How this site handles data
This is an operational technical data notice, not a legally approved privacy policy. It documents how the live site currently works so that its data boundaries are visible. It may change as the product evolves; formal legal review remains pending.
Anonymous address lookups
You do not need an account to run a lookup. The public Bitcoin address you enter is still sent to the Degrees of Satoshi API so the API can return its result. “Anonymous” here means that the lookup does not require an email or user account; it does not mean the request never reaches a server.
When you compare addresses, the small comparison set is stored in your browser’s sessionStorage. It stays tab-local rather than becoming part of your private-save account. Each address must still be sent separately to the API when you look it up.
Research metrics and attribution
The site uses a privacy-minimized site-event client configured for https://metrics.degreesofsatoshi.com/api/v1/site-event. That endpoint counts only closed, allowlisted combinations of an event name, page surface and content identifier. The browser sends the request without credentials and with a no-referrer policy. The handler does not write a Bitcoin address, lookup result, email, handle, URL or query string, full referrer, cookie, raw IP value, free text or stable visitor identifier. It reads the request origin only to enforce the exact CORS allowlist. Counts describe aggregate interactions, not people or sessions, and Cloudflare Analytics Engine currently retains the aggregate event data for three months.
The Bitcoin address-graph report has a separate release-specific interaction counter. When its endpoint is enabled, an accepted event contains only a fixed release identifier, an allowed event name and a matching allowlisted asset name. The research-event handler does not write a Bitcoin address, email address, free text, full referrer, cookie or raw IP value. Cloudflare can still process ordinary request, delivery and security data as the infrastructure provider. This notice does not claim that Cloudflare Web Analytics is enabled.
If you select Check an address from that report, the browser stores only the fixed value research_report in tab-local sessionStorage. If you later choose to save a result and confirm the email link, that value can be retained as the account’s first-touch source and carried internally through a publication checkout and verified contribution. Arbitrary source values are rejected, the source is not placed in Stripe parameters or metadata, and it never affects scoring, ranking, access, or publication eligibility. Closing the tab clears the browser copy; deleting the account removes the linked database attribution through the same account-deletion process described below.
Optional private saves
If you choose Save this result, the system stores the email address you provide, the Bitcoin address, and a methodology-stamped score snapshot. These saves are private account data; they do not publish an address or prove that you control it. Saving does not create a Sentario marketing consent.
A free account can hold at most 25 distinct saved addresses. Refreshing an address already in the account is still allowed. If the account is full, email confirmation still signs you in but does not add the new address; you can remove an existing address and try again. The community publication contribution is not an account upgrade and does not increase this limit.
The email confirmation link expires after one hour. After confirmation, the browser receives a session that can last up to 30 days; the database stores a hash of the session token rather than the token itself.
Optional community submission
A saved result remains private unless you separately choose Publish score. Publication requires a public name, a security check when configured, and confirmation of the versioned publication disclosure. Publication is currently free; a one-time US$2 community publication contribution may be introduced later. Any such contribution helps deter spam and supports moderation and continuity of the community archive. It never affects rank and does not verify identity, ownership, or address control. Saving, email confirmation, and Sentario email consent never publish a score. Sharing never publishes a score or starts checkout.
Immediately before publication, the server validates and scores the saved address from the active immutable artifact, and rejects addresses present in the reviewed catalog or emergency protection list. Publication fails closed if the active catalog cannot be checked. The public community archive can show the public name; degree and current rank; the month the address was first observed on-chain; its derived placement after genesis and observed span; the Satoshi-lineage connection month; methodology, artifact, and block-height stamps; the date the stable profile first entered the community record; the date the current address was added; and account-submission metadata. The Bitcoin address is always hidden. This combination of score, month-level history, and community-record dates may still help someone correlate the profile with public blockchain data; hidden does not mean anonymous.
The public entry is submitted from an email-confirmed account. Email confirmation confirms access to an inbox; it does not verify who owns or controls the Bitcoin address. One email-confirmed account may publish one active submission. Duplicate address fingerprints, protected public names, rate limits, Turnstile when configured, payment controls, and moderation controls reduce impersonation and spam. The archive indexes address profiles, not people or entire wallets, and carries no paid ranking advantage.
Your Bitcoin address, email, account identifier, private saved-address label, Turnstile token, payment identifiers and status, and Sentario preference are not public community-archive fields. No wallet connection, message signature, or address-control proof is collected. The current publication disclosure version is 2026-08-09-history-v1.
Public information can be copied, indexed, cached, screenshotted, or reshared by other services. Unpublishing makes the stable profile and its opaque link unavailable to public reads while leaving the saved result, profile slug, and historical community-record dates private in the account for reactivation. While that dormant stable profile is retained, its public name and address fingerprint remain reserved to the same email-confirmed account to prevent reassignment. This continuity rule does not verify identity, ownership, or address control. Permanently deleting the linked saved address or deleting the account deletes the retained profile record and releases those reservations. It cannot remove copies already made elsewhere.
Email and the optional Sentario launch notice
The confirmation email is a service message needed to complete a private save. After you sign in, a separate account control lets you opt in to exactly one email when Sentario opens. It is not enabled by saving or confirmation, and saving works without it. If you opt in, the system stores one reusable current-preference record for that single launch notice, including its purpose, disclosure version, account-settings source, and latest grant or withdrawal timing.
If you cancel the Sentario launch email from your account, the system marks that preference as withdrawn. A later explicit opt-in updates and reuses the same record rather than creating an unbounded consent history. The current preference record remains with the account until the account is deleted.
For information about Sentario’s broader services, see the Sentario privacy policy. That policy is separate from this operational technical notice.
Service providers
Cloudflare provides the site, API infrastructure, storage, aggregate research metrics, and security controls such as Turnstile when configured. It processes request, delivery, and security data needed to operate and protect those services.
Resend processes the email address and delivery data needed to send confirmation messages and, if you separately opt in, the single Sentario launch notice.
Stripe hosts the publication checkout and processes the payment and fraud-prevention data needed to complete the one-time contribution. Degrees of Satoshi does not collect or store full payment-card details. The system stores the limited payment identifiers, amount, currency, and status needed to reconcile publication, refunds, and disputes.
Google Fonts supplies the page fonts from fonts.googleapis.com and fonts.gstatic.com. When those fonts load, your browser may send normal request metadata to Google.
Retention and deletion today
Expired or consumed confirmation records and expired or revoked sessions become cleanup-eligible 24 hours later. An hourly job deletes up to 10,000 confirmation records and 10,000 sessions per run, so cleanup may take longer when there is a backlog. Confirmation records also have a global 50,000-row system cap. The one-hour confirmation expiry, 30-day session expiry, and authentication-record cleanup are not a general database-retention schedule.
You can unpublish a community submission, remove individual addresses, cancel the optional Sentario launch email, delete your account and private saved data, or log out from the Private saves panel. Unpublishing keeps the underlying save and dormant stable profile private. Permanently deleting the saved address currently linked to that profile also deletes its opaque slug and profile history. Account deletion removes confirmation records associated with the account email, the user record, sessions, saved addresses, score snapshots, active or dormant public-submission records, and consent records, and expires the session cookie.
Saved account, address, snapshot, and current consent-preference data otherwise remain until user action or a future retention process adopted after legal review. No broader database retention deadline is promised by this notice.
Wallet safety boundary
Degrees of Satoshi scores public on-chain addresses. It will never ask you to connect a wallet, sign a message, or provide a seed phrase, private key, wallet password, or xpub. Do not submit any of those secrets. An address lookup, saved result, or community submission is not proof of identity, ownership, or control.