Privacy Policy
What we collect, why, and what we refuse to keep.
This document is being reviewed by counsel before launch. It describes how Durfeenz actually operates today.
What we collect
At sign-up: your email, a hashed password, and your date of birth. At verification: the name, date of birth, country, and where provided the address and phone number shown on your identity document, together with the document type. If you connect an exchange, we store an encrypted API key and its permitted scope.
Why we collect it
To establish that you are old enough and permitted to use the service where you live, to meet anti-money-laundering obligations, to operate the features you ask for, and to keep an audit trail of decisions affecting your account.
What we do not keep
We do not store your password, only a hash of it. We do not store your exchange withdrawal rights, because we refuse keys that have them. Our audit records deliberately hold derived facts — such as whether an age requirement was met — rather than your date of birth, document details or keys.
Who sees it
Verification documents are reviewed by authorised staff only, and every decision is recorded with the reviewer’s identity. We use service providers for hosting, database and email; we do not sell personal data, and we do not share it for advertising.
How long we keep it
Identity and audit records are retained for the period required by financial-crime rules, which is typically several years after an account closes. Accounts are closed rather than erased, because deleting the record of a decision would defeat the audit trail.
Your rights
Depending on where you live you may request access to your data, correction of it, or its deletion where no legal obligation requires us to keep it. Contact us and we will explain what applies to you.