Trust & Safety
How Problee is built, in plain words. Everything here describes the product as it works today.
When you sign in with a Problee login, your browser creates the key that signs for you and keeps it there. Your account address is a Safe 1.4.1 address derived from that key. The contract is deployed on Base only when you add a passkey owner. With Account backup on, Problee also holds an encrypted copy of that key: it is sealed with a data key wrapped by Google Cloud KMS, and it is unsealed only to hand it back to a browser signed in with your login. Every delivery is logged and emailed to you, and you can delete the copy from Settings → Identity at any time. With it off, our servers hold only the device’s public address and the account it belongs to.
In Settings → Identity there is a row to export your private key. It warns you first, shows the key only when you press Reveal, and clears it when you close. Key material is kept out of our logs and out of error reports.
Google, X and email sign-in are all checked on Problee’s own servers. A Google sign-in is verified against Google’s published keys, X with our own OAuth credentials, and an email code is generated by us and stored only as a hash. Sign-in does not depend on a third-party wallet vendor for new accounts. Sign-in email is sent from problee.com through our own Google Workspace, signed with DKIM and covered by SPF.
We never collect card numbers, bank details, or seed phrases. Cards are handled by Stripe’s hosted checkout, so card numbers never reach Problee. USDC purchases are direct on-chain transactions. MetaMask, Coinbase Wallet and WalletConnect sign a message in their own app: Problee receives your public address and that signature, never a key.
Problee Money is play money. It has no cash value and cannot be moved out — the token contract refuses a transfer unless a Problee venue is part of it. Markets settled in real collateral are not offered today; when they are, an account will need a passkey owner before it can place orders in them.
Email security@problee.com. Tell us what you found, the steps to reproduce it, and what you expected to happen. We will acknowledge your report within two business days.