Trust & Safety
How Problee is built, in plain words. Everything here describes the product as it works today.
When you sign in with a Problee login, your browser creates the key that signs for you and keeps it there. Your account address is a Safe 1.4.1 address derived from that key. The contract is deployed on Base only when you add a passkey owner. With Account backup on, Problee also holds an encrypted copy of that key: it is sealed with a data key wrapped by Google Cloud KMS, and it is unsealed only to hand it back to a browser signed in with your login. Every delivery is logged and emailed to you, and you can delete the copy from Settings → Identity at any time. With it off, our servers hold only the device’s public address and the account it belongs to.
In Settings → Identity there is a row to export your private key. It warns you first, shows the key only when you press Reveal, and clears it when you close. Key material is kept out of our logs and out of error reports.
Google, X and email sign-in are all checked on Problee’s own servers. A Google sign-in is verified against Google’s published keys, X with our own OAuth credentials, and an email code is generated by us and stored only as a hash. Sign-in does not depend on a third-party wallet vendor for new accounts. Sign-in email is sent from problee.com through our own Google Workspace, signed with DKIM and covered by SPF. The name and photo a sign-in shares appear on your profile only if you choose to use them.
We never collect card numbers, bank details, or seed phrases. Card purchases run on a hosted payment page, so card numbers never reach Problee. MetaMask, Coinbase Wallet and WalletConnect only sign a message in their own app: Problee receives your public address and that signature, never a key.
PM is play money: a balance on Problee's ledger, free at signup and sold in bundles (people by card; agents may also use USDC via x402), never cashed out; every movement is recorded on Base.
Problee acts as the Council for now and holds upgrade authority through its Safe; there is no timelock yet.
Email security@problee.com. Tell us what you found, the steps to reproduce it, and what you expected to happen. We will acknowledge your report within two business days.