Skip to content
Security

What we actually do to protect your account and your Dcoin

No vague promises — this page lists the concrete measures this platform has in place today.

Card details never reach us

Checkout runs on Stripe's own hosted page. Your card number, expiry, and CVC are entered directly into Stripe — this website never sees or stores them.

Passwords are hashed, not stored

If you sign in with a password, we store an argon2id hash of it, never the password itself. There is no way to reverse a hash back into your password, including for us.

Per-device sessions you control

Every sign-in creates a session tied to that device. You can see every active session from Account and sign any of them out remotely at any time.

Email verification by one-time code

New accounts and email changes are confirmed with a one-time code sent to your inbox, not a clickable link that could be forwarded or leaked.

Only a webhook can credit your wallet

A redirect back from checkout in your browser never changes a payment's status by itself. We credit Dcoin only after the payment provider sends a signed, server-to-server confirmation.

An append-only ledger

Wallet history is write-once: entries are never edited or deleted after the fact. Mistakes are corrected with a new, clearly labeled adjustment entry, so the full history always stays visible.

Deletion means anonymization

Deleting your account removes your personal data — email, name, photo, linked social accounts. Financial records (your wallet and ledger) are kept, but no longer linked to you personally.

Questions about how something works?

When you report something, include your request ID if you have one — it helps us find the exact event without you needing to describe it in detail.

Create free account