We collect your email, handle, submitted content, and basic device info for security. We don't collect payment card details (Stripe handles that) or identity data beyond a KYC-verified boolean for Anonymous Expert Solvers. We don't sell your personal data — ever. We may create and license de-identified data derived from platform activity (Derived Data) — see §4. GDPR, CCPA, and Thai PDPA rights apply where relevant. Contact privacy@reallysolved.com for any data request.
1. What We Collect #
When you create an account and use ReallySolved, we collect:
- Account information: email address, username/handle, and password hash
- Submitted content: Truths you submit, verification votes, and comments
- SIQ activity: your reputation score history and tier progression
- Device & security data: IP address, browser type, and session tokens — used only for security, fraud prevention, and abuse detection
- Analytics: page views and feature usage, aggregated and anonymized. We use privacy-respecting analytics with no third-party ad tracking
2. What We Don't Collect #
We do not sell personal data. We never have and we never will.
We also do not collect:
- Identity documents or biometric data: KYC verification for the Anonymous Solver tier is handled entirely by our third-party KYC provider (Persona or Onfido). We receive only a verified-tier boolean — a pass/fail signal. The underlying identity data never reaches Really Solved LLC's servers.
- Payment card information: All payments are processed by Stripe. We receive only transaction confirmation and payout metadata. We never see or store card numbers, bank account details, or CVV codes.
3. How We Use It #
We use the data we collect to:
- Operate and improve the ReallySolved platform
- Authenticate your account and maintain session security
- Detect and prevent abuse, spam, and coordinated inauthentic behavior
- Calculate and display SIQ scores and Solver tier standings
- Send transactional emails (account verification, password reset, bounty notifications)
- Comply with legal obligations
We do not use your personal data for advertising, behavioral profiling, or sale to third parties.
4. Derived Data — De-Identified & Aggregated #
What Derived Data is. In addition to the uses listed in §3, we use content collected through the platform to create de-identified datasets ("Derived Data"). Derived Data may take the form of aggregated or structured derivatives — such as statistical trends, semantic embeddings, feature vectors, points of model disagreement, benchmark datasets, and aggregated accuracy metrics — or de-identified textual records (such as model-disagreement and resolution outcomes) to which our de-identification measures have been applied, compiled from platform activity including user-submitted Truths, multi-model comparisons, and expert-authored resolutions. Derived Data is not sold or licensed in personally identifiable form.
How we use and commercialize Derived Data. We may use Derived Data for internal analytics, platform research, product improvement, and benchmarking. We may also license Derived Data to third parties — including AI research organizations, academic institutions, and commercial AI developers — for purposes including AI model training, evaluation, and analytics. This is distinct from selling personal data: we license only de-identified data from which an individual cannot reasonably be identified. See also Terms of Service §6 (Data Ownership & Derived Data) for the full contractual basis.
De-identification standard. Before any Derived Data is commercialized or licensed, we apply our de-identification pipeline, which includes: (a) named-entity recognition and scrubbing via our Presidio-based pipeline, applied to both submitter identifiers and third-party names referenced in content; (b) k-anonymity controls to reduce the risk of re-identification through quasi-identifying combinations; and (c) generalization and bucketing of remaining quasi-identifying fields. For users in the EEA or UK, this process is designed to render the data anonymous within the meaning of GDPR Recital 26, such that the resulting Derived Data is intended to fall outside the scope of personal-data processing.
Downstream licensees. Any organization that receives Derived Data from us is contractually prohibited from attempting to re-identify individuals from it, from combining it with other datasets in a manner that could enable re-identification, and from using it for any purpose other than those specified in the license agreement.
Legal basis (GDPR Art. 6(1)(f) — Legitimate Interests). We process submitted content to create Derived Data on the basis of our legitimate interests in operating, improving, and commercially sustaining the platform — and the broader public interest in advancing AI model accuracy and accountability research. We have assessed that this processing does not override users' fundamental rights, given that (a) the commercial output is intended to be anonymized data that is no longer personal data, (b) our de-identification pipeline is designed to strip both submitter and third-party identifiers before any commercialization, and (c) users may object to this processing at any time by contacting privacy@reallysolved.com (we will honor objections for future processing; Derived Data already in circulation in anonymized form cannot be recalled).
What this is not. This section describes the use of de-identified data. It is entirely separate from the "We do not sell personal data" commitment in §2, which remains fully in effect. We do not sell, rent, or trade your personal information. The Derived Data pipeline is designed so that the output is no longer personal data before it leaves our systems for any commercial purpose.
5. Sharing #
We share data only with the following categories of third parties, and only to the extent necessary:
- KYC processor (Persona/Onfido): receives identity data from Anonymous Expert Solver applicants. We receive only a verification result.
- Payment processor (Stripe/Deel): handles all payment and payout transactions. Receives necessary payout information for bounty disbursement.
- Hosting provider (Netlify): hosts the platform. Processes data as a data processor on our behalf.
- Legal compliance: we may disclose data in response to a valid court order, subpoena, or legal process. We will notify you to the extent permitted by law.
Derived Data licensees: We may license de-identified Derived Data (see §4) to AI research organizations, academic institutions, and commercial AI developers. These licensees receive only de-identified data — not personal data — and are contractually prohibited from re-identifying individuals.
We do not share personal data with advertisers, data brokers, or marketing platforms.
6. Cookies #
At launch, we use only essential cookies: session authentication, CSRF protection, and security tokens. We do not use third-party tracking cookies or advertising cookies.
We do not use cookies for behavioral profiling, retargeting, or any form of cross-site tracking.
You can block cookies through your browser settings. Blocking session cookies will prevent you from logging in.
7. GDPR — EU & EEA Users #
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation:
- Access: request a copy of the personal data we hold about you
- Rectification: request correction of inaccurate data
- Erasure: request deletion of your personal data ("right to be forgotten")
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Restriction: request that we limit how we use your data
- Complaint: lodge a complaint with your national supervisory authority
To exercise these rights, contact privacy@reallysolved.com. We will respond within 30 days.
8. CCPA — California Residents #
If you are a California resident, the California Consumer Privacy Act gives you equivalent rights to know, delete, correct, and opt out of sale of your personal information. We do not sell personal information. Derived Data (see §4) is de-identified data that does not meet the CCPA definition of "personal information" under Cal. Civ. Code §1798.140 — we apply the four-part de-identification standard (technical and administrative controls, public commitment, downstream licensee prohibition on re-identification, and no reasonably available re-identification method) before any commercialization.
To submit a CCPA request, contact privacy@reallysolved.com. We do not discriminate against users who exercise their CCPA rights.
9. Thai PDPA — Thailand Residents #
If you are located in Thailand, the Personal Data Protection Act B.E. 2562 (PDPA) grants you rights substantially equivalent to those described in Section 6 above: access, rectification, erasure, portability, and objection.
To exercise your PDPA rights, contact privacy@reallysolved.com. We will respond within 30 days.
10. Data Retention #
We retain account data while your account is active and for 30 days after account deletion, after which it is permanently removed.
Submitted Truths and verification votes may persist as part of the platform's public record after account deletion, to preserve the integrity of the verification history. On request, we will redact your handle from historical submissions, but the anonymized verification record may be retained.
Security logs (IP addresses, session data) are retained for 90 days and then deleted.
11. Children #
ReallySolved is for users 18 and over. We do not knowingly collect personal data from anyone under 18. If we become aware that a user is under 18, we will terminate their account and delete their data promptly. If you believe a minor has created an account, contact privacy@reallysolved.com.
12. International Transfers #
ReallySolved's infrastructure is hosted on Netlify, which primarily processes data in the United States. If you access the platform from the EU, EEA, or other regions with data transfer restrictions, your data may be transferred to the US.
We rely on Standard Contractual Clauses (SCCs) for EU-to-US data transfers where applicable. Our data processors are required to maintain appropriate safeguards.
13. Contact — Data Privacy #
For all privacy-related requests, questions, or complaints, contact our data privacy team at privacy@reallysolved.com.
Really Solved LLC · Wyoming, USA