Legal Documentation · Effective March 2025

Privacy Policy

How DevEleven collects, processes, and protects your information across our non-custodial social engagement protocol, micro-task feeds, and smart escrow system.

0%

Custody of private keys

Zero

Data sold to ad brokers

100%

Read-only verification

Public

On-chain settlement

01 / Scope & Controller

Scope and data controller

This Privacy Policy applies to the services, websites, micro-task feeds, and smart escrow contracts operated by DevEleven (“DevEleven”, “we”, “our”, or “us”). DevEleven is the data controller responsible for personal information processed through the platform.

Our platform connects creators seeking authentic social engagement with independent earners who complete verified engagement tasks. This policy explains what information is collected, how it is processed to verify tasks and distribute rewards, and how public blockchain settlement interacts with user privacy.

For any privacy inquiries or legal notices, our designated contact is contact@develeven.io or through our online Support Desk at /support.

02 / Data Collection

Information we collect

DevEleven adheres to strict data minimization. We only collect information essential for account security, task verification, and financial settlement:

  • Account & OAuth Identity: When authenticating through GitHub, we receive your permanent numeric GitHub ID, GitHub username, primary verified email address, and avatar image. When signing in through Google, we receive your primary email address and display name. If you configure a password in Settings, it is stored strictly as a salted, one-way cryptographic hash.
  • Social Campaigns & Task Data: For campaign creators, we record the target URL (such as a GitHub repository or profile), task goals, and escrowed points. For earners, we record task completion timestamps, claimed campaigns, and earned points.
  • Solana Wallet & Payment Identifiers: When you purchase points or subscriptions via Solana Pay, we record the unique order reference public key and the on-chain transaction signature. When you withdraw earnings, we store your destination Solana wallet address, payout token (USDC or USDT), and payout transaction hash.
  • Support Correspondence: When you submit an issue through our Support Desk, we collect your name, email address, category selection, message text, and an assigned ticket reference code.
  • Technical Request Logs: Standard HTTP request data including IP addresses, timestamps, and browser user-agent headers are collected to prevent DDoS attacks, enforce rate limits, and detect multi-account farming.
03 / Exclusions & Safety

What we never collect

To eliminate custody risks and protect user privacy, DevEleven enforces clear technical boundaries:

  • Private Keys & Recovery Phrases: We never request, process, or store secret keys or seed phrases. Your wallet credentials remain strictly inside your self-custodial wallet.
  • Credit Card Numbers: We do not store or process traditional payment cards. Subscriptions and points purchases are settled on-chain via Solana Pay.
  • Private Repositories & Source Code: Our task verification engine queries public actions only. We never request write permissions or access to private repositories.
  • Government Identification: We do not require national ID uploads, passport scans, or biometric data for standard platform participation.
04 / Data Processing

How we use your information

We process personal data strictly to deliver platform functionality and maintain ecosystem integrity:

  • Authentication: Maintaining secure user sessions and preventing unauthorized access to account settings.
  • Task Verification & Escrow Releases: Verifying genuine social engagement via read-only APIs and atomically transferring points from campaign escrow to the earner balance.
  • Payment Settlement & Withdrawals: Verifying Solana Pay transaction finality and broadcasting non-custodial crypto withdrawals to verified earner wallet addresses.
  • Anti-Abuse & Sybil Prevention: Detecting automated bot scripts, sybil attack rings, and duplicate claim submissions to ensure real human engagement for creators.
  • Support Resolution: Addressing disputed task claims, payment matching questions, and technical support inquiries.
05 / Decentralized Ledgers

Public blockchain records

The Solana network is an open, permissionless, and immutable public ledger. When you make a payment via Solana Pay or initiate an earner cashout, the following information is broadcast to the network:

  • Your public wallet address.
  • The token transferred (USDC or USDT) and numeric amount.
  • The transaction timestamp and cryptographic signature.

These records are publicly searchable by anyone on block explorers such as Solscan. Due to the decentralized and immutable nature of blockchain networks, DevEleven has no ability to edit, modify, or delete on-chain transaction history.

06 / Verification Engine

Task verification engine

DevEleven verifies social actions using official, read-only third-party endpoints. For GitHub campaigns, our backend queries public REST endpoints to verify whether an action was completed:

  • Repository stars: Checked via public star status endpoints.
  • User follows: Checked via public user following endpoints.

These verification checks only inspect public status codes. DevEleven never requests write scopes, git commit rights, or access to private repositories.

07 / Third Parties

Third-party sharing

DevEleven does not sell, lease, or monetize your personal data with third-party advertisers, data brokers, or profiling companies.

We share data exclusively with trusted technical infrastructure providers necessary to operate the application:

  • Convex Cloud: Provides serverless database infrastructure, reactive state sync, and encrypted storage.
  • Solana RPC Infrastructure: Transmits on-chain payment requests and queries transaction finality.
  • OAuth Identity Providers: GitHub and Google validate identity tokens during authentication.

We will disclose account records only if strictly compelled to do so by a valid, legally binding court order or government subpoena.

08 / Security & Retention

Security and data retention

We implement robust technical and organizational security controls:

  • Encryption: All web traffic is encrypted in transit using TLS 1.3. Backend databases are encrypted at rest with industry-standard cryptographic algorithms.
  • Access Control: Database mutations enforce strict user-level authorization rules. No user can read or modify another user's private credentials.
  • Retention Policies: Account data is retained for the lifetime of your active account. Financial ledger records and claim logs are retained for up to 36 months to resolve billing disputes, prevent sybil attacks, and comply with accounting standards.
09 / User Rights

Your privacy rights

Regardless of your location, you have clear rights regarding your personal data:

  • Right of Access: You can review your account profile, points balance, campaign history, and withdrawal activity directly in your dashboard.
  • Right to Rectification: You can update connected accounts and passwords from your account settings at any time.
  • Right to Erasure: You can request the permanent deletion of your off-chain account data, profile details, and email by submitting a ticket to our Support Desk.
  • Right to Discontinue: You may cease participating in tasks or pause active campaigns whenever you choose.
10 / Tracking

Cookies and technical logs

DevEleven uses strictly essential authentication session cookies to maintain your login state securely across sessions.

We do not use advertising cookies, third-party marketing pixels, or cross-site tracking scripts. Standard web server logs (IP address, user-agent) are retained temporarily for security auditing, DDoS defense, and rate-limiting abusive requests.

11 / Contact

Contact and dispute desk

If you have questions about this Privacy Policy, wish to exercise your data protection rights, or have a dispute regarding task verification, you can contact us through:

Questions & Answers

Frequently asked questions

Common questions about blockchain settlement, read-only API access, and account privacy.

No. DevEleven is completely non-custodial. We never request, transmit, or store your private keys or seed phrases. All transactions and withdrawals are signed directly by you inside your self-custodial wallet.

When you sign in via GitHub, we receive your public numeric GitHub ID, username, primary verified email address, and avatar image. When verifying tasks, our system performs read-only checks against public GitHub endpoints. We never request write access to your repositories or private code.

DevEleven processes payments and cashouts on the Solana blockchain. Because Solana is an open, decentralized ledger, transactions—including token amounts, timestamps, and public wallet addresses—are recorded on-chain and visible on public block explorers. This is an inherent property of blockchain networks.

You can request complete account closure and off-chain data deletion at any time by opening a ticket at our Support Desk (/support) or emailing contact@develeven.io. We will delete your account records, linked profile metadata, and email from our database. On-chain transaction records cannot be modified or deleted.

We're here to help

Questions about your account data?

Our support team reviews tickets daily and responds within 24 hours to assist with disputes, verification checks, or data deletion requests.