1. Who we are
ZTOR Services Incorporated publishes the iKnow Blockchain website and related educational software, including hosted plugins, MCP-style APIs, and educational materials. We have not published a street address on this site. Contact us at the role addresses listed in Section 10.
2. What this policy covers
| Layer | Covered here? | Notes |
|---|---|---|
| Website (iknowblockchain.com) | Yes | Marketing / educational site |
| Hosted services, plugins, and APIs | Yes | Access may be invitation, preview, or general; practices described by data category |
| OAuth sign-in / accounts | Available to invited or approved users of selected hosted services | General self-service access is not currently available; legacy invitation credentials remain in use for some clients |
| Third-party sites, AI hosts, public blockchains | Linked / distinguished only | Their terms govern their processing |
3. Website — information practices
3.1 Website forms, advertising and analytics
- No contact-form database on the website server (forms open your email client via
mailto:). - The website code does not include advertising trackers.
- The website code does not include site-owned analytics. Infrastructure providers may still process request metadata as described below.
3.2 Browser storage
Your light/dark appearance choice may be saved in your browser’s local storage under a key such as ikb-mode. You can clear it via your browser’s site-data settings. We do not treat this as an account profile.
3.3 Fonts and hosting (website stack)
- Fonts may load from Google Fonts, which receives network information needed to serve those requests (including IP address).
- The website is hosted through OpenAI Sites using Cloudflare infrastructure. Hosting providers process request information to deliver and secure the site; their privacy policies apply.
- Website hosting (OpenAI Sites / Cloudflare) is separate from hosted-plugin / API infrastructure (Cloudflare Workers / D1). Each layer has its own information practices.
- Infrastructure providers may process standard request metadata (for example IP address, user-agent, timestamps) as described in their policies. We do not promise “no logging” at the platform layer.
3.4 Contacting us by email
Email links and request forms open your email application. If you send the email, your address, message, and attachments reach our Microsoft 365 mailbox and are used to respond and handle the issue. Please avoid sending sensitive information that is not needed.
We retain correspondence as needed to handle your request, then delete or de-identify it under an internal schedule. Absolute, immediate, or permanent deletion from every backup or archive cannot be guaranteed (for example, Microsoft 365 backups or legal holds may delay or limit erasure). We will review deletion requests for correspondence we control and any applicable record-keeping obligations.
3.5 Blockchain information on the website
The address lookup on this website is a fictional demonstration. It does not query a blockchain. Donations, if shown, are made through your own wallet; on-chain transactions are publicly visible. This website does not request wallet access or connect to a wallet.
(Real public-address or NFT lookups, if any, occur only via hosted services/plugins/APIs described below — not via the website demo.)
3.6 External links
Links to other publishers (news, docs, directories) take you to sites with their own privacy practices.
4. Hosted services, plugins, and APIs — information practices
Access modes: Hosted tools may be offered under invitation, private preview, or broader access. Status changes (for example from invitation to general availability) do not by themselves change the data categories below.
4.1 What the services do
Provide sourced educational answers, ecosystem news/project discovery, blockchain comparisons (as available), and read-only public-network lookups (addresses, coins, tokens/CATs, NFTs, or similar) using third-party blockchain data and metadata providers. Results can be stale, partial, or wrong. One address is not an entire wallet. We do not independently guarantee NFT authenticity.
4.2 What we intentionally do not do
- No custody, wallet signing, transaction submission, trading, seed-phrase or private-key collection.
- Application-level logging / observability for query text and lookup payloads is disabled where engineered. Observability disabled ≠ zero platform logs — Cloudflare and other infrastructure may still process request metadata.
- We do not claim automatic 24-hour deletion of rate-limit counters, Durable Object quota state, or similar operational state.
4.3 Data categories that may still be processed
| Category | Practice | Notes |
|---|---|---|
| Invitation / access credentials | Opaque bearer tokens (or similar) for invitees / preview users | Legacy invitation access is separate from OAuth sign-in. Storage is layer-specific: the host typically stores hashes of credentials (not raw bearer secrets in app logs); client tooling may keep a token in an OS credential helper; protect device and invite files. We do not claim that tokens “never persist” anywhere. |
| OAuth identity and access | Auth0 and the selected identity provider, currently Google, process sign-in, identity/profile information and authentication/security metadata | Our service validates token claims and uses a derived hashed subject identifier for access, quotas and revocation. Hashing does not guarantee anonymity. AI hosts may store authorization credentials under their own practices. |
| Invitation lifetimes | Default about 1 day; may be issued for up to about 7 days; some older invites may run about 30 days | Lifetimes vary by invite — there is no universal “7-day for all” claim. Expiry ≠ full deletion of all related operational artifacts. |
| Rate limiting / abuse control | Hashed IP (or similar) and Durable Object (or similar) quota state | Hashed-IP rate windows are abuse-control intervals, not personal-data deletion deadlines. Not a promise of anonymity. |
| Content database (D1) | Educational content / backups on the Workers/D1 stack | Approximately 90-day educational content/backup retention: protected active/previous versions, ≥10 content snapshots, 3 newest verified SQL backups. Not personal-data / auth / support retention. Protected versions and retained verified backups can remain beyond 90 days. |
| Hosting / platform logs (Workers / D1) | Separate from the website OpenAI Sites stack | Platform may retain request metadata per provider policy. Application-level logging settings do not eliminate provider-side processing. |
| Third-party blockchain data / NFT index or metadata providers | Server-side lookups | Public addresses, puzzle hashes, token ids, and/or NFT ids may be sent to providers to fulfill a request. Identifiers are not necessarily anonymous. Providers are described here by category; this policy and the public Rights notice do not maintain a named vendor inventory. |
| AI host | User’s chosen AI product | Prompts and tool results are processed under the AI host’s terms. We do not assume our service receives the full chat, and we do not control host retention or training. |
4.4 Age and children’s privacy
The Service is intended for adults (18+). Educational content may still be useful to teens, but we do not operate age verification and do not claim verified age. We do not knowingly collect personal information from children under 13, and we do not direct marketing to children. If you believe a child under 13 has provided personal information to us (for example by email), contact privacy@iknowblockchain.com. COPPA may apply if the service is directed to children under 13 or we have actual knowledge we are collecting personal information from a child under 13.
5. How we use information
We use information to:
- Operate, secure, and improve the website and hosted services;
- Respond to email and partnership/support requests;
- Enforce access limits and prevent abuse;
- Comply with law and protect rights and safety.
We do not use hosted plugins/APIs to custody assets or execute trades.
6. Sharing
We share information with:
- Infrastructure and processors needed to run the site and services (for example Cloudflare, OpenAI Sites hosting layer, Microsoft 365, Google Fonts);
- Authentication providers, including Auth0 and the selected identity provider (currently Google), to support OAuth sign-in and security;
- Third-party blockchain data / NFT index or metadata providers when you (or your AI host on your behalf) request a hosted lookup;
- Authorities when required by law or to protect rights/safety;
- Successors in a merger or asset transfer, with notice where required.
7. Retention
| Category | Retention posture |
|---|---|
| Website localStorage theme | Until you clear browser data |
| Email correspondence (M365) | Retained as needed to handle the request, then deleted or de-identified under an internal schedule. Absolute erasure from every backup or legal hold is not promised. |
| Invitation credentials / hashed rate-limit state | For invite validity and abuse control. Invite TTLs vary (≈1 day default; up to ≈7 days; some older ≈30 days). Expiry is not a promise that every related artifact is deleted immediately. Hashed-IP windows are not deletion SLAs. |
| D1 educational content & SQL content backups | Approximately 90-day educational content/backup policy (active/previous protected versions; ≥10 snapshots; 3 newest verified SQL backups). Not a personal-data deletion SLA. |
| Rate-limit / Durable Object operational state | Retained for abuse control; inactive quota state can remain until updated. There is no automatic 24-hour deletion guarantee. |
| OAuth accounts and operational state | Retained as needed for authorized access, security and abuse control. Authentication-provider profiles/logs and AI-host credentials have separate retention from educational-content backups. Token expiry is not deletion of account data. Contact privacy@iknowblockchain.com about revocation or deletion of data we control; provider retention and applicable holds can limit erasure. |
| Provider-side logs | Governed by each provider’s policies — outside our sole control |
| AI-host records | Outside our control |
| Public blockchain data | Public and not erasable by us |
8. Security
We aim for reasonable administrative and technical measures appropriate to a small educational service (including disabling app-level query logging where engineered, hashing invitation secrets on the host, and using client credential helpers). No method of transmission or storage is 100% secure. Report suspected vulnerabilities to security@iknowblockchain.com.
9. Your choices and requests
Email privacy@iknowblockchain.com about your information, access revocation, or deletion of account data or correspondence we control. Deleting an app-login profile does not delete your Google account or records controlled solely by your AI host or authentication provider. We will review the request and applicable record-keeping needs. Absolute, immediate deletion from every backup or archive cannot be guaranteed.
We cannot erase: public chain data; copies held solely by your AI host; or provider logs we do not control.
Your applicable privacy rights are not limited by this policy. Contact us with requests concerning information we control.
10. Contacts
| Role | Address |
|---|---|
| Privacy | privacy@iknowblockchain.com |
| Security | security@iknowblockchain.com |
| Legal | legal@iknowblockchain.com |
| Support / feedback | support@iknowblockchain.com / feedback@iknowblockchain.com |
| Partnerships | partnerships@iknowblockchain.com |
| General | hello@iknowblockchain.com |
No response-time service-level agreement is offered.
11. Changes
If we materially change practices, we will update this policy and set a new effective date when the revised policy is published. For material expansions of use (for example, starting to sell data or enabling public accounts), we will provide clearer notice — and where required, consent — rather than silent retroactive switches.