01Who we are
This policy explains how [to be completed: legal entity], registered at [to be completed: registered address] (“NoFomo”, “we”, “us”), handles personal data when you use the website, the app, the public API and the MCP server (the “Interface”). We are the controller of that data for the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, and a “business” for the purposes of the California Consumer Privacy Act as amended by the CPRA, to the extent those laws apply to us.
Contact for anything in this policy: [to be completed: privacy email].
02The short version
- We don’t ask for your name, email, phone number or ID to use the Interface. There are no accounts.
- Wallet addresses and transactions are public blockchain data. We index and display them; we can’t delete them from the chain.
- Our servers keep short-lived request logs (including IP address) for security and rate limiting.
- We set one first-party cookie to remember your cookie choice. No analytics or advertising run today.
- We don’t sell or share personal information, and we don’t use it for advertising.
03Data we process
Public blockchain data
When you connect a wallet, join a cluster, arm or revoke a mandate, or when your agent does any of these, the wallet address, amounts, times and transaction hashes are recorded on Robinhood Chain by the network itself, not by us. We read this public data from the chain and index it to show clusters, agent pages, statistics and the network graph, and to serve the API. A wallet address can be personal data if it can be linked to you.
Wallet connection in your browser
When you connect a wallet in the app, your browser tells the app your public address and network. Nothing is sent to our servers except the public data needed to answer the requests you make (for example, asking the API for your positions by address). Wallet libraries keep connection state in your browser’s local storage; see the Cookie Policy for the exact keys.
Server and API logs
Like any web service, our hosting infrastructure records technical data about requests: IP address, time, URL and method requested, response status, user agent and referrer. The API and MCP endpoints additionally record request parameters (for example a market or wallet address you query) and rate-limit counters keyed by IP address.
Cookies and similar storage
We store your cookie choices in a first-party cookie called nf_consent. Optional categories (preferences and analytics) are off until you switch them on. Full details are in the Cookie Policy.
Messages you send us
If you email us, for example with a security report or a rights request, we process your email address and the contents of your message.
What we don’t collect
We never receive your private keys or seed phrase. We don’t run analytics, session recording, fingerprinting or advertising pixels, and we don’t buy data about you. If we ever add analytics, it will only run after you opt in and this policy will be updated first.
04Why we use it, and our legal bases
| Purpose | Data | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Providing the Interface, preparing transactions you ask for, showing your positions | Wallet address, public chain data, request data | Performance of our contract with you (Art. 6(1)(b)) |
| Indexing and publishing public network activity and statistics | Public chain data | Legitimate interests in running a transparent market interface (Art. 6(1)(f)) |
| Security, abuse prevention, rate limiting, debugging | Server and API logs | Legitimate interests in keeping the service safe and available (Art. 6(1)(f)) |
| Sanctions and restricted-jurisdiction controls | IP-derived location, wallet address | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
| Remembering your cookie choice | nf_consent cookie | Legal obligation to record consent; strictly necessary storage |
| Optional preferences and analytics (not used today) | As described when introduced | Your consent (Art. 6(1)(a)), which you can withdraw at any time |
| Answering your messages and requests | Email address, message | Legitimate interests, or legal obligation for rights requests |
05Who we share it with
We use a small number of service providers who process data for us under contract:
- Hosting and delivery: Vercel Inc. hosts the website, app and API and processes request logs.
- Blockchain access: RPC node providers for Robinhood Chain receive the queries our servers make, and, when your wallet talks to the chain, the queries your wallet makes.
- WalletConnect, only if you choose it: the WalletConnect (Reown) relay carries encrypted messages between the app and your mobile wallet.
We may also disclose data where the law requires it, to protect our rights or users’ safety, or to a successor in a merger or acquisition, subject to this policy. We do not sell personal information and we do not “share” it for cross-context behavioural advertising, as those terms are defined in the CCPA/CPRA.
06International transfers
Our providers may process data outside your country, including in the United States. Where we transfer personal data from the EEA or the UK to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider’s certification under the EU-US Data Privacy Framework and its UK extension, as applicable. Public blockchain data is replicated globally by the network itself.
07How long we keep it
- Server and API logs: no longer than 30 days, unless we need a specific record longer to investigate or defend against a security incident or abuse.
- Rate-limit counters: minutes to hours; they expire automatically.
- Our index of public chain data: for as long as we operate the Interface. The underlying data stays on the blockchain permanently regardless of what we do.
nf_consentcookie: 12 months, after which we ask again.- Emails: as long as needed to handle the matter, then up to 2 years for our records, unless the law requires longer.
08Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and get a copy;
- correct inaccurate data;
- delete data (the “right to be forgotten”);
- restrict or object to processing based on legitimate interests;
- data portability;
- withdraw consent at any time, without affecting earlier processing;
- under the CCPA/CPRA: know what we collect, delete, correct, and opt out of sale or sharing (we do neither), and not be discriminated against for exercising your rights.
Blockchain data cannot be erased. Transactions on Robinhood Chain are permanent and public. We can stop displaying a wallet address in parts of the Interface we control on request where the law requires it, but we cannot remove it from the chain, block explorers or other indexers.
To exercise a right, email [to be completed: privacy email]. We may ask you to prove control of a wallet (for example by signing a message) before acting on a request about that wallet. We will respond within one month (GDPR / UK GDPR) or 45 days (CCPA/CPRA), and tell you if we need an extension. You may use an authorised agent under the CCPA/CPRA.
You can also complain to a data protection authority: in the EU, the authority where you live or work; in the UK, the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concern first.
09Browser privacy signals
Optional cookies and storage stay off unless you turn them on, so a browser that sends Do Not Track or Global Privacy Control gets the same privacy-protective default as everyone else. Because we do not sell or share personal information, there is nothing further for those signals to opt you out of today.
10Security
We use HTTPS everywhere, strict security headers, least-privilege access to infrastructure and short log retention. No system is perfectly secure; if you find a vulnerability please follow our responsible disclosure process.
11Children
The Interface is not intended for anyone under 18 and we do not knowingly process children’s personal data. If you believe a child has sent us personal data, contact us and we will delete it.
12Changes to this policy
We will update this policy when our processing changes, and before we introduce any new category of data or any analytics. The “Last updated” date shows the current version. For material changes we will give notice on the Interface.
13Contact
Privacy questions and requests: [to be completed: privacy email]. Controller: [to be completed: legal entity], [to be completed: registered address].