Skip to main content
Sign in

PoolIndex Privacy Notice

Version beta-2026-09-20.3. Effective 2026-09-20. Last updated 2026-09-20. © 2026 Lior Elbaz, Israel. All rights reserved. No copying, sale, or commercial use without prior written permission from Lior Elbaz. Closed Beta. This document is not a legal certification.

Who operates PoolIndex

PoolIndex is operated by Lior Elbaz, Israel. Contact for privacy questions: privacy@POOLINDEX_DOMAIN (configuration required before Closed Beta launch). This notice describes what the running application actually stores. It is not a claim of certification under any privacy statute.

Account data

WHAT: email, scrypt password hash (not the password), optional display name, unique user ID, invite code, role, plan, account status, created/last-login timestamps. WHY: authenticate you, isolate testers, enforce invite and stage caps. WHERE: file store under var/beta/state.json on the operator host. RETENTION: while the account exists, then as in DATA_RETENTION.md. WHO: you (your own record) and Beta operators/admins. THIRD PARTIES: email/outbox delivery if a mail provider is configured.

Consent records

WHAT: user ID, Terms version, Privacy version, acceptance timestamp. WHY: prove you accepted the documents you were shown; support later re-acceptance when versions change. WHERE: account record in var/beta/state.json. RETENTION: with the account. WHO: you and operators. Checkboxes in the UI are not sufficient by themselves — the server rejects registration without acceptTerms and acceptPrivacy.

Public wallet addresses

WHAT: checksummed public 0x addresses you paste or connect. WHY: read-only eligibility/pool checks you request, and Free/Pro wallet-slot limits. WHERE: (1) browser sessionStorage for the address currently in the UI session; (2) the account record (user.wallets) on the server. RETENTION: on the account until you request closure or an operator removes the binding. WHO: you and operators. PoolIndex does not request or store private keys, seed phrases, recovery phrases, or wallet passwords. Secret-shaped input is rejected.

Sessions and tokens

WHAT: HMAC-signed session cookies, session IDs, email-verify and password-reset token hashes, expiry times. WHY: keep you signed in and complete verification/reset. WHERE: HTTP-only cookie plus var/beta/state.json. RETENTION: sessions expire (about 7 days) or are revoked on logout/disable; unused tokens expire. WHO: the operator host. IP addresses are not stored in the session record.

IP and security events

WHAT: security log lines may include event type, user ID, email, optional IP (login attempts), and a short detail code. WHY: detect abuse, lockouts, and admin actions. WHERE: var/beta/security.jsonl. RETENTION: product policy in DATA_RETENTION.md; LEGAL REQUIREMENT TO CONFIRM. WHO: operators. Rate limiting also keeps short-lived in-memory IP counters that are not written as a user profile.

Scan activity and telemetry

WHAT: scan started/completed/failed, query text (truncated), sources used, duration, item counts, blocked counts, source failures, resource-limit events, application errors, app version, user ID. WHY: debug Closed Beta quality and host protection — not advertising. WHERE: var/beta/telemetry.jsonl, var/beta/scans/{userId}.jsonl, var/beta/errors.jsonl. RETENTION: DATA_RETENTION.md. WHO: operators. Queries can be personal; they are stored to investigate failures.

Deep Hunt and leads

WHAT: hunt records (query, plan, progress counters, public URLs seen, lead cards, evidence snippets from public sources, optional public wallet used for research, pause/stop state). WHY: persist an investigation you started so it survives refresh. WHERE: var/beta/hunts/{userId}/{huntId}.json. RETENTION: until account closure processing, then operator policy. WHO: you (your hunts) and admins (stop/stats). Continuous Hunt, if enabled later on Pro, re-reads stored public leads. PoolIndex does not access private blockchain information.

Feedback

WHAT: feedback type, optional short note, source name, claim/lead id, result host, app version, status. WHY: judge whether results help testers. WHERE: var/beta/state.json. RETENTION: DATA_RETENTION.md. WHO: you and operators. Notes that look like seed material are rejected.

Email / outbox

WHAT: verification, password reset, and hunt-notification mail (recipient, subject, body/link, timestamp). WHY: operate the account and optional hunt alerts. WHERE: var/beta/outbox.jsonl and, if configured, an external MailProvider. RETENTION: DATA_RETENTION.md. WHO: operators and the mail provider if one is configured. Terms acceptance is not marketing consent. PoolIndex does not send promotional mail in this Beta.

Admin actions

WHAT: invite creation, user status/plan/role patches, kill-switch changes, feedback status, hunt stops, deletion processing. WHY: run a closed test. WHERE: state.json plus security.jsonl. WHO: admin-role operators listed in POOLINDEX_ADMIN_EMAILS.

International hosting and APIs

The operator host for this preview is the machine running PoolIndex (this Cloud/preview environment is ephemeral; durable copies may live on the operator's Linux backup host). Third-party APIs (GitHub, Internet Archive/Wayback, public Ethereum/Arbitrum RPC, and similar) may process query URLs, repository searches, or public addresses outside that location. LEGAL REVIEW REQUIRED for transfer/legal-basis analysis. See PROCESSORS.md.

Your requests

You may request account closure, a copy of your account record, a correction, or a privacy question from the account page or by emailing privacy@POOLINDEX_DOMAIN (configuration required before Closed Beta launch). Closure is request-plus-operator-process in this Beta so security logs are not silently destroyed. User A cannot request deletion of User B.

Changes

If collection practices change, we publish a new Privacy version. You may be asked to accept it before continuing.