Policy template
Privacy Policy
A plain-language outline of the information needed to operate and secure the membership platform.
Draft requiring qualified review
This is a product template, not legal advice or a finalized policy. Qualified counsel must review and tailor it for the operating entity, jurisdictions, providers, and actual production practices before launch.
Career and income data
Resume text, job descriptions, cover letters, recruiter messages, pasted opportunity text, and interview answers are processed only in the active browser and are not submitted to CoinPork. If a member saves a career profile or scam review, CoinPork receives only a member-approved alias, SHA-256 fingerprint, character or term count, reduced pattern identifiers, dates, states, and bounded notes—not the original text, name, contact line, recruiter contact, or application document.
Application, interview, offer, skill-plan, and realized-income records store member-entered aliases, role or skill labels, sources, stages, dates, self-scores, compensation components, received amounts, and notes. Members must not enter Social Security numbers, identity-document details, bank information, background-check records, work-eligibility documents, passwords, or authentication material. Career exports contain the reduced saved records and leave CoinPork control when downloaded.
Household benefits and value data
The official-resource directory and benefit-scam message checker can be used without saving a record. Scam message text is processed only in the active browser and is not submitted to CoinPork. A saved opportunity profile contains only a U.S. state code, broad resource-category identifiers, and a review date; it does not contain eligibility answers, household income, an address, identity data, immigration status, or disability details.
Application, document-readiness, confirmed-value, consumer-action, housing-comparison, caregiver, and education-aid records store member-approved aliases, official source URLs, categories, stages, dates, entered amounts, reduced arithmetic, and bounded notes. Members must not enter names, email addresses, phone numbers, street addresses, Social Security or benefit numbers, identity documents, account information, tax returns, financial statements, medical records, diagnoses, transcripts, essays, passwords, authentication material, application contents, or correspondence. CoinPork does not submit these records to agencies or providers. External links and downloaded exports leave CoinPork control and are governed by the member's device and the external provider.
Life Admin and Savings data
Recall Watch sends only generic product keywords and, when supplied, a vehicle year, make, and model to fixed CPSC, FDA, and NHTSA endpoints. It stores those reduced watch terms, official response summaries, provider availability, timestamps, and match identifiers. Members must not enter or store a VIN, plate, owner, address, purchase record, lot associated with a person, or other vehicle or product ownership identifier. Recall results are not complete coverage or a product-safety determination.
Medical-bill, energy, travel, childcare, and broadband records store aliases, broad state codes, official URLs, entered totals, calculated comparisons, workflow states, dates, and bounded notes. Saved text rejects common names, contact details, addresses, identity data, medical details, policy, account, claim, reservation, ticket, VIN, document, and authentication patterns. Bills, EOBs, diagnoses, treatment information, provider and patient details, insurance records, passenger and child data, service addresses, applications, correspondence, and source documents must remain outside CoinPork.
A Life Admin concierge request creates a normal support ticket containing the member's reduced scope, questions, review category, and selected-record count. A private quote request is visible to the member and CoinPork administrators until an operator records a real reviewed offer; it is not automatically shared with a vendor. Annual Life Admin statements report member-authored ledger categories separately because entries can overlap and do not represent verified ROI.
Member Action and Recovery Center data
Official recovery sweeps, provider and complaint observations, FTC refund watches, household deadlines, state-level weather watches, and realized-savings ledgers store member-entered aliases, public organization names, broad state codes, dates, amounts, workflow states, official source URLs, reduced public response summaries, and bounded notes. FDIC, CFPB, FTC, and National Weather Service requests send only the public organization name, bounded keyword, or state code needed for the selected check. NCUA, SEC, and federal recovery searches use direct official handoffs.
Members must not enter names, addresses, contact details, account or claim numbers, license or passport numbers, identity documents, applications, receipts, statements, correspondence, credentials, or authentication material. A monthly Action Desk request creates a normal support ticket from its reduced scope and questions. Appointment RSVPs use an existing member account and a published session record. Private buying requests remain visible to the member and CoinPork administrators; verified benefit inventory is displayed from operator-managed funded campaigns. CoinPork does not submit outside actions, establish eligibility or wrongdoing, guarantee savings, or require a CoinPork identity-document upload.
Advanced operations, route evidence, and accountant rooms
Advanced Operations Desk L2 trackers, intent inspection results, and Treasury Policy Workspace records are stored only in the current browser and can be included in an encrypted Local Data Vault backup. Live receipt, smart-account, NFT, and public-address checks send the selected network and submitted public identifier to CoinPork and the configured read-only provider for that request; CoinPork does not treat an address as proof of identity or ownership.
Route Reliability Index stores provider, network, asset, outcome, timing, and one-way hashes of receipt evidence after checking the submitted public transactions. Raw transaction hashes are not retained, and aggregate cohorts remain unpublished until at least five distinct members contribute. Accountant Collaboration Rooms store structured summaries and comments encrypted at rest, plus an access-token hash and prefix, expiry, revocation, and access times. Raw access tokens are shown once inside a URL fragment, files are not accepted, and access ends when the room expires, is revoked, or the owner loses eligible account access.
Assurance Operations data
Findings, policies, SSDF and ASVS readiness maps, threat models, VEX-oriented decisions, cryptographic inventories, reliability totals, vendor registers, retention registers, and release gates store member-entered labels, narratives, states, roles, dates, aggregate counts, public reference URLs, and selected CoinPork record metadata. Narrative fields must not contain credentials, private keys, recovery material, personal records, source code, or proprietary evidence. Scheduled checks recalculate member-entered due and expiry states and can create notifications.
Evidence Request Rooms retain a one-way access-token hash and prefix, expiration, bounded public scope, and encrypted requester labels, contact routes, questions, reasons, owner responses, and selected evidence metadata. Raw tokens are shown once in a URL fragment and are not recoverable by CoinPork. Public signed release records deliberately expose the member decision, calculated summary, and selected record titles, types, states, and dates; they are unlisted and request no indexing, but anyone with the link can copy them.
Assurance Workbench data
Questionnaire answers, control mappings and tests, policy exceptions, access-review labels, recovery objectives, contract-obligation notes, processing inventories, supplier worksheets, SAMM roadmaps, AI evaluations or incidents, and audit-preparation projects store member-entered labels, narratives, states, role labels, dates, counts, and selected CoinPork record metadata. These tools require no CoinPork identity-document upload and do not discover external data, verify a named person, or connect to identity, supplier, contract, audit, or AI systems.
Exports contain the selected record and its stored bounded content. CSV cells that begin with spreadsheet-formula characters are prefixed for safer opening. Scheduled checks recalculate due or gap states and may create deduplicated notifications. Members must not enter credentials, wallet secrets, personal records, source code, regulated records, or proprietary evidence in narrative fields and remain responsible for lawful collection, retention, sharing, and deletion.
Client Assurance Studio data
Client trust centers, control schedules, executive briefs, vulnerability context, reduced infrastructure-review results, tabletop exercises, insurance packets, AI cards, subprocessor registers, CSF profiles, and retainers store member-entered labels, narratives, role labels, dates, monetary terms, states, public URLs, and selected CoinPork record metadata. Infrastructure source files are processed in the browser; CoinPork receives only the filename, size, detected format, SHA-256 digest, selected rule states, and matching line numbers—not the source contents.
Privacy request intake stores an access-token hash and prefix, expiration, public scope, and encrypted requester labels, contact routes, request details, relationship notes, identity-check notes, and response records. Raw bearer tokens appear once in a URL fragment. Optional trust-center, AI-card, and subprocessor pages deliberately expose the published content and evidence metadata; anyone with a link can copy it. CISA KEV and FIRST EPSS lookups send only a CVE identifier to those public services and store their dated response or error state.
Member Value Studio data
Outcome playbooks, member-entered DeFi and staking records, identity and purchasing worksheets, service launches, monthly digests, and client portfolios store bounded labels, dates, values, states, notes, and selected CoinPork record metadata. Public addresses are optional labels and are not treated as proof of ownership or identity.
Selected cost-basis CSV, classification text, log, and source files are processed in the active browser. CoinPork receives only the submitted filename, byte size, format, SHA-256 digest, row count, selected finding categories, counts, member-reviewed states, bounded line numbers, and notes—not the original contents, matched values, or locally replaced copy. Refreshing before export can remove unsaved browser results.
Connected Member Value data
Evidence graphs, terms and fee records, merchant trust pulses, client acceptance work, deterministic draft metadata, trusted-contact labels, review requests, value entries, monthly priorities, renewal dates, and selected CoinPork record metadata are stored with the member account. Trusted-contact labels are member-authored and should not contain secrets or unnecessary personal information; CoinPork does not verify or contact those people through this workflow.
Selected 1099-DA CSV files and workspace archives are read first in the active browser. For a 1099-DA review, CoinPork receives only submitted file metadata, SHA-256, bounded exception fields, member notes, and selected record metadata—not the source CSV. A member who confirms restore sends the selected supported record payloads to CoinPork for additive storage. Workspace exports contain supported private record payloads and should be stored securely.
The Evidence Copilot uses selected CoinPork record metadata and deterministic templates; it does not send those records to an external AI provider. A Professional Review Credit creates a normal support ticket containing the submitted scope, questions, review category, and selected-record count.
SMB Cloud and AI Security data
SaaS, OAuth, asset, access-lifecycle, credential-rotation, AI-vendor, agent-spending, continuity, and maintenance-package records store member-submitted labels, categories, dates, states, amounts, owner roles, permission summaries, notes, and selected CoinPork record metadata. Members should use aliases and role labels where possible and must not submit administrator credentials, OAuth tokens, credential values, confidential prompts, or unnecessary personal information.
Selected SaaS configuration exports, cloud IAM policy files, and browser-extension manifests are processed in the active browser. CoinPork receives only submitted filename, byte size, format, row count, SHA-256, selected rule identifiers, counts, bounded line references, member-reviewed states, extension label and version, and declared permission summaries—not the original file contents. Extension manifest labels and declared permissions may still reveal information about installed software.
For payment-detail changes, previous and proposed raw values are converted to SHA-256 fingerprints in the browser. CoinPork receives the fingerprints, counterparty label, change category, selected independent channel, member-recorded confirmation state, dates, and note—not the raw payment details. A fingerprint can still be sensitive when the original value is guessable or available elsewhere.
Operations and AI Control data
License, security-budget, logging, remediation, incident, vendor-exit, and agent-drill records store member-submitted labels, bounded scope, dates, states, costs, seat counts, role labels, control selections, task notes, and timeline entries. Potential savings are calculated from submitted cost and seat values and are not treated as realized value.
Selected invoice, configuration snapshot, shadow-tool, MCP connector, and AI tool-call log files are processed in the active browser. CoinPork receives only submitted filenames, byte sizes, formats, row counts, SHA-256 digests, reduced tool fields, transport totals, selected rule identifiers, aggregate counts or amounts, bounded row references, member-reviewed states, and notes—not the original files, invoice references, payment values, connector endpoints, commands, arguments, environment-variable names or values, or log contents.
Incident timelines and tasks can contain sensitive operational context. Members should use bounded descriptions, avoid protected forensic evidence and unnecessary personal information, and retain authoritative evidence through an appropriate incident-response process. These services require no CoinPork identity-document upload and do not connect to billing, accounting, cloud, SaaS, MCP, AI-agent, logging, payment, or emergency systems.
Everyday Security and Recovery data
Email-rule and file-sharing exports are processed in the active browser. CoinPork receives only the submitted filename, size, format, row count, SHA-256 digest, selected-pattern labels and counts, bounded row numbers, states, and notes—not mailbox messages, file contents, recipient addresses, destinations, or the original export.
Device, router, lost-device, impersonation, awareness, BYOD, disposal, and cyber-handbook records store member-entered aliases, scope, dates, control or task states, aggregate participation counts, selected sanitization labels, approval states, notes, and selected CoinPork record metadata. Members should avoid serial numbers, addresses, names, credentials, payment details, confidential evidence, and unnecessary personal information.
These services require no CoinPork identity-document upload and do not connect to mailboxes, file services, devices, routers, identity providers, mobile-device managers, payments, remote-control services, training systems, or sanitization vendors.
Information collected
Document account details and requested changes, notification delivery and read state, membership and payment references, reward ledger activity, withdrawal destinations, support communications, private member buying requests and their operator review state, Academy scores and completion history, weekly mission completions, monthly season progress and private activity-calendar signals, roadmap votes, optional profile alias, presentation and visibility preferences, XP history, level, collectible unlocks, game session timing, decisions, verified scores, and proportionate security signals such as hashed network identifiers and session metadata. Academy attempts store an answer-set hash for integrity and do not retain the raw selected answers.
Digests, reports, and private transcripts
The Weekly Digest, Reports Center, and Achievement Passport calculate summaries from account, membership, reward, payment, payout, learning, game, collectible, support, and security records already described in this policy. Opening, filtering, or printing these views does not itself publish the member's activity, create reward eligibility, produce financial activity, or add a new category of profile data. Printed reports, private certificates, and downloaded CSV files are handled by the member's browser and device, so members should store, share, or dispose of those copies securely.
Leaderboards and game records
Leaderboard participation is optional. Public rankings display the chosen alias, level, relevant seasonal XP, and verified game score—not the member's name, email, reward balance, payment amount, or withdrawal history. Turning participation off removes the profile from new rankings without deleting private activity records needed for account history, integrity, abuse review, or disputes.
Optional public progress profiles
Profile publication is off by default and is a separate choice from leaderboard participation. While enabled, a profile URL can show the chosen alias, earned title, avatar theme, membership month and year, lifetime and seasonal XP, level and season tier, Academy and mission counts, verified game records, and selected owned collectibles with earned dates. It never publishes the account name, email, reward balance, payments, withdrawals, payout destination, referral activity, spending, or private risk signals.
Disabling publication makes the route unavailable, but does not delete private progress records required for account operation and integrity. Public member profiles ask search engines not to index them, but that instruction cannot prevent a person who has the link from viewing or sharing the page while publication remains enabled.
Local planning, library, and navigation preferences
The Safety Center stores only generic checklist identifiers and completion selections in the browser's local storage. Planning Studio stores only selected plan identifiers, local start dates, and completed generic milestone identifiers. The Weekly Digest focus board stores a UTC week identifier plus up to three generic focus identifiers and their local checkmarks. The Operations Library stores only canonical worksheet identifiers saved to the member's kit. Library searches are filtered locally and worksheet answers are neither collected nor stored by CoinPork. The Member Command Center may store a short list of favorited and recently opened internal feature links. Command Center search terms are filtered on the device and are not stored or sent to CoinPork. These selections are not used for eligibility or risk decisions or included in public profiles. Calendar and worksheet exports are created on the device from published generic text.
Clearing site data or using another browser removes or separates that local progress and navigation history. Printed and downloaded worksheets leave CoinPork' control and should be handled safely. Members must never enter or place credentials, recovery phrases, private keys, authentication codes, API secrets, unnecessary wallet addresses, balances, transaction evidence, or sensitive personal details into checklists, calendar notes, or worksheets.
Practice Vault, bundles, and briefing preferences
The Practice Vault stores a maximum of 100 bounded member-written titles and notes, canonical categories, local timestamps, and optional CoinPork dashboard links only in the current browser's local storage. CoinPork does not receive Vault entries. Members can create a local JSON backup and later merge it into a browser; that downloaded file leaves CoinPork' control. Operational Benefit Bundle downloads are generated from fixed published text and do not upload completed answers. The Member Briefing may store only canonical issue identifiers marked as read and generic Vault follow-up references on the device.
Clearing site data removes Vault entries and briefing read state unless the member retained a backup. The Vault is not a password manager or secure evidence repository. Members must never place credentials, authentication codes, recovery phrases, private keys, real wallet addresses, balances, transaction evidence, government identifiers, medical information, or other sensitive personal data in Vault notes or downloaded worksheets.
Guardian, emergency, and calendar preferences
The Weekly Guardian Drill accepts fixed published answer choices only. The browser may store up to 26 sanitized entries containing the UTC week, canonical drill identifier, best score, and completion time. The Emergency Action Center stores only canonical scenario-step identifiers marked complete. It has no free-text incident field and does not receive or upload evidence. The Member Calendar may store one optional Safety Center review date locally; calendar exports are generated on the device from server-provided factual boundaries and that optional date.
These local selections are not used for rewards, XP, expertise claims, eligibility, risk decisions, profiles, or leaderboards. Clearing site data removes them. Members must not place real incidents, credentials, authentication codes, recovery phrases, private keys, unnecessary wallet addresses, or sensitive personal information into any downloaded plan or calendar.
Monthly Guardian Case File
The Monthly Guardian Case File creates a protected server session and records its canonical case and month, submitted fixed-choice answer indexes, timing, score, outcome, capped non-convertible XP, and collectible award. The fictional case accepts no real address, transaction, message, provider record, credential, recovery material, or uploaded evidence. Case records may be used for private progress, integrity review, aggregate service measurement, and an optional public progress profile when separately enabled.
Account portability downloads
The Account Archive is generated only after authenticated request and may contain account identifiers, email, profile settings, membership and payment references, rewards, withdrawal destinations, XP, learning and game records, collectibles, support messages, and redacted security history. It excludes password hashes, sessions, authentication secrets, private keys, recovery phrases, and stored network or device hashes. The response is marked private and no-store, but the downloaded ZIP leaves CoinPork' control and should be encrypted or stored securely by the member.
Installable and offline behavior
In production, CoinPork may register a service worker that caches a bounded public emergency-reference page, public offline fallback, icon, and required static presentation assets. It is explicitly configured not to cache dashboard pages, admin pages, login pages, API responses, or authenticated account data. Development previews unregister CoinPork service workers and remove their public caches to prevent stale preview assets. Removing site data or the installed application removes the local offline cache.
Field Guide study preferences
The Crypto Field Guide filters its published reference entries on the device. If a member saves a concept or marks it reviewed, the browser stores only canonical concept identifiers in local storage. Search terms, recall choices, and study progress are not sent to CoinPork, used for rewards or eligibility, or included in public profiles. Clearing site data removes this local progress. Members should search only generic concepts and must not enter account, wallet, transaction, financial, or other personal information.
Daily Knowledge Challenge history
The Daily Knowledge Challenge is generated from the published Field Guide catalog and current UTC date. Individual answers stay in the active browser session. If a member completes a set, the browser may store up to 31 sanitized entries containing only the UTC challenge date, best score from zero through ten, and completion timestamp. CoinPork does not receive this history, use it for rewards, eligibility, risk decisions, certificates, profiles, or leaderboards, or treat it as evidence of expertise.
Decision Review Lab selections
The Decision Review Lab stores only canonical review-template identifiers, control identifiers, and the fixed selection “evidence found” or “concern” in the browser's local storage. The lab has no free-text fields and does not send the review subject, evidence, selections, coverage, or concern history to CoinPork. Clearing site data removes these selections. Printed and downloaded copies are created on the device and leave CoinPork' control. Members must not add names, domains, account identifiers, wallet addresses, balances, transaction details, credentials, recovery material, or other sensitive information to exported copies.
Market Mechanics Lab inputs
The Market Mechanics Lab uses only fictional numeric inputs held in the active browser session. It does not request names, assets, provider identities, wallet addresses, balances, holdings, transactions, live market data, or account connections, and it does not send or save model inputs or results to CoinPork. Refreshing or closing the page resets the examples. The displayed calculations are educational illustrations and are not quotes, forecasts, recommendations, eligibility records, or evidence of member financial activity.
CoinPork Markets and private Market Desk
Public market pages request a server-cached, read-only snapshot from the configured data provider and display its attribution, timestamp, and fallback state. The Member Market Desk stores watchlist identifiers, alert conditions, manually entered holdings and cost-basis totals, theses, invalidation rules, review dates, and sourced event notes in browser local storage. These workspace records are not sent to CoinPork, connected to a wallet or exchange, used for rewards or eligibility, or included in the server Account Archive. A member-created Market Desk export leaves CoinPork' control. Clearing site data removes the local workspace unless the member retained an export.
Operations Intelligence data
Background market rules are stored with the member account so a scheduled server job can evaluate them when the member is offline; evaluations, observed values, and trigger timestamps are retained with the rule, and triggered conditions can create in-site notifications or optional email. Public addresses, native-balance snapshots, sourced protocol events, fee comparisons, and monthly checkup choices are stored in browser local storage and can be included in the encrypted Local Data Vault. A submitted public address and selected network are sent to CoinPork and the configured read-only RPC only when the member requests a refresh; CoinPork does not store that request as a portfolio record. Historical CSV text remains in the active browser component and is not uploaded.
Wallet Permission Lab preferences
The Wallet Permission Lab filters a published catalog on the device. The browser may store only canonical permission-pattern identifiers, check identifiers, and the fixed state “evidence confirmed” or “concern.” Search terms are not stored or sent to CoinPork, and the lab has no field for a domain, application, address, contract, payload, signature, transaction, balance, credential, or recovery material. Printed and downloaded generic worksheets leave CoinPork' control. Clearing site data removes saved check states.
Transaction Anatomy Lab progress
The Transaction Anatomy Lab uses only published fictional cases with deliberately invalid training identifiers. The browser may store a canonical case identifier, best score from zero through four, and completion timestamp for each completed case. Individual answer choices stay in the active browser session. The lab has no field for a real hash, address, payload, signature, wallet connection, provider record, or account information, and it sends no case answers or progress to CoinPork. Clearing site data removes saved best scores.
Ledger Links Daily progress
Ledger Links uses only published crypto terms and fixed relationships. The browser may store up to 31 UTC-day entries containing the canonical board identifier, canonical solved-group identifiers, miss count from zero through four, and an optional completion timestamp. Current tile selections stay in the active browser session. CoinPork does not receive puzzle choices or history or use them for rewards, XP, rankings, certificates, profiles, eligibility, or expertise claims. Clearing site data removes local progress and streak history.
Authenticator and payout safety records
When enabled, authenticator protection stores an encrypted authenticator secret, hashed one-time recovery codes, and verification timestamps. Raw recovery codes are shown only when created or replaced. Payout Safety Lock stores member-provided labels, assets, payout destinations and tags, email-confirmation token hashes and expiry, cooling and revocation timestamps, and the optional withdrawal-freeze time. Account Archive exports include full payout destinations and authenticator status but exclude authenticator secrets and recovery-code hashes.
SafeSend, Wallet Shield, live address watches, and Breach Watch
SafeSend stores the member-submitted public target, a keyed decision record containing its masked hint and SHA-256 target hash, optional asset, amount and bounded note, assessment findings, provider status, and timestamps. Unsigned calldata and EIP-712 JSON are processed for the requested check but the raw payload is not retained; only a SHA-256 digest and bounded findings are stored. A member can delete a report unless it is linked to a requested human review. Linked reviews, operator responses, response deadlines, and any membership-time credit are included in the Account Archive.
Live Wallet Shield and SafeSend provider lookups send only the public address, public contract, HTTPS dApp URL, or unsigned public transaction fields that the member submits to the configured security provider. CoinPork applies a bounded response size and does not request a wallet connection, private key, recovery phrase, signature, transaction broadcast, identity document, or custody. Provider coverage and results may be incomplete and are not a safety verdict.
Live Wallet Watch is optional. Enabling it stores a private label, the public EVM address, configured network, synchronization and emergency-mode timestamps, and signed provider activity events such as direction, category, asset, public transaction hash, public counterparty, and event time. The configured monitoring provider receives the public address. Removing a watch deletes its CoinPork event history and requests provider removal when no other active CoinPork watch needs that address. Wallet watches and events are included in the Account Archive.
Breach Watch is separately opt-in. When enabled, CoinPork sends the verified login email to the configured Have I Been Pwned account API and stores consent and check timestamps plus returned breach name, title, domain, breach date, data classes, and verification flags. It does not send or receive the account password. Members can pause monitoring and erase stored breach metadata from the feature page; the records are also included in the Account Archive while retained.
Local Data Vault, Record Studio, goals, and accessibility
The Local Data Vault reads only an allowlist of CoinPork browser-local keys and creates an AES-GCM encrypted download using a member-selected passphrase. CoinPork does not receive the passphrase, plaintext backup, or restored content and cannot recover a forgotten passphrase. Transaction Record Studio parses and normalizes an imported CSV in the active browser session without uploading it. The file and normalized rows are cleared by refresh or the clear control. Selected Command Center goals and accessibility preferences are stored locally and may be included in the encrypted local backup.
Assessments and referral campaigns
The Quarterly Operations Assessment records a protected session, canonical quarter and assessment, fixed-choice answers, timing, score, and pass or review outcome. It accepts no real account, wallet, provider, incident, or transaction material and creates no cash reward or XP. Referral campaign links may record a sanitized campaign label and share channel with the existing referral visit record. QR images, SVG banners, and message text are generated in the browser; CoinPork does not send messages or post on a member's behalf.
Safety Concierge local records
The Suspicious Message Check processes pasted text only in the active browser tab and downloads findings without the submitted message text. The Second-Look Approval Room stores bounded proposal details, reviewer labels, decision notes, timestamps, and SHA-256 proposal fingerprints in browser local storage; exported or imported packages leave CoinPork' control. The Incident Case Concierge reads records already held by the browser-private Incident Locker and creates preparation files locally. It does not transmit a complaint to IC3, the FTC, Chainabuse, an exchange, or another provider. Safe Address Book counterparty records remain device-local as separately described.
These tools must not contain credentials, authentication codes, recovery material, private keys, unnecessary personal information, or evidence-file contents. Clearing browser data removes local records unless the member retained an export. Anyone receiving an exported package can read its contents unless the member separately protects it.
Member Services records and live checks
Reward Credit Rescue reads existing offer receipts, disputes, offerwall conversions, and authenticated callback-event metadata to create a member-requested download. It excludes raw callback payloads, passwords, provider secrets, and identity documents. The Personal Earnings Optimizer reads cleared provider and sponsor outcomes from the account while optional elapsed-time entries remain in browser local storage; local time never changes rewards, eligibility, or provider status.
Wallet Authority Watch can send a member-submitted public address and network to the configured security provider for an approval lookup, then stores only the returned-response fingerprint, provider name, check time, bounded signals, and optional member-created authority reminders on the device. Live Link Verification can send the complete HTTPS URL submitted by the member to the configured dApp-risk provider; CoinPork does not open that URL in the member's browser. Transaction Simulator can send member-supplied unsigned public transaction fields to the configured simulation provider and does not connect, sign, broadcast, or store the raw transaction on the CoinPork server.
Provider Migration Project Manager and Office Hours question briefs are stored only in the current browser and may be included in a member-created encrypted Local Data Vault backup. Their separate JSON, calendar, or text exports leave CoinPork' control. Members must exclude credentials, authentication codes, private keys, recovery phrases, identity documents, and unnecessary personal or financial information.
Expanded member-service records
The Payment Request Inspector decodes pasted text and supported QR images locally. Address Deception Guard compares member-supplied public values with the device-local Safe Address Book. Contract Change Watch stores member-entered public contract snapshots and configured-provider response fingerprints locally; an optional live lookup sends the public contract and network to the configured security provider. Security Update Watch stores selected product identifiers, member-entered versions, review status, notes, and dates locally. Recovery Readiness stores authored step identifiers, a date, and a bounded no-secrets note locally. These tools do not open a wallet, install an update, contact a trusted person, sign, broadcast, revoke authority, or prove safety.
The Annual Membership Value Review calculates a private report from existing account records and creates downloads on request. Member Savings Club reads verified partner-benefit, demand, and redemption records already described elsewhere. Private Buying Requests store the category, item, quantity, optional budget ceiling, timing, bounded requirements, operator status and response, and any matched verified campaign. Requests are limited to the member and administrators; CoinPork does not automatically publish or send them to a partner. Status changes can create an account notification and audit record.
Transfer Guardian, exposure, shared-wallet, and developer data
Transfer and bridge case files, standard ENS resolution baselines, stablecoin exposure entries, and Safe configuration baselines are stored in browser local storage and can be included in a Local Data Vault backup. A member-requested receipt, ENS, or Safe refresh sends the submitted public transaction hash, name, address, and selected network to CoinPork and the configured read-only provider; the request is not stored as a server portfolio or wallet-ownership record. Record Studio CSV contents and exception analysis remain in the active browser session.
Member Developer Hub stores API-token labels, prefixes, SHA-256 token hashes, expiry, revocation and last-use times. Raw tokens are shown once and not stored. Webhook records include a label, public HTTPS destination, chosen event types, an encrypted signing secret, enabled state, and delivery results. Signing secrets and token hashes are excluded from account archives. A configured endpoint receives only selected market-alert or opted-in public-address event data.
No routine government-ID collection
CoinPork currently does not request or store a government-ID image as part of routine registration, earning, support, conversion, or withdrawal. Independent payment, offer, or payout providers may collect identity information under their own notices, and future legal or contractual requirements may require this policy and product flow to change with appropriate notice.
Crypto operations, verification rooms, and business-service data
Batch payment CSV text and results remain in the active browser session; each requested receipt check sends the selected network and public transaction hash to CoinPork and the configured read-only RPC. File Notary reads selected files locally to calculate SHA-256 fingerprints and does not upload file contents or names. Recurring cost and authority records, operations-score choices, protocol dependency history, protocol calendar entries, provider-migration evidence reminders, and the business workspace are stored in local browser storage and can be included in the encrypted Local Data Vault.
Verification Rooms store the member identifier, room kind and title, expiration and access metadata, an encrypted payload, a one-way access-token hash and prefix, and encrypted optional confirmation notes. Counterparty rooms can contain public payment instructions; payment-proof rooms can contain a public transaction hash, destination, expected amount, receipt snapshot, and reconciliation findings. Public access and confirmation requests use rate-limiting security context, and complete secret-links grant access until expiry or revocation. Access tokens are never included in account archives.
Protocol scans send a public contract address and selected network to the configured read-only RPC. Snapshot imports send the entered public space identifier to Snapshot's public API. Professional-assistance submissions create an ordinary protected support ticket containing the entered specialty, urgency, jurisdiction, budget range, scope, and requirements; members must exclude identity numbers, credentials, secrets, and unnecessary personal or financial information.
Receivables, team operations, evidence timestamps, and fee alerts
Receivable invoices store the selected network and asset, destination, amount, status, dates, and an encrypted customer label and memo. Protected invoice links use a one-way access-token hash and prefix; raw access tokens are not retained or included in account archives. A requested payment check sends the selected public transaction hash to CoinPork and the configured read-only RPC, then stores an encrypted receipt snapshot and reconciliation result. Invoice creation, viewing, and verification never connect a wallet, request a signature, or initiate a transfer.
Team Operations Workspaces store membership roles, invited email addresses, work-item titles and descriptions, assignees, evidence fingerprints, state changes, independent approvals, and an immutable activity trail. Workspace members can see the roster and shared records according to their server-enforced role. Evidence Timestamp Desk stores only the SHA-256 fingerprint calculated in the browser, a bounded label and note, signing metadata, revocation state, and public verification code; selected file bytes and file names are not uploaded. External anchoring is prepared as a member-controlled export and is not submitted automatically.
Fee Window Alerts store a network, member-defined gas-price threshold, enabled state, last observation, notification preference, and quiet hours. The scheduled evaluator requests current public gas-price data from the configured read-only RPC and may create an in-site notification or optional email. Quote-audit records and monthly-close selections are device-local unless the member downloads an export. These server and local records are included in their applicable Account Archive or encrypted Local Data Vault categories as described by those tools.
Freelancer, import, statement, transparency, and endorsement data
Freelancer Office stores the project name, currency, budget, status, access metadata, and encrypted client label, proposal, terms, milestones, time, and expenses. A raw client-link token is shown once and retained only as a one-way hash. Credential Endorsements similarly store an encrypted request, token hash and prefix, status, displayed endorser name, statement, signature, and revocation state. The member chooses whether to share each protected link; a recipient can copy what it reveals.
The Universal Transaction Importer processes selected CSV text, file names, normalized rows, and SHA-256 fingerprints in the active browser session without uploading file contents. Receivables Pro templates and stablecoin review notes are stored in browser local storage and may be included in the encrypted Local Data Vault. The Stablecoin Transparency Monitor receives the same server-cached market snapshot used elsewhere but does not send private notes to CoinPork.
A requested Multichain Statement sends the entered public EVM address, selected network, and date filters through CoinPork to that network's public Blockscout endpoint; CoinPork does not store the address or returned statement as a portfolio record. Monthly Close Review creates a protected support ticket containing the selected period, checklist summary, bounded note, and optional manifest fingerprint, not source files. Public verification APIs and widgets intentionally expose signed record status and bounded credential, evidence, or endorsement fields to anyone who has the public code.
Advanced Utility Lab data
Allowance Watch stores the selected network, public owner, token and spender addresses, titles, check times, and bounded read-only results. Transaction preflight sends the submitted public transaction fields to the configured RPC and stores a bounded report containing the network, public sender and destination when provided, native value, calldata byte count, decoded summary, observations, and warnings; raw calldata is not retained in the report. Software Watch stores the package ecosystem, name, exact version, optional public GitHub repository, timestamps, and bounded OSV and release observations. Webhook Control Room stores endpoint identifiers, event labels, status codes, errors, sources, and times for up to 100 observations; it does not retain webhook event bodies in those observations.
Receipt and invoice OCR runs in the browser with CoinPork-hosted worker, language, and WebAssembly assets; selected image bytes and extracted text are not uploaded by that tool. Receive-only Bitcoin address derivation runs in the browser and does not send the entered xpub or derived addresses to CoinPork. The xpub can still reveal relationships among public addresses and should be handled accordingly.
Client File Room encrypts selected bytes in the browser and sends CoinPork only an AES-GCM ciphertext envelope, bounded file metadata, an access-token hash and prefix, expiry, revocation state, and access counts. The raw access token and decryption key are placed after the URL fragment and are not included in the initial page request or Account Archive; anyone with the complete link can retrieve and decrypt the file while access remains available. Offline Continuity Workspace stores an encrypted package in browser-managed origin-private storage and can import or export that ciphertext. Clearing site data, storage eviction, or losing the passphrase can permanently remove access.
Authority & Resilience Center data
Authority watches store member-selected public networks, account, collection, owner, operator, and Safe addresses plus bounded RPC or Safe-service observations, timestamps, and change fingerprints. Clear-signing reports store public transaction fields, the member's expected destination and decoded fields, and a bounded preflight report; raw submitted calldata is not retained. Dependency Radar parses the selected package-lock, SPDX, or CycloneDX JSON in the browser and uploads only up to 75 reviewed ecosystem, package-name, and exact-version records. The source document is not uploaded. Those records are sent to OSV, while CoinPork separately retrieves the public CISA catalog.
Provider Change Radar stores the selected public URL, response status, ETag, Last-Modified value, content hash, check times, and errors; query parameters are prohibited and page bodies are not retained. Refund Desk stores the BTCPay invoice identifier, refund terms, reason, optional reviewer role label, workflow state, and an attached pull-payment identifier plus bounded read-only payout status. It does not create or approve the refund. Recovery Coordinator stores generic role labels, cadence, canonical checklist acknowledgements, and dates, and rejects obvious secret material.
The Passkey-Locked Private Vault keeps its credential identifier, salt, IV, ciphertext, and update time only in browser local storage. The plaintext and WebAuthn PRF-derived key are not sent to or recoverable by CoinPork. Imported and exported envelopes remain encrypted. Browser or authenticator incompatibility, local-data clearing, or loss of the creating passkey can permanently remove access.
Trust & Continuity Suite data
Authority Graph derives display relationships from the member's existing public-address watch records. RPC Consensus stores the selected network, optional public contract address, endpoint labels, same-block observations, hashes, times, and errors; configured endpoint URLs are not exposed to members. Domain Trust stores a public domain, optional DKIM selector, public DNS and TLS observations, dates, and errors. Stablecoin Exit Readiness stores a public asset label, network, contract, official disclosure URL, route labels, bounded public observations, and errors.
Backup Restore Lab hashes both selected files in the browser and sends only SHA-256 values, byte sizes, checklist answers, and dates; file names and bytes are not uploaded. Wallet Request Inspector runs only in the browser and does not save submitted JSON. Software Authenticity temporarily processes a public artifact and Sigstore bundle in server memory, stores the artifact name, byte size, SHA-256, expected issuer and identity, result, and date, then discards both uploads. Do not submit proprietary software, credentials, private keys, recovery material, or confidential documents.
A member-published Client Trust Portal displays only selected record titles, types, states, and update dates plus the member-written summary and optional public links. It deliberately omits private record payloads and results. Connected Safety Review sends selected record metadata plus the member's question through the existing review service. x402 Seller Lab stores member-entered public blueprint fields and generated planning JSON but does not contact a facilitator or process a payment.
Client Trust Operations data
Client workspaces store a generic label, scope, cadence, tags, authorization confirmation, and related record references. Website baselines store a public HTTPS URL, response metadata, selected security headers, aggregate cookie flags, bounded mixed-content counts, body hash, score, dates, and errors. Smart-signature reports store the public signer, network, final digest, verification method and result, and a signature hash; supplied signature bytes are not retained. ERC-7579 draft module watches store public account and module addresses, exact type, additional context, observations, and errors.
Dependency and provenance documents and DMARC XML are parsed in the browser. CoinPork receives only bounded component lists, structural provenance summaries, differences, and aggregate mail-authentication counts; source files, raw XML, and source IPs are not retained. Transaction-policy fixtures and test results remain in the browser. Saved policies contain only member-entered chain, destination, value, atomicity, and calldata rules.
Public evidence packs and client reports contain member-selected record metadata and an Ed25519 integrity signature; they deliberately omit private payloads and do not constitute an audit or certification. Questionnaire questions are protected by a secret-fragment link and submitted answers are encrypted at rest for the owner, but CoinPork does not verify responder identity. Metered API records contain member-entered product, customer-label, usage, invoice-state, reviewed-payment, fulfillment, and optional transaction-hash fields; CoinPork does not process or verify those payments or deliver the resource.
Trust Agency Studio data
Managed packages, CSF readiness maps, evidence-expiration entries, incident postmortems, AI governance registers, and license reviews store bounded member-entered labels, states, dates, exclusions, summaries, owners, and selected record references. Optional public service and postmortem pages expose only the deliberately selected signed summary fields; they are unlisted and ask search engines not to index them, but anyone with the link can copy them.
OpenAPI JSON or YAML, dependency-license inventories, and selected C2PA media are processed in the browser. CoinPork receives only reduced summaries and, for a saved C2PA inspection, the locally calculated file SHA-256, byte count, MIME type, SDK version, and bounded validation counts. Source files, raw manifests, detailed signer fields, and full provenance are not uploaded by these tools. The pinned C2PA browser SDK loads WebAssembly from CoinPork; remote-manifest and OCSP retrieval are disabled, so an inspection does not deliberately contact locations embedded in the selected media.
Authorized security.txt, script-inventory, accessibility, and domain-radar checks send a public HTTPS target to CoinPork. CoinPork retrieves bounded public page content or queries the public crt.sh certificate-transparency interface and stores reduced observations, source errors, timestamps, and change fingerprints rather than full page bodies. Automated accessibility results are heuristics, certificate names are not proof of impersonation, and missing source data is never treated as a pass.
Protected vulnerability-disclosure inboxes retain a one-way access-token hash and prefix, expiration, access counts, and encrypted report fields. Raw tokens are shown once in a secret-fragment link and are not included in Account Archive exports. Attachments are not accepted, reporter identity is not verified, and recipients must not submit credentials, personal records, exploit payloads, or other secrets.
How information is used
Describe uses for account operation, payment verification, reward eligibility, fraud review, payouts, support, legal compliance, service measurement, and essential communications.
Providers and disclosures
Name the processors actually enabled in production and explain which data they receive. Payment secrets and full credentials must never be exposed to browser code. Clarify legal disclosures and prohibit sale or sharing claims unless verified against real practices.
Sponsored-offer data
If BitLabs is enabled, its embedded wall can receive the opaque account identifier required for reward attribution and can independently collect network, device, cookie, survey, demographic, and activity information under its own notices. Disclose the exact production integration, lawful basis or consent where required, international transfers, retention, opt-out choices, and links to the provider's current privacy terms before showing the wall. CoinPork should not send the member's email address in the wall URL.
Business Growth Suite data
A published business profile stores the member's chosen business name, slug, headline, summary, availability, fixed-price service catalog, public payment destinations, and portfolio references. Protected inquiries and orders store public workflow facts, encrypted client contact and note fields, one-way access-token hashes, token prefixes, status, and expiration metadata. Approved satisfaction records publish only the submitted alias, rating, and comment after explicit client consent and business-owner review.
Crypto income records store member-entered asset units, USD estimates, dates, public references, and encrypted notes. Address-control records store the public EOA, network, nonce, message fingerprint, verification time, and encrypted signed message and signature; they do not establish identity or legal ownership. Opportunity listings are visible to other paid members only after administrator review. Receipt file contents stay in the browser and are not uploaded; the metadata manifest exists only in the current tab until exported. Account archives include decrypted member-owned business fields but exclude access-token hashes and raw access secrets.
Merchant Success data
Merchant Success can store private CRM notes, stages, tags, next actions, milestones, quote and booking details, client contact fields, seller-hosted delivery links and instructions, download counts and expiration, monthly report snapshots, reputation records, and human tune-up requests and replies. Protected client viewers receive only the bounded client-facing fields; public directory and widget views use only the member's published storefront plus selected categories and public region label.
Optional BTCPay configuration stores the server URL and store identifier plus an encrypted API key and encrypted webhook secret. Those secrets are not returned by the API or included in the account archive. A configured BTCPay request sends invoice data to the member's server, and signed callbacks send invoice event data to CoinPork. External Cal.com or other scheduling links send visitors directly to that provider under its separate terms and privacy practices. CoinPork does not request identity documents for these internal tools, but outside providers may impose separate requirements.
Retention and security
Set evidence-based retention periods for account, ledger, payment, payout, audit, and risk records. Describe safeguards accurately without guaranteeing absolute security.
Rights and contact
Add rights, request methods, identity verification, appeal processes, regulator details, international transfer mechanisms, and a verified privacy contact appropriate to supported jurisdictions.
Draft status: requires review · Effective date: not yet set