pr0d / LEGAL
Privacy policy.
pr0d is an identity and wallet layer that other applications build on. This policy explains what we collect, why, how long we keep it, and the choices you have. It is written to be read, not skimmed past.
Who this covers
pr0d is operated by HODL Labs FZCO (“pr0d”, “we”). This policy applies to three groups of people, and we act in a different role for each:
- Developers who create an account in the pr0d dashboard and register applications. For your account data, we are the controller.
- End users who sign in to an application built on pr0d. The application’s owner decides what to collect and why; we process end-user data on their behalf, as their processor, under our terms with them.
- Visitors to pr0d.io and docs.pr0d.io.
What we collect
Developer accounts
Your email address, the one-time codes we send to verify it, the applications and environments you register, the sign-in methods and factors you configure, and a log of sign-ins to the dashboard (time, IP address, browser).
End users of applications built on pr0d
Only what the sign-in method needs. Depending on the method an application turns on, that is:
- An email address and the one-time codes sent to it.
- The account identifier, name, and email a social provider (Apple, Google, X, or Privage) returns after a sign-in. We do not receive the provider password.
- Passkey public keys and credential identifiers. The private key never leaves the user’s device.
- Second-factor enrolment data: an authenticator-app secret, or a passkey as above.
- Session records: the device type, browser, IP address, and times a session was issued, renewed, and revoked.
- For applications using pr0d Wallet, the wallet addresses created for a user and the policies the application sets for them.
Website visitors
pr0d.io uses a privacy-focused analytics service (Tracedart) to count visits and page views. The interactive sign-in demo on pr0d.io runs entirely in your browser; nothing you type into it is sent to us or stored.
Why we use it
- To sign people in and keep them signed in across their devices.
- To let users and applications see active sessions and revoke them.
- To send one-time codes and account notices by email.
- To detect and block abuse, such as repeated failed codes or sign-in attempts from unusual locations.
- To run, secure, and improve the service, and to meet legal duties.
We do not sell personal data and we do not use it for advertising.
How long we keep it
- One-time codes expire within minutes and are deleted after use or expiry.
- Session records are kept while a session is active and for 90 days after it ends, for security review.
- Account and end-user identity data is kept for as long as the account or application exists, then deleted within 30 days of deletion.
- Logs needed to investigate abuse are kept for up to 12 months.
Your choices
You can see, correct, export, or delete your developer account data from the dashboard, or by emailing us. If you are an end user of an application built on pr0d, contact that application first: its owner decides what is collected and can act on your request, and we will help them do so.
Depending on where you live, you may have rights under laws such as the UAE Personal Data Protection Law, the GDPR, or the CCPA, including the right to access, correct, delete, or restrict the use of your data, and to complain to a supervisory authority. We will respond to a request within 30 days.
Where data is processed
pr0d runs on Cloudflare’s network, which processes data in multiple regions. Where data leaves the region it was collected in, we rely on standard contractual clauses or an equivalent safeguard.
Children
pr0d is a developer service and is not directed at children. Applications built on pr0d are responsible for any age requirements that apply to their own users.
Changes and contact
We will post changes here and update the date at the top. For anything material, we will tell developers by email first.
Questions about this policy or your data: privacy@pr0d.io.
Legal entity. HODL Labs FZCO, a company licensed by IFZA (trade licence 45659), Dubai Silicon Oasis, Dubai, United Arab Emirates. This policy is governed by the laws of the United Arab Emirates.