Privacy policy
Last updated 7 September 2026.
What we collect
Account data. Your name, email address, hashed password, and the organisations you belong to.
Operational data you provide. Sites, machines, power rates, cost entries, and machine telemetry you upload or sync.
Pool data. Payout history retrieved using credentials you supply, or CSV files you upload.
Technical data. IP address, user agent and timestamps for authentication events and administrative actions, kept as an audit trail.
Analytics. We use Google Analytics 4 on this website to count page views and a small number of product events — a signup, a pool connected, a glossary term opened. What it can record is deliberately limited: an event says that something happened and which feature it happened in, never whose it was or how much. No satoshi amount, fiat value, machine label, worker name, organisation name or email address is ever sent, and record identifiers are stripped out of page paths before they leave your browser.
Analytics storage is denied by default, so no analytics cookie or identifier is set on your device unless you consent. Advertising signals and personalisation are switched off, and IP addresses are anonymised.
We do not use advertising trackers, and we do not sell data to anyone.
Pool credentials
Pool API credentials are encrypted at rest with per-organisation envelope encryption. They are never displayed again after you enter them — not to you, not to our support staff, not masked, and not on request. Our administrative tools have no ability to read or export them.
Credentials must be read-only. JouleBook cannot move funds, change a payout address, or write to a mining machine.
Why we process it
To operate the Service: attributing payouts, computing costs, producing reports, and billing you. The lawful basis is performance of our contract with you, and our legitimate interest in keeping the Service secure.
Payments
Card payments are processed by Razorpay and Bitcoin payments by a self-hosted BTCPay Server. We never see or store your card details. We retain the invoice record — amount, currency, satoshis paid, and the BTC price at settlement — because we are required to.
Retention
Account and financial records are kept while your account is open and for as long as tax law requires afterwards. Telemetry is retained according to the retention period configured for the instance. Audit records outlive the organisation they describe, deliberately: an audit trail that is deleted along with its subject is not an audit trail.
Your rights
You can export everything your organisation holds at any time, on any plan. You can ask us to delete an organisation entirely. Write from the account address to support@joulebook.com.
Support access
Our staff can, for support purposes, view an organisation's data through a time-limited session that expires after 30 minutes, is read-only unless write access is explicitly requested, is recorded with a stated reason, and displays a banner to anyone using that account at the time.
Sub-processors
Hosting infrastructure, Razorpay for card payments, and CoinGecko and mempool.space for public market data. Public market data requests do not include anything about you.
Contact
security@joulebook.com for anything involving a vulnerability or a data incident.