Scope
This Privacy Policy explains what information DAGCore processes when you use the DAGCore website, mining pool, Stratum service, RPC endpoints, APIs and other services at dagcore.net (the “Services”), why, for how long, and what rights you have.
DAGCore is built to collect as little as possible. No account is needed to mine, to use the RPC or to use the API. This Policy should be read together with the DAGCore Terms of Service.
1Who is responsible
DAGCore
Email: contact@dagcore.net
Website: dagcore.net
2What we process, and for how long
Mining pool
When you mine, the pool processes your wallet address, your IP address, your connection details, the shares you submit and their difficulty, and the rewards and payments that follow from them.
- Payout records — wallet addresses, shares credited, amounts paid and transaction hashes — are kept permanently. They are needed to prove every payment was correct, to answer disputes, and to distribute any staked reward that becomes available later, according to the work that earned it.
- Our servers' logs record which IP address connected with which wallet address: the pool's log whenever you mine, and the display-name service's log when a signature does not verify. They are kept for at most 7 days, and in practice usually less.
- No database stores IP addresses.
Miner display names
If you set a display name by signing a message with your wallet, we store the name, your wallet address and the date. It is kept until you remove or change it, which you can do at any time the same way.
Website and API
Our web server logs each request: time, requested page or endpoint, response status, referring page and browser user-agent.
- In access logs, your IP address is shortened before it is written — the last part of an IPv4 address, and everything after the first 48 bits of an IPv6 address, is removed. Access logs are kept for 14 days.
- Error logs may contain a full IP address when a request causes a server error or is refused. They are kept for 14 days.
- Rate limiting counts requests per IP address in memory only. Nothing is written to disk, and the counts are lost when the server restarts.
Wallet lookups
The mining page and the explorer let anyone enter a wallet address and see its balance and payment history. We do not record who looked up which address, apart from the shortened IP in the access log described above.
Contact form
When you use the contact form, we receive your name, email address, subject and message.
- They are not stored on our server. They are sent directly by email to the operator's mailbox and kept there as long as needed to answer you and handle any follow-up.
- Your IP address is not included in that email. It is written to the server's system log, kept for at most 7 days, and used only to limit abuse.
Backups
Copies of the pool's payout database contain wallet addresses and display names, but no IP addresses. They are kept on this server for 7 days, and a copy is also stored with Hetzner for 30 days.
The copy that leaves this server is encrypted before it is sent, to keys held outside it. Hetzner stores a file it cannot read, and neither can this server: it can write a backup and cannot open one. A separate encrypted backup of configuration secrets is stored the same way and contains no personal data.
3What is public
Some information is public by design:
- The miner list shows each miner's display name, if set, the last four characters of the wallet address, estimated hashrate, that hashrate as a share of the pool's, and status. It does not show full addresses or earnings.
- Wallet lookups show balances and payments to anyone who enters the address.
- The blockchain records every payment the pool makes, including the recipient address and amount. This is public and permanent, independent of DAGCore.
A display name sits next to four characters of your address, and payments to your address are visible on the chain. Taken together, a display name can be connected to the address that carries it. Choose a name you are comfortable being known by, or leave it empty.
IP addresses are never shown publicly.
4Why, and on what legal basis
- To provide the Services you use — operating the pool, calculating and paying rewards, showing your statistics, answering your message. This is necessary to provide what you asked for.
- To keep the Services secure and working — rate limiting, preventing fraud and manipulation, detecting attacks and abuse, investigating faults. This is based on our legitimate interest in running reliable and secure infrastructure, and is limited to what those purposes need.
- To meet legal obligations, where they apply.
We do not use your data for advertising, we do not profile you, and we do not make automated decisions that have legal or similarly significant effects on you.
5Who else processes data
- Cloudflare, Inc. — every request to the website, RPC and API passes through Cloudflare, which provides DNS, network protection and the connection to our server. On the contact page, Cloudflare Turnstile checks that the visitor is not an automated script; it sees your IP address and browser information, and we send it your IP address to verify the check. Cloudflare is based in the United States; transfers rely on the safeguards Cloudflare provides for such transfers.
- netcup GmbH, Germany — hosts the server that runs the Services.
- Hetzner Online GmbH, Germany — stores the encrypted backups: the payout database, which holds wallet addresses and display names, and the configuration secrets, which hold no personal data. Both are encrypted before they leave our server, to keys Hetzner does not have.
- Email — contact form messages are delivered through the operator's own mail server and received in a Google (Gmail) mailbox. Google is based in the United States.
Fonts are served from our own server; no third-party font service is used.
We do not sell or rent personal data, and we do not share it with advertisers or data brokers.
We may disclose information when legally required, or when reasonably necessary to investigate attacks, fraud, botnets or cryptojacking involving our infrastructure.
6Cookies
The website sets one cookie, explorer_region, which remembers the number
format, date format and time zone you choose. It is kept for one year and is used only for that.
We use no analytics, advertising or tracking cookies, and no browser local storage.
Cloudflare does not normally set cookies on an ordinary visit. It may set a security cookie if it needs to challenge a request it considers suspicious.
7Your rights
Under the GDPR you may ask to access your personal data, to correct it, to have it deleted, to restrict its processing, to object to processing based on legitimate interests, and to receive it in a portable form.
Two limits apply:
- The blockchain cannot be changed. Payments already recorded on the chain cannot be deleted by us or anyone else.
- Payout records are needed to prove correct payment. We may keep them even after a deletion request, where they are needed for that purpose or to defend legal claims.
Because there are no accounts, we may ask you to prove that you control a wallet address — for example, by signing a message with it — before acting on a request about that address. We will not ask for more than we need.
To make a request, write to contact@dagcore.net.
You may also complain to the Romanian data protection authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), or to the authority where you live.
8Age
The mining pool is intended for people aged 18 or older.
9Security
We use reasonable technical measures to protect the information we process: firewalls, restricted administrative access, rate limiting, encrypted backups and regular updates. No Internet service can be fully secure.
10Changes
We will update this Policy when the Services or the way we process data change. The current version is published on dagcore.net with the date of its last update.