Privacy policy
Document version: epora-beta-3
41BIT LLC is the controller responsible for personal data it processes to operate the hosted Epora web application and API. Send privacy requests to 41BIT LLC, the sole service operator, using the contact below. This policy does not govern independently operated wallets, public blockchain participants, or copies of the software hosted by others.
Data used by the service
The service processes wallet addresses, public key hashes, public transactions, balances, contract configuration, and participant roles. Its indexer collects public blockchain records, including participants named by other users who may never visit Epora. Proposal functions store titles and descriptions, transaction data, creator key hashes, collected signatures, and timestamps. Wallet sign-in stores a public key hash and first and latest sign-in times. Support messages contain the information you choose to send. Do not put secrets or unnecessary personal information in proposals or support messages.
Keys and the public blockchain
Your connected wallet handles private keys and signing. Epora does not ask for a seed phrase or private key. Addresses and key hashes can still identify you when linked to other information. Submitted blockchain transactions and contract data are public and can be copied worldwide. We cannot erase or change records held on the blockchain by other participants. Avoid placing names, contact details, or other private information on-chain.
Purposes and legal bases
We use necessary wallet and proposal data to provide the functions you request. Where data protection law requires a legal basis, providing requested functions supports performance of our agreement with you. Public blockchain indexing, service security, abuse prevention, and fault diagnosis support our legitimate interests in operating and protecting the service. The agreement basis does not apply to people who have no agreement with us. Legal obligations may require other processing. Where separate consent is required for optional processing, it must be requested separately from beta risk acceptance.
Cookies and browser storage
The service uses a session cookie to record the network and version of your beta acknowledgement. Wallet sign-in uses a separate cookie with a seven-day validity period. Browser storage can also hold your last wallet choice, address mappings, recent recipients, display preferences, proposal drafts, and pending wallet updates. These support the application and are not advertising cookies. Your browser controls persistence, including whether it restores session cookies. Clearing storage can remove settings and drafts and require you to sign in or accept the notice again.
Connection data and diagnostics
Hosting systems receive technical connection data, such as IP addresses, request details, and browser information. Abuse controls store a hash derived from caller identity rather than a raw IP address in their database table. This is not a promise of anonymity. When Sentry error reporting is configured, it receives error details and diagnostic context. The application filters recognized sensitive fields before sending Sentry events. Other service logs may contain error details. Session replay and performance tracing are disabled in the application configuration. Error reporting, when enabled, can run before you accept the beta notice.
Who receives data
Saved proposal titles, descriptions, transaction details, and signatures are visible to the creator and authorized wallet participants, including before blockchain submission. Hosting and database providers process data needed to run the service. Blockfrost and Koios process chain-data requests. Blockfrost may also receive signed transactions for submission. If you use mobile pairing, WalletConnect/Reown supplies relay services. Your chosen wallet receives connection and signing requests. Sentry receives diagnostics when configured. Public blockchain participants receive data included in submitted transactions. We may disclose data when legally required or when necessary to address fraud, security incidents, or legal claims. Contact us for details about the providers used by the hosted service.
Processing locations
41BIT LLC is a United States company. Service providers and blockchain participants may process data outside your country. Provider regions and transfer arrangements depend on the hosted deployment. Where applicable data protection law restricts an international transfer, the transfer requires a valid legal mechanism. Contact us for the locations and safeguards that apply to your data. Public blockchain publication makes transaction data available worldwide.
How long data is kept
Retention depends on the purpose of the record, operational needs, and applicable legal duties. Public blockchain records persist independently of us. Off-chain wallet indexes, proposals, signatures, and sign-in registrations do not all have automatic deletion periods. Expiry of an authentication challenge or rate-limit window does not mean its database record is immediately deleted. Provider logs and backups have separate retention settings. Contact us for current retention details or to request deletion. We may need to retain records for legal obligations or claims, and blockchain copies cannot be deleted by us.
Your rights and requests
Depending on applicable law, you may request access, correction, deletion, restriction, or a portable copy of personal data. You may be able to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. You may complain to your competent data protection authority. Send requests to the contact below. We may need proportionate identity checks, but will never ask for your seed phrase or private key. Some requests have legal exceptions or cannot change public blockchain data.
Policy changes
We may update this policy when the service or its data practices change. The document version identifies the current text. Material changes to the beta terms or risk disclosures require a new acknowledgement. Read the current policy before supplying information or using wallet features.
Sole service operator, contracting party and privacy contact
41BIT LLC
Wyoming limited liability company. Entity ID: 2026-001999964.
Business mailing address: 5830 E 2nd St, Ste 7000 #36418, Casper, Wyoming 82609, United States
Legal notices, privacy requests and support: info@41bit.io