Privacy policy
Last updated: 24 September 2026
This policy explains what Bitcointalk Academy (“the Academy”, “we”) collects when you use bitcointalkacademy.com, why we collect it, who else receives it, how long we keep it, and what you can ask us to do with it. We try to collect as little as possible. The Academy is free, has no paid tier, and does not sell personal data.
Who is responsible
Bitcointalk Academy is a community-built education project. It is not affiliated with Bitcointalk.org or its administrators. The Academy team decides how the personal data described here is used (under laws such as the GDPR, that makes us the “data controller”). You can reach us about anything in this policy through the contact form.
When you visit the site
- Server logs. Like every website, our server receives your IP address, browser user agent, the page you asked for and the time. The web server keeps these in standard access logs, which we use for security and troubleshooting.
- Abuse limits. To stop spam and guessing attacks, the app counts requests per IP address on some routes, such as Login Key sign-in and sign-up, the contact form, link suggestions, corrections and the simulations. These counters are kept in memory only, are never written to our database, and expire on their own.
- Cookies and browser storage. We use a small number of cookies and local-storage entries. Analytics and advertising cookies are only used if you allow them. The cookie policy lists each one and lets you change your choice.
- Referral links. If you arrive through a member's referral link (a link ending in
?ref=and a code), we store the code in a cookie for 30 days and record the visit: the referral code, a one-way hash of your IP address (not the address itself), your browser user agent and the page you landed on. If you then create an account, we record that the referral led to a sign-up so the member who referred you gets credit.
If you create an account
- Email account: your display name, email address, password (stored only as a salted hash, never in readable form), preferred language, whether you asked for the newsletter, your own referral code, and the referral code that brought you, if any.
- Login Key account: no email is needed. We create a Public ID (for example
honest_narwhal_3488) and show you a Login Key once; we keep only a hash of the key. A display name is optional. - Learning activity: lessons completed, quiz and final-quiz answers and scores, certificates and passports issued, XP and level, streaks, achievements, daily quests, simulation results, league standings, “My First 30 Days” progress and daily activity totals. We use this to show your progress, issue certificates, run streaks and leaderboards, and produce overall statistics about how the courses are used.
What other people can see:
- Your display name, level, XP and whether your forum account is verified can appear on the public leaderboards. If you refer other members, your display name and number of referrals can appear on the promoter leaderboard.
- Anyone who has one of your certificate or passport codes (for example because you shared the link) can open its verification page, which shows your display name and what you completed. A passport also shows your Bitcointalk username and user ID if you verified your forum account. Passports are unlisted by default and their pages tell search engines not to index them.
Bitcointalk account verification (optional)
If you choose to verify your forum account, you give us your numeric Bitcointalk user ID. We create a one-time code, valid for 60 minutes, and keep only a hash of it. You place the code in your forum profile, and our server fetches your public profile page from bitcointalk.org to look for it.
- We store your forum user ID, your forum username as it appeared at that moment, and the date and method of verification.
- We keep an audit trail of each verification step: start, check, success or the reason it failed, cancellation and unlinking. We never store the content of your profile page.
- Your forum rank, activity and merit are stored only if you ask us to refresh your forum stats.
- You can unlink your forum account at any time from your account settings. This clears the forum details from your account. The records of your past verification attempts (the forum user ID and username each one used) and the audit trail are kept.
Things you send us
- Contact form: your name, email address, subject and message. Messages are stored in our database and read in the Academy's admin inbox. When email sending is set up, a copy is also emailed to the site admins. We use your email address only to reply.
- Link suggestions and lesson corrections: the link or correction you send, the reason you give, and a name if you choose to add one.
- Voices interviews: your answers, linked to your account if you are signed in, or to an email address you give if you are not. An anonymous submission publishes no name. A submission under your name uses your verified forum username.
- Campaign submissions and reports: the campaign details you send, linked to your account, and a contact email if you give one. A report on a listing is linked to your account if you are signed in.
- Newsletter: your email address, language and whether you have confirmed. You confirm by email and can unsubscribe with the link in any newsletter email.
- Push notifications: if you turn them on, we store the push address and keys your browser gives us, your browser's user agent and your notification settings. Messages travel through your browser maker's push service. Turning notifications off stops them.
Public forum information about other people
The Academy writes about the Bitcointalk community. The Campaign Radar lists signature campaigns taken from public forum threads, including each campaign manager's forum username and profile link; our server reads the relevant public bitcointalk.org pages every day to keep listings current. A manager who asks not to be listed is removed and stays removed. Lessons and articles may credit forum members by username when they draw on their public posts, always with a link to the source. Voices interviews that name a member are published only with that person's written permission. If you are named anywhere on the Academy and want that changed or removed, use the contact form.
Other services that receive data
- Google Analytics 4 (Google) — only if you allow analytics cookies, and only while Google Analytics is switched on for the site. It records the pages you view, approximate location, device and browser details, and a few interaction events such as opening a campaign's forum thread. We never send your name, email address or account ID to Google Analytics. According to Google, Analytics 4 does not log or store IP addresses. Google handles this data under its own privacy policy.
- A-Ads (a-ads.com) — our ad spaces normally show our own “Advertise here” placeholder, which loads nothing from anyone else. If third-party ads are switched on, ads are loaded from A-Ads in an embedded frame, and only if you allow marketing cookies. When that frame loads, A-Ads receives your IP address and browser details and may use its own cookies.
- Cloudflare Turnstile — if this bot check is switched on, the Login Key sign-up form loads it from Cloudflare, which receives your IP address and browser signals to tell people from bots.
- Hosting — the site and its database run on a server we rent from Hetzner. Everything you send us is stored there.
- Email delivery — when email sending is set up, account emails (such as address confirmation), newsletter confirmations and admin notifications pass through an email delivery service, which handles the recipient's address and the message.
- Bitcointalk.org — our server requests public forum pages (your profile during verification, public campaign threads). These requests come from our server, not your browser, so your IP address is not sent. Links to bitcointalk.org and other sites take you to services with their own privacy policies.
- AI drafting for the Digest — when it is switched on, editors can ask Anthropic's Claude API to draft Digest text from structured public forum data. Account data is never sent to it, and nothing it writes is published without a person reviewing it.
Some of these services may process data outside the country you live in.
Why we use your data
- To provide what you asked for — your account, courses, quizzes, certificates, passport, verification, notifications and replies to your messages.
- To keep the site safe and working — server logs, abuse limits, bot checks and fraud checks on referrals. This is in our legitimate interest and yours.
- To run the referral programme and credit members who bring in new learners.
- With your consent — analytics cookies, marketing cookies and the newsletter. You can withdraw consent at any time; doing so does not affect what happened before.
How long we keep it
- A sign-in lasts up to 30 days after your last visit.
- Forum verification codes expire after 60 minutes. Email confirmation links expire after 48 hours, or 24 hours for a link you ask us to send again.
- The referral cookie lasts 30 days; your cookie choice is remembered for a year.
- Google Analytics keeps its data for the retention period set in our Analytics account.
- We do not yet run automatic deletion schedules. Account data, learning records, messages and submissions stay in our database until you ask us to delete them or we remove them ourselves. You can ask at any time.
Your choices and rights
- Change your cookie choice at any time on the cookie policy page.
- In your account you can unlink your forum account, change your password, choose whether your passport is public, and turn notifications on or off. Newsletter emails carry an unsubscribe link.
- You can ask for a copy of your data, for mistakes to be corrected, for your account and data to be deleted, or object to how we use it. Account deletion and data export are not self-service yet, so send the request through the contact form and say which account it is about (your email address or Public ID). We may need to confirm the account is yours before acting. We will never ask for your password, Login Key, private keys or seed phrase. We aim to answer within one month.
- If you live in the EU, the UK or another country with a data-protection authority, you can also complain to that authority.
Security
Connections to the site are encrypted (HTTPS). Passwords, Login Keys and verification codes are stored only in hashed form. Admin tools require an admin account, and key admin actions are recorded in an audit log. No system is perfectly secure, so please use a password you don't use anywhere else and keep your Login Key private.
Children
The Academy is not designed for children, and we do not knowingly collect data from anyone under 16. If you think a child has created an account, tell us through the contact form and we will delete it.
Changes to this policy
When this policy changes we update the date at the top, and we note significant changes in the changelog.