Legal

Privacy Policy

The short version: our tag sets no cookie and reads no storage on your visitors. We keep a hashed IP and a hashed user agent to stop fraud and to count, and a country derived from the IP. This website itself uses analytics cookies, and only if you accept the banner. We do not build profiles across sites and we do not sell anything.

Working draft. A licensed attorney will review these terms before publisher payouts begin.

Last updated 26 September 2026.

1. Three very different sets of people

This policy covers three groups whose data we treat completely differently. Publishers are people with a PraxNet account, and we hold real account data about them because we have to pay them. Visitors to a publisher's site are people who happen to load a page containing our tag, and we deliberately hold almost nothing about them. Visitors to this website are people reading praxnet.ai, and what we count about them depends entirely on how they answer the banner at the bottom of the page.

The second and the third are not the same thing and are not governed by the same system, which is why they have a section each rather than one paragraph that blurs them together.

2. What we collect from publishers

  • Account. Email address, name, country, and a password hash if you did not sign in with Google. We never see your Google password.
  • Sites. The domain, category, language, the regions your audience is in, your traffic range, where your traffic comes from, your social links, and the analytics screenshot you upload. The screenshot is stored privately and is visible only to the person reviewing your application.
  • Payout. Your chain and wallet address. We never ask for and never hold a private key, a seed phrase or an exchange login. Nobody at PraxNet can move your funds; we can only send to the address you confirmed.
  • Support. Anything you write to us, and our replies.

3. What the ad tag collects from your visitors

This is the part that matters most, so it is written out in full.

The tag sets no cookie, reads no cookie, and touches no localStorage, sessionStorage or IndexedDB. There is no identifier stored on a visitor's device by us, ever, and therefore nothing to sync, sell or leak.

When an ad is requested, our server sees, as any web server does:

  • The IP address, which we immediately hash with a secret salt. We store the hash and not the address. The hash lets us tell that two requests came from the same place without letting us tell where that place is.
  • The user agent string, hashed the same way and for the same reason.
  • A country, derived from the IP before it is hashed. Country only. Not a city, not a postcode, not coordinates.
  • The page the ad is on, from the Referer header, used to confirm the placement is running on a domain the publisher verified.
  • Whether the ad was rendered and whether it was at least half on screen, which is what an advertiser is paying for.

We use those to count impressions and clicks, to decide which ad to show for the country, to enforce a frequency cap so one person is not shown the same ad all day, and to detect automated traffic. That is the complete list of purposes.

4. What we do not do

  • We do not build a profile of a person across sites. There is no identifier to build one with.
  • We do not fingerprint devices.
  • We do not sell, rent or share personal data with data brokers.
  • We do not pass anything about a visitor to an advertiser. An advertiser sees aggregate counts.
  • We do not run third-party trackers inside the tag. It talks to our own server and nowhere else.
  • We do not load advertiser JavaScript. Creatives are images.

5. Visitors to this website (praxnet.ai)

Everything above is about the ad tag, which runs on other people's sites. This section is about this website, the one you are reading. They are two separate systems and they behave differently, so they are written up separately rather than folded into one comfortable paragraph.

We use Google Tag Manager and Google Analytics 4 to count visits and see which pages people actually read. Whether we ask you before loading them depends on where you are, because the law does.

Where the law requires asking first, we ask before anything loads. That is the European Economic Area, the United Kingdom, Switzerland, Turkey, Brazil, Quebec, China, Saudi Arabia, Nigeria and Vietnam. A banner appears on your first visit and nothing is loaded until you answer it. Choosing Essential only means nothing loads: not a reduced version, not a cookieless mode, the container is never inserted into the page at all.

Everywhere else analytics is on when you arrive. That includes the United States, the rest of Canada, Australia, Japan, South Korea, India and most of the rest of the world, where the rule is that we tell you and let you opt out rather than that we ask first. This section is the telling. Below is the opting out.

Your choice is kept in a cookie in this browser. The switch here needs JavaScript. Without it, clearing the cookies for praxnet.ai resets the choice.

Turning them off writes your choice and expires the Google cookies this browser is already carrying, on every domain we can reach. That last part is best effort: a cookie can only be removed by a browser that agrees the name, the path and the domain all match, and we do not control what Google wrote. Clearing the cookies for praxnet.ai yourself is the version that always works.

These are the cookies involved:

  • _ga is Google's. It holds a random identifier so that two page loads can be counted as one visit rather than two. Two years.
  • _ga_* is Google's. One cookie per analytics property, holding the state of the current session. Two years.
  • praxnet_consent is ours. It holds one word, granted or denied, which is the choice you made on the banner or with the switch above. 180 days. Nothing on our servers ever writes it.
  • praxnet_consent_required is ours. It holds 1 or 0, meaning whether the law where your request arrived from requires us to ask before loading analytics. It is set from the country our host tells us the request came from, it holds no identifier and nothing about you, and it is what makes the rest of this section work, so it is strictly necessary and it is set whichever way you answer. 180 days.

We do not run an advertising pixel on this site today. There is no _fbp and no _fbc cookie here, because nothing on this site sets one. If we later run ad campaigns and an ad platform sets them, this section is where it will be written down.

Attribution at signup. When somebody creates a publisher account we read whatever ad-attribution identifiers their browser is carrying, such as the Google Analytics client id, and store them on that account. It is how we can tell, months later, which advertising campaign found a publisher who turned out to be a good one, which is the only honest way to decide where to spend a marketing budget. It is tied to the account, it is not sold, it does not go to a data broker, and it is never joined to anything about your readers. To measure which of our own ads work, when you create an account, submit a site or have one approved we send the advertising platforms we buy ads from (Meta, for example) your account id, a hashed copy of your email address, any Meta browser and ad click identifiers stored with your account, and, when it happens in your browser, the IP address and browser details it sent us.

None of this reaches your visitors. Our tag still sets no cookie and reads no storage on your site, and nothing in this section changes that.

6. How long we keep things

  • Hashed IPs and user agents: up to 40 days at the edge, which covers the conversion window plus a margin, then deleted.
  • Aggregate counts with no visitor data in them: kept, because they are what your earnings are calculated from and you are entitled to check them.
  • Fraud investigation records: up to 30 days beyond the hold they relate to.
  • Publisher account and payment records: for as long as the account is open, and afterwards for as long as tax and accounting law requires.

7. Who processes data for us

Supabase (database and authentication), Vercel (hosting), Cloudflare (the ad server and its edge network), Resend (email), and Google (Tag Manager and Analytics on praxnet.ai, with your consent, and nowhere else). Each is used for the purpose named and none of them receives publisher payout details other than as part of our own database.

8. Your rights

Under GDPR, UK GDPR and CCPA you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask us not to sell it, which is simple in our case because we do not. Write to support@praxnet.ai and we will answer within 30 days.

Note what we cannot do: because visitor IPs are hashed with a salt we do not reverse, we cannot find a specific visitor's records to delete them. That is a deliberate design choice, and the trade is that there is far less to delete in the first place.

9. What we accept onto the network

A short summary of the policy, because it is a privacy question as much as an editorial one. Advertisers on this marketplace are crypto category businesses and every creative is a human-reviewed image. Publishers are crypto and web3 focused sites read by a person before approval. We refuse illegal content, malware and cryptojacking, hate speech, adult content, piracy, and traffic that was bought, automated or exchanged. The full list is in our Terms of Service.

10. Children

The service is not for anyone under 18 and we do not knowingly collect data from children.

11. Changes

If we change what we collect or why, we will email publishers before it takes effect rather than updating this page quietly.

12. Contact

support@praxnet.ai