<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Privacy on GetSmart Help Internal</title><link>/tags/privacy/</link><description>Recent content in Privacy on GetSmart Help Internal</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 26 May 2026 14:41:51 +0200</lastBuildDate><atom:link href="/tags/privacy/index.xml" rel="self" type="application/rss+xml"/><item><title>Security &amp; Privacy</title><link>/docs/security--privacy/</link><pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate><guid>/docs/security--privacy/</guid><description>&lt;h1 id="security--privacy">Security &amp;amp; Privacy&lt;/h1>
&lt;p>GetSmart Token is operated by &lt;strong>Digital Financial Aid Corporation&lt;/strong>, a 501(c)(3) nonprofit committed to protecting learner data and platform integrity.&lt;/p>
&lt;hr>
&lt;h2 id="security-measures">Security Measures&lt;/h2>
&lt;h3 id="infrastructure">Infrastructure&lt;/h3>
&lt;ul>
&lt;li>&lt;strong>Hosting&lt;/strong>: Cloudflare Pages (DDoS protection, WAF, edge network)&lt;/li>
&lt;li>&lt;strong>API&lt;/strong>: Edge Worker functions with no persistent server-side processes&lt;/li>
&lt;li>&lt;strong>Database&lt;/strong>: MongoDB Atlas with encryption at rest and in transit&lt;/li>
&lt;li>&lt;strong>Auth&lt;/strong>: Coinbase OAuth — we never store passwords&lt;/li>
&lt;/ul>
&lt;h3 id="blockchain">Blockchain&lt;/h3>
&lt;ul>
&lt;li>&lt;strong>Network&lt;/strong>: Base (Ethereum L2) — immutable public ledger for badge records&lt;/li>
&lt;li>&lt;strong>Contracts&lt;/strong>: Smart contract addresses published and verifiable on &lt;a href="https://basescan.org">basescan.org&lt;/a>&lt;/li>
&lt;li>&lt;strong>No private keys stored&lt;/strong>: The platform never holds user wallet keys&lt;/li>
&lt;/ul>
&lt;h3 id="ai-agent">AI Agent&lt;/h3>
&lt;ul>
&lt;li>&lt;strong>Cloud mode&lt;/strong>: API key held server-side in Cloudflare Edge Worker — never exposed to the client browser&lt;/li>
&lt;li>&lt;strong>Local / Air-Gap mode (Module 5)&lt;/strong>: The Gemma 4 model runs entirely in the user&amp;rsquo;s browser via WebGPU. Zero data leaves the device during local inference.&lt;/li>
&lt;/ul>
&lt;h3 id="data-in-transit">Data in Transit&lt;/h3>
&lt;ul>
&lt;li>All traffic served over HTTPS / TLS 1.3&lt;/li>
&lt;li>API calls to Google Gemini API made server-side only&lt;/li>
&lt;/ul>
&lt;hr>
&lt;h2 id="privacy-policy">Privacy Policy&lt;/h2>
&lt;h3 id="what-we-collect">What We Collect&lt;/h3>
&lt;ul>
&lt;li>Name and email address (for course enrollment and badge applications)&lt;/li>
&lt;li>Coinbase Wallet address (to issue NFT badges and $GETS tokens)&lt;/li>
&lt;li>Learning progress (which missions completed, evidence submitted)&lt;/li>
&lt;/ul>
&lt;h3 id="what-we-do-not-collect">What We Do Not Collect&lt;/h3>
&lt;ul>
&lt;li>Passwords (handled entirely by Coinbase OAuth)&lt;/li>
&lt;li>Payment card information&lt;/li>
&lt;li>Biometrics or sensitive personal data beyond what&amp;rsquo;s listed above&lt;/li>
&lt;/ul>
&lt;h3 id="how-we-use-your-data">How We Use Your Data&lt;/h3>
&lt;ul>
&lt;li>To issue NFT badges and $GETS tokens to your wallet&lt;/li>
&lt;li>To send course mission emails&lt;/li>
&lt;li>To review badge applications&lt;/li>
&lt;li>We do &lt;strong>not&lt;/strong> sell data to third parties&lt;/li>
&lt;/ul>
&lt;h3 id="user-rights-gdpr">User Rights (GDPR)&lt;/h3>
&lt;ul>
&lt;li>Right to access your personal data&lt;/li>
&lt;li>Right to request data deletion (subject to on-chain records, which are immutable)&lt;/li>
&lt;li>Right to data portability&lt;/li>
&lt;li>Requests: &lt;a href="mailto:hello@getstoken.org">hello@getstoken.org&lt;/a>&lt;/li>
&lt;/ul>
&lt;hr>
&lt;h2 id="responsible-disclosure">Responsible Disclosure&lt;/h2>
&lt;p>If you discover a security vulnerability in the GetSmart platform:&lt;/p></description></item></channel></rss>