QED Proof is run by Nuraveda, a sole proprietorship based in Toronto, Ontario, Canada, operating as Nuraveda Lab (“Nuraveda Lab”, “we”). This policy explains what we collect when you use qedproof.site and the QED Proof service, why we collect it, who helps us process it and what you can ask us to do with it. Questions go to [email protected].
1. What we collect
Account details. When you sign in with GitHub, we receive your GitHub username, display name, avatar and email address. When you sign in with Google, we receive your name, email address and profile picture. When you use an email sign-in link, we receive your email address. Our authentication provider also records sign-in times, IP addresses and browser details to keep accounts secure.
Workspace details. Workspace names, who belongs to each workspace and their role, and the names of your API keys. We keep only a one-way hash of each API key; you see the key itself once, when you create it.
Claims and receipts. When your agents send claims, we store what they tell us: the agent’s reference, the action, the target (for example a repository name or a URL), the parameters you include (limited to 4 KB) and the time. When we check a claim, we record the facts our verifier read at the destination, such as whether a commit exists on a branch or the HTTP status a URL returned. We record fingerprints and facts like these, not the content of your code, posts or messages.
Connections. If you install our GitHub App, we store its installation ID so we can check your repositories with read-only access. We don’t store long-lived GitHub tokens; we mint a short-lived token for each check.
Alerts. Where you configure alerts, the destination details (for example a Discord channel webhook).
Contact form. If you write to us through the contact form, we store your name, email address, company (if you give one), the topic, your message and the page you sent it from, and we post a short notification to a private Discord channel our team reads. We don’t store your IP address or browser details with it; your IP address is used only briefly, to limit how many messages can be sent in a minute.
Website analytics. On our public website (not the signed-in console at /app), we use Google Analytics 4 to understand which pages are visited. It uses cookies such as _ga, and its advertising features are turned off. Google Tag Manager loads our Google tags on the same public pages, with advertising storage turned off, and doesn’t load if your browser sends Global Privacy Control. We also use Umami, a cookieless analytics service that collects no personal data. See Cookies and local storage.
Advertising measurement. We use Meta’s tools to measure whether our advertising works. See Advertising measurement.
2. Why we use it
- To run the service: sign you in, check your agents’ claims at their destinations, issue and store signed receipts, and send the alerts you ask for.
- To keep it secure: prevent abuse, enforce rate limits and investigate problems.
- To improve the public website, using aggregated analytics.
- To contact you about your account, security issues or changes to these terms.
- To reply to messages you send through the contact form.
3. Public receipts and the blockchain
Receipts are designed to be checked by anyone. A receipt you share by link can be read by anyone who has the link.
To make receipts tamper-evident, we record the root hash of our receipt log on Base Sepolia (Base's public test network), as often as every ten minutes when there are new receipts. These hashes don’t reveal what any receipt says, but anything recorded on a public blockchain is permanent: we can’t change or remove it, and nobody else can either. During the current preview, anchors are recorded on the Base Sepolia test network.
4. Who processes it
We use these service providers to run QED Proof. They process data on our behalf, under their own security and privacy commitments:
- Amazon Web Services (United States, Ohio region): our API, signing keys (AWS KMS) and secrets.
- Supabase (hosted on AWS in the United States): our database and account sign-in.
- Cloudflare (global network): website hosting, DNS and protection against attacks.
- GitHub: sign-in, and the read-only checks you authorize through our GitHub App.
- Google: sign-in with Google, and Google Analytics and Google Tag Manager on our public website.
- Umami: cookieless page analytics on our public website.
- Email delivery providers: to send sign-in links and account email.
- Meta Platforms: advertising measurement (the Meta Pixel and the Conversions API).
- Discord, only if you set up Discord alerts.
We don’t sell your personal information. We share a limited set of data with Meta to measure our advertising, as described under Advertising measurement, and you can opt out.
5. Advertising measurement
On our public website only, we use the Meta Pixel to record page views. It sets a cookie such as _fbp. When you create a workspace, and when a workspace starts a paid plan, our servers tell Meta through its Conversions API. We send a one-way hash of your email address and of your account or workspace ID, and for sign-up your IP address and browser details. We never send the content of your claims or receipts, and nothing from the signed-in console pages.
Opting out: we honour Global Privacy Control. If your browser sends it, the pixel doesn’t load, and we don’t send Meta your sign-up or subscription. You can also opt out at any time by emailing [email protected].
6. Where it’s stored
We are based in Canada. Our systems store data in the United States, and our providers may process it in other countries. Wherever it’s processed, we protect it as this policy describes. Data held in another country may be accessible to that country’s authorities under its laws.
7. How long we keep it
We keep account and workspace data for as long as your account is active. If you ask us to delete your account, we delete your account and workspace data within 30 days, except where we must keep something to meet a legal obligation or to resolve a dispute.
Receipts are built to be permanent, because their value is that they can’t be quietly changed. On request, we delete the receipt contents we hold, but the cryptographic hashes already in our log and on the blockchain remain. They don’t reveal those contents.
Contact-form messages are kept while we’re in touch with you and for follow-up, and deleted on request.
Security logs are kept for a limited period, then deleted.
9. Security
Data is encrypted in transit. Signing keys live in AWS KMS and can’t be exported. API keys are stored only as hashes, and our GitHub access is read-only and short-lived. No system is perfectly secure; if a breach creates a real risk of significant harm to you, we will notify you and the authorities as the law requires. Read more on our security page.
10. Your rights
You can ask to see the personal information we hold about you, correct it, delete it, or withdraw consent where we rely on it. Email [email protected] and we will reply within 30 days. We may need to confirm your identity first.
In Canada, you can complain to the Office of the Privacy Commissioner of Canada. In the EU or UK, you also have the rights to data portability, to object, and to restrict processing, and you can complain to your local data protection authority. Our legal bases are performing our contract with you, our legitimate interest in running and securing the service, and your consent for analytics. In California, you can ask what we collect and ask us to delete it. We don’t sell personal information. Our advertising measurement with Meta may count as “sharing” under California law. You can opt out by turning on Global Privacy Control, which we honour, or by emailing us.
11. Children
QED Proof is a service for businesses and developers, and isn’t meant for anyone under 16. We don’t knowingly collect information from children.
12. Changes and contact
If we change this policy, we will update the date at the top, and tell account holders about significant changes by email or in the product before they take effect. Contact: Nuraveda, a sole proprietorship based in Toronto, Ontario, Canada, operating as Nuraveda Lab, [email protected].