01What we collect
Account: your name, email address, a password hash (never the password), whether your email is verified, and when the account was created. Your sign-in session is a random token in a secure cookie; we do not store your IP address or browser details with it.
Projects and teams: project names, team membership and roles, invitations (sent to the address you enter), API key hashes and labels, monitored identifiers, webhook URLs and signing configuration, and directory listings you choose to publish.
Billing: handled by Stripe. We keep the Stripe customer and subscription references, plan, status and period dates. Stripe holds your card details, billing name, address and any tax ID you add (used to calculate tax); we never receive the full card number.
Usage: counts of operations per project per month for allowances, and aggregate service statistics (totals per endpoint and status, flushed every 60 seconds). These aggregates do not contain IP addresses, identifiers you looked up, API keys, request bodies or user agents.
Evidence: when anyone resolves a public identifier, the public documents fetched and the checks performed are stored as evidence history. This is public data published by the identifier’s controller and is not linked to who asked.
Security: to stop abuse, sign-in and email endpoints keep short-lived rate-limit counters keyed by IP address, deleted within a day; our infrastructure providers may log connection data briefly for security.
Messages: what you send to [email protected].
02Why we use it (legal bases)
- To provide the Service and bill for it (contract): accounts, projects, keys, monitoring, webhooks, subscriptions, invoices.
- To keep it secure and reliable (legitimate interests): rate limits, fraud and abuse prevention, aggregate capacity statistics.
- To meet legal duties (legal obligation): tax, accounting and lawful requests.
- Transactional email (contract): verification, password reset, team invitations and account deletion only. We do not send marketing email without your consent.
05How long we keep it
- Account and project data: until you delete the account. Deletion removes your login immediately and closes your projects, keys, webhooks and listings.
- Sign-in sessions: 1 hour after last activity; expired sessions and one-time links (1 hour; invitations 7 days) are removed automatically.
- Monitoring events: shown for 30 days.
- Aggregate service statistics: 400 days.
- Billing records: as long as tax and accounting law requires (typically up to 7 years), kept by Stripe and in our records.
- Encrypted backups: rotate out within 90 days.
06Your rights
Depending on where you live (including under the GDPR, UK GDPR and US state laws such as the CCPA/CPRA), you may access, correct, export or delete your personal data, object to or restrict processing, and withdraw consent. Most of this is self-service in the console, including account deletion. For anything else, email [email protected]; we answer within 30 days and may need to confirm it is you. You may also complain to your local data protection authority.
We do not sell or “share” personal information as those terms are defined in California law, and we do not use it for cross-context behavioural advertising.
07International transfers
DID.is runs in the United States (AWS us-east-1). When we transfer personal data from the EEA, UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK addendum) in our providers’ data processing terms, or on the providers’ certification under the EU–US Data Privacy Framework where applicable.
08Security
Traffic is encrypted with TLS. Passwords and API keys are stored only as hashes; one-time secrets are shown once and never logged. Servers are not reachable directly from the internet, and backups are encrypted. No system is perfectly secure; if a breach affects your data we will tell you and the authorities as the law requires. Report vulnerabilities to [email protected].
09Children
The Service is not directed to children under 16 and we do not knowingly collect their data. If you believe a child has given us data, email us and we will delete it.
10Changes and contact
We will post changes here and, if they are material, email you before they take effect. Contact: Blockchain Intelligence LLC, 30 N Gould St STE N, Sheridan, WY 82801, United States, [email protected].
Questions about this document? Write to [email protected]. We reply within 2 business days.