Privacy Policy

Last updated: March 2026

1. Who we are

CleanProof is operated by Simeon Hagmüller, Austria. Contact: hello@cleanproof.io

2. What data we collect

When you use CleanProof we collect:

  • Email address (via authentication)
  • Phone number (for verification, stored as a hash — not the raw number)
  • GPS coordinates of cleanup locations
  • Before and after video footage of cleanups
  • Device fingerprint (for fraud prevention)
  • Reputation score and activity history
  • Lightning address (if provided for withdrawals — stored in your profile)
  • Interview video and photo content (if you participate in a coordinator-recorded interview with consent)

Funders additionally provide:

  • Name and contact details submitted via inquiry form
  • Lightning payment hash for your pool deposit

3. Why we collect it

  • Email and phone: to authenticate your identity and prevent Sybil attacks
  • GPS and video: to verify cleanups are genuine and create permanent proof of impact
  • Device fingerprint: to detect and prevent fraudulent submissions
  • Activity history: to calculate reputation scores and rewards

4. Legal basis (GDPR)

We process your data on the basis of:

  • Contract performance: to provide the CleanProof service you signed up for
  • Legitimate interests: fraud prevention and platform integrity
  • Consent: for promotional use of cleanup footage (you may withdraw consent at any time)

5. Data retention

Video footage is retained permanently as cryptographic proof of cleanup activity. This is fundamental to CleanProof's transparency architecture. GPS coordinates and submission data are retained permanently for the same reason. Account data is retained while your account is active and for 2 years after deletion.

6. Who we share data with

We do not sell your data. We share minimum necessary data with service providers solely to operate the platform:

  • Twilio (SMS verification — receives your phone number to send a verification code)
  • BTCPay Server (Lightning payments — processes Lightning invoices and payments)
  • Railway (infrastructure — hosts the self-custodial Lightning node that sends payouts)
  • Alby relays (Nostr relays — carry encrypted payment commands between CleanProof and our Lightning node; message contents are encrypted in transit)
  • Resend (email delivery — receives your email address to send transactional and notification emails)
  • Base44 (platform infrastructure — hosts all application data)

All service providers are contractually required to process data only as instructed.

7. Your rights (GDPR)

You have the right to:

  • Access the data we hold about you
  • Correct inaccurate data
  • Delete your account and associated data (except permanent proof records — see section 5)
  • Object to processing
  • Data portability

To exercise these rights contact hello@cleanproof.io

8. Cookies

CleanProof uses only essential cookies required for authentication. No advertising or tracking cookies are used.

9. Security

All data is encrypted in transit and at rest. We use industry-standard security practices. In the event of a data breach affecting your personal data we will notify you within 72 hours as required by GDPR.

10. Children

CleanProof is not intended for users under 13 years of age. We do not knowingly collect data from children under 13.

11. Changes

We may update this policy. We will notify users of significant changes via email. The current version is always available at cleanproof.io/privacy.

12. Contact

Data controller: Simeon Hagmüller, Austria

Email: hello@cleanproof.io