Legal
Privacy Policy
Last updated 9 October 2026
SybilZero is a service that helps businesses see when one person is behind several accounts. This policy explains what personal data we handle, why, for how long, who else sees it, and the choices you have. It covers our website, our dashboard and our API.
1. Who we are
SybilZero is operated by Josue Kouka, a sole proprietor operating as SybilZero in British Columbia, Canada ("we", "us"). You can reach us about privacy at [email protected].
2. Two roles, and which one applies to you
We handle personal data in two different roles.
- Customer account data: we are the controller. This is data about the businesses and people who sign up for SybilZero, visit our website, or contact us.
- End-user data: we are the processor. This is data about the people who use our customers' websites and apps (for example, someone signing up at a casino or a software product that uses SybilZero). The customer decides why and how it is used; we process it on the customer's instructions, as set out in our Data Processing Addendum. If you are one of those people and have a question or a request, please contact the business you signed up with first. We will help them answer you.
3. What we collect
Customers (controller)
- Account details: email address, a password stored only as a salted hash, or the identifier and email returned by GitHub or Google if you sign in with them; your project names, settings and API keys (stored hashed).
- Billing details: handled by Stripe. We keep subscription status, plan and usage counts, not full card numbers.
- Usage and logs: how many checks you run, and web server logs (IP address, URL, browser details, time). Server logs are kept for 30 days.
- Messages: what you write to us.
- Cookies and storage: a session cookie that keeps you signed in, a cookie that protects forms against forgery, a short-lived cookie for on-screen notices, and a theme preference stored in your browser. We do not use advertising or analytics cookies.
End users (processor)
When a customer runs a check, they send us some or all of the following:
- the email address used to sign up or claim something (we also keep a normalised form, for example without Gmail dots or "+tag" suffixes);
- the user's IP address, user agent and some request headers;
- a device fingerprint and browser signals collected by our script: for example time zone, language, screen, hardware, graphics and fonts, plus yes/no results of checks that tell whether the browser is being tampered with;
- optional identifiers the customer chooses to send: a phone number, a payment-method fingerprint, a payout account or a crypto wallet. These are hashed with a secret key as soon as they arrive; the original value is never stored;
- a promotion or reward identifier, and any other fields the customer includes.
From this we produce: a risk score and verdict (allow, review or block) with the reasons; what the IP address resolved to (country, city, time zone, network and whether it is a VPN, proxy, Tor or hosting address); links between accounts that share a device, network or identifier; and, if the customer uses it, an exclusion list of accounts they do not want back.
We do not ask customers to send special categories of personal data, government identifiers, card numbers or similar, and our terms forbid it.
4. Why we use it
- To run the service and deliver results to the customer who requested them (contract, and the customer's instructions for end-user data).
- To keep the service secure, prevent abuse and fraud against us, and fix problems (our legitimate interests).
- To bill and keep accounting records (contract and legal obligation).
- To answer you and give support (contract and legitimate interests).
- We do not sell personal data, use it for advertising, or combine one customer's data with another's. Matching between accounts happens only inside a single customer's own data, and identifier hashes are specific to each customer.
5. Automated decisions
A verdict is a signal for the customer, not a decision about a person by us. We recommend that customers review borderline cases (the "review" verdict exists for that) and offer a way to contest a result. The customer remains responsible for what it decides and for informing its users.
6. How long we keep it
- Check records (including the identifier hashes attached to them) are deleted automatically after 90 days, except records of accounts a customer has put on its exclusion list, which are kept so later sign-ups can still be linked to them.
- Exclusion list entries are kept until the customer removes them or closes its account.
- Customer account data is kept while the account is open and deleted within 30 days after it is closed, except what we must keep for accounting and legal reasons (for example invoices).
- Server logs are kept for 30 days.
Customers can delete individual records from the dashboard at any time.
7. Who we share it with
We use these providers to run the service. They act on our instructions and may process data only for the purpose shown.
| Provider | What it does for us | Data involved | Location |
|---|---|---|---|
| Akamai Connected Cloud (Linode) | Hosting of the application and its database | All data processed by the service | Fremont, California, United States |
| Cloudflare | DNS, proxy and content delivery for the website, and email routing for a former domain | Web requests to sybilzero.com (IP address, URL, user agent) pass through its network; the API host is DNS only | Global network |
| IPLocate (iplocate.io) | Looking up where an IP address is and what kind of network it belongs to (country, city, time zone, provider, VPN, proxy, Tor and hosting flags) | IP addresses sent in checks | Provider's own infrastructure |
| Stripe | Subscription billing and payments for Customers | Customer billing contact and payment details (end users' data is not sent to Stripe) | United States and Canada |
| Google (Google Workspace) | Email and support correspondence | Messages you send us | Provider's own infrastructure |
| jsDelivr | Content delivery network that serves the open-source ThumbmarkJS library loaded by the SybilZero agent in end users' browsers | End users' IP address and browser request details, seen by the CDN when the library is fetched | Global network |
Our website also loads open-source libraries (styling, icons and interface scripts) from public content delivery networks such as jsDelivr, cdnjs and unpkg, which can see your IP address when you visit. We may disclose data when the law requires it, to protect our rights or others' safety, or in a sale or restructuring of the business, with notice to affected customers. We do not share data for others' marketing.
We will update this list before adding a provider that handles end-user data and tell customers by email.
8. Where it is processed
We are based in Canada and our servers are in the United States (see the table above). Personal data of people in the European Economic Area, the United Kingdom or Switzerland may therefore be transferred outside those regions. Where the law requires it, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum), which are part of our Data Processing Addendum, and on safeguards described there.
9. Security
We protect data with encrypted connections (TLS), keyed hashing of optional identifiers, hashed passwords and API keys, separation of each customer's projects and keys, and restricted access to our systems. No system is perfectly secure. If a breach affects personal data we will notify affected customers without undue delay, so they can meet their own obligations. To report a vulnerability, write to [email protected].
10. Your rights
Depending on where you live (including under the GDPR, the UK GDPR and Canadian privacy law) you can ask to access your data, correct it, delete it, restrict or object to its use, receive a copy, and withdraw consent where we rely on it. You can also complain to your data protection authority; in Canada that is the Office of the Privacy Commissioner of Canada or your provincial regulator.
- For customer account data, write to [email protected]. We respond within 30 days.
- For end-user data, contact the business whose website or app you used. If you contact us, we will pass your request to them, because we cannot decide on their behalf.
11. Children
SybilZero is a business service and is not directed at children. Our customers must not use it to process data about people under the age at which they may lawfully use their own service.
12. Changes
We will post changes here with a new date and, for material changes, email customers at least 30 days beforehand.
13. Contact
Josue Kouka, a sole proprietor operating as SybilZero in British Columbia, Canada. Privacy: [email protected]. Support: [email protected].
Questions about this page? Write to [email protected]. See also: Terms of Service, Privacy Policy, Data Processing Addendum.