PROVE IT
PRIVACY POLICY
Last updated September 10, 2026. This policy explains what PROVE IT collects when you verify an achievement, what it keeps, and what it never shows publicly.
VERIFY WITHOUT OVERSHARING.
Your badge is public. The numbers, accounts and wallet data behind it stay private.
1. WHO WE ARE
PROVE IT (joinproveit.com) is the controller of the personal data described here. For any privacy request, contact privacy@joinproveit.com.
2. DATA WE COLLECT
- ✓Account data — email address, display name, handle, avatar, and your Passport visibility setting.
- ✓Verification results — which achievement you earned, the platform used, the milestone tier reached, and the verification timestamp.
- ✓Private verification evidence — the underlying values read at verification time (for example an exact follower count or a wallet address), stored in a restricted area that public pages never read.
- ✓Content you create — Room posts and direct messages you send.
- ✓Technical data — basic log and analytics information such as IP address, device/browser type and pages viewed, used for security and to understand aggregate usage.
3. THIRD-PARTY PLATFORM AUTHENTICATION
To verify a social achievement you authorize PROVE IT through the platform's own official login and permission screen. We never ask for and never receive your social account password. Authorization is initiated by you, one platform at a time, and can be revoked at any time in that platform's app/security settings.
Access tokens returned by these platforms are exchanged and used inside our server handlers only. They are used once to read the specific value needed for the badge, are never sent to your browser, and are not stored.
TIKTOK
Used to verify: follower milestones.
WHAT WE READ
Through TikTok Login Kit with read-only basic profile and user info permissions, we read your TikTok open ID, display name and follower count. We do not post, message, delete, or modify anything on your TikTok account, and we do not read your videos' content or your private data beyond what is needed for the badge.
Used to verify: follower milestones, via the read-only instagram_business_basic permission for professional accounts. No publishing, messaging or moderation access.
YOUTUBE
Used to verify: subscriber milestones, via Google's read-only https://www.googleapis.com/auth/youtube.readonly scope. We read your channel once per verification and cannot upload, post or modify anything.
PROVE IT's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
TWITCH
Used to verify: follower milestones, via the read-only moderator:read:followers scope. No write operations of any kind.
WALLET
Wallet ownership is proven with a free off-chain signature. No transaction, no gas, no spending approval, and we never ask for a seed phrase or private key. After ownership is proven we read only public blockchain data needed for eligible achievements.
4. HOW WE USE DATA
- ✓To verify achievements and issue badges
- ✓To display your Passport when you choose to publish it
- ✓To determine ACCESS Room eligibility and enable verified messaging
- ✓To prevent fraud, abuse and manipulated verification
- ✓To operate, secure and improve the service
Legal bases where GDPR applies: performance of a contract (running your account and verifications), legitimate interests (security and abuse prevention), and consent (each platform authorization you grant).
5. WHAT IS PUBLIC AND WHAT IS NOT
PUBLIC
- ✓Badge earned and achievement name
- ✓Verification status and date
- ✓Public milestone tier (e.g. 100K+)
- ✓Display name, handle and avatar
PRIVATE
- ✕Platform access tokens (never stored)
- ✕Exact follower / subscriber counts
- ✕Wallet balance and transaction history
- ✕Full wallet address
- ✕Email address
- ✕Direct messages
6. SHARING
We do not sell personal data and we do not use it for advertising. We share data only with the infrastructure providers needed to run PROVE IT (hosting, database and authentication, analytics), with the platform you choose to connect during that authorization, and where required by law.
7. RETENTION
Account and verification records are kept while your account is active. Access tokens are not retained. When you delete your account, your profile, badges, private verification evidence, Room membership and messages are deleted or irreversibly anonymised, except where limited records must be kept for legal or security reasons.
8. YOUR RIGHTS AND DELETION
You can access, correct, export or delete your data, withdraw a platform authorization, make your Passport private again, or object to certain processing. Disconnect a platform in its own settings, and email privacy@joinproveit.com to request deletion of your PROVE IT account and associated data. We respond within 30 days.
9. SECURITY AND TRANSFERS
Data is encrypted in transit, verification evidence is stored in a restricted area protected by row-level access rules, and sensitive credentials are held server-side only. Our providers may process data outside your country using appropriate safeguards such as the EU Standard Contractual Clauses.
10. CHILDREN
PROVE IT is not intended for children under 13 (or the higher minimum age in your country). We delete accounts we learn belong to underage users.
11. CHANGES AND CONTACT
We may update this policy; the "last updated" date above will change. Questions or requests: privacy@joinproveit.com.