superchainSuperSecure™ ↗
privacy notice

What the ledger knows, and how to be erased.

superc.com is a public ledger, so the honest question is not whether it holds personal data but which values are personal, which of them are erasable, and who else touches them. This notice answers those three questions.

operator · [set LEGAL_ENTITY_NAME] · revised 2026-09-21

01
controller
[set LEGAL_ENTITY_NAME], [set LEGAL_ENTITY_ADDRESS]. Privacy requests: [set LEGAL_PRIVACY_EMAIL].
02
what is stored
On the hash chain (inputs to a transaction hash — cannot be changed without breaking every later block): the event type, a timestamp, an optional document fingerprint (sha-256), and one or two addresses. An address is HMAC-SHA256 of the owner's registry contact under a secret only the operator holds. It is a keyed pseudonym: the same owner always maps to the same address, the contact cannot be recovered without the secret, and with the secret the operator can. It is therefore pseudonymised personal data, not anonymous data.
Off the hash chain (not hash inputs — erasable): the public label (an @name, a .extension, or an agreement reference), an opaque event reference, and — if a person opts in — an identity row (display name, username, avatar, company). Identity rows default to hidden.
Never stored: file contents, filenames of private files, agreement text, email addresses in the clear.
03
where it comes from
Records are synced from the SuperFile registry (superfile.com) and, for executed agreements, from SuperFile's deal room. Executed-agreement records are hash-only by default: fingerprint and time, no parties, no reference — unless the operator turns on party publication. Nothing is collected from you by this site itself beyond ordinary server logs.
04
lawful basis
Registry records are processed on the basis of the legitimate interest in a tamper-evident public register of names and extensions that registrants and third parties can verify, balanced by pseudonymising the owner and masking labels in listings. Opt-in identity rows are processed on consent, withdrawable at any time. Server logs are kept for security (legitimate interest).
05
erasure — what happens
Send a request to [set LEGAL_PRIVACY_EMAIL] naming the record (its transaction hash, address, or the @name). After verifying you are the person concerned, the operator appends a record.redact tombstone transaction and clears the record's off-chain values: label, event reference and identity row. The tombstone is public and points at the redacted record; it carries no copy or hash of the erased value.
What cannot be erased: the transaction hash, the address (the pseudonym), the timestamp and any document fingerprint — they are inputs to hashes that later blocks, signed checkpoints and the Bitcoin anchor already commit to. Erasing them would falsify the record for everyone else, which is the interest the ledger exists to protect. Because the address is only meaningful with the operator's secret, redaction leaves a pseudonym no third party can resolve.
Handled within one month. You can also ask for access, rectification of an identity row, or restriction, and you may complain to your supervisory authority.
06
retention
Ledger records: indefinite by design (see 05 for what redaction removes). Identity rows: until you withdraw them or request erasure. Server and access logs: kept by the hosting subprocessor for its standard period, then discarded. Redaction reasons are stored as a short category only.
07
subprocessors
Supabase — Postgres database hosting the ledger.
Vercel — web hosting, edge network, scheduled jobs, access logs.
OpenTimestamps calendar servers — public calendars receive a sha-256 of each signed checkpoint (never a record, never a value) to anchor it in Bitcoin.
GitHub — hosts the independent witness that re-verifies published checkpoints and stores its own observation log; it sees only what this site already publishes.
SuperFile (superfile.com) — the registry the records are synced from; a sister service of the operator.
08
cookies · analytics
The site sets no cookies of its own and runs no analytics or advertising scripts. There is nothing to consent to.
09
security
Base tables are locked; the public reads only granted read-only functions; writes go through one authenticated path; append-only triggers refuse updates and deletes at the database. Report a vulnerability via /.well-known/security.txt.
10
open-source notice
Bitcoin anchoring uses the opentimestamps JavaScript library, licensed under the GNU LGPL-3.0. It is loaded as a separate module at run time (dynamic import) and is not modified; its source and licence are at github.com/opentimestamps/javascript-opentimestamps.