DoLerGen Operations LLC ("FillProof," "we") is the data controller for personal information processed through fillproof.io and the FillProof service. Contact: support@fillproof.io · 30 N Gould St, Sheridan, WY 82801, USA.
your email, a password we store only as a modern salted hash (argon2id), wallet addresses you choose to track, billing handled by Stripe, and standard server logs.
fonts, and no marketing cookies. Exactly two cookies exist, both strictly necessary. We do not sell or share personal information for advertising. There is nothing here that requires a cookie consent banner, and so there isn't one.
processed to read that public data.
Account data: email address; password (stored only as an argon2id hash — we cannot read it); organization name if you provide one. Service data you submit: wallet addresses and optional labels; plan and add-on selections; support correspondence. Billing data: handled by Stripe. We receive and store subscription status, plan, invoice metadata, and a customer reference — never full card numbers. Automatic data: IP address, user agent, request timestamps and paths (server logs, used for security and rate limiting); session records. Cookies (complete list):
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
| fp_session | Keeps you signed in | Strictly necessary | Up to 30 days (7-day idle timeout) |
| fp_csrf | Blocks forged form submissions | Strictly necessary | Session |
Both are first-party, HttpOnly where applicable, and never used for tracking. We set no other cookies. Free audit: the wallet address you submit is processed transiently to generate the report and is not stored afterward. What we do not collect: no government IDs, no sensitive categories (health, biometrics, precise geolocation), no data from children, no purchased data-broker lists.
| Purpose | Data | GDPR legal basis |
|---|---|---|
| Provide the Service: accounts, verification runs, dashboards | Account, service, automatic | Contract (Art. 6(1)(b)) |
| Billing, invoicing, tax | Billing | Contract; legal obligation |
| Security: authentication, rate limiting, abuse and fraud prevention | Automatic, account | Legitimate interests (Art. 6(1)(f)) |
| Transactional email: verification links, password resets, billing and service alerts | Contract | |
| Legal compliance, sanctions screening, responding to lawful requests | As required | Legal obligation |
| Service improvement using de-identified, aggregated data | Derived | Legitimate interests |
We do not use personal information for targeted advertising, do not sell it, and do not make automated decisions producing legal or similarly significant effects about you.
Public blockchains are public, append-only records operated by no single party. When you submit a wallet address, we read publicly available on-chain data about it and store derived verification records. Wallet addresses are pseudonymous identifiers and may constitute personal data where linkable to you. Immutability: we can delete the records we hold, but no one can alter or erase data recorded on a public blockchain itself; deletion rights below apply to our systems.
We share personal information only with service providers acting on our instructions, and as required by law. We do not sell personal information and do not share it for cross-context behavioral advertising.
| Provider | Function | Data touched | Location |
|---|---|---|---|
| Stripe | Payment processing, invoicing, tax | Billing details you enter with Stripe; email | USA (EU-US Data Privacy Framework participant) |
| Resend | Transactional email delivery | Email address, message content | USA |
| Alchemy | Blockchain RPC (reads on-chain data) | Wallet addresses queried; no account identity | USA |
| Hetzner Online GmbH | Hosting and databases | All service data | Germany (EU) |
| Healthchecks.io | Uptime monitoring | Operational pings only; no personal data | EU |
Other disclosures: to comply with law or valid legal process; to protect rights, safety, and the integrity of the Service; in a merger, acquisition, or asset sale (with notice); with your direction or consent.
Primary hosting and databases are in Germany (EU). Where data is transferred to US providers, we rely on the EU-US Data Privacy Framework (where the provider is certified) and/or Standard Contractual Clauses, plus supplementary measures as appropriate.
de-identified within 90 days of account deletion, except as needed for legal, tax, or security obligations.
(published on the pricing page), including Vault retention you purchase; upon account deletion, per the same 90-day rule.
backups as they rotate.
Argon2id password hashing; API keys stored as hashes and displayed once; TLS in transit; least-privilege access; single-use, expiring verification and reset tokens; monitoring with a dead-man's switch. No method is 100% secure; we will notify you and regulators of a breach as required by applicable law.
Regardless of where you live, you may: access the personal information we hold about you; correct it; delete it; and export it in a portable format. Email support@fillproof.io from your account address; we will verify the request and respond within 30 days (extendable once with notice where the law allows). You will not be discriminated against for exercising rights. If we deny a request, you may appeal by replying to our decision; we will respond to appeals within 45 days. Authorized agents may submit requests where the law provides, subject to verification.
You additionally have the rights to restriction of processing, to object to processing based on legitimate interests, and to withdraw consent where processing is based on consent (without affecting prior processing). You may lodge a complaint with your supervisory authority (for the UK, the ICO). Legal bases are listed in Section 3. We do not conduct automated decision-making with legal effects.
Twenty US states currently have comprehensive privacy laws. FillProof extends the core rights in Section 9 to all users voluntarily; specific statutes may not presently apply to us given their thresholds. For California residents (CCPA/CPRA): Categories collected: identifiers (email, IP, wallet addresses you submit); commercial information (subscription records); internet activity (server logs). Sources: you; your devices; public blockchains. Purposes: Section 3. Disclosed for business purposes to the subprocessors in Section 5. We do not sell personal information and do not share it for cross-context behavioral advertising, and have not in the preceding 12 months; we have no actual knowledge of selling or sharing data of consumers under
purposes permitted without a right to limit. Rights: know/access, delete, correct, portability, non-discrimination — exercise per Section 9. Global Privacy Control: because we do not sell or share personal information for advertising, there is no sale/share for a GPC signal to opt out of; we honor its intent by default.
The Service is for adults 18+. We do not knowingly collect personal information from anyone under 18; if you believe a minor has provided data, contact us and we will delete it.
We do not track users across third-party sites, so DNT signals do not change our behavior — there is nothing to disable.
We will post updates at fillproof.io/privacy with a new effective date, and for material changes will notify you by email or in-product notice at least 14 days in advance.
support@fillproof.io · DoLerGen Operations LLC, 30 N Gould St, Sheridan, WY 82801, USA.
© 2026 DoLerGen Operations LLC ·
Terms · Privacy
By continuing to use this site you agree to the Terms.