Privacy and trust controls

Published anonymously. Not promised as impossible to correlate.

Account email, verification, and submission are separate records

The email on a signed-in account is used only to establish eligibility through a one-time verification link. The verification ledger stores an account ID, a one-way token hash, issue and expiry times, and used/verified timestamps. The separate credential ledger stores an account ID, a one-way credential hash, issuance time, expiry, and use state. A rate submission stores no account ID, email, authentication identity, IP address, user agent, contributor pass, verification token, or credential hash.

What “published anonymously” means here

Aggregate views never display contributor identities, raw records, submission IDs, email-verification records, credentials, or proof requests. This release does not use blind signatures or another unlinkable credential system. An operator with access to the separate verification/credential ledgers and application timing could potentially make a correlation inference, even though there is no database foreign key from an account to a rate submission. We therefore do not claim untraceability or impossible account-to-submission linking.

Credential and repeat-abuse controls

Verification links and credentials are cryptographically random and stored only as hashes. Verification links expire after 15 minutes, can be used once, and have a server-side resend cooldown and hourly cap. Credentials expire after 30 minutes, are consumed once, and have a separate cooldown and weekly account cap. A hashed browser-session key preserves short-window rate limiting without storing raw IP addresses on a submission.

Structured commercial fields only

The form collects a company business name, role, broad region band, day-rate band, rotation pattern, and payment-reliability choice. It has no notes field, no uploads, no client/principal/location/tasking field, no contract name, and no date field. Do not enter operational or identifying details.

Optional proof-review status, no uploads

After a contribution, you may record a detached request for optional proof review. This release accepts no documents and retains no evidence files. Do not send evidence through the site. A proof request is not verification; only a future review process that can delete redacted commercial evidence immediately after review may set a submission to verified. Evidence and account identity are never included in public aggregates.

Five submissions before company results

Company names, partial counts, and company-level distributions are suppressed until at least five qualifying submissions exist for that company. This rule is enforced in the server query, not only in the interface.

Infrastructure limits

This is an application-database privacy design, not a promise about every system on the network path. Browsers, CDNs, hosting providers, network operators, and platform logs may process IP addresses or request metadata outside this application database and outside CircuitRates' direct control.

Check contributor eligibility