Skip to content

Legal

Privacy policy

No accounts, no analytics, no ads. Here is exactly what we process, why, for how long, and how to exercise your rights.

Last updated

01Who we are

This policy explains how [to be completed: legal entity], registered at [to be completed: registered address] (“NoFomo”, “we”, “us”), handles personal data when you use the website, the app, the public API and the MCP server (the “Interface”). We are the controller of that data for the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, and a “business” for the purposes of the California Consumer Privacy Act as amended by the CPRA, to the extent those laws apply to us.

Contact for anything in this policy: [to be completed: privacy email].

02The short version

  • We don’t ask for your name, email, phone number or ID to use the Interface. There are no accounts.
  • Wallet addresses and transactions are public blockchain data. We index and display them; we can’t delete them from the chain.
  • Our servers keep short-lived request logs (including IP address) for security and rate limiting.
  • We set one first-party cookie to remember your cookie choice. No analytics or advertising run today.
  • We don’t sell or share personal information, and we don’t use it for advertising.

03Data we process

Public blockchain data

When you connect a wallet, join a cluster, arm or revoke a mandate, or when your agent does any of these, the wallet address, amounts, times and transaction hashes are recorded on Robinhood Chain by the network itself, not by us. We read this public data from the chain and index it to show clusters, agent pages, statistics and the network graph, and to serve the API. A wallet address can be personal data if it can be linked to you.

Wallet connection in your browser

When you connect a wallet in the app, your browser tells the app your public address and network. Nothing is sent to our servers except the public data needed to answer the requests you make (for example, asking the API for your positions by address). Wallet libraries keep connection state in your browser’s local storage; see the Cookie Policy for the exact keys.

Server and API logs

Like any web service, our hosting infrastructure records technical data about requests: IP address, time, URL and method requested, response status, user agent and referrer. The API and MCP endpoints additionally record request parameters (for example a market or wallet address you query) and rate-limit counters keyed by IP address.

Cookies and similar storage

We store your cookie choices in a first-party cookie called nf_consent. Optional categories (preferences and analytics) are off until you switch them on. Full details are in the Cookie Policy.

Messages you send us

If you email us, for example with a security report or a rights request, we process your email address and the contents of your message.

What we don’t collect

We never receive your private keys or seed phrase. We don’t run analytics, session recording, fingerprinting or advertising pixels, and we don’t buy data about you. If we ever add analytics, it will only run after you opt in and this policy will be updated first.

04Why we use it, and our legal bases

PurposeDataLegal basis (GDPR / UK GDPR)
Providing the Interface, preparing transactions you ask for, showing your positionsWallet address, public chain data, request dataPerformance of our contract with you (Art. 6(1)(b))
Indexing and publishing public network activity and statisticsPublic chain dataLegitimate interests in running a transparent market interface (Art. 6(1)(f))
Security, abuse prevention, rate limiting, debuggingServer and API logsLegitimate interests in keeping the service safe and available (Art. 6(1)(f))
Sanctions and restricted-jurisdiction controlsIP-derived location, wallet addressLegal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))
Remembering your cookie choicenf_consent cookieLegal obligation to record consent; strictly necessary storage
Optional preferences and analytics (not used today)As described when introducedYour consent (Art. 6(1)(a)), which you can withdraw at any time
Answering your messages and requestsEmail address, messageLegitimate interests, or legal obligation for rights requests

05Who we share it with

We use a small number of service providers who process data for us under contract:

  • Hosting and delivery: Vercel Inc. hosts the website, app and API and processes request logs.
  • Blockchain access: RPC node providers for Robinhood Chain receive the queries our servers make, and, when your wallet talks to the chain, the queries your wallet makes.
  • WalletConnect, only if you choose it: the WalletConnect (Reown) relay carries encrypted messages between the app and your mobile wallet.

We may also disclose data where the law requires it, to protect our rights or users’ safety, or to a successor in a merger or acquisition, subject to this policy. We do not sell personal information and we do not “share” it for cross-context behavioural advertising, as those terms are defined in the CCPA/CPRA.

06International transfers

Our providers may process data outside your country, including in the United States. Where we transfer personal data from the EEA or the UK to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider’s certification under the EU-US Data Privacy Framework and its UK extension, as applicable. Public blockchain data is replicated globally by the network itself.

07How long we keep it

  • Server and API logs: no longer than 30 days, unless we need a specific record longer to investigate or defend against a security incident or abuse.
  • Rate-limit counters: minutes to hours; they expire automatically.
  • Our index of public chain data: for as long as we operate the Interface. The underlying data stays on the blockchain permanently regardless of what we do.
  • nf_consent cookie: 12 months, after which we ask again.
  • Emails: as long as needed to handle the matter, then up to 2 years for our records, unless the law requires longer.

08Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and get a copy;
  • correct inaccurate data;
  • delete data (the “right to be forgotten”);
  • restrict or object to processing based on legitimate interests;
  • data portability;
  • withdraw consent at any time, without affecting earlier processing;
  • under the CCPA/CPRA: know what we collect, delete, correct, and opt out of sale or sharing (we do neither), and not be discriminated against for exercising your rights.

Blockchain data cannot be erased. Transactions on Robinhood Chain are permanent and public. We can stop displaying a wallet address in parts of the Interface we control on request where the law requires it, but we cannot remove it from the chain, block explorers or other indexers.

To exercise a right, email [to be completed: privacy email]. We may ask you to prove control of a wallet (for example by signing a message) before acting on a request about that wallet. We will respond within one month (GDPR / UK GDPR) or 45 days (CCPA/CPRA), and tell you if we need an extension. You may use an authorised agent under the CCPA/CPRA.

You can also complain to a data protection authority: in the EU, the authority where you live or work; in the UK, the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concern first.

09Browser privacy signals

Optional cookies and storage stay off unless you turn them on, so a browser that sends Do Not Track or Global Privacy Control gets the same privacy-protective default as everyone else. Because we do not sell or share personal information, there is nothing further for those signals to opt you out of today.

10Security

We use HTTPS everywhere, strict security headers, least-privilege access to infrastructure and short log retention. No system is perfectly secure; if you find a vulnerability please follow our responsible disclosure process.

11Children

The Interface is not intended for anyone under 18 and we do not knowingly process children’s personal data. If you believe a child has sent us personal data, contact us and we will delete it.

12Changes to this policy

We will update this policy when our processing changes, and before we introduce any new category of data or any analytics. The “Last updated” date shows the current version. For material changes we will give notice on the Interface.

13Contact

Privacy questions and requests: [to be completed: privacy email]. Controller: [to be completed: legal entity], [to be completed: registered address].

Cookie settings

Choose what we may store on this device. You can change this at any time from the footer.

  • Strictly necessary

    Needed for the site to work and to remember your choices here, and to keep a wallet connection you started. These can't be switched off.

  • Preferences

    Remember interface choices such as dismissed hints and layout settings. We don't set any preference storage today; this switch covers it if we add some.

  • Analytics

    Aggregate, privacy-respecting measurement of how pages are used, so we can improve them. No analytics run today, and none will run unless you allow them here.

Full list of every cookie and storage key: cookie policy.