Privacy notice
Privacy notice
1. In brief
There is no sign-up, no password and no email. We run no analytics, no advertising and no third-party trackers of any kind, and we do not sell or share data.
There is one thing we collect about what you do here, and only if you choose to send it: a problem report. If something breaks you can press Report a problem, record the flow that failed, read what the recording contains, and send it to us. Nothing records until you start it, nothing is sent until you have seen it, and secrets are removed in your browser before it leaves. Section 3 is the whole of it.
We record one other thing, and only about a wallet we have withheld from the public leaderboards: the address, the ground, and the reason. It changes what a ranking on this website shows and nothing else — never your funds, tokens, trades or referral earnings — and you may appeal it. Section 4, and section 11 of the terms.
The part that should actually concern you is not us. It is that a blockchain and IPFS are public and permanent by design, and everything you do through this site lands on one or both. Section 5 is the part worth reading twice.
The sections below are the binding text; this one is for orientation.
2. What we hold
2.1 Server logs
Requesting a page necessarily tells our hosting provider your IP address, your user agent, the URL you asked for and the time. This is the ordinary technical record of delivering a web page, and we use it only to serve the site and to identify abuse — traffic floods, upload abuse, scripted hammering of the RPC. It is not used to build a profile of you.
2.2 Local storage on your device
One item, thehood.cookie-notice, recording that you dismissed the cookie notice so it does not reappear. It is a flag with no identifier in it, it never leaves your browser, and clearing your site data removes it. Full detail in the cookie notice.
2.3 Your account, if you sign in
Browsing this site creates no account. Signing in does, and signing in means proving you hold a wallet by signing a message — never a password, and never anything we could use to move your funds. From that point we hold a record keyed to your wallet address containing only what you put in it: a display name if you set one, a profile picture if you upload one, whether your profile is public, private labels you have written against other wallets, and your alert preferences.
A signed-in session is carried in a cookie that identifies the session and nothing else. It is strictly necessary — the site cannot know it is you without it — and it ends when you sign out. A profile picture you upload is stored by us and served from our own domain rather than pasted from somewhere else, which is why it survives and why nobody else can swap it later.
Everything in this record is optional except the address, and all of it can be erased from your settings page. What that erases, what it keeps and why is set out in section 8.
2.4 Your connected X account
Connecting X is optional. It is required only to mint a referral code or to hold a KOL rank, and the reason is that a wallet costs nothing to create — without it, one person with a script holds as many referral codes as they have addresses.
We ask X for read-only access and store four things:
- X’s own account identifier — a number, not your handle. This is the identity we key on, because a handle can be renamed and the freed name claimed by somebody else.
- Your handle, as a display cache, refreshed when we re-check.
- Whether the account carries a live X Premium badge, and when we last asked. A badge is a subscription and lapses, so we re-read it daily rather than recording it once.
We do not receive or store your posts, your followers, your email address or your password, and the access we are granted cannot post, follow, like or message as you. We do not keep the token X issues: it is used once to read the profile and discarded, and the daily re-check uses an application credential that identifies this platform rather than you.
What reaches the public blockchain is a true or false against your wallet address, and nothing else. No handle, no account identifier and no other X data is ever written to a public ledger.
The pairing is permanent. A wallet and an X account are bound to each other once connected: it cannot be moved, changed or removed. That is a deliberate restriction rather than a limitation — your referral name and your KOL standing are both tied to the handle, and allowing the link to move would carry them to a different one. To use a different X account, connect it to a different wallet.
2.5 Referral records
If you mint a referral code we record the code, the name attached to it, and which wallets were attributed to it and when. If you arrive through somebody else’s link we record which code brought you, once and permanently — that binding is what decides who is paid, so it cannot be rewritten afterwards, by you or by us.
These rows are about more than one person, which is why erasing your account does not delete them: they record who referred somebody else and what that person is owed. Section 8 says so in the place it matters.
2.6 What we still do not do
We run no analytics, embed no pixels, and load no fonts, scripts or stylesheets from a third-party CDN. There is no advertising identifier, no cross-site tracking and no profile built from your behaviour. The only cookies we set are the session described in 2.3 and two short-lived ones that exist for the length of an X connection round trip and are cleared the moment it finishes.
3. Problem reports
The site has a Report a problem button. Pressing it lets you record what your browser is doing while you reproduce a fault, read the recording, and send it to us. It is the only thing on this site that collects anything about your visit, and it never happens unless you make it happen.
3.1 It is voluntary, and consented to one incident at a time
There is no standing permission and no setting to leave on. Every report is a separate, deliberate act with two gates: nothing is recorded until you press Start, and nothing is sent until you have read the recording and pressed Send. Between those two you can discard it, and closing the panel discards it. The recording lives in your browser’s memory until you send it, and vanishes if you do not.
Until you press Start, the recorder is not running. It is not idling, not buffering, and not installed — the code that watches network requests is not attached to your page at all.
3.2 What a report contains
- Network requests made by this page while you were recording — the method, the address, the status, how long it took, and the request and response bodies.
- Console output, JavaScript errors and their stack traces, and moves between pages within the site.
- The page you were on, your browser’s user-agent string, and the start and stop times of the recording.
- Anything you type into the note — an optional sentence describing what you were trying to do.
- Your wallet address, if you are signed in when you send it. It is taken from your session, so a report can be answered. Send it while signed out and it is anonymous, and the reference number is then the only handle anyone has on it — including you.
It is not a session recording in the sense that phrase usually carries: it does not capture your screen, your keystrokes, your mouse, or the contents of the page. Nothing reconstructs what you were looking at.
3.3 What is removed, in your browser, before anything is sent
Redaction happens on your device, before the report is transmitted — not on our server when it arrives. That distinction is the whole of it: a secret stripped after transmission has already been transmitted. What must not be stored is never sent.
These are removed and replaced with the word “redacted”:
- Sign-in signatures and the challenge nonces that go with them. That pair is a credential — anyone holding it could sign in as you.
- Session tokens, passwords, API keys, authorization values, JWTs, one-time codes and card numbers, wherever they appear, including inside request and response bodies.
- Anything shaped like a private key or a seed phrase. Nothing here ever handles one — your wallet extension does, and this page cannot read it — but the rule is absolute regardless.
- Email addresses.
Request and response headers are not captured at all, in either direction, so an authorization header or a cookie cannot be in a report whatever else happens.
3.4 What is deliberately kept, and why
Wallet addresses, balances and trade amounts are kept. We would rather say so than imply a protection that does not exist:
- Every one of those values is already public. They live on a public chain that anyone can read with a block explorer, permanently, with or without us — which is the subject of section 5 and was true long before this feature existed.
- Removing them would make the report useless. A failure here is a chain read that reverted or a quote that came back wrong, and both of those are addresses and amounts. A recording with them stripped cannot be told apart from a recording of something else, and asking you to send one would be dishonest.
- There is no way to remove only yours. Your wallet, the token, the curve and the factory are the same shape; a rule that removed some addresses and left others would read as a stronger promise than it could keep.
So the protection is that you see it first. The review screen shows the exact payload — not a summary of it, the thing itself — and it is not sent until you press the button.
3.5 How long a report is kept, and how to have one deleted
Reports are kept for 12 months from the day they are sent, and are deleted after that. One that is still being worked on is kept until it is closed, and then falls under the same 12 months.
To have one deleted sooner, write to privacy@thehood.markets and quote the reference number shown when it was sent. It is deleted outright — not marked hidden. If you sent it while signed in, quoting your wallet address is enough; if you sent it anonymously the reference is the only way to identify it, which is why the panel says to keep it.
Reports are read by the protocol owner and by nobody else. They are not shared with any third party, and there is no analytics or support product behind the button — the report is stored in our own database and read in our own admin panel.
4. Your wallet address
Connecting a wallet grants this site permission to read your address. That happens in your browser. We do not store your address, do not link it to an identity and do not record which addresses have visited.
There is one exception, and stating it is the point of this paragraph. If we withhold a wallet from the public leaderboards, we store that wallet address together with which of the two grounds applied, the reason we recorded, and the date — see section 11 of the terms, which also sets out your right to appeal. The record is kept after an exclusion is lifted, so that an appeal can be answered from what actually happened. It is read by us and by nobody else, it is not shared with any third party, and it affects visibility on this website only — never your funds, your tokens, your trades or your referral earnings.
Reads that concern only your own account — your balance, a simulated trade, waiting for a receipt — are sent through your wallet’s RPC connection rather than ours, deliberately, so your activity does not accumulate at our endpoint. When no wallet is installed they fall back to the public Robinhood Chain endpoint.
Your wallet extension is its own program with its own privacy policy. We cannot read its storage and it does not report to us.
5. What is public and permanent
These are consequences of the technology, not choices we make, and none of them is reversible.
- On-chain activity. Every launch, buy, sell, graduation and fee claim is recorded on Robinhood Chain against your address, permanently, and is readable by anyone with a block explorer. Addresses are pseudonymous, not anonymous: if your address is ever linked to you — by an exchange, a public post, an ENS-style name or chain analysis — the whole history becomes attributable.
- Project metadata. The name, symbol, description and links you enter when launching are written on chain and cannot be edited or removed afterwards.
- Uploaded artwork. Images sent to the site are pinned to IPFS via a pinning provider. IPFS is a public, content-addressed network: anyone can fetch the file, and it cannot be deleted — unpinning stops us serving it, but any node that copied it keeps serving it forever. Do not upload anything containing personal data, metadata you would not publish, or an image you may want withdrawn.
6. Who else is involved
Three categories of provider necessarily see traffic:
- Our hosting provider — receives your request in order to return the page, and therefore sees your IP address.
- The RPC endpoint for Robinhood Chain — sees our server’s reads for server-rendered pages, not yours. For account-scoped reads your own wallet chooses the endpoint.
- The IPFS pinning provider and public gateways — receive uploaded artwork, and a gateway sees the request when your browser loads an image.
Each has its own privacy policy. We do not send any of them information about you beyond what the request itself requires.
7. Sharing and selling — what we do not do
- We do not sell your personal data.
- We do not share it with advertising or behavioural-targeting networks.
- We do not profile you, fingerprint you, or attempt to identify you across sites or visits.
- We do not link a wallet address to an identity, or keep a record of which addresses have visited. The single exception is one you create yourself: a problem report you chose to send while signed in carries your address, so that it can be answered.
This is less a promise than an arithmetic consequence of sections 2 and 3: apart from a report you deliberately sent, there is nothing here to sell, share or profile.
8. Your rights
Depending on where you live you may have rights to access, correct, delete or object to the processing of your personal data. Write to privacy@thehood.markets and we will act on anything we actually hold. In practice that means a problem report you chose to send — quote its reference number and it is deleted outright — and a server log line.
Be aware of the limit, because it is absolute: we can delete a server log entry. We cannot delete a blockchain record or an IPFS file, and neither can anyone else. No law, request or court order changes that — the data is replicated across machines nobody controls. Treat every on-chain action as published the moment you sign it.
Our lawful basis for the little we do process is legitimate interest: delivering the site and keeping it available.
9. Retention
- Server logs — kept only as long as they are useful for delivery and abuse prevention, and rotated by the hosting provider.
- Problem reports — 12 months from the day they are sent, or until the fault is closed and 12 months have passed, whichever is later. Deleted sooner on request; see section 3.5.
- Leaderboard exclusions — kept indefinitely, including after an exclusion has been lifted. The record is what an appeal is answered from, and deleting it would leave a wallet that was cleared with no evidence that it was. Section 4.
We keep no other records of what you do here.
10. Children
The site is not intended for anyone under 18 and we do not knowingly process their data. If you believe a minor has used it, tell us at privacy@thehood.markets.
11. Changes to this notice
If this notice changes, the date at the top of the page changes with it. A change that introduced any tracking would also change the cookie notice and the notice on the site, before it took effect.
12. Contact
The Hood’s contracts are immutable, audited by Claude Fable 5. Nothing on this site is financial, investment, legal or tax advice.