Legal

Privacy Policy

Effective: 27 March 2026  ·  Operator: Duncan West, sole operator of Fixatum

This policy explains what data Fixatum collects, how it is used, and what is recorded permanently on-chain. Fixatum is designed to be minimal by default — we collect only what is necessary to operate the service.


What goes on-chain permanently

The following data is written to the Hedera public blockchain and cannot be deleted by Fixatum or anyone else:

— Your Ed25519 public key (submitted in the payment memo)

— Your Hedera account ID

— The derived DID: did:hedera:mainnet:z{PUBLIC_KEY}_{ACCOUNT_ID}

— Timestamp of DID issuance

By registering, you accept that this information becomes permanently public on the Hedera network.

What Fixatum stores internally

Fixatum stores the following in a private SQLite database on Railway infrastructure:

— Your Hedera account ID, DID, and registration timestamp

— The payment transaction ID and amount (in tinybars)

— The identity screening result (CLEAR / REVIEW) at time of registration

— Query account balance and usage statistics if you use the paid Score API

Fixatum does not store your private key, IP address, email address, or any personal identifying information beyond what is described above.

Score queries

Free-tier score queries are rate-limited by IP address. IP addresses are used only for rate limiting and are not logged, stored, or linked to any identity record.

Paid-tier score queries are identified by Hedera account ID, which you provide explicitly as an API key parameter. No other identifying data is collected.

What Fixatum never holds

Fixatum never receives, stores, processes, or has access to your private key at any point. Your private key never leaves your own system. If you lose it, it cannot be recovered.

Third-party services

Fixatum uses the following third-party infrastructure:

Hedera network — public blockchain for DID anchoring and screening calls

HederaToolbox — Hedera API platform used for provenance logging and identity screening

Kraken — used to fetch live HBAR/USD price data for display purposes only. No user data is sent to Kraken.

Railway — cloud hosting for the Fixatum API server and database

Cloudflare — DNS and static site hosting

Fixatum does not use advertising networks, tracking pixels, analytics scripts, or cookies of any kind.

On-chain screening

During DID registration, Fixatum performs an on-chain behavioural analysis of your Hedera account via HederaToolbox. This analysis examines publicly available on-chain transaction patterns. It is not a legal sanctions check and does not query any government watchlist. The result (CLEAR or REVIEW) is stored internally and factors into your credibility score.

Data retention

On-chain data is permanent by design. Internal database records are retained indefinitely as they form the basis of the credibility scoring system. There is currently no automated deletion process.

If you have a specific data request, contact hello@fixatum.com. Note that on-chain data cannot be deleted regardless of any request.

Changes to this policy

This policy may be updated at any time. The effective date above reflects the most recent revision. Continued use of the service constitutes acceptance.

Contact

Questions about this policy: hello@fixatum.com