that is stored on a public blockchain or content that is stored on IPFS beyond our control.

Right to Restrict Processing

In some jurisdictions (like the EU), you have the right to request that we limit processing of your data in certain circumstances. For example, if you contest the accuracy of data, or if you object to our processing pending verification of something. Practically, since we do minimal processing, this might not often apply, but if you make such a request we can, for instance, stop using your email or pause analytics tracking for your sessions.

Right to Object

You have the right to object to certain processing activities. For instance, you can object to processing based on our legitimate interests or to receiving direct marketing. In our context, you might object to analytics collection or to any automated decision-making (though we don't really perform decisions that affect you legally—content moderation decisions are about content allowed on the platform, not about you personally).

Right to Withdraw Consent

Where we rely on your consent to process data, you have the right to withdraw that consent at any time. For example, if you consented to receive a newsletter, you can unsubscribe (withdraw consent) and we will stop sending it. Withdrawing consent won't affect the legality of what we did prior, but it will stop future processing.

Right to Data Portability

For data you provided to us, in some cases you have the right to request that we provide it in a structured, commonly used, machine-readable format so you can transfer it to another service. Given we don't have profile accounts in the traditional sense, the most likely portable data could be something like your content or your list of content hashes.

Exercising Your Rights

To exercise any of your rights, please contact us via the information in the Contact Us section below. Provide sufficient information for us to verify your identity (for example, contacting us from the email address in question, or signing a message with your wallet to prove it's yours, if the request is wallet-specific).

  • No Fee in General: We will not charge you for making a request or exercising your rights, except in cases where a request is manifestly unfounded or excessive.
  • Impact of Deletion or Restriction: If you request deletion of your data or if you restrict our processing of it, note that this could affect your ability to use XVALID.

We are dedicated to honoring your rights. If you have any concerns about your data or need assistance understanding or executing any rights, please reach out. We will happily explain and guide you through the process, as your trust is very important to us.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or as required by law. Because we practice data minimization, in many cases your data is stored for a relatively short duration or can be removed on request. Here are our general retention practices:

Wallet Addresses and Content Records

We may keep records of wallet addresses interacting with our platform and associated content hashes indefinitely on our systems, as part of the ongoing operation of the Service. However, if you request deletion of your data, we can disassociate your wallet from any user profile or email, and we can remove content hashes from our index as described. The blockchain itself will have a permanent record of your transactions; we do not control that retention.

Email and Contact Information

If you provided an email for communications, we will retain that email address for as long as you continue to want to receive communications or need an account with us. If you unsubscribe from emails or request deletion, we will promptly remove your email from our active mailing lists. We may still keep a record of your email in an "opt-out list" to ensure we don't accidentally send you emails in the future.

Analytics Data

Analytics information is often collected in aggregate form and may be stored by our analytics providers for a certain retention period. We do not maintain identifiable analytics logs on our own servers long-term. Web server logs containing IP addresses are typically rotated and deleted within a short period (often 30 days to 90 days) unless needed for security analysis.

Content Moderation Data

If content of yours was flagged or removed due to moderation, we may keep a record of that action. This is to maintain auditability and possibly to prevent re-submission of the same banned content. Such records might be kept as long as needed for enforcement purposes, potentially indefinitely if it pertains to serious violations.

Backups and Legal Obligations

  • Our database backups may contain your data and could be retained for some additional time even after data is deleted from the live system.
  • We might be required to keep certain data for a longer period to comply with laws or regulations.
  • If we receive a legal notice or are involved in a dispute, we might need to preserve relevant data until it is resolved.

Children's Privacy

XVALID is not intended for use by children or minors. We do not knowingly collect personal information from anyone under the age of 13.

Minimum Age

By using XVALID, you represent that you are at least 18 years old or the age of majority in your jurisdiction. If you are under 18 (or under the relevant age of majority), you may only use XVALID with the involvement and consent of a parent or legal guardian.

No Collection from Children

We do not intentionally gather personal data from children under 13. If we become aware that we have inadvertently collected personal data from a child under 13, we will delete that information as soon as possible.

Parental Guidance

If you are a parent or guardian and you discover that your minor child under 13 has provided personal information to XVALID or is improperly using our platform, please contact us immediately. We will take prompt action to remove the data and restrict the child's access.

Changes to This Privacy Policy

We may update or revise this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons.

Notification of Changes

We will post the updated Privacy Policy on our website xvalid.io and update the "Last Updated" date at the top. If changes are significant, we may provide a more prominent notice or seek your consent as required by law.

Scope of Changes

Any updated policy will apply to all current and past users of our Services and will replace any prior versions, except to the extent we receive your consent for materially different uses of your data (if required). We will not reduce your rights under this Privacy Policy without your explicit consent.

Review Period

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Continuing to use XVALID after a revised Privacy Policy has been posted means you accept the terms of the updated Policy.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or any aspect of your privacy when using XVALID, please do not hesitate to contact us:

  • Email: privacy@xvalid.io
  • Postal Mail:
    XVALID Project Team – Privacy Inquiry
    123 Blockchain Ave., Suite 0x00,
    Dallas, TX 75201, USA

We are the entity responsible for your personal data (the "data controller" under GDPR terminology). You can reach out to our Data Protection Officer (if one is appointed) or the privacy team via the contact information above. We will respond to inquiries as soon as possible, typically within a few business days.

Complaints

We prefer to address your privacy concerns directly and amicably. However, if you feel we have not adequately resolved an issue, you have the right to lodge a complaint with your local data protection authority. For EU users, this could be your country's supervisory authority. For Singapore, you can contact the Personal Data Protection Commission (PDPC). For California, you can reach out to the California Attorney General's office for CCPA-related complaints.

Thank you for reading our Privacy Policy. Your privacy is important, and we appreciate the trust you place in XVALID. We are dedicated to safeguarding your data and building a platform that respects user privacy by design. Enjoy using XVALID with confidence that we've got your privacy in mind every step of the way!