← Back to Bitcoin Education Archive

Privacy Policy

Last updated: July 26, 2026

Our commitment: We do not sell, share, or monetize your data. Ever.

We collect the bare minimum needed to power your experience. No tracking, no ads, no third-party analytics.

1. What We Collect

Account Data (stored in Firebase)

DataPurpose
UsernameDisplay on leaderboard, PlebTalk forum, LightningMart, and direct messages
Email (if provided)Account verification via magic link sign-in
Sign-in providerGoogle, Twitter/X, GitHub, Facebook, Nostr (NIP-07), or Lightning (LNURL-auth) authentication
Profile pictureOptional avatar upload (resized to 128px JPEG, stored in Firestore)
TOTP 2FA secretEncrypted TOTP secret for two-factor authentication (if enabled)
Points & rankGamification and leaderboard
Streak & visit countDaily streak tracking and visit bonus
Channels visitedProgress tracking and exploration map
Orange TicketsGiveaway eligibility and referral rewards
Referral codeReferral program tracking
Giveaway entry (Lightning address)Prize distribution if you win
Hidden badges earnedBadge/achievement tracking
Weekly XP (weeklyXP)Weekly leaderboard ranking (resets every Monday)
Monthly XP (monthlyXP)Monthly leaderboard ranking (resets on the 1st of each month)
Nook inventory (streakFreezes, hintTokens, hashBoosters, doubleXPCharges, bonusSpins, raffleEntries)Consumable item counts for Nacho's Nook shop
Owned cosmetics (ownedCosmetics)List of purchased cosmetic items (Profile Frame, Chat Flair, Pinned Badge, Nacho Skin, Second Mining Rig)
Double XP expiry (doubleXPExpiry)Tracks when Double XP multiplier expires
Shop purchase history (shop_purchases subcollection)Server-side log of Nook purchases for audit and dispute purposes
Scholar certification statusCertification tracking
FavoritesSaved channel list sync across devices
BookmarksSaved channel bookmarks synced across devices via Firestore
Social links (Twitter/X, Instagram, TikTok, GitHub, Nostr)Display on public profile (optional, user-provided)
Contact email (if provided)Display on public profile for contact (optional, separate from sign-in email)
Online presence (lastSeen timestamp)Show online/away/offline status on leaderboard and profiles (can be disabled in Settings)
Blocked users listSynced block list to prevent unwanted messages across devices

Direct Messages (stored in Firebase)

DataPurpose
Message textDeliver private messages between users
Sender & recipient IDsRoute messages to correct users
TimestampsDisplay message times, sort conversations
Unread countsShow unread badge notifications
⚠️ Direct messages are private between participants but are stored on Firebase servers. We may access messages when investigating abuse reports. Messages are not end-to-end encrypted.

PlebTalk Forum (stored in Firebase)

DataPurpose
Posts & repliesCommunity discussion
Author username & IDAttribution and profile linking
UpvotesContent ranking

LightningMart Marketplace (stored in Firebase)

DataPurpose
Listing details (title, description, price, images)Display marketplace listings
Seller username & IDAttribution and profile linking
Buyer-seller messagesFacilitate transactions
Uploaded imagesStored as base64 in Firestore (max 5MB, resized to 800px)

Bitcoin Beats (stored in Firebase)

DataPurpose
Audio file (Firebase Storage or base64)Store and play user-uploaded music tracks (max 50MB each via Storage)
Track metadata (title, artist, genre)Display track information in the music player
Album/EP metadata (album title, type, year, track number)Group tracks into albums or EPs for organized display
Cover art (image file)Album/track artwork shared across grouped uploads
Play countTrack popularity and display play statistics
LikesTrack popularity and user preferences
Author ID & usernameAttribution and track ownership
Copyright confirmationRecord that uploader confirmed rights ownership
⚠️ Music uploads are public. Any audio you upload to Bitcoin Beats (including bulk album/EP uploads of up to 20 tracks) is visible and playable by all users. You must own the copyright or have permission to upload. See our Terms of Service for copyright and takedown policies.

Global Chat (stored in Firebase)

DataPurpose
Chat messagesDisplay in the public global chat room
Sender username & IDAttribution and user identification
TimestampsMessage ordering and display
Reply referencesThreading replies to specific messages
⚠️ Global Chat messages are public. All messages in Global Chat are visible to every user on the site in real time.

DJ Mode (stored in Firebase)

DataPurpose
DJ username & IDDisplay who is currently DJing
Current track info (title, artist, audio URL)Broadcast now-playing info and stream audio to listeners
Playback positionSync listener playback to DJ's current position
Sound effect eventsRelay DJ sound effects to listeners in real time
DJ queueManage turn-based DJ booth access

Online Presence (stored in Firebase)

DataPurpose
User ID & usernameIdentify who is online
Last seen timestampDetermine active users (within last 3 minutes)

Presence data is automatically deleted when you leave the site. The online user count is displayed next to the Global Chat icon.

IRL Sync Events (stored in Firebase)

DataPurpose
Event title, date, locationDisplay and search for meetups
Event description & linkProvide event details to attendees
Cover photo (Firebase Storage)Display event imagery (max 3MB)
Host user ID & display nameAttribution and event management
Attendee list (user IDs)RSVP tracking and attendance count
⚠️ IRL Sync events are public. Event details (title, date, location, description, host name, attendee count) are visible to all users. Your user ID is added to the attendee list when you RSVP. 603BTC LLC is not responsible for events organized by users — see our Terms of Service for liability details.

In-App Notifications (stored in Firebase)

DataPurpose
Notification type & messageAlert you about sats claims, new DMs, streak milestones, and exploration achievements
Sender & recipient IDsRoute notifications to the correct user
TimestampsDisplay notification times and expiration
Read/unread statusBadge count and notification management

Community Statistics (stored in Firebase)

DataPurpose
Aggregate counters (channel reads, quests, spins, chats, PVP matches)Display community-wide activity stats — no individual user data
User countDisplay total registered users

Community statistics are fully anonymous aggregate counters. They do not contain any personally identifiable information.

Price Predictions (stored in Firebase)

DataPurpose
Prediction (up/down), price at timeTrack daily prediction accuracy
Accuracy stats (total, correct, streak)Display prediction stats on profile
Active predictionsPending predictions resolved server-side via Cloud Function every 6 hours

Telegram Bridge (via Cloud Function)

Global Chat messages may be forwarded to a linked Telegram group via a secure Cloud Function. Messages from Telegram users are also displayed in Global Chat. The bridge transmits: username, message text, and image/GIF URLs. No personal data beyond your chosen username is shared with Telegram.

Bitcoin Dashboard / Top Indicators

The Bitcoin Dashboard fetches public market data from third-party APIs including CoinGecko, ColintalksCrypto (CBBI), alternative.me (Fear & Greed), mempool.space, and Bitbo.io. No user data is sent in these requests — they are read-only public API calls. Indicator data may be cached in your browser's localStorage for up to 1 hour.

PVP Battles (stored in Firebase)

DataPurpose
Battle results & scoresTrack PVP battle history and rankings
Opponent pairingMatch players for competitive quizzes

Nacho's Trails (stored in Firebase)

DataPurpose
Trail progress (channels completed)Track which channels you've read in each guided learning path
Exam scores & answersGrade trail exams (25 questions each) and award badges/points
Trail badges earnedTrack Meadow/Mountain/Summit completion

Bitcoin Buddy (stored in Firebase)

DataPurpose
Username & experience levelMatch teachers with learners
Goal (Learn or Teach)Complementary matching logic
Optional intro messageShared with matched buddy to start conversation
Timezone estimateProximity matching preference

Buddy pool entries are deleted when matched or after 30 days of inactivity.

Shareable Certificates (stored in Firebase)

DataPurpose
Certificate ID & verification URLGenerate a public shareable link to your Scholar Certification
Username, score, dateDisplay on the public verification page

Certificate verification pages are publicly accessible by design — they prove your achievement.

Sats vs Bits Vote (stored in Firebase)

DataPurpose
Vote (sats or bits)Community denomination poll
Device fingerprint hashAnti-cheat: prevent duplicate voting (hashed, not personally identifiable)

Your First Bitcoin Purchase (local only)

DataPurpose
Selected regionShow region-appropriate exchange recommendations
Step progressRemember where you left off in the guided flow

No purchase data, exchange credentials, or financial information is collected or stored. Referral links redirect to third-party sites governed by their own privacy policies.

Meetup-in-a-Box (no data collected)

Template downloads are generated client-side as text files. No data is sent to our servers.

Reports (stored in Firebase)

DataPurpose
Reporter & reported user IDsProcess abuse reports
Report reasonCategorize and prioritize reports
TimestampTrack report timeline

Timechain TV (YouTube & Local Data)

Timechain TV embeds content using standard YouTube IFrame embeds. When you use the video player, YouTube may collect data according to their own privacy policy. We do not transmit your identity to YouTube. Locally in your browser, we store your 'last station' and 'mute/autoplay' preferences so your experience is preserved between visits.

Third-party content & opinions. All videos shown on Timechain TV are publicly embeddable third-party uploads from YouTube. Bitcoin Education Archive does not own, host, verify, or endorse the content. Opinions, price predictions, investment theses, and statements expressed belong solely to the individual creators and speakers — not to us. Nothing on Timechain TV is financial, investment, legal, or tax advice. See our Terms for the full disclaimer.

Anonymous live-viewer presence. To show the live viewer counter on each channel, your browser writes a small presence record to our database every ~30 seconds containing only: (1) the channel id you are currently watching, and (2) a server timestamp. For signed-in users this record is keyed by your auth UID; for anonymous users it is keyed by a randomly-generated local id (stored in your browser's localStorage as tctv_viewerId). The record is deleted when you leave Timechain TV or close the tab, and automatically expires after ~65 seconds of inactivity. No IP, location, or identifying information is stored in the presence record.

Watch-time tracking. We count minutes watched on Timechain TV to power badges and the point reward system (10 points per 10 minutes). Anonymous users have watch time stored only in localStorage. Signed-in users have their cumulative watch time stored in their Firestore user document. You can clear this at any time via Settings → Reset Account.

Local Data (stored in your browser only — never sent to us)

DataPurpose
Theme preferenceDark/light mode
Language preferenceTranslation setting
Audio/sound settingsSound effect preferences (site + Nacho)
Nacho interaction countFriendship level calculation
Nacho questions askedQuestion badge tracking
Nacho equipped accessory & colorsCloset/outfit selection and customization
Nacho chat history (Nacho Mode)Conversation continuity within sessions
Nacho question analyticsLast 100 questions (local only, helps improve answers)
Nacho trivia progressWhich trivia questions you've answered
Blocked users (local copy)Fast block checking without server round-trip
Referral code (pre-signup)Stores referral link code before account creation
Pending signup dataTemporarily stores username/email during email verification
Visited channelsCheckmarks and exploration map (also synced to Firebase if signed in)
BTC price cacheCached price for marketplace USD conversion
Liked tracks (Bitcoin Beats)Remember which tracks you hearted
Chat message countTrack total messages for chat badges
Chat streak & last chat dateDaily chat streak tracking for rewards
DJ sets countTrack total DJ sessions for DJ badges
DJ songs broadcast countTrack songs broadcast for DJ badges
DJ tune-in countTrack how many DJ sets you've listened to
Nacho position (draggable)Remember where you placed the Nacho mascot on screen
First Purchase step & regionResume buying guide where you left off
Trail progress (local cache)Fast load of trail status (also synced to Firebase)
NWC connection stringStored in sessionStorage (cleared when tab closes) for Lightning wallet connection

We do not collect your real name, physical location, browsing history outside the Site, or any financial information (other than a Lightning address if you enter the giveaway). IP addresses are only collected during sats faucet claims for multi-account abuse detection — they are not collected during normal browsing, sign-in, or any other activity.

2. How We Use Your Data

3. User Profiles

When you create an account, a public profile is visible to other signed-in users. Your profile displays:

Your email, sign-in provider, and blocked list are never visible to other users.

4. Data Storage

Server-side data is stored in Google Firebase (Firestore), hosted in the United States. Firebase is operated by Google and subject to Google's enterprise security practices and certifications.

Client-side data is stored in your browser's localStorage and in the PWA's service worker cache. This data stays on your device and is never transmitted to us.

Direct messages and forum posts are stored in Firebase Firestore. Messages are not end-to-end encrypted. We may access message content when investigating abuse reports.

5. Third-Party Services

We use the following third-party services:

ServicePurposeData Shared
Firebase AuthenticationAccount sign-inEmail, provider token
Firebase FirestoreData storageAccount data, messages, posts, listings
Firebase Cloud MessagingPush notifications (opt-in)Device token
Google OAuthGoogle sign-inGoogle account email/name
Twitter/X OAuthTwitter sign-inTwitter account info
GitHub OAuthGitHub sign-inGitHub account email
Facebook OAuthFacebook sign-inFacebook account info
Nostr (NIP-07)Nostr sign-in via browser extensionPublic key, signed auth event
LNURL-authLightning wallet sign-inLinking key, signed challenge
QR Server APIGenerate QR codes for Lightning authLNURL string (no user identity)
Cloudflare Workers AINacho AI — question answering powered by Meta Llama 4 Scout (a large language model hosted by Cloudflare)Question text only (no username, no user ID, no account data)
mempool.space APILive BTC price, block height, feesNone (read-only public API)
GitHub PagesWebsite hostingStandard web server logs
CoinGecko APIMarket data, price charts, dominanceNone (read-only public API)
ColintalksCrypto (CBBI)On-chain indicator dataNone (read-only public API)
alternative.meFear & Greed IndexNone (read-only public API)
Bitbo.ioETF flow dataNone (read-only public data)
RainbowChart.comRainbow chart formula referenceNone (formula only, no API calls)
Firebase Cloud FunctionsSecure Telegram bridge, server-side operationsChat messages (username + text)
Telegram Bot APIBridge Global Chat to Telegram groupUsername and message text

We do not use Google Analytics, Facebook Pixel, ad networks, or any tracking/analytics services.

6. Data Sharing

We do not share, sell, rent, or monetize your data with anyone. Data visible to other users includes:

7. Cookies & Local Storage

We take a minimal, privacy-first approach to browser storage. Here is an exact breakdown of what we store and why:

Cookies

We set one first-party cookie under normal operation:

Firebase Authentication may set a short-lived __session cookie to manage your sign-in state. This is an HttpOnly, first-party session cookie. It contains no personal data beyond an opaque auth token and is cleared when you sign out or it expires.

We do not use:

Because we do not use non-essential cookies, you are not required to give cookie consent under GDPR/ePrivacy rules. There is no cookie banner because there is nothing to consent to beyond functional operation.

Browser localStorage

The majority of your in-app state is stored in your browser's localStorage — entirely on your device, never transmitted to us unless you create an account. Examples of what we store locally:

You can clear all localStorage data at any time from your browser settings, which will reset app preferences and cached progress. If you have a signed-in account, your server-side profile (XP, badges, wallet balance, posts) is unaffected.

Service Worker Cache

The app operates as a Progressive Web App (PWA). A service worker caches app assets (scripts, stylesheets, images) on your device for offline access and faster loading. This cache contains only static app files — no personal data. You can clear it via your browser's "Clear site data" or "Clear cache" function.

8. Nacho (AI Mascot) Privacy

Nacho's AI answers are powered by Meta Llama 4 Scout, a large language model (LLM) hosted by Cloudflare Workers AI. Cloudflare processes questions on our behalf under their Privacy Policy. The Llama model is provided by Meta; see Meta's Llama 4 license. We do not use your questions to train AI models.

9. Content Moderation & Filtering

All user-generated content (Global Chat messages, forum posts, DMs, usernames, articles) is filtered client-side before submission. No content is sent to external moderation services. Filters include:

Filtering is performed entirely in your browser. No message content is sent to external moderation APIs or third-party services. Blocked messages are never stored in Firebase.

10. Messaging & Communication Safety

11. Your Rights

You can:

When you delete your account, all your data is permanently removed from our Firebase database, including messages, posts, listings, and reports. Local browser data must be cleared separately.

12. Children

The Site is educational and suitable for all ages. We do not knowingly collect personal information from children under 13. The direct messaging feature is available only to registered users. If you are a parent and believe your child has provided personal information or been contacted inappropriately, please contact us immediately and we will take action.

13. Data Security

We use industry-standard security measures including:

14. Data Retention

Account data is retained as long as your account exists. Direct messages are retained as long as both participants' accounts exist. Forum posts and marketplace listings are retained indefinitely unless deleted by the author or removed by administrators. If you delete your account, all associated data is permanently deleted from Firebase. Anonymous visit data (visitor ID and count) may be retained for aggregate statistics but contains no personally identifiable information.

15. Sats Faucet (Claim Sats)

Data Collected for Sats Claims (stored in Firebase)

DataPurpose
Withdrawal history (amounts, timestamps)Track claim activity and enforce daily/lifetime limits
Truncated Lightning invoice (first 50 characters + "...")Audit trail for payouts — we do NOT store full invoices
Daily claim trackingEnforce 1-claim-per-24-hours cooldown and 200 sats/day cap
Lifetime total claimedEnforce 15,000 sats lifetime cap per user
Device fingerprint hashAnti-abuse: detect multi-accounting (hashed, not personally identifiable)
IP address (at claim time only)Anti-abuse: detect multiple accounts claiming from the same network
Server-side daily points trackingEnforce 500 pts/day cap per user — tracked in Firebase, not browser

Firestore Data Structure

Sats claim data is stored in the following Firebase subcollections under your user document:

Privacy note: We intentionally do NOT store full Lightning invoices. Only the first 50 characters are retained (followed by "...") for basic audit purposes. This means we cannot reconstruct the full payment destination after the claim is processed.

16. Donate XP for Charity — Data Practices

17. Changes

We may update this Privacy Policy from time to time. Changes will be reflected in the "Last updated" date above. Continued use of the Site after changes constitutes acceptance.

18. Ownership

The Bitcoin Education Archive is owned and operated by 603BTC LLC. "Bitcoin Education Archive" is a trademark (™) of 603BTC LLC. All original Site content, design, code, and branding are © 2026 603BTC LLC. All rights reserved.

19. Contact

Questions about privacy? Email info.603btc@gmail.com.


Terms · DMCA · TCTV Terms

© 2026 603BTC LLC · Bitcoin Education Archive™ · bitcoineducation.quest