Legal
Privacy Policy
Effective 4 August 2026 · applies to the Pasiv desktop app, the Pasiv Companion mobile app, and pasiv.network
The short version.
- Pasiv works without an account. Mining runs on your machine, and pools pay your address directly.
- Your payout address is never sent to our servers. It goes only to the mining pool you chose.
- We never ask for private keys or seed phrases, and the app has no way to spend from your wallet.
- Analytics are anonymous, minimal, and can be switched off in the app's settings.
- We don't sell data, show ads, or track you across the web.
1. Who we are
Pasiv ("we", "us") makes the Pasiv desktop mining app and operates the website pasiv.network. For anything in this policy, contact support@pasiv.network.
2. What the desktop app processes
Stored on your device only
Your configuration — payout addresses, chosen coin, Auto mode and other toggles — and the local fee ledger are stored on your machine. They are not uploaded to us.
Mining pools (when you press start)
Mining means your machine connects directly to the pool configured for your coin (currently MoneroOcean for Monero and HeroMiners for Zephyr and Salvium). The pool necessarily sees your IP address, payout address, and mining activity (shares, hashrate, worker name). Pools are independent services under their own privacy terms; Pasiv is not in that path and does not receive this data.
Auto / Max-Profit mode (opt-in)
If you enable Auto mode, the app periodically fetches public market data — coin prices from CoinGecko and pool statistics from HeroMiners — to rank coin profitability. These are ordinary web requests: the services see your IP address and an app identifier in the request, nothing about your wallet.
Software updates
The app checks a signed release manifest on our release CDN (hosted on Supabase Storage) to offer updates. The host sees standard request metadata (IP address, user agent). Updates are cryptographically signed and verified on your device before install.
Optional wallet sign-in
You can optionally sign in with a wallet (e.g. MetaMask or Phantom) using a signed message. If you do, your public wallet address is stored with our authentication provider (Supabase) as your account identifier. Signing in never exposes private keys, and Pasiv cannot move funds. Email support@pasiv.network to delete this record.
Pasiv Cloud and the mobile companion (opt-in)
Pasiv Cloud is off unless you turn it on in Settings. With it on, the desktop app sends a status row for each machine to Supabase roughly every 30 seconds, so the Pasiv Companion app on your phone can show it and start or stop it. That row contains:
- The machine's name (and any name you give it in the companion), operating system, and Pasiv version.
- A hardware summary (e.g. CPU model, core count, GPU model) used to show the rig and estimate earnings.
- Which coin is selected, whether Auto mode is on, mining state, hashrate, accepted/rejected shares, and how long the current session has been mining.
- If a miner fails to start, one word for why, chosen from a fixed list:
binary_missing,blocked_by_security,permission_deniedorother. It lets the companion tell you a rig needs attention instead of showing an error with no cause. The underlying message can name files and folders on your machine, so it stays on your device — only the category is sent, and it is one of those four words, never any part of the message itself.
Payout addresses are not included. They stay on your device and at your pool. Earlier builds did send them; they were never read, they have been deleted, and the server now discards the field no matter which version sends it.
The companion can only start a rig, stop it, or ask it to update — and an update installs a release we signed, verified against a key built into the app before anything is written to disk, so it cannot deliver anything else. It cannot change which coin you mine, your pool, or your payout address — the app has no way to express those commands, and commands expire after two minutes. Turning Pasiv Cloud off stops the sync; email support@pasiv.network to delete the stored rows.
Analytics in the mobile companion (anonymous, optional)
The Pasiv Companion app sends a small set of anonymous events to PostHog (US cloud), and a shorter list than the desktop because there is less to do on a phone:
- Events: the app opening, signing in, opening the demo, starting or stopping a rig, and renaming a rig. The rig's name is never sent — only that a rename happened.
- If the app crashes: the error's type (for example
StateError) and the place in Pasiv's own code it happened, as a filename and line number. The error message is never sent, because a message can quote whatever the app was holding at the time — an address, a rig name, a folder on your phone. Nor is the full stack: only the lines that are Pasiv's own code, never the ones from Flutter or other libraries. - Attached to each event: the app version and the platform (iOS or Android). Nothing else.
- No wallet address, no payout address, no rig or team names, no screen contents, no session recording, and no advertising identifier.
- No profile is built about you. The app never identifies you to PostHog, and the SDK is configured so it cannot create a person profile even by accident. Nothing is linked across apps, so there is no tracking in Apple's sense and no tracking permission prompt.
- Turn it off in Settings → Anonymous usage data, reachable whether or not you are signed in. Switched off, the app does not start the analytics SDK at all — it makes no request to PostHog, rather than making one and discarding it.
Analytics in the desktop app (anonymous, optional)
The desktop app sends a small set of anonymous product events to PostHog (US cloud) so we can tell whether features work:
- Events: app opened, mining started/stopped, coin switched, Auto mode toggled, payout address saved (the coin name only — never the address).
- No autocapture, no session recording, no screen contents, and "Do Not Track" is respected.
- Events are anonymous — we do not build identified profiles.
- You can turn analytics off entirely in Settings.
3. What the website processes
pasiv.network is a static site. It uses PostHog for anonymous page-view and click analytics (e.g. which download button was pressed), loads fonts from Google Fonts (Google sees your IP when serving them), and serves downloads from our release CDN. The site sets no advertising cookies.
4. What we never collect
- Private keys or seed phrases — never asked for, never stored, no UI exists for them.
- Payout addresses on our servers — they live on your device and at your chosen pool.
- Files, documents, clipboard, camera, microphone, or anything else on your machine unrelated to mining.
- Browsing history or cross-site tracking of any kind.
5. Service providers
| Provider | Purpose | What they see |
|---|---|---|
| PostHog (US) | Anonymous product & site analytics (desktop app, companion app, website) | Anonymous events, IP for ingestion. No identity, no profiles, no advertising ID. |
| Supabase | Optional wallet sign-in; Pasiv Cloud rig sync; release hosting | Public wallet address (if you sign in); rig status rows if Pasiv Cloud is on (never payout addresses); download request metadata |
| Vercel | Website hosting | Standard web server logs |
| Google Fonts | Web fonts on the site | IP address when fonts load |
| Mining pools | The mining itself (your choice of pool) | IP, payout address, shares/hashrate |
We share data with no one else, and we never sell it.
6. Retention and your rights
Analytics events are anonymous and kept only as aggregate product statistics. The only personal record we can hold is the public wallet address of an optional sign-in — email us and we will delete it. Depending on where you live (e.g. GDPR in the EU/UK, CCPA in California) you may have rights of access, correction, deletion, and objection; we honour requests to support@pasiv.network regardless of jurisdiction. Account deletion has its own page: pasiv.network/account-deletion. Uninstalling the app removes its local data.
7. Children
Pasiv involves cryptocurrency and is not intended for anyone under 18. We do not knowingly process children's data.
8. Changes
If this policy changes materially, we'll update this page and note it in the app's release notes. The effective date above always reflects the current version.