· LEGAL · PRIVACY
IN EFFECT — PRELIMINARY
This document is published and in effect as of the effective date below. It is preliminary pending final review by outside counsel, and we may revise it as a result. We will post any material change here and update the effective date.

Privacy Policy

How TrueStake collects, uses, and protects your data. We read public on-chain data, identify you by email only, and never touch KYC documents, exchange keys, or your private keys.

Effective 2026-07-01 · Last updated 2026-09-05

Who we are

TrueStake ("TrueStake," "we," "us") provides audit-defensible Ethereum staking financials — a read-only analytics and tax-reporting tool. This policy explains what data we hold, why, how it is protected, and the choices you have.

TrueStake is operated by its founder and can be reached at support@truestake.io.

The principle: we collect the minimum

Data we never collect cannot be breached, subpoenaed, leaked, or sold. Data minimization is a security decision that shapes every feature we build. TrueStake derives your reward history from public on-chain data — we do not need, and therefore do not collect, the categories listed under "What we never collect" below.

What we collect

DataPurposeNotes
Email addressAuthentication (email + passkey) and, when necessary, incident or account notification.Your primary identifier. We do not collect your legal name.
Validator public keys and withdrawal addressesTo look up your on-chain reward history.Public on-chain data, but treated as personal data and encrypted at rest.
Fee-recipient addressesTo attribute execution-layer and MEV rewards to your validators.Treated as personal data and encrypted at rest.
Staking reward dataThe core product — a reconciled, timestamped record of your rewards.Derived from public on-chain sources.
Stripe customer IDTo manage your subscription.A reference token, not payment data. Card data is held by Stripe, not TrueStake.
First-party product eventsAggregate product analytics (page views, feature usage).Tied to a session identifier, not resold. See "Analytics."

Validator public keys, withdrawal addresses, and fee recipients are public on the Ethereum blockchain. We nonetheless treat them as personal data because they can, in combination, identify you — and we encrypt them at rest accordingly.

What we never collect

These are permanent product non-goals, not deferred features:

  • Government ID, passport, SSN, or date of birth. No KYC — ever.
  • Exchange API keys or account credentials. We never connect to exchange accounts.
  • Validator or withdrawal private keys. The keys that control your stake never leave your possession. Keys never leave the chain.
  • ETH or other assets in custody. TrueStake cannot move funds and holds no crypto assets.
  • Your legal name or billing address. We identify you by email only; billing address, if any, is held by Stripe.
  • Payment card data. Stripe handles billing end-to-end.
  • IP address or location in our application database. IP addresses appear only transiently in infrastructure access logs under our vendors' retention policies; we do not copy them into our application database or use them for analytics.

The complete, canonical list — with rationale — is our public data-minimization standard.

How we use your data

We use the data above only to:

  1. Deliver the product — derive, reconcile, and display your staking-reward record and generate your tax report exports.
  2. Authenticate you — email + passkey sign-in via our auth provider.
  3. Operate and secure the service — incident response, abuse prevention, and account notifications.
  4. Bill you (when paid plans are active) — subscription management via Stripe.

We do not sell, license, or share your data with data brokers or advertisers, and we do not use your reward data, tax figures, or any customer data to train machine-learning models.

Sub-processors

We rely on a small set of vendors to process data on our behalf. The current roster, and which vendors touch personal data versus only public on-chain data, is maintained in our public Sub-Processor Disclosure. In summary:

  • Supabase — database, authentication, and encrypted storage of personal data.
  • Vercel — application hosting; transient access logs.
  • Stripe — payment processing (holds billing data we do not).
  • Sentry — error monitoring.
  • Resend — transactional email delivery.
  • Cloudflare — network and edge infrastructure.
  • GitHub — source-code hosting and build automation. Holds developer credentials; no customer data is in the source repository.
  • OVHcloud — bare-metal hosting for the Ethereum node we operate ourselves. Holds no account data and has no access to TrueStake systems, but it is the company whose machine runs the node that queries your validator identifiers against the chain.

That is the complete list. If a vendor is not named here or in the Sub-Processor Disclosure, it does not process your personal data.

Data retention

We retain your account data for as long as your account is active. Your derived reward record is retained so your historical tax reports remain reproducible. You may delete your account at any time from your account settings (see "Your choices"); after a 30-day grace period an automated sweep permanently erases the account, its records, and its export files. Infrastructure access logs are retained under our vendors' own retention policies, which we do not control.

Security

Personal data — including validator public keys, withdrawal addresses, and fee recipients — is encrypted at rest. We enforce row-level security so each user can access only their own data. TrueStake itself holds no SOC 2, ISO 27001, or PCI certification; our vendors' own certifications cover their infrastructure, not our application layer. Report a vulnerability via our security posture.

Your choices

  • Access and export. Your reward record and tax exports are available to you in-product (XLSX/CSV).
  • Deletion. Delete your own account from the danger zone of your account settings — no email, no waiting on us. You confirm by typing DELETE, after which your account is scheduled for deletion and you have 30 days to change your mind using the single-use undo link we email you. After the 30-day grace period a daily automated sweep permanently erases the account and everything we hold for it — your stored records and your generated export files. Two things it does not reach, and we would rather say so: your Stripe billing record, which Stripe holds under its own retention rules and which we can ask them to remove on request, and copies inside our vendors' backups and access logs, which age out under the retention policies described above. Email support@truestake.io if you would rather we did it for you, if you cannot sign in, or to have the billing record removed too.
  • Correction. Contact us to correct account data.

If you reside in a jurisdiction that grants specific data rights (for example, California or the EU/UK), contact us and we will honor the rights available to you under applicable law. We will expand this section with jurisdiction-specific detail as our launch footprint is finalized.

Analytics

We collect first-party product-usage events (e.g., page views, feature usage) tied to a session identifier to understand and improve the product. We do not use third-party advertising trackers, and we do not copy IP addresses or precise location into our analytics.

Children

TrueStake is not directed to, and does not knowingly collect data from, anyone under 18.

Changes to this policy

We will post any changes here and update the "Effective" date. Material changes will be communicated to account holders by email.

Contact

Questions about this policy or your data: support@truestake.io.

Citations