Privacy Policy
Overview
This Privacy Policy describes what Descrimen collects, why it is collected, how it is used, and the choices available to you. Descrimen operates a bug bounty platform that matches researchers with web3 programs. The platform processes personal data of researchers and program contacts.
Descrimen is the data controller for account data described in this policy. The KYC provider acts as a separate controller for identity verification data. See the KYC Policy for details.
Data We Collect
Account data: email address, password hash, wallet address, display name, PGP key if provided.
Activity data: IP address at login and submission, user agent, timestamps, page views, API calls.
Submission data: vulnerability description, proof of concept, affected contracts, severity assessment, attachments, chat messages between researcher and program.
Payout data: destination wallet, amount, token, transaction hash, KYC status, charity election, timestamps.
Triage data: AI-assisted severity classification, deduplication hashes, program response, validation outcome.
Why We Collect It
Account data is collected to operate the platform, authenticate users, and route notifications. Activity data is collected for security, fraud prevention, and abuse detection. Submission data is collected to deliver the core service of triage and validation. Payout data is collected to execute payments and maintain financial records. Triage data is collected to improve the platform and reduce duplicate work.
Legal bases include contract performance, legitimate interest in fraud prevention, and compliance with applicable laws including sanctions and anti-money-laundering regulations.
Third Parties We Share With
KYC provider: receives identity documents and verification results for users who initiate cashout above threshold. The KYC provider is contractually restricted from using the data for other purposes.
Cloudflare: receives IP, user agent, and request metadata at the edge for DDoS protection, WAF, and caching.
Wallet RPC providers: receive transaction broadcast requests when payouts are issued. RPC providers can observe on-chain activity independently of Descrimen.
Infrastructure providers: hosting, object storage, and email delivery services receive data necessary to operate the platform.
Descrimen does not sell personal data. Descrimen does not share personal data with advertisers.
On-Chain Data
Payouts and certain platform events are recorded on-chain. On-chain data is public, immutable, and outside the scope of this policy. Descrimen cannot delete, modify, or recover on-chain data.
Researchers who elect charity payout, or who receive payments in native tokens, should assume the destination wallet is linkable to the source wallet through standard chain analysis.
Data Retention
Account data is kept until the user requests deletion. Deletion removes email, password, and profile fields from active systems within 30 days.
Submission data is kept for 7 years after closure for audit, dispute resolution, and regulatory compliance. Submission content is encrypted at rest and access-restricted.
Payout data is kept for 7 years to comply with financial record-keeping obligations.
IP logs are kept for 30 days, then permanently deleted. IP logs may be retained longer if linked to an active fraud or sanctions investigation.
Account data of suspended or banned users is retained for 5 years for abuse prevention.
Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: request a copy of the personal data Descrimen holds about you
- Deletion: request erasure subject to retention obligations above
- Export: receive your data in a machine-readable format
- Correction: request correction of inaccurate data
- Objection: object to processing based on legitimate interest
- Restriction: request that processing be limited during a dispute
Submit requests to privacy@descrimen.example. Descrimen responds within 30 days. Verification of identity is required before disclosure.
Cookies
Descrimen uses a minimal set of cookies for authentication and security. No tracking cookies. No third-party advertising. See the Cookie Policy for the full list.
Security
Descrimen encrypts submission content and payout records at rest. Data in transit is protected by TLS. Access to production data is restricted to named personnel and logged.
Descrimen does not store full identity documents. KYC documents are handled by the provider under its own security program. Wallet private keys are never collected or stored by Descrimen—users sign transactions client-side or through their own wallet.
Despite these measures, no system is fully secure. Researchers should not include unnecessary personal data in submissions. Do not paste private keys, seed phrases, or credentials into submission fields.
Children
Descrimen is not directed to children. You must be at least 18 years old to use the platform. Descrimen does not knowingly collect data from minors. If you believe a minor has registered, contact privacy@descrimen.example for deletion.
International Transfers
Descrimen operates infrastructure in multiple regions. Data may be processed in the United States, the European Union, and other jurisdictions. Where data leaves the European Economic Area, Descrimen relies on Standard Contractual Clauses or an equivalent transfer mechanism.
The KYC provider may process data in jurisdictions outside your residence. The provider's privacy policy governs that processing.
Changes
Descrimen may update this Privacy Policy. Material changes will be announced by email and in-platform notice 30 days before they take effect. The "Last updated" date above reflects the most recent revision.