pasiv

Legal

Privacy Policy

Effective 4 August 2026 · applies to the Pasiv desktop app, the Pasiv Companion mobile app, and pasiv.network

The short version.

1. Who we are

Pasiv ("we", "us") makes the Pasiv desktop mining app and operates the website pasiv.network. For anything in this policy, contact support@pasiv.network.

2. What the desktop app processes

Stored on your device only

Your configuration — payout addresses, chosen coin, Auto mode and other toggles — and the local fee ledger are stored on your machine. They are not uploaded to us.

Mining pools (when you press start)

Mining means your machine connects directly to the pool configured for your coin (currently MoneroOcean for Monero and HeroMiners for Zephyr and Salvium). The pool necessarily sees your IP address, payout address, and mining activity (shares, hashrate, worker name). Pools are independent services under their own privacy terms; Pasiv is not in that path and does not receive this data.

Auto / Max-Profit mode (opt-in)

If you enable Auto mode, the app periodically fetches public market data — coin prices from CoinGecko and pool statistics from HeroMiners — to rank coin profitability. These are ordinary web requests: the services see your IP address and an app identifier in the request, nothing about your wallet.

Software updates

The app checks a signed release manifest on our release CDN (hosted on Supabase Storage) to offer updates. The host sees standard request metadata (IP address, user agent). Updates are cryptographically signed and verified on your device before install.

Optional wallet sign-in

You can optionally sign in with a wallet (e.g. MetaMask or Phantom) using a signed message. If you do, your public wallet address is stored with our authentication provider (Supabase) as your account identifier. Signing in never exposes private keys, and Pasiv cannot move funds. Email support@pasiv.network to delete this record.

Pasiv Cloud and the mobile companion (opt-in)

Pasiv Cloud is off unless you turn it on in Settings. With it on, the desktop app sends a status row for each machine to Supabase roughly every 30 seconds, so the Pasiv Companion app on your phone can show it and start or stop it. That row contains:

Payout addresses are not included. They stay on your device and at your pool. Earlier builds did send them; they were never read, they have been deleted, and the server now discards the field no matter which version sends it.

The companion can only start a rig, stop it, or ask it to update — and an update installs a release we signed, verified against a key built into the app before anything is written to disk, so it cannot deliver anything else. It cannot change which coin you mine, your pool, or your payout address — the app has no way to express those commands, and commands expire after two minutes. Turning Pasiv Cloud off stops the sync; email support@pasiv.network to delete the stored rows.

Analytics in the mobile companion (anonymous, optional)

The Pasiv Companion app sends a small set of anonymous events to PostHog (US cloud), and a shorter list than the desktop because there is less to do on a phone:

Analytics in the desktop app (anonymous, optional)

The desktop app sends a small set of anonymous product events to PostHog (US cloud) so we can tell whether features work:

3. What the website processes

pasiv.network is a static site. It uses PostHog for anonymous page-view and click analytics (e.g. which download button was pressed), loads fonts from Google Fonts (Google sees your IP when serving them), and serves downloads from our release CDN. The site sets no advertising cookies.

4. What we never collect

5. Service providers

ProviderPurposeWhat they see
PostHog (US)Anonymous product & site analytics (desktop app, companion app, website)Anonymous events, IP for ingestion. No identity, no profiles, no advertising ID.
SupabaseOptional wallet sign-in; Pasiv Cloud rig sync; release hostingPublic wallet address (if you sign in); rig status rows if Pasiv Cloud is on (never payout addresses); download request metadata
VercelWebsite hostingStandard web server logs
Google FontsWeb fonts on the siteIP address when fonts load
Mining poolsThe mining itself (your choice of pool)IP, payout address, shares/hashrate

We share data with no one else, and we never sell it.

6. Retention and your rights

Analytics events are anonymous and kept only as aggregate product statistics. The only personal record we can hold is the public wallet address of an optional sign-in — email us and we will delete it. Depending on where you live (e.g. GDPR in the EU/UK, CCPA in California) you may have rights of access, correction, deletion, and objection; we honour requests to support@pasiv.network regardless of jurisdiction. Account deletion has its own page: pasiv.network/account-deletion. Uninstalling the app removes its local data.

7. Children

Pasiv involves cryptocurrency and is not intended for anyone under 18. We do not knowingly process children's data.

8. Changes

If this policy changes materially, we'll update this page and note it in the app's release notes. The effective date above always reflects the current version.