Privacy Policy
OpenGiveaway is built so that a giveaway can be proved fair without publishing who entered it. This page explains what we hold, why, and for how long.
Last updated 02 October 2026
1 Who this covers
This policy applies to opengiveaway.org and the OpenGiveaway service. It covers three different people:
- Organizers — people who sign in, create a team and run giveaways.
- Participants — people who appear on an uploaded entry list, or who visit a public giveaway page to check whether they were included.
- Auditors — anyone verifying a draw, in the browser or with the command-line verifier. Verification needs no account and we do not ask who you are.
If you are a participant and want to know why your email or handle is on a particular list, the organizer who uploaded it is the right person to ask. Clause 2 explains why.
2 Two kinds of data
There are two clearly separate sets of personal data in the product, and we hold them in different capacities.
- Organizer data — your email address, your team, your giveaways, your payments. We decide what to collect and why, so for this data we are the controller.
- Entry lists — the emails and social handles an organizer uploads. We never gather these ourselves, we do not decide what goes in them, and we use them only to run the draw the organizer asked for. For this data the organizer is the controller and we are a processor acting on their instructions.
That split matters in practice: we will not add, edit or remove someone from an entry list on our own initiative, and a request to be taken off a list is one we pass to the organizer rather than act on ourselves.
Organizers whose own law requires a written processor agreement — a GDPR Article 28 contract, or a data processing agreement under the DPDP Act — can ask us for one at [email protected]. Our governing law and venue are set out in the Terms.
3 Your account and team
To run a giveaway you need an account. Signing in is by email address and password, and we store:
- your email address, and a cryptographic hash of your password — never the password itself;
- whether you have confirmed your address, and when you last signed in;
- your team — its name, its URL slug, its members and their roles;
- invitations you send, which store the invited email address and expire on their own;
- the giveaways you create: title, description, prize tiers, schedule, timezone and the Bitcoin block you picked;
- payment records — amount, currency and tier. Publishing is free at the moment, so these are all zero-value rows; no payment provider is connected and no card details exist anywhere in the system.
We use this to operate your account, review giveaways before they go live, bill you once per published giveaway, and email you about your own giveaways. We do not sell it, and we do not use it to advertise to you.
4 Entry lists you upload
An entry list is a file you upload once a giveaway is approved. Each row identifies an account on a platform — an email address, or a handle on X, Instagram, TikTok, YouTube, Facebook, Threads, Telegram, Discord, Reddit or LinkedIn. The uploaded file is stored privately and is readable only by your team and by our systems; it is never served to the public.
When the list is locked, every identifier is normalized to a canonical source:account form and then committed as a salted hash. Each giveaway has its own 32-byte secret that lives only in the backend, and the commitment for an identifier is derived from that secret. This is the whole point of the design: the published fingerprint of the list cannot be tested against a guessed list of email addresses, because a guess alone is not enough to reproduce a commitment.
The plaintext identifiers of winners are kept alongside the draw so you can contact them. Those are visible to your team only, never on the public page.
You are responsible for having a lawful basis to upload a list and to enter people into a draw, and for telling participants that their entry will be committed to a public fingerprint. If you collected entries under a promise you cannot keep here, do not upload them.
5 What becomes public
A published giveaway has a page anyone can read without signing in. That page, and the proof files beside it, contain:
- the giveaway’s title, description and prize tiers, as you wrote them;
- the number of entries, and a count per source (for example 1,200 from X and 300 by email);
- the Merkle root of the entry list, the OpenTimestamps proof, the draw block height and hash, and the derived seed;
- for each winner: their rank, their position in the list and their
id_commit— the salted commitment, not their identifier.
Plaintext identifiers are never published. The one exception is under your control: a giveaway can be set to publish its full entry list, so that anyone can recompute every commitment. That is off by default, and turning it on is a decision to publish your participants’ identifiers. Do not turn it on for lists of email addresses unless the people on them agreed to that.
A winner can prove the commitment is theirs without anybody learning who they are, which is how a draw stays auditable and private at the same time.
6 Participants checking an entry
Checking an entry needs no account. You pick where you entered, type the handle or email you entered with, and the site tells you whether you are on the sealed list.
What happens to what you type:
- it is sent to our lookup endpoint, which returns the salt and Merkle path for that identifier if it exists on the list;
- the proof is then checked in your browser against the fingerprint published when the list was locked — so a wrong or invented answer is caught locally rather than trusted;
- we do not store the identifier you typed, and we do not keep a log of who looked themselves up.
Your IP address is held in memory for up to a minute to rate-limit lookups, and is not written to a database. Where a human check is switched on, the lookup and sign-in forms load Cloudflare Turnstile, which sees your IP address and browser details to tell people from bots; it sets no advertising cookies. Our hosting provider keeps short-lived request logs as described in clause 8.
7 Cookies and tracking
There is no advertising, no analytics and no third-party tracking on this site. We set no cookies for marketing or measurement, which is why you are not asked to accept any.
Signing in sets a session cookie so you stay signed in between pages. It is strictly necessary for the dashboard to work, and clearing it signs you out. Public giveaway pages, the verifier and the protocol pages work with cookies disabled entirely.
Small preferences — such as the “show the technical detail” toggle on a public page — are kept in your browser’s own storage and never sent to us.
8 Who else sees data
We keep the list of third parties deliberately short. In normal operation these are all of them:
- Supabase — database, authentication and file storage, hosted in the European Union. Account data, giveaways, uploaded entry lists and published proof files live here.
- OpenTimestamps calendar servers — timestamping. Only the 32-byte commitment hash is sent. No personal data leaves with it.
- mempool.space and blockstream.info — public Bitcoin block data. Pages that show the current block height ask these explorers directly from your browser, so they see your IP address and that you requested a block height. We require independent explorers to agree before a draw is accepted, which is why more than one is used.
- Email delivery — confirmation and invitation emails are sent through Supabase’s authentication email service, which receives the recipient’s address and nothing else.
- Cloudflare Turnstile — an optional human check on the entry lookup and sign-in forms, used to stop automated abuse. When switched on, your browser contacts Cloudflare, which sees your IP address and browser details. We do not send it your email or the identifier you look up.
- Vercel — hosting and delivery for this website, which keeps standard short-term request logs including IP addresses.
We may also disclose data where the law requires it, or to establish or defend a legal claim. If our business is transferred, data transfers with it and this policy continues to apply until we tell you otherwise.
Data is stored in the European Union while the service is operated from India, so personal data does cross borders. Where a transfer is covered by the GDPR we rely on the European Commission’s Standard Contractual Clauses with the providers above; the DPDP Act permits transfers out of India except to territories the Indian government restricts, and we do not use providers in any restricted territory.
9 Storage and retention
- Account and team data — kept while your account exists, and deleted within 30 days of you closing it.
- Uploaded entry files — kept while the giveaway exists, so that a locked list can be re-verified. Delete a giveaway and its uploads go with it.
- Winner identifiers — kept with the drawn giveaway, so you can still reach a winner months later.
- Published proof files — kept indefinitely. They are the proof; see clause 11.
- Payment records — kept for 8 years to meet Indian tax and accounting obligations, even if the giveaway they paid for is deleted. A deleted giveaway leaves its payment record behind with the link to the giveaway removed.
- Lookups by participants — not retained at all.
10 Your rights
Under India’s Digital Personal Data Protection Act, 2023 you may ask us for access to your data, ask us to correct or complete it, ask us to erase it, withdraw a consent you gave us, and nominate someone to exercise these rights if you die or become incapacitated. If you are in the EEA or the UK, the GDPR may also give you the right to object to or restrict processing and to receive your data in a portable form; we honour those requests too rather than arguing about which law applies.
If we get it wrong, complain to us first and we will tell you what we found. You can then escalate to the Data Protection Board of India, or to your own supervisory authority if you are in the EEA or the UK.
Write to [email protected]. We acknowledge within 48 hours and respond within 30 days. We may need to confirm who you are before acting, particularly on a deletion request.
If your request concerns an entry list, tell us which giveaway. We will identify the organizer and pass it on, because for that data they decide and we do not.
11 Deletion, and its one limit
Almost everything here can be deleted. A giveaway that is still a draft, awaiting review, rejected, approved, failed or invalid can be removed by a team owner or admin, and its uploaded lists go with it. A live giveaway can be unpublished and then deleted.
One thing cannot be undone. Once an entry list is locked, its fingerprint is timestamped on the Bitcoin blockchain and the public page becomes the proof of the draw. We cannot delete a drawn giveaway, and we cannot alter its published proof — doing so would break every verification link in circulation and destroy the audit trail the product exists to provide. We also cannot remove anything from the Bitcoin blockchain, which no one controls.
What is published at that point is a set of salted commitments, entry counts and hashes — not names, not email addresses, not handles — unless the organizer chose to publish the full list under clause 5. If you need a giveaway and its list gone, delete it before the list is locked.
12 Children
The service is not for children. You may not create an account if you are under 18. The DPDP Act requires verifiable parental consent before processing the data of anyone under 18 in India, and forbids tracking or targeted advertising towards them — we do neither to anyone. Organizers must not upload an entry list containing under-18s without that consent. Tell us at [email protected] if you believe we hold a child’s data and we will remove what we can.
13 Changes
We will update this page when the product changes and move the “last updated” date at the top. For a change that materially affects you we will email account holders at least 30 days before it takes effect. Continuing to use the service after that means you accept the new version.
Questions about this policy
Write to [email protected].