Legal · Privacy

Privacy Policy

Effective: 8 October 2026 Last updated: 8 October 2026 Controller: Ondrej Dvorak, Czechia
Contents
  1. Overview
  2. Data we collect
  3. Wallet and on-chain data
  4. Your code
  5. On your device
  6. How we use data
  7. Third parties
  8. Retention
  9. Security
  10. Children
  11. Your rights
  12. Changes to this policy
  13. Contact
Section 01

Overview

This policy explains how Ondrej Dvorak ("we", "us"), who operates Nacodex, handles data when you use the Nacodex code audit service at nacodex.help (the "Service") or the Nacodex Android app (the "App"). We are the data controller.

In shortYour account is your public wallet address: no name, email or password. We keep what an audit needs (your code, only for a short time), your orders, reports, payments, contributions and rewards. No advertising, no tracking, no third-party analytics. Your code is processed by Anthropic's Claude AI to run the audit you ordered, and for nothing else.
Section 02

Data we collect

DataWhyKept where, how long
Wallet addresspublic, on-chainYour account: signs you in and links your orders, payments, contributions and rewards.Our server, while your account exists.
Code you senda ZIP, or a public GitHub repository and commitTo run the audit you ordered.Our server. The code archive is deleted 7 days after the order is finished; the repository name and commit stay with the order.
Orders and reportsThe areas and depth you chose, the price, the status, your optional note and the report, so you can follow and read them.Our server, while your account exists.
PaymentsThe transaction signature, amount and currency, to verify and credit each payment and keep correct accounts.Our server, and the public Solana blockchain (permanent).
ContributionsThe text you send, your optional note, and our evaluation.Our server, while your account exists.
$Nacodex rewardsWhat was credited to your wallet and why.Our server, while your account exists.
Emailonly if you write to usTo answer you, for example an export or deletion request.Our mailbox, as long as needed to handle the request.
Technical logsRequest times, errors and wallet identifiers, to run the Service, limit abuse and fix faults.Our server, for a limited time.
What we do not collectYour name, phone number, location, contacts, photos, device advertising ID, or anything about other apps on your device. We never see or store your wallet's private key or recovery phrase.
Section 03

Wallet and on-chain data

You sign in by signing a one-time message with your Solana wallet. The signature proves you control the wallet; it moves no funds. A wallet address is a pseudonymous identifier; we do not try to link it to your real-world identity.

Payments are transactions on the public Solana blockchain. Their sender, receiver, amount and time are visible to anyone, permanently. Neither we nor anyone else can delete them.

Section 04

Your code

  • Scanned before upload. The App and the website scan a ZIP for secrets on your own device before anything is sent, and block the ones they detect. The scan runs locally; its findings are not sent to us, only the counts of what was blocked or flagged.
  • GitHub repositories. For a repository order we download the repository from GitHub at the commit you confirmed. You prove ownership by adding a file with a token to the repository.
  • AI processing. Audits and contribution evaluations are performed with Anthropic's Claude AI from our server. Your code is sent to Anthropic for that processing only.
  • Rule improvements. When an audit finds a kind of defect our rules do not cover yet, we keep a general description of that kind of defect. That description never contains your code, file names or identifiers. You are rewarded in $Nacodex for it as if you had contributed it yourself. We do not use your code to train AI.

We do not sell your code, publish it, or share it with anyone else.

Section 05

On your device

  • App. The App keeps its sign-in token encrypted with a key held in the Android Keystore, excluded from device backups, plus a local record of payments it is still finishing. It checks for order updates from your phone; we use no push-notification service.
  • Website. The website keeps its sign-in token and the record of unfinished payments in your browser's storage. A ZIP you have paid for is kept in your browser only until the order is sent, then removed.
  • Uninstalling the App, or clearing your browser's data for nacodex.help, removes these local copies.
Section 06

How we use data, and why we may

  • To sign you in, take payment, run the audit you ordered and deliver the report: performance of the contract you enter when you sign in or order (Art. 6(1)(b) GDPR).
  • To evaluate contributions and credit $Nacodex rewards: performance of the contract (Art. 6(1)(b)).
  • To keep payment records as the law requires (Art. 6(1)(c)).
  • To keep the Service secure and to improve the Nacodex rules with general, non-identifying descriptions of defects: our legitimate interests (Art. 6(1)(f)).

We do not use your data for advertising, profiling or automated decisions with legal effect on you.

Section 07

Third parties

We do not sell, rent or share your data with advertisers, data brokers or marketing platforms. The App and the website contain no advertising, tracking pixels or third-party analytics. The website loads no third-party scripts or fonts.

The Service depends on these third parties:

  • Anthropic processes code for audits and contribution evaluations (section 4). This happens outside the EU under the safeguards of Anthropic's data-processing terms.
  • The Solana network. To prepare and send a payment, the App and the website contact a public Solana RPC node directly, which sees your wallet address and the transaction.
  • Your wallet app (for example Seed Vault, Phantom, Solflare, Backpack or Jupiter) has its own privacy policy.
  • GitHub, when you order an audit of a repository hosted there.

We disclose data to authorities only when the law requires it, and then only what is required.

Section 08

Retention

  • Uploaded code archives are deleted automatically 7 days after the order is finished.
  • Reports, order records, payments, contributions and rewards are kept while your account exists, so you can read them and so we keep correct accounts.
  • After you ask for deletion, we erase your data within 30 days, except payment records we must keep by law, which we keep only as long as required.
  • Blockchain transactions are public and permanent; nobody can delete them.
Section 09

Security

  • All traffic between the App or the website and the Service is encrypted (HTTPS).
  • The App stores its sign-in token encrypted (section 5).
  • Audits run on our server under a separate, restricted account that has no access to our database, payments or server settings.
  • Access to the server and its database is limited to the operator and the operator's own maintenance tools.

No system is perfectly secure. If you believe your data or your account was compromised, write to us at once.

Section 10

Children

The Service is not meant for anyone under 16. It requires a crypto wallet and involves payments on a blockchain. We do not knowingly collect data from children; if we learn that we have, we delete it.

Section 11

Your rights

You can ask for:

  • Access: a copy of the data we hold for your wallet;
  • Correction of inaccurate data;
  • Deletion of your account and its data;
  • Restriction of processing while a dispute is resolved;
  • Portability: your data in a machine-readable format;
  • Objection to processing based on our legitimate interests.

Write to support@nacodex.help from any address and state your wallet address. The App's Profile screen and the website's Profile page prepare this email for you ("Export my data", "Delete account"). Requests are free and answered within 30 days.

ComplaintsYou may complain to the Czech data-protection authority, Úřad pro ochranu osobních údajů (uoou.gov.cz), or to the authority where you live.
Section 12

Changes to this policy

We may update this policy when the Service, the law or our practices change. We will change the "Last updated" date above and, for material changes, announce them on nacodex.help or in the App.

Section 13

Contact

Privacy questions, data requests and concerns:

Email
support@nacodex.help
We answer within 30 days. English and Czech.
Controller
Ondrej Dvorak
Czechia · nacodex.help
Terms of Use (EULA)Privacy PolicyCopyrightsupport@nacodex.help
Nacodex · © 2026 Ondrej Dvorak
← pukapasoft.xyz