Browse documentation
Privacy policy
Publication draft. The operator must supply its legal identity, privacy contact, effective date, applicable data-location information, and retention schedule before offering this service publicly.
Project privacy and pseudonymity
The public design uses project branding and wallet-based accounts. It does not publish the creator’s personal biography, home address, age, legal name or personal social accounts. There are no name, email or phone fields in the user registration flow.
This is pseudonymous access, not guaranteed anonymity. Public wallet histories, deposits, RPC queries, IP addresses at infrastructure providers and combined metadata can reveal relationships. The service does not provide a mixer, zero-knowledge identity layer or anonymity network. Applicable disclosure and recordkeeping duties are not removed by using a project brand.
Information processed
The application processes wallet addresses, network identifiers, signed authentication challenges, session identifiers, terms acceptance, token metadata, payment preparations, public transaction hashes, service balances, accounting records, model selections, request identifiers, API key hashes, request fingerprints, community eligibility observations and accounting metadata. The legacy personal-compute route also stores inference response text.
The local application does not request seed phrases or wallet private keys. It does not require an email address for wallet sign-in. Wallet addresses may become personal information when linked to a person.
Prompts and responses
Prompts pass through the operator's server to OpenRouter and the selected upstream provider. The community gateway does not intentionally persist prompt or response bodies. It retains a SHA-256 request fingerprint for accounting identification; such a fingerprint is not a guarantee of anonymity, especially for predictable inputs. It stores model, wallet, key identifier, reservation, actual cost, status and provider generation ID when available.
The separate legacy /api/compute service saves responses for accounting and recovery. Those responses may repeat personal information from the prompt. Infrastructure or provider logging can process content beyond the local database. The operator must configure logging consistently with its published policy.
Do not submit confidential or sensitive information unless you understand and accept the relevant provider's processing terms. This application does not guarantee zero data retention by OpenRouter or a model provider.
Purposes
Information is used to authenticate wallets, execute requested operations, verify transactions, maintain balances, prevent replay or abuse, reconcile provider usage, support users, and meet applicable recordkeeping obligations. The bundled application does not include advertising trackers or sell personal information.
Service providers
OpenRouter and model providers process inference requests. RPC providers process blockchain queries and submissions. Pinata processes creator-supplied metadata when automatic IPFS upload is enabled. Coinbase supplies exchange-rate information. Remote image hosts can receive browser request data when their logos or token images load. Hosting providers may receive network and operational logs.
Processing can occur in countries different from the user's country. The operator must assess and disclose applicable international-transfer arrangements for its deployment.
Cookies and local storage
An HttpOnly session cookie authenticates the user and expires after 24 hours. Local storage can retain pending transaction hashes to support recovery. These are functional storage mechanisms. The bundle does not include non-essential analytics cookies.
Public records
Blockchain transactions and public IPFS token metadata can be permanent and visible to others. Removing a local listing does not delete those external records. Do not put private personal information into token metadata or an onchain memo.
Retention and rights
The operator must retain information only as reasonably necessary for the stated purposes and applicable obligations. Before production, it must establish a documented retention and deletion schedule, including backups and response text. Authentication challenges and sessions should be routinely pruned after expiry.
Depending on applicable law, users may request access, correction, deletion, restriction, or other rights using the published privacy contact. Identity verification may use a wallet signature. Mandatory records and public blockchain data may not be removable. The operator will explain applicable limits.
Security and incidents
The service uses signed wallet authentication and server-side credential handling. No system is risk-free. The operator must protect its database, keys, backups, and infrastructure and respond to incidents under applicable law. Report suspected incidents through the configured support channel; do not send private keys.
Community and observatory records
Community names, token addresses, registrant wallets, thresholds, budget statistics, deposit transaction hashes and aggregate usage are public. API key secrets are revealed once and stored as hashes; they are not published. Internal allocation references are omitted from public funding responses.
The observatory stores public token prices and block identifiers for up to 30 days and does not create a profile of a private individual from that data alone. Wallet holdings are queried from public RPC services to verify access. The operator must still consider whether combined records identify a person.
No invented retention promise
This local build has no automatic retention workflow for every accounting, session, backup or legacy response record. The operator must implement a lawful retention schedule before stating that such data is routinely deleted. A stated no-content-storage design does not mean all metadata or third-party content is erased.
Public measurements
Authenticated session heartbeats record session ID, chain-and-wallet account and last-seen time to calculate aggregate five-minute active-wallet counts. Public activity omits wallet addresses, prompts and key identifiers. Provider-credit history is published only when the operator enables the public treasury flag. Model observations are retained for 90 days and indexed market observations for 30 days. Other accounting retention remains governed by the operator retention policy. The configured PostgreSQL or Turso provider processes the hosted application database; WalletConnect/Reown processes QR pairing metadata when that optional connection method is used.