Legal
Privacy.
This describes what the PynqEarn client and the PYNQ service actually do with data. Where something is undecided, it says so rather than covering it with a general clause.
Last updated on the date this site was built. This policy covers the PYNQ website, the PynqEarn desktop client for Windows, and the PYNQ measurement service they talk to.
The short version
- A measurement describes a connection, not a person. Eight numbers, a connection class, a time window and a random identifier.
- Nothing is submitted until you turn contribution on, and the setting records when you did.
- No addresses, adapter names, hostnames, network names, machine or user names, locations, or anything about your traffic ever leave the device.
- An account is optional. Without one, nothing about you is held at all beyond a random identifier you can reset.
- There is no advertising, no analytics, no tracking pixel and nothing is sold.
What the client measures
A measurement run makes a short, bounded set of probes and records the result on your own machine first. The run measures: round-trip latency and its distribution, jitter, packet loss, DNS resolution time, download and upload throughput against the PYNQ endpoint, and whether the connection stayed usable across the run.
The full record stays on your computer, in a database under your own user profile. That local record contains more than is ever sent, including the name of your network adapter and its addresses, because that is useful to you when you are looking at your own results. You can open the folder, delete individual runs, or delete all of them, from Settings.
What is sent, if you turn contribution on
Contribution is off when the client is installed. Turning it on records a timestamp, so there is a record of when consent was given. Each submission contains exactly this and nothing else:
| Field | What it is |
|---|---|
| Schema version | Which submission format this is |
| Device identifier | A random UUID created on your machine. Not derived from hardware. Resettable from Settings |
| Client version | For example pynq-desktop/0.1.0 |
| Start and end time | The measurement window |
| Connection class | wifi, ethernet, other or unknown, and whether Windows reports the connection as metered |
| Scope | loopback, lan or internet: how far the run actually reached |
| The figures | Median and 95th percentile latency, jitter, packet loss, DNS time, download and upload throughput, stability |
| Failures | Which probes did not produce a reading, and whether each failed or was unavailable |
That list is the whole of it. It is built in one file in the client, so it can be checked rather than taken on trust.
What the service necessarily sees
Any server sees the address a request comes from. The PYNQ service does not store it. Before a submission is recorded, the address is hashed with a random value that is generated when the service starts and never written down. The result is a short bucket that lets the service refuse a flood from one source, and that cannot be reversed to an address or matched to the same address after a restart.
The service logs one line per request: the method, the path, the status, how long it took, and that bucket. No address, no payload, no account identifier.
Accounts
An account is optional and nothing else depends on it. The client measures and contributes without one.
Signing in happens in your own browser, through Privy, who handle the authentication. PYNQ never sees a password, a seed phrase or a private key, and the client holds no credentials of its own. What PYNQ stores against an account is: the account identifier Privy issues, when the account was first seen and last seen, which devices you have claimed, and a wallet address if and only if you explicitly link one and Privy confirms it belongs to you.
An email address, if you sign in with one, is read from Privy each time it is displayed and is never written into PYNQ’s own database.
A sign-in shared with another product
PYNQ uses the same sign-in provider, and the same application within it, as another product from the same team. If you already have an account there, signing in to PYNQ uses it rather than creating a new one, and PYNQ sees the same account identifier that product does.
What PYNQ does with that: it records the identifier and nothing else. Your email address and any wallet you have linked stay where they are; they are read from Privy when they are displayed to you and are never copied into PYNQ’s database. The two products keep separate databases, and PYNQ never writes anything back to the other one.
Needs reviewWhether to keep sharing the sign-in, or to separate the two products, is an open decision. If they are separated later, existing PYNQ accounts will be issued new identifiers and contributors will need to sign in again. That should be said here before it happens.
Privy is a separate company and their handling of your data is governed by their own policy. Signing in sends your browser to their service.
Measuring throughput, and Measurement Lab
Throughput, the download and upload speed, is the one measurement that needs somewhere to send real data to. PYNQ can measure it against its own endpoint, or against Measurement Lab, a non-profit platform that exists so that anyone can measure the internet without running their own infrastructure.
Measurement Lab is off by default. If you turn it on, you are told what follows before you choose it, and the choice is recorded with the date.
- Your client connects directly to a Measurement Lab server. They see what any web server sees: your IP address, the bytes transferred, the timing, and connection detail such as round-trip time and retransmissions.
- Measurement Lab publishes every measurement into the public domain, under a Creative Commons Zero waiver. There is no way to exclude a test. That is the arrangement: free infrastructure in exchange for open data.
- Your IP address implies an approximate location, and it is part of what they publish. This is the one place where something that could locate you leaves your machine, and it goes to them rather than to PYNQ.
- PYNQ sends them nothing: no device identifier, no account, nothing that ties the measurement to your PYNQ contributions.
- Their policy allows an automated client four tests a day. PYNQ enforces that in the software, at randomised times, and it is not a setting you or we can raise.
A full test runs for ten seconds at whatever speed your connection sustains, so on a fast line it moves a lot of data. PYNQ caps it, 250 megabytes per direction by default, and a measurement cut short by that cap is reported as "at least" rather than as an exact figure.
Needs reviewThe wording a contributor reads in Settings before choosing Measurement Lab should be reviewed before public release: it is the moment they agree to their measurements being published, and it needs to be unmistakable.
The website
The site sets no cookies and runs no analytics. It stores one value in your browser, for the session only, to remember that you have already seen the opening animation.
The sign-in page is the one page that loads code from somewhere else: the Privy library is fetched from a public package CDN when you open it. Visiting any other page on this site contacts nothing but this site.
How long things are kept
- Your local measurement history: until you delete it, or until you uninstall and remove the application data.
- Submitted measurements: kept, because the point of the dataset is a record over time.
- The request log: as configured by the operator.
- An account: until you ask for it to be removed.
Needs reviewRetention periods for the request log and for submitted measurements need a decision, and a deletion route for an account needs to exist before this can say how to use it.
What is never collected
- The contents of your traffic, the sites you visit, or anything about what you do online. PYNQ measures the pipe, not what goes through it.
- Your IP address, in storage.
- Your location, by any means, including from an address.
- Network names, adapter names, hostnames, your machine name or your user name.
- Anything from other applications on your computer.
Your choices
- Contribution can be turned off at any time, and is off by default.
- The device identifier can be replaced at any time from Settings, which detaches future submissions from earlier ones.
- Local history can be deleted, in part or in full.
- An account can be signed out of, and the stored sign-in is deleted from the machine when you do.
Needs reviewA route for a contributor to request deletion of measurements already submitted needs to exist, and a contact address for privacy requests needs to be published here. Both are required before this policy is complete.
Children
Needs reviewWhether the service is offered to people under 16, and what that requires, is a decision for the operator.
Changes
If what the software does changes, this page changes with it, and the date at the top changes. It is written from the code rather than from a template, so a change here means a change there.