Draft pending legal review. We publish it now so you know how things work today; wording may change before it is final.
Privacy policy. What we keep, and why.
We collect as little as we can: a wallet address, the data you submit, your consent, and a hashed IP for abuse prevention. Some records live on public blockchains and are permanent. Everything else you can ask us to delete.
Last updated
Who we are
OptiLearn (optilearn.ai) is a data marketplace for AI and robotics. People contribute recordings and data against open bounties, a person reviews each one, and approved contributions are licensed to AI labs. In this policy, “we” means the team that operates OptiLearn. You can reach us at hello@optilearn.ai.
What we collect
We keep the minimum needed to review your work, pay you and prove where the data came from.
- Wallet address. The address you connect or paste. It is where rewards are sent and how your submissions are grouped.
- Submitted media and details. The file you upload or record, its name, size, type and duration, the bounty it was made for, your chosen payout stock, any title or notes you add, and a SHA-256 fingerprint of the file.
- Consent records. Which consent statements you confirmed for each submission, and when.
- Review records. The reviewer's score, reward, notes and decision, and payout details once paid.
- A hash of your IP address. We store a salted, one-way hash of your IP, never the IP itself, to rate-limit uploads and stop abuse.
- Email, only if you choose it. If you sign in with email, our sign-in provider Privy verifies it and creates a wallet for you. We receive the email address and the wallet address.
- Inquiries. If you ask about licensing a dataset, the name, work email, organisation, role, use case and budget you send us.
We do not ask for your name, phone number, ID documents or date of birth to contribute. We never see or hold the private keys to your wallet, including a wallet created for you by Privy.
How we use it
- To review submissions against the capture standard and the bounty brief.
- To calculate and send rewards, and to show you their status in Portfolio.
- To write provenance attestations for approved contributions.
- To build, annotate and deliver licensed datasets.
- To detect duplicates, fraud and abuse, and to rate-limit requests.
- To answer your messages and licensing inquiries.
- To meet legal obligations, such as tax, sanctions and record keeping rules.
How submitted data is used and licensed
Approved submissions become training data. We license them to AI and robotics teams under research, commercial or exclusive terms, as described in the terms and the docs. Before delivery we remove audio from video and strip location and device metadata from files.
Buyers receive the file, its annotations, the consent record and the attestation reference. Contributors appear in buyer manifests as a salted hash of their wallet and a two-letter country, never a name, email or IP. Rejected submissions are not used for training and are deleted within 30 days of the decision.
Public and permanent onchain data
Two things we do are public by design, and cannot be undone by us or anyone else:
- Payouts on Robinhood Chain. Each reward is a token transfer from our wallet to yours, visible on the public explorer with both addresses and the amount.
- Attestations on OP Mainnet. Each approved contribution gets an attestation through the Ethereum Attestation Service. It contains your wallet address, the submission ID, modality, bounty, the file's SHA-256 fingerprint, the review score and the payout stock. Anyone can read it on easscan.
Attestations never include the file itself, your email, IP hash, reviewer notes or the dollar value of the reward. If your wallet address is linked to you elsewhere, that link can make these records personal to you.
How long we keep it
- Approved submissions and consent records: for as long as the data is part of a dataset we license, and afterwards for as long as needed to handle legal claims about it.
- Rejected submissions: deleted within 30 days of the review decision. We keep the fingerprint to detect resubmission of the same file.
- IP hashes: used for rolling rate-limit windows and kept no longer than 90 days.
- Licensing inquiries: up to 24 months after our last contact, unless they turn into a contract.
- Onchain records: permanent, as described in section 5.
Your rights
Depending on where you live, you can ask to access, correct, export or delete your data, and to object to or restrict how we use it. You do not need to give a reason. Email hello@optilearn.ai from any address and include your wallet address. To confirm the wallet is yours we may ask you to sign a short message with it; this never costs gas and never moves funds.
We reply within 30 days. If you are unhappy with our answer you can complain to your local data protection authority.
Deleting a submission
Send the submission ID from Portfolio and your wallet address to hello@optilearn.ai. Within 30 days we delete the file from our storage and remove it from every future dataset delivery, and we tell the buyers who received it. Our licenses require buyers to stop using removed items in new training runs.
We cannot pull back copies already delivered and used, recall a reward that was paid, or erase an onchain attestation. An attestation holds only a fingerprint of the file, so once the file is deleted the fingerprint can no longer be matched to any content we hold.
Age
OptiLearn is for people aged 18 and over. We do not knowingly accept submissions from anyone younger, or submissions that show children. If you think we have, email us and we will delete it.
International transfers
Our service providers and buyers may be in countries other than yours, including the United States. Where the law requires it, we use contractual safeguards such as standard contractual clauses for those transfers.
Security
Files are stored privately and served only through short-lived signed links. Operator tools are protected by a secret that is never sent to your browser. IP addresses are hashed with a secret salt before storage, and API responses never include storage keys or IP hashes, for example in GET /api/submissions. No system is perfectly secure; if a breach affects you, we will tell you and the relevant authority as the law requires.
Changes to this policy
We will post any change here and update the date at the top. If a change affects how we use data you already gave us, we will say so on the site before it takes effect.
Contact
Email hello@optilearn.ai for anything about privacy, or see the contact page for other channels.
