Privacy Policy
Last updated: 4 August 2026
The short version. We never store raw IP addresses — they are one-way hashed the moment they arrive and the original is thrown away. We don't sell your data. We keep the minimum needed to pay you correctly and to stop fraud.
1. What we collect
From link owners (you)
- Telegram ID, and your username and first name if your Telegram privacy settings expose them. This is how we identify your account.
- Your links — destination URLs, aliases, and any private notes you add.
- Earnings data — balance, lifetime earnings, tier, referral relationships.
- Your TRC20 wallet address, so we can pay you.
- Security events — sign-ins, wallet changes, withdrawal requests, with timestamps.
- A display name, only if you opt in to the public leaderboard.
From visitors to your links
- A one-way hash of the IP address. We compute a salted HMAC and store only that. The raw address is never written to our database. We use it to count a unique visit and to enforce the cooldown — nothing else.
- Country code, at country level only.
- Browser user-agent, used for abuse detection.
- Time of visit and which link was opened.
What we never collect
- Raw IP addresses.
- Your Telegram messages, contacts, or phone number.
- Payment card details — there are none; we pay in crypto only.
- Precise location.
2. Why we hold it
- To run the service — creating links, counting visits, crediting your balance.
- To pay you — a wallet address is required for a payout.
- To prevent fraud — hashed IPs and user-agents let us detect bot traffic that would otherwise get every honest user removed by advertisers.
- To keep visitors safe — destinations are checked against threat feeds.
- To meet legal obligations where they apply.
3. Who we share it with
We do not sell your data. We do not run third-party analytics or advertising trackers on this website. Data is processed by these providers purely as infrastructure:
- Cloudflare — serving, DDoS protection, bot filtering.
- Supabase — the database.
- Telegram — message delivery. Your use of Telegram is governed by Telegram's own privacy policy.
- Threat-intelligence feeds (URLhaus, ThreatFox, OpenPhish and similar) — we check destination URLs against them.
- Advertising partners, where ads are enabled on the gateway. These partners may set their own cookies on the gateway page and are governed by their own policies.
We may disclose data where legally compelled to do so.
4. Cookies
This marketing website sets no cookies and contains no trackers. Elsewhere on the Platform we use only what is functionally required: a session cookie for the dashboard, an unlock cookie for password-protected links, and — if you choose it — a "trusted device" cookie. Advertising partners on the gateway may set their own.
5. How long we keep things
- Account and earnings records — while your account exists, plus any period required for financial record-keeping.
- Hashed visit data — retained for fraud analysis, then aged out.
- Security and money audit logs — kept deliberately, because being able to reconstruct a disputed payout protects you as much as us.
- Deleted links — removed, though the short code may stay reserved so it cannot be taken over by someone else.
6. Your rights
Depending on where you live, you may have the right to access, correct, export, or erase your data, to object to processing, or to complain to your data protection authority. To exercise any of these, contact us through the bot.
We will always honour a deletion request except where we are legally required to retain a record — for example a completed payout.
7. Security
We take this seriously and design for it:
- IP addresses are one-way hashed with a secret salt, never stored raw.
- Administrative access requires a password plus mandatory two-factor authentication.
- Sessions can be bound to your device and revoked at any time.
- All money-moving operations are logged to an append-only audit trail.
- Database access is locked down so that public keys cannot reach sensitive functions.
No system is perfectly secure. We will notify affected users promptly if a breach materially affects them.
8. Children
The Platform is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has an account, contact us and we will remove it.
9. International transfers
Our infrastructure providers operate globally, so your data may be processed outside your country. We rely on these providers' standard contractual safeguards.
10. Changes
If we change this policy materially we will announce it through the bot. The date at the top always reflects the current version.
11. Contact
Reach us through @FortressCryptBot.