Privacy
The short version
A wallet address is public information that already exists on a public chain; we do not create it and we cannot hide it. What we add is an account around it, the things you write, and the encrypted messages you send. We ask for no name, no email and no document. We never see a private key.
Your messages are encrypted on your own device before they leave it. What we store is text we cannot read, and no amount of legal process changes that, because we do not hold the key.
What we store
| What | Why |
|---|---|
| Your wallet address, and the signed message proving you control it | It is the identity. Without it there is no account. |
| A handle, display name and bio, if you choose to set them | So people can recognise you without seeing an address. |
| Your privacy setting and whether amounts are shown | It is applied in the database query, not in the page, so a hidden holding is never sent. |
| Topics, replies, archive entries and poll votes you write | They are the public content of the site. |
| Encrypted message envelopes and your devices' public keys | To deliver a message to your other devices. We cannot decrypt any of it. |
| Gift records: sender, recipient, token, amount, transaction hash | To show the gift and match it to the transfer the chain reports. |
| Membership snapshots: which asset, which tier, when | So a tier does not flicker when a price moves or an RPC fails. |
| A session cookie | To keep you signed in. No advertising cookie, no third-party tracker, no analytics pixel. |
| The date and version of your agreement to the terms | Because consent has to be recorded to mean anything. |
Who else touches it
The site runs on Vercel and the database is Neon; both process data on our instructions. Asset and price data comes from Robinhood's public API, and balances are read from a Robinhood Chain node. Those reads send a contract and an address, which are already public, and never anything about you as a person.
We do not sell data, and there is nobody to sell it to.
Why we are allowed to
For your account, your content and your messages, the basis is your consent, given the first time you signed in and withdrawable at any time. For keeping the service standing up and safe from abuse, the basis is legitimate interest. There is no processing here for advertising or profiling.
How long
Account data and content stay while the account exists. Ask for deletion and we remove the account, its profile, its messages and its device keys, and detach its authorship from anything left standing.
Two things survive, and it is fair to say so plainly. What is already on chain — a transfer, an address — cannot be deleted by us or by anyone, because a public ledger is not ours to edit. And a post someone else has quoted stays readable as a quotation, with the authorship removed.
Your rights
You may ask what we hold about you, correct it, take it with you in a portable format, restrict what we do with it, withdraw consent, or have it deleted. Write to privacy@hoodler.social from any channel you like, and prove control of the wallet by signing a message we will send back. We answer within fifteen days.
Children
hoodler is not intended for anyone under 18, and we do not knowingly keep data about a child.