SybilZero
  • Why SybilZero
  • How It Works
  • What We Check
  • Pricing
  • FAQ
Log In Try freeStart Free Trial →
  • Why SybilZero
  • How It Works
  • What We Check
  • Pricing
  • FAQ
  • Log In

Legal

Privacy Policy

Last updated 9 October 2026

SybilZero is a service that helps businesses see when one person is behind several accounts. This policy explains what personal data we handle, why, for how long, who else sees it, and the choices you have. It covers our website, our dashboard and our API.

1. Who we are

SybilZero is operated by Josue Kouka, a sole proprietor operating as SybilZero in British Columbia, Canada ("we", "us"). You can reach us about privacy at [email protected].

2. Two roles, and which one applies to you

We handle personal data in two different roles.

  • Customer account data: we are the controller. This is data about the businesses and people who sign up for SybilZero, visit our website, or contact us.
  • End-user data: we are the processor. This is data about the people who use our customers' websites and apps (for example, someone signing up at a casino or a software product that uses SybilZero). The customer decides why and how it is used; we process it on the customer's instructions, as set out in our Data Processing Addendum. If you are one of those people and have a question or a request, please contact the business you signed up with first. We will help them answer you.

3. What we collect

Customers (controller)

  • Account details: email address, a password stored only as a salted hash, or the identifier and email returned by GitHub or Google if you sign in with them; your project names, settings and API keys (stored hashed).
  • Billing details: handled by Stripe. We keep subscription status, plan and usage counts, not full card numbers.
  • Usage and logs: how many checks you run, and web server logs (IP address, URL, browser details, time). Server logs are kept for 30 days.
  • Messages: what you write to us.
  • Cookies and storage: a session cookie that keeps you signed in, a cookie that protects forms against forgery, a short-lived cookie for on-screen notices, and a theme preference stored in your browser. We do not use advertising or analytics cookies.

End users (processor)

When a customer runs a check, they send us some or all of the following:

  • the email address used to sign up or claim something (we also keep a normalised form, for example without Gmail dots or "+tag" suffixes);
  • the user's IP address, user agent and some request headers;
  • a device fingerprint and browser signals collected by our script: for example time zone, language, screen, hardware, graphics and fonts, plus yes/no results of checks that tell whether the browser is being tampered with;
  • optional identifiers the customer chooses to send: a phone number, a payment-method fingerprint, a payout account or a crypto wallet. These are hashed with a secret key as soon as they arrive; the original value is never stored;
  • a promotion or reward identifier, and any other fields the customer includes.

From this we produce: a risk score and verdict (allow, review or block) with the reasons; what the IP address resolved to (country, city, time zone, network and whether it is a VPN, proxy, Tor or hosting address); links between accounts that share a device, network or identifier; and, if the customer uses it, an exclusion list of accounts they do not want back.

We do not ask customers to send special categories of personal data, government identifiers, card numbers or similar, and our terms forbid it.

4. Why we use it

  • To run the service and deliver results to the customer who requested them (contract, and the customer's instructions for end-user data).
  • To keep the service secure, prevent abuse and fraud against us, and fix problems (our legitimate interests).
  • To bill and keep accounting records (contract and legal obligation).
  • To answer you and give support (contract and legitimate interests).
  • We do not sell personal data, use it for advertising, or combine one customer's data with another's. Matching between accounts happens only inside a single customer's own data, and identifier hashes are specific to each customer.

5. Automated decisions

A verdict is a signal for the customer, not a decision about a person by us. We recommend that customers review borderline cases (the "review" verdict exists for that) and offer a way to contest a result. The customer remains responsible for what it decides and for informing its users.

6. How long we keep it

  • Check records (including the identifier hashes attached to them) are deleted automatically after 90 days, except records of accounts a customer has put on its exclusion list, which are kept so later sign-ups can still be linked to them.
  • Exclusion list entries are kept until the customer removes them or closes its account.
  • Customer account data is kept while the account is open and deleted within 30 days after it is closed, except what we must keep for accounting and legal reasons (for example invoices).
  • Server logs are kept for 30 days.

Customers can delete individual records from the dashboard at any time.

7. Who we share it with

We use these providers to run the service. They act on our instructions and may process data only for the purpose shown.

ProviderWhat it does for usData involvedLocation
Akamai Connected Cloud (Linode)Hosting of the application and its databaseAll data processed by the serviceFremont, California, United States
CloudflareDNS, proxy and content delivery for the website, and email routing for a former domainWeb requests to sybilzero.com (IP address, URL, user agent) pass through its network; the API host is DNS onlyGlobal network
IPLocate (iplocate.io)Looking up where an IP address is and what kind of network it belongs to (country, city, time zone, provider, VPN, proxy, Tor and hosting flags)IP addresses sent in checksProvider's own infrastructure
StripeSubscription billing and payments for CustomersCustomer billing contact and payment details (end users' data is not sent to Stripe)United States and Canada
Google (Google Workspace)Email and support correspondenceMessages you send usProvider's own infrastructure
jsDelivrContent delivery network that serves the open-source ThumbmarkJS library loaded by the SybilZero agent in end users' browsersEnd users' IP address and browser request details, seen by the CDN when the library is fetchedGlobal network

Our website also loads open-source libraries (styling, icons and interface scripts) from public content delivery networks such as jsDelivr, cdnjs and unpkg, which can see your IP address when you visit. We may disclose data when the law requires it, to protect our rights or others' safety, or in a sale or restructuring of the business, with notice to affected customers. We do not share data for others' marketing.

We will update this list before adding a provider that handles end-user data and tell customers by email.

8. Where it is processed

We are based in Canada and our servers are in the United States (see the table above). Personal data of people in the European Economic Area, the United Kingdom or Switzerland may therefore be transferred outside those regions. Where the law requires it, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum), which are part of our Data Processing Addendum, and on safeguards described there.

9. Security

We protect data with encrypted connections (TLS), keyed hashing of optional identifiers, hashed passwords and API keys, separation of each customer's projects and keys, and restricted access to our systems. No system is perfectly secure. If a breach affects personal data we will notify affected customers without undue delay, so they can meet their own obligations. To report a vulnerability, write to [email protected].

10. Your rights

Depending on where you live (including under the GDPR, the UK GDPR and Canadian privacy law) you can ask to access your data, correct it, delete it, restrict or object to its use, receive a copy, and withdraw consent where we rely on it. You can also complain to your data protection authority; in Canada that is the Office of the Privacy Commissioner of Canada or your provincial regulator.

  • For customer account data, write to [email protected]. We respond within 30 days.
  • For end-user data, contact the business whose website or app you used. If you contact us, we will pass your request to them, because we cannot decide on their behalf.

11. Children

SybilZero is a business service and is not directed at children. Our customers must not use it to process data about people under the age at which they may lawfully use their own service.

12. Changes

We will post changes here with a new date and, for material changes, email customers at least 30 days beforehand.

13. Contact

Josue Kouka, a sole proprietor operating as SybilZero in British Columbia, Canada. Privacy: [email protected]. Support: [email protected].


Questions about this page? Write to [email protected]. See also: Terms of Service, Privacy Policy, Data Processing Addendum.

SybilZero ONE PLAYER. ONE BONUS.
  • Terms
  • Privacy
  • DPA
  • API Docs
  • Support
© 2026 SybilZero