Skip to content
ConsentPool

Privacy Policy

Updated September 9, 2026

Kelly Quinn Nicholes, an individual in Utah, United States, operates ConsentPool. This policy describes the current testing service. For privacy questions or requests, contact social-accounts@consentpool.com.

Information we process and why

We store account email addresses, display names, login and session records, and password hashes where password login is used. Google sign-in supplies an account identifier, verified email address, and profile name to create or find your account. Session cookies keep you signed in and protect account actions.

We store social handles, platform identifiers, verification attempts and outcomes, and the link between a verified social identity and your ConsentPool account. A public handle can be recorded when someone targets it, even if its owner has never joined. We use these records to find targets, prevent false claims, and enforce opt-out.

If you use pool features, records include requests, requirements, contributions, wallet addresses, transaction references, uploaded deliveries and their metadata, disputes, notifications, and administrator decisions. They support pool operation, participant access, review, and recovery. Hosting and application logs record requests and failures for operation and security; infrastructure providers can also receive your IP address and browser information when serving requests.

Social authorization and token handling

When a verification method is enabled, you authorize it at the platform. We check the returned account identifier and username against the account you intend to claim. X proof requests basic read access, Instagram professional proof requests basic professional profile access, and TikTok proof requests basic and username profile access. Verification does not authorize posting or ongoing use of your account for discovery.

Creator proof tokens are used briefly on the server and are not saved for later use. X and TikTok flows request token revocation after use. Instagram tokens are discarded without extension; discarding them does not revoke the grant. You can remove grants in the platform's connected-app settings, including Instagram's Apps and Websites. Removing a grant does not delete the stored ownership link or verification record.

Pending authorization records expire after ten minutes. The server stores protected attempt information to prevent replay and erases temporary verifier material when consumed or cleaned up. Outcome and identity records remain. Discovery uses separate operator credentials and shares submitted search terms with the selected provider. Personal Instagram DM verification is not available; do not send verification codes or private messages for that purpose.

Who can see information

Pool requests and target handles are visible to visitors. Delivered files are kept in private storage and access is restricted to authorized participants and review workflows. Administrators can inspect operational and moderation records. Do not put private information in a public request.

Vercel hosts the application, Neon stores application data, and Cloudflare provides DNS, private file storage, email forwarding, and scheduling. Contact emails are forwarded to our dedicated Gmail mailbox. Google and any social platform you use process sign-in or verification requests under their own privacy policies. These providers process data needed to deliver their services. This version has no advertising integration or external AI service configured.

Blockchain addresses, transaction hashes, and escrow data submitted to Cardano are public and replicated outside our control, including on the test network. We cannot erase those records. Use of a wallet can link its public activity to a pool.

Retention, requests, and current limits

Account, pool, ownership, opt-out, and audit records currently have no automated deletion schedule. Backup and infrastructure retention also depend on the provider. ConsentPool has no working self-service account deletion or full personal-data export. A contribution-record download is not a complete account export.

Contact us to request access, correction, or deletion of application data. We will assess the request and explain what can be done; this page does not promise an implemented automated deletion or export service. We may need to verify control of your account before acting. Do not email passwords, wallet keys, or identity documents. Permanent creator opt-out blocks targeting; it does not erase your data.

You can sign out, stop using the service, or remove provider grants. Changes to this policy will be posted here with a new date. See the Terms of Service for the current testing-service conditions.