DATA PROTECTION & BLOCKCHAIN TRANSPARENCYPrivacy & storage

Privacy Policy

Effective date: 2026. How DEGENBID handles client data, on-chain records, and device storage across Robinhood Chain and Web3 rails.

1. Non-Custodial Protocol Architecture

DEGENBID is a decentralized, non-custodial attention orderbook and token visibility protocol operating on Robinhood Chain.

Protocol use does not require a traditional user account. We do not custody user private keys, and do not manage fiat balances. Your interaction with the protocol occurs directly through your self-custodial EVM wallet (MetaMask, Rabby, OKX, Phantom, etc.) and autonomous smart contracts.

2. Information We Process (and What We Do NOT)

We adhere strictly to data minimization principles under the General Data Protection Regulation (GDPR Art. 5(1)(c)).

What We Process

  • Public Wallet Addresses: Classified as pseudonymous personal data under GDPR Art. 4(1). Used strictly to calculate leaderboard scores, token balances, and claim rights.
  • Terms Acceptance: Wallet address and namespace, Terms version and document hash, signed agreement message, signature, and acceptance time. Stored on our server to record your agreement and remember it across devices. A message signature does not disclose your private key or authorize a payment.
  • UPBIDER Supporter Profiles: Email and subscription consent, confirmation status, invitation relationships, and delivery status. If you choose to connect X or a wallet, we also store your X user ID and username or verified wallet address, together with the connection time. These connections are associated with your private email profile and help prevent the same account being linked to multiple profiles. They are not shown in the public invite ranking. See the details below.
  • Technical Metadata: IP address, user-agent, and timestamps processed in volatile memory by Edge nodes (Cloudflare/Vercel) for DDoS protection.
  • Client Preferences: Dark/light mode, local UI tags, and cookie consent state stored directly on your browser.

What We NEVER Collect

  • No real names or government identity documents.
  • No phone numbers. Email is optional for UPBIDER updates.
  • No credit card, banking, or fiat payment details.
  • No private keys, seed phrases, or wallet passwords.
  • No KYC profiling or biometric data.

UPBIDER email and optional connections

Your email subscription works after confirmation without connecting X or a wallet. Connecting X sends you to X to authorize read-only access to your profile ID and username. We use the access token to retrieve that profile and do not retain it. We do not request access to post, follow accounts, or read private messages. Connecting a wallet requires a message signature proving ownership; it does not authorize a transaction or token approval. Verification challenges expire after five minutes for wallets and ten minutes for X.

You can remove individual connections from your private supporter dashboard. Removing a connection deletes its association with your supporter profile; it does not change public blockchain records. To withdraw your email subscription, use the unsubscribe link in your email. Supporter records expire 90 days after signup and are removed by the retention cleanup, including linked identities. Expired profiles cannot access connections or receive updates.

3. Blockchain Immutability & GDPR Article 17 Notice

Notice regarding European Data Protection Board (EDPB) Guidelines 02/2025 on Blockchain:

When you initiate transactions on Robinhood Chain or any public EVM network (such as placing a bid, claiming rewards, or transferring BID), transaction details and your public wallet address are permanently recorded onto a decentralized, cryptographically validated public ledger.

By virtue of decentralized consensus and cryptographic immutability, on-chain records cannot be modified, deleted, or erased. The GDPR "Right to Erasure" (Article 17) cannot be executed against data permanently committed to the blockchain.

However, any off-chain indexed cache, auxiliary server logs, or local device storage maintained by the operator can be erased upon legitimate request.

4. Complete Inventory of Cookies & Local Storage

In full accordance with the ePrivacy Directive and EDPB cookie transparency guidelines, here is an exact accounting of what is stored on your device:

IdentifierTypeClassificationPurposeRetention
themelocalStorageStrictly NecessaryStores dark / light mode preference to prevent flash of unstyled contentPersistent
degenbid_cookie_consentlocalStorageStrictly NecessaryRecords your cookie choices and timestamps for compliance verification12 months
degenbid_consentCookieStrictly NecessaryAllows server-side rendering (SSR) to adapt immediately to your consent status12 months
upbider_supporter / upbider_x_stateHttpOnly cookiesNecessary for supporter access and X linkingOpen your private confirmed-email dashboard and bind an X authorization response to your browser.Supporter: 90 days / X: 10 minutes
@reown/* / wagmi.storelocalStorageStrictly NecessaryMaintains non-custodial wallet connection session and active chain IDSession / Active
babki_presence_sidsessionStorageFunctionalAnonymous ephemeral per-tab presence identifier for real-time online countPer tab session
babki_rat_tagslocalStorageFunctionalCustom client-side user labels and notes assigned to board tokensPersistent
Optional AnalyticsCookie / StorageOptional (Opt-In)Aggregated latency and board interaction metrics (Strictly disabled unless consented)Subject to consent

5. Third-Party Infrastructure & RPC Processors

When querying or transacting with the protocol, network traffic communicates with the following external infrastructure:

  • Robinhood Chain RPC Nodes: Your browser sends JSON-RPC queries to retrieve contract states, token prices, and broadcasts signed transactions.
  • Reown AppKit / WalletConnect: Relays cryptographic handshake requests between your browser and your mobile or desktop wallet.
  • Neon PostgreSQL & Cloudflare / Vercel: Manages off-chain indexed orderbook state and edge caching to deliver sub-second leaderboard updates.

6. Your Rights & How to Control Your Data

Under the GDPR (EU/EEA), UK GDPR, and California Consumer Privacy Act (CCPA/CPRA), you have the right to:

  • Withdraw your cookie or storage consent at any moment via the settings trigger below.
  • Clear local browser storage via your browser settings anytime.
  • Request the deletion of any off-chain indexed records associated with your wallet address.
  • Object to any non-essential automated data processing.

7. Contact & Governance

For data protection inquiries or to submit an off-chain data erasure request, contact our maintainers via GitHub Issues at checkra1neth/degenbid or inspect our protocol documentation on About and Protocol Rules.