Private BetaTest-money pilotcloudflare-snapshot
← Back to Styx

Privacy Policy

Version 1.0 — Effective February 27, 2026

1. Information We Collect

We collect the following categories of information:

  • Account information: Email address, hashed password, date of birth (optional)
  • Behavioral data: Contract details, attestation records, proof submissions, streak data
  • Financial data: Stripe customer ID, transaction history (payment details are processed and stored by Stripe, not by Styx)
  • Review data: Fury audit verdicts, accuracy scores, honeypot results
  • Technical data: IP address (for geofencing), device type, app version

2. How We Use Your Information

  • Operating the behavioral contract and peer review system
  • Processing financial stakes through Stripe escrow
  • Calculating and maintaining your integrity score
  • Enforcing health guardrails (Aegis Protocol)
  • Geofencing compliance for jurisdictional restrictions
  • Detecting fraud and ensuring review integrity
  • Sending notifications about contracts, attestations, and verdicts

3. Data Storage and Security

Your data is stored in PostgreSQL databases with encryption at rest. All API communication uses HTTPS. Proof media files are stored in Cloudflare R2 with zero-egress architecture — files are served only via time-limited signed URLs and never leave the storage provider unnecessarily.

Passwords are hashed using bcrypt. Authentication uses HttpOnly cookies with CSRF protection. All financial data is append-only with a hash-chained audit log (Truth Log).

4. Peer Review Privacy

When your proof is submitted for Fury review, reviewers see the proof content but not your identity. Reviews are anonymized. Your proof media is accessible only via signed URLs that expire after the review period.

5. Enterprise (B2B) Data

If your employer uses Styx Enterprise, aggregated and anonymized behavioral metrics may be shared with your organization. Individual contract details, proof content, and personal attestations are never shared with your employer. Anonymization uses a salted hash to prevent re-identification.

6. Third-Party Services

  • Stripe: Payment processing and escrow management
  • Cloudflare R2: Proof media storage
  • Google Gemini: AI features (goal ethics screening, grill-me, ELI5) — no personal data is sent to AI models

7. Data Retention

Account data is retained while your account is active. The Truth Log (hash-chained audit trail) is append-only and retained permanently for financial integrity verification. Upon account deletion, personal identifiers are removed but anonymized audit records are retained for compliance.

8. Your Rights

  • Access: View your data through the Profile and Settings pages
  • Deletion: Request account deletion through Settings (GDPR Article 17)
  • Export: Request a copy of your data by contacting us
  • Correction: Update your information through your profile

9. Cookies

Styx uses essential cookies only: an HttpOnly authentication cookie (styx_auth_token), a CSRF protection cookie (styx_csrf_token), and SSE stream tickets. We do not use tracking cookies, analytics cookies, or third-party advertising cookies.

10. Children’s Privacy

Styx is not intended for anyone under 18 years of age. We do not knowingly collect personal information from minors. If we discover that a user is under 18, their account will be terminated and associated data deleted.

11. Changes to This Policy

We will notify you of material changes via email or in-app notification at least 14 days before they take effect. The current version is always available at this URL.

12. Contact

For privacy inquiries, contact privacy@styx.protocol.

Related Policies