How can we help?
Common questions, plus our terms, privacy, AML, and RG policies in one place.
Privacy Policy
topbit Protocol Interface
Effective Date: This policy takes effect on the day the casino opens for real-money play.
Last Updated: 19 June 2026
About this draft. topbit is an early-stage, decentralised protocol. This policy describes what information the Interface handles and the choices you have. It is published in good faith, will be reviewed by qualified counsel, and is not legal advice.
1. Overview
This Privacy Policy explains how the topbit Interface (topbit.io) collects, uses, and handles information when you use the service.
topbit is a decentralised protocol and collects minimal personal data by design. Your on-chain identity is your wallet address, a pseudonymous identifier. We do not collect your name, email address, or government ID as part of normal operation.
2. Information We Collect
2.1 Blockchain Data (Public and Immutable)
Every bet, settlement, and fund movement is a transaction recorded on Solana. This data is:
- •Public: visible to anyone through a Solana block explorer such as Solscan
- •Permanent: it cannot be deleted, changed, or erased; this is a fundamental property of the blockchain
- •Pseudonymous: linked to your wallet address, not your real-world identity
It includes your wallet address, bet amounts, game outcomes, win and loss amounts, timestamps, and vault interactions.
2.2 Technical Data (Collected by the Interface)
When you visit topbit.io, our servers and infrastructure automatically collect:
- •IP address
- •browser type and version
- •device type and operating system
- •pages visited and time spent
- •referring URL
- •access timestamps
We use this for security, anti-fraud, and running the service.
2.3 Session Data
When you authenticate with your wallet, we create a session record containing:
- •wallet address (pseudonymous)
- •session creation time and expiry
- •IP address at session creation
- •user-agent string
2.3a Consent Records
When you connect your wallet, you affirmatively accept the Terms of Service and AML Policy. We record that acceptance as proof of agreement, containing:
- •wallet address (pseudonymous)
- •the document type, version, and a SHA-256 hash of the exact text you accepted
- •a timestamp and the approximate country at the time of acceptance
This record shows what you agreed to and when. Its legal basis is legal obligation and contract performance.
2.4 Risk and Compliance Data
Our automated risk monitoring records:
- •betting behaviour and activity patterns
- •network and connection metadata, including signals associated with VPNs, hosting services, and automated tooling
- •an internal risk score held per wallet
We use this to detect and prevent fraud, money laundering, and prohibited activity, and to meet our AML obligations.
2.5 Cookies and Local Storage
The Interface uses:
- •Local storage: to remember your interface preferences (such as theme), your acceptance of the Terms, and your acknowledgment of the jurisdiction notice
- •Session tokens: held in memory only, not as persistent cookies
We do not use third-party advertising cookies or cross-site tracking.
3. How We Use Your Information
We use the information we hold to:
- •provide the gambling service (wallet address, session data), on the basis of contract performance
- •detect fraud and bots (IP address, betting patterns, risk score), on the basis of our legitimate interest
- •meet our AML obligations (wallet address, IP address, transaction data), on the basis of legal obligation
- •secure and operate the Interface (IP address, user-agent, access logs), on the basis of our legitimate interest
- •resolve disputes (any of the above), on the basis of our legitimate interest
We do not use your data for advertising or profiling, and we do not sell it.
4. Sharing of Information
We share data only in these cases:
- 1.Infrastructure providers: our content delivery and security provider processes IP addresses and request metadata to deliver and protect the Interface.
- 2.Solana network: all on-chain transactions are broadcast to the public Solana network and recorded permanently.
- 3.Legal authorities: we disclose information when legally compelled by a court order, subpoena, or equivalent process from a competent authority. We will notify you where we are legally permitted to.
- 4.Blockchain analytics (Planned): we intend to use third-party blockchain-analytics tools for AML compliance once that integration is live (see our AML Policy Section 5).
We do not sell personal data, and we do not share data with advertisers.
5. Data Retention
We retain data as follows:
- •On-chain transaction data: permanent (recorded on the blockchain; cannot be deleted)
- •Session records: 90 days after session expiry, except that records tied to AML or compliance events are kept for 5 years (see our AML Policy)
- •IP and access logs: 12 months
- •Risk and compliance records: 5 years (regulatory requirement)
- •AML flagging records: 5 years
- •Consent acceptance records: 7 years after your last interaction
6. Blockchain Data and Your Right to Erasure
We cannot delete your on-chain data. Transactions on Solana are permanent and immutable; no party can override this.
For the off-chain data we hold (session records, IP logs), you can request deletion by contacting [email protected]. We will respond within 30 days. We may decline deletion of AML or compliance records where the law requires us to keep them.
7. International Data Transfers
The Interface is served globally through a content delivery network, and data may be processed in several countries. We maintain appropriate safeguards for international transfers consistent with applicable law.
On access restrictions: the Protocol blocks access at the network level from the United States, United Kingdom, and Australia, and from the comprehensively sanctioned jurisdictions in our AML Policy Section 6. Our Terms of Service list further restricted territories that players must certify they are not playing from, including several EU member states. Where the off-chain personal data we hold relates to a person in the EU, we aim to apply data-protection principles consistent with the General Data Protection Regulation (GDPR) and international best practice. We will confirm our EU/GDPR posture with qualified counsel; this section states our good-faith approach.
8. Security
We use technical and organisational security measures, including:
- •HTTPS/TLS for all Interface traffic
- •DDoS protection and a web application firewall
- •server-side session-token hashing (tokens stored as SHA-256 hashes)
- •no storage of private keys or seed phrases
- •an encrypted off-chain database with daily backups
No security measure is perfect. If you find a security vulnerability, report it to [email protected].
9. Children's Privacy
The Interface is strictly for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has used the Interface, contact us at [email protected].
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or the law. Updates are posted here with a revised date. Continued use of the Interface after an update means you accept it.
11. Contact
General and legal enquiries: [email protected] Data deletion requests: [email protected]
Response time: within 30 days.
This Privacy Policy was last reviewed on 19 June 2026.
Questions about this document?
Contact us