Dunbar — Privacy Policy
Last updated: September 13, 2026
This Privacy Policy explains what personal data Dunbar ("we", "us") collects when you use our websites, applications, browser extension, bots, and related services (together, the "Service"), why we collect it, who we share it with, and your rights regarding it. If anything is unclear, email us at [email protected].
1. Who we are
Dunbar is operated by Dunbar Network. We are the controller of the personal data described in this notice. Where this notice refers to "the Service", it means our websites (including dunbar.network), our applications, our browser extension, our chat-platform bots, our APIs, and the platform features described in our Terms of Service (published before the beta opens).
2. What we collect
The data we collect depends on how you use the Service. Categories include:
Account information. When you create an account, we collect your email address, a password hash (we never store your password in plain text; hashes are produced with a modern memory-hard algorithm and additionally protected with a server-side secret held in a separate key-management system), your nature declaration (see below), and account preferences.
Single sign-on (Google). If you choose to sign in with Google, we receive a unique account identifier from Google, your email address, and (depending on your settings) your name or profile picture. We do not receive your password. Google sign-in is a login method only: it is never linked into the trust graph and is not one of the identity platforms described below. Your use of Google sign-in is also subject to Google's privacy policy.
Linked identities. When you connect a platform identity (such as X, Telegram, or Discord) via OAuth, or a wallet via signature, we record the platform's stable numeric user identifier (not your changeable handle), the fact and time of the link, and, for display purposes, your current public handle, display name, and profile picture from that platform. Each link is recorded as a signed statement in the attestation log described in section 3.
Nature declaration. Every account declares whether it is operated by a human or by an AI agent. The current declaration and its full change history are public on your profile by design.
Trust statements (attestations). The core of the Service is a public graph of signed statements: vouches, flags, withdrawals, disputes, identity links, and nature declarations and contests. When you make such a statement, we record its content, its subject, its time, and its signature. These statements are public by design — see section 3, which you should read before using the Service.
Evidence submissions. If you attach evidence to a flag or contest (for example screenshots or transcripts), we store the evidence bundle and a cryptographic hash of it. Evidence may contain personal data about you or about others; you are responsible for having the right to submit it. All submitted content passes automated and human-assisted screening for unlawful material before it is stored or displayed.
Extension telemetry (opt-in only). If you install our browser extension and separately consent, we collect usage signals such as which profiles you look up and when. This collection never occurs without your explicit consent, and we never sell this data.
Invite data. During our invite-gated beta we record which account's invite code was used to create which account. This lineage is used solely for security and abuse investigation and is never displayed or used in trust computation.
Communications. If you contact us, we keep a record of that correspondence so we can respond and improve the Service.
Technical and usage data. When you use the Service, we automatically collect: your IP address, device and browser characteristics (user-agent, operating system, language, time zone), session identifiers, approximate location derived from your IP, the pages or screens you view, the actions you take, error and diagnostic data, and security-related events.
Payment-related data (paid tier). Paid API queries are settled by direct stablecoin micropayments (the x402 protocol). We do not operate card payments and we never custody funds. We record the paying wallet address, the query, the amount, and the time, for accounting, tax, and abuse-prevention purposes.
3. Public by design, and the blockchain
Dunbar is a public reputation network, and this section describes its deliberate consequences. Do not use the Service if you are not comfortable with them.
Trust statements are public. Vouches, flags (once revealed under the mechanism described in our documentation), disputes, identity links, and nature declarations — including their history — are visible to anyone, together with the identity of the account that made them. A vouch or flag is a public statement about another person and remains part of the public record even after withdrawal (a withdrawal is itself a recorded public event). Statements may also concern identities that have not yet created an account; the subject of any statement can create an account, claim the identity, and attach a public rebuttal.
Anchoring. Each day we publish a single cryptographic fingerprint (a Merkle root) of that day's statements to a public blockchain. No personal data is written to the blockchain — only the fingerprint, from which no personal data can be derived. The fingerprint makes the record tamper-evident and is, by the nature of public blockchains, permanent.
Deletion and the anchored record. When content is deleted (by you, by us, or following a valid request), we delete the stored bytes. The previously published fingerprints remain on the blockchain, but they do not contain and cannot reveal the deleted content. See section 9 for how this interacts with your legal rights.
Scores. Trust scores are computed from the public statement graph, always from a stated vantage point. Scores are automated opinions derived from other users' public statements; they are not stored on any blockchain and are not assertions of fact by us.
4. Why we collect it (and our lawful basis)
For users in the EU, EEA, and UK, we identify a lawful basis under the GDPR and UK GDPR for each purpose:
- To provide the Service (operating your account, recording and displaying the attestations you choose to make, computing scores, providing lookups): performance of our contract with you (Art. 6(1)(b)).
- To display attestations and profiles publicly, which is the Service's stated function: performance of our contract with you and our legitimate interest in operating a public trust network (Art. 6(1)(f)); for statements made by other users about you, the legitimate interests of those users and of persons consulting the network, balanced by the dispute, weighting, and screening safeguards described in our documentation.
- To screen submitted content for unlawful material before storage or display: legal obligation (Art. 6(1)(c)) and legitimate interest.
- To keep the Service secure and prevent abuse, fraud, and Sybil attacks (including invite lineage and rate limiting): legitimate interest and, where applicable, legal obligation.
- To collect extension telemetry: your consent (Art. 6(1)(a)), withdrawable at any time.
- To send service emails (security alerts, transactional notifications, changes to terms): performance of our contract.
- To send product updates or marketing: your consent, withdrawable at any time.
- To comply with legal requests and establish, exercise, or defend legal claims: legal obligation or legitimate interest.
We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising as those terms are defined under California law. We never sell raw behavioural telemetry.
5. Who we share it with
We share personal data only as described below. Our service providers act as our processors and are contractually required to handle personal data on our instructions and to keep it secure.
- Hosting: Hetzner Online GmbH (Germany/Finland; EU data centres) hosts the core Service.
- Edge, storage, and security: Cloudflare, Inc. provides content delivery, security, evidence-bundle storage, and abuse screening.
- Key management: Google LLC (Google Cloud KMS) holds cryptographic keys; no other personal data is processed there.
- Sign-in provider: Google LLC, where you choose Google sign-in.
- Identity platforms: X, Telegram, Discord, and wallet providers, where you choose to link them; the exchange is limited to the OAuth or signature flow you initiate.
- Content-moderation provider: a specialist provider that reviews content our automated screening cannot resolve, on our behalf and under confidentiality.
- Email: Resend, Inc. (US) sends transactional emails (including beta notifications) and, with consent, updates.
- Logs and monitoring: Better Stack, Inc. (US) processes service logs — which may include IP addresses — for uptime monitoring and security alerting.
- The public: attestations, nature declarations, disputes, and profile information are public by design, as described in section 3.
- Professional advisers: auditors, accountants, lawyers, and insurers, on a need-to-know basis.
- Authorities and third parties: where required by law, regulation, court order, or valid legal process, or where we believe disclosure is necessary to investigate fraud or abuse, protect the rights and safety of Dunbar or our users, or enforce our Terms of Service.
- Successors in a corporate transaction: if Dunbar is involved in a merger, acquisition, financing, restructuring, or sale of assets, personal data may be transferred as part of that transaction, subject to confidentiality and to this Privacy Policy.
A current list of the specific providers we use is available on request from [email protected].
6. International transfers
The Service is operated by Dunbar Network and hosted primarily in the EU; some of our providers (including Cloudflare, Google, Resend, and Better Stack) are based in the United States. Where we transfer personal data of users in the EU, EEA, or UK to a country without an adequacy decision, we rely on appropriate safeguards, including the EU–US Data Privacy Framework and UK–US Data Bridge where the provider is certified, and the European Commission's Standard Contractual Clauses with the UK International Data Transfer Addendum otherwise. You may request a copy of the safeguards by emailing [email protected].
7. How long we keep it
- Account data: for the lifetime of your account, plus a limited period after closure to handle outstanding obligations, disputes, or legal claims.
- Public attestations: attestations are a public record by design and are retained indefinitely while the network operates, subject to section 8. Withdrawn vouches remain visible as withdrawn.
- Sealed contest flags that never reveal: deleted upon their published expiry period.
- Evidence bundles: while the associated revealed flag stands; removed content is deleted with a tombstone note retained.
- Extension telemetry: per the retention period stated in the consent flow; deleted on consent withdrawal.
- Invite lineage: for the duration of the beta security-validation period, then deleted or anonymised.
- Security logs and abuse-prevention data: typically up to twelve months, longer where required to investigate a specific incident.
- Payment and transaction records: typically seven years, in line with tax and accounting requirements.
8. Cookies and similar technologies
We currently use only strictly necessary cookies and similar technologies: session cookies to keep you signed in (httpOnly, secure), CSRF tokens to protect against cross-site request forgery, and technical artefacts placed by our content delivery network (Cloudflare) to route requests and protect the Service. These are required for the Service to function and do not require consent.
We do not currently use analytics or marketing cookies. If we introduce any technology that requires consent under the law of your region, we will request that consent through a banner shown only in regions where it is legally required, and the relevant processing will not run for you until you consent. Where your region's law does not require consent and only strictly necessary technologies are in use, no banner is shown. You can also control cookies through your browser settings; refusing strictly necessary cookies may prevent parts of the Service from functioning.
9. Your rights
To exercise any right, email [email protected] from the address on file, or use in-product controls where available. We may need to verify your identity before responding.
If you are in the EU, EEA, or UK (GDPR and UK GDPR): you have the rights of access, rectification, erasure, restriction, data portability, and objection, and the right to withdraw consent at any time and to lodge a complaint with your supervisory authority (in the UK, the Information Commissioner's Office).
How erasure works on a public trust network. You can delete your account at any time. On deletion we remove your profile, contact, and technical data, and unlink your platform identities. Statements you made remain part of the public record other users have relied on, attributed to a deactivated account. Statements about you made by other users are those users' own published speech; we will assess erasure requests concerning them case by case, balancing your rights against the exceptions in Art. 17(3) (including other users' freedom of expression and the establishment or defence of legal claims), and we always preserve your ability to attach a public dispute. Blockchain fingerprints cannot be deleted by anyone, but contain no personal data.
If you are a California resident (CCPA/CPRA): you have the rights to know, access, correct, and delete personal information, to opt out of sale or sharing (we do neither), and to non-discrimination for exercising these rights.
If you are a resident of another US state with a comprehensive privacy law, you may have similar rights, and we will honour valid requests in line with applicable law.
10. Security
We use technical and organisational measures to protect personal data, including encryption in transit and at rest, memory-hard password hashing with separately stored key material, hardware-backed key management, network isolation of the origin infrastructure, rate limiting, logging and monitoring, and restricted administrative access. No system is perfectly secure; use a strong, unique password and the additional security features we offer.
11. Children
The Service is not intended for, and is not directed at, individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will take appropriate steps to delete it.
12. Changes to this notice
We may update this Privacy Policy from time to time. The "Last updated" date reflects the most recent change. Material changes will be communicated through the Service or by email where appropriate.
13. Contact
Dunbar Network [email protected]