01What we collect
- Account. Your email address, or your Solana wallet’s public address if you sign in with a wallet.
- Devices you link. Device type, brand and model; its identifier (such as a VIN or a meter’s device ID); its battery level, charging state and energy used per hour; and the grid region where it is used.
- Access you grant us. To read a device we store the access you give: a Smartcar authorization for vehicles, or your Home Assistant address and access token, or your Shelly cloud key and device ID. These are encrypted, used only to read energy data, and deleted when you remove the device.
- Program records. The windows you join, verification results, credits and redemptions.
- Technical data. Standard server logs (IP address, browser, time of request), kept for security.
We do not collect your exact location, trips or driving history, and we cannot unlock, start or control your device.
02How we use it
- To sign you in and keep your account secure.
- To build your baseline, verify shifted energy and issue credits.
- To detect fraud and enforce fair-use rules.
- To publish aggregate statistics (for example, total kWh shifted per region) that cannot identify you.
03What goes on-chain
Only a salted hash of your account, the window, the shifted kWh and the credits are combined into a batch fingerprint (a Merkle root) that is written to Solana. Your email, wallet, device identifiers and readings are never published.
04Who we share it with
We never sell or rent your personal data. We share it only with service providers that help us run the Service, under contract and for that purpose only:
- Authentication: Privy (sign-in and embedded wallets).
- Device connections: Smartcar (vehicles), and your own Home Assistant instance or Shelly Cloud account (home devices), each read-only.
- Hosting: our cloud infrastructure provider.
We may disclose data if required by law or to protect the Service and its users from fraud.
05Cookies and storage
We use only what is needed to keep you signed in (your browser’s local storage and a session token). We do not use advertising or cross-site tracking cookies.
06How long we keep it
Account and program records are kept while your account is open and for as long as needed for accounting, fraud prevention and legal obligations. Device readings are kept for up to 24 months. When you unlink a device, we stop collecting its data.
07Your rights
You can ask to access, correct or delete your data, or to receive a copy of it, at any time. California residents have rights under the CCPA/CPRA, including to know, delete and correct personal information and to not be discriminated against for using these rights. We do not sell or share personal information for cross-context behavioral advertising.
To make a request: the contact address listed on our official channels. We will answer within 30 days.
08Security
Data is encrypted in transit (HTTPS), access to production systems is restricted, and device access is read-only. No system is perfectly secure; if a breach affects you, we will tell you as required by law.
09Children
The Service is not intended for anyone under 18, and we do not knowingly collect their data.
10Changes
We will post any update here and change the date at the top. Significant changes will be announced in the app.
11Contact
Privacy questions or requests: the contact address listed on our official channels.