Privacy and data
work2own has no accounts, emails or passwords. You are your wallet address. This page lists what is stored, where, and who can see it.
Public
On Robinhood Chain (public to everyone, forever): every transaction you send, and everything the escrow records: quests you create or join, your claim status and chosen payout token, gigs you fund or work on, payouts and refunds, and the fingerprints (hashes) of proofs, deliveries and rejection reasons.
In the app (public, no sign-in needed):
- Your profile: name, headline, bio, skills, links, photo, and the track record counted from the escrow.
- Your blue check and the verified project it comes from.
- Quest descriptions and steps, and the list of workers on each quest with their status, payout token and reservation time.
- Gig posts (title, brief, links, budget, delivery time, number of applicants), including after someone was hired, when the post also shows the hired worker's address.
- Projects.
- An overview of any address's activity: quests, claims, gigs (without private texts), payouts and pending refunds.
Private
| Data | Who can read it |
|---|---|
| Quest proofs (your answers, notes, links) | You, the quest's employer, and work2own's operator and arbiter. Stored unencrypted on the work2own server |
| The delivery and the rejection reason of a gig | The employer, the worker and the arbiter |
| The brief attached to a funded gig | The employer, the worker and the arbiter. It is a copy of the gig post, which stays public |
| Gig applications and notes | The applicant and the employer |
| The payout country you declared | Only you, after sign-in |
Private data is stored in the work2own database and shown only after you sign in with the right wallet.
What work2own stores
- Copies of on-chain events, to show pages quickly.
- The texts behind on-chain fingerprints: proofs, deliveries and rejection reasons.
- Quest descriptions and steps, gig posts and applications, profiles, photos (at most 40 KB each) and projects.
- Your declared payout country, together with the country of your connection at the moment you declared it.
- Sign-in sessions: only a SHA-256 hash of the session token is stored, never the token itself. Sessions end after 7 days or when you disconnect.
- Results of the operator's on-chain checks.
IP addresses: the work2own API uses them only in memory, to limit how many requests one address can make per minute, and does not store them in its database. The database stores the country of your connection (from Cloudflare) when you declare your payout country. Web server and Cloudflare logs may contain IP addresses.
Deletion: you can remove your photo at any time. There is currently no self-service way to delete a profile, proof, gig post, application or project. On-chain data can never be deleted by anyone.
Third parties
- Cloudflare serves the site and provides the country of your connection.
- Logo.dev serves the stock token and project logos. Your browser loads them directly from
img.logo.dev. - Robinhood Chain RPC answers the app's chain reads.
- Your wallet signs messages and transactions. work2own never receives your private keys.
Your browser
The app keeps your sign-in session for each wallet, and the wallet connection itself, in your browser's local storage. If local storage is unavailable, the session lasts until the page is closed. The app's code contains no analytics or advertising trackers.