Privacy Policy

Last updated: July 26, 2026

This Privacy Policy explains what personal data we process when you use the Crypto Hodlers website, why we process it, who we share it with, and what rights you have.

1. About this Policy

This Privacy Policy ("Policy") sits alongside our Terms and Conditions, available on the Website at /terms. Defined terms used in the Terms — such as "Hodler NFT", "Project IP", and "Hodler Lab team" — have the same meaning in this Policy.

The Crypto Hodlers project ("Crypto Hodlers", "Hodler Lab team", "we", "us", or "our") is operated by the Hodler Lab team from Ukraine. For the purposes of the Ukrainian Law "On Personal Data Protection" and, where applicable, the EU General Data Protection Regulation ("GDPR"), we are the controller of the personal data we process through the Website. You can reach us through the channels listed in Section 14.

We have written this Policy in plain language. Where a section uses legal terms with a specific meaning under Ukrainian law or the GDPR, we have tried to flag them; if anything is unclear, please contact us.

2. What we collect

The Website is, by design, a low-data product. We do not run analytics that profile your behavior, we do not host user-uploaded files, and we do not ask you to enter personal information like an email, phone number, real name, or postal address. The data we process falls into a small set of categories.

Wallet data

  • Wallet addresses you connect to the Website, and any additional wallets you link to your account.
  • Cryptographic signatures you produce when signing in or linking a wallet, together with the short, single-use challenge message we issue for that purpose. Signatures are used to verify that you control the wallet and are not retained beyond what is needed for the verification.
  • ENS names that resolve from connected wallets — read from the public blockchain at the time of display, not stored by us as a separate identifier.

Account session data

  • A JSON Web Token ("JWT") issued after you sign in, stored in your browser's local storage. The token expires after one day. It encodes your wallet address and an account identifier; it does not encode any sensitive personal data.
  • Wallet connection state stored by the wallet library in a browser cookie, used to remember that you have a wallet connected between page loads. This cookie is functional, not analytics.

Optional linked accounts

  • If you choose to link your X (Twitter) account, we store the X account identifier so we can display it on your public Crypto Hodlers profile.
  • If you choose to link your Discord account, we store the Discord account identifier so we can sync server roles and compute Memories (the Website's name for the achievements you earn through gameplay, on-chain holdings, and public social signals) based on your public activity in our official Discord server. The Discord identifier itself is never displayed publicly on your profile.

Gameplay and Memories

  • Records of your participation in interactive features we offer on the Website — for example, scores and round counts in our games, and any Memories you have earned. Memories are derived from data we already process: your in-game activity, your public activity on linked social accounts where applicable (Discord server activity, the fact that you have linked X), and the Hodler NFTs your linked wallets hold on chain.

Profile preferences

  • The Hodler NFT you choose as your avatar — a pointer to a token you already own on chain, not an image uploaded by you.
  • The banner you choose from a preset gallery we host — a small identifier indicating which option you picked.

Server operational data

Standard server logs (request URL, HTTP method, response status, timing, error traces). Logs are sanitized before being written: passwords, tokens, signatures, challenges, IP addresses, user agents, and similar sensitive values are masked. Wallet addresses may appear in logs as part of API paths.

3. What we do not collect

We want to be specific about what is not collected, because it shapes everything else in this Policy. We do not collect, and we have no plans to collect:

  • email addresses;
  • phone numbers;
  • real names, dates of birth, or any other identity-document information;
  • postal addresses or precise location data;
  • payment card details or bank account information;
  • government-issued identifiers (passport numbers, national IDs, tax IDs);
  • biometric data;
  • files, images, or other content uploaded by you — the Website provides no mechanism for you to upload anything; everything we display on your profile is either selected from options we host, chosen from NFTs you already own on chain, or pulled from public on-chain data;
  • free-text fields filled in by you — the Website does not currently provide any such fields; the only "name" shown alongside your account is your wallet address or its ENS name.

If we ever start to collect a new category of data, we will update this Policy and, where required by law, ask for your consent before doing so.

4. What is public, and what is not

Some of the data we process is shown openly on your Crypto Hodlers profile and is therefore visible to anyone who can view the profile. Other data is held internally and never publicly displayed.

Public on your profile

  • The wallet addresses you have connected and linked to your account.
  • The avatar Hodler NFT you have chosen.
  • The banner option you have selected.
  • The X account identifier you have linked, if any.
  • Your gameplay scores and rankings, displayed on public leaderboards on the relevant game pages and visible to anyone.
  • All Memories you have earned, displayed in a public Memories section on your profile.

Private, never displayed publicly

The Discord account identifier you have linked, if any. We never reveal "this Crypto Hodlers profile belongs to Discord user X." The Discord identifier is used only to compute Memories from your public Discord activity in our official server and to keep server roles in sync; it is not surfaced on the Website.

On-chain data

Anything that is already on a public blockchain — your wallet's holdings, transfers, and royalty-share claims — is visible to anyone on the internet through any blockchain explorer, regardless of what we do.

5. How we use this data

We process the data described in Section 2 only for the following purposes, and on the legal bases noted next to each.

To sign you in and run your account

We use your wallet address, the challenge, and your signature to verify ownership of the wallet and to issue a session token. We store the account record, your linked wallets, and your profile preferences so the Website can work across sessions. Legal basis: performance of a contract (our Terms) — GDPR Article 6(1)(b).

To deliver Discord-based features

If you link your Discord account, we read your public activity in our official Discord server to compute Memories, and we maintain server roles tied to your wallet holdings. We never read your direct messages, your activity in private channels, or your activity in any other Discord server — Discord's API does not give us access to those things, and we do not request such access. Legal basis: your consent at the point of linking; you can disconnect Discord at any time — GDPR Article 6(1)(a).

To display your X handle

If you link your X account, we store the X account identifier and display it on your profile. Legal basis: your consent — GDPR Article 6(1)(a).

To run game features, leaderboards, and Memories

We store the results of your participation in games and similar interactive features on the Website (such as scores, rounds played, and best results) and rank them on public leaderboards on the relevant game pages. We also compute Memories, aggregated from your in-game activity, your social signals (your public activity in our official Discord server where you have linked Discord, and the fact that you have linked X), and your on-chain collection progress (the Hodler NFTs your linked wallets hold); all of these Memories are displayed in a public Memories section on your profile. Legal basis: performance of a contract (our Terms) for the game and Memories features themselves — GDPR Article 6(1)(b); the underlying linked-account inputs rely on the consent you gave when linking the relevant account, as described above.

To keep the Website secure and prevent abuse

We use server logs, nonces, and rate-limiting signals to detect and prevent abuse, fraud, and attacks. Legal basis: our legitimate interest in operating a secure service — GDPR Article 6(1)(f).

To comply with law

Where applicable law requires us to retain or disclose data, we do so. Legal basis: legal obligation — GDPR Article 6(1)(c).

We do not use your data for behavioral profiling, advertising targeting, or automated decision-making that produces legal effects on you.

6. On-chain data

A significant part of the Website is a window onto data that already lives on a public blockchain — your holdings of Hodler NFTs, your transfers, and your interactions with the Royalty Share Contract described in Section 8 of the Terms. We read this data through standard blockchain queries when you visit the Website, and we display it back to you and, in places, to other visitors.

We do not control on-chain data. We cannot delete it, edit it, or make it private — that is a property of the blockchain itself, not a policy choice we can make for you. If you do not want a particular activity to be publicly associated with your wallet, the only effective remedy is not to perform that activity on chain.

7. Storage in your browser

We use a small number of items of browser storage, each essential to the operation of the Website and none used for analytics or tracking:

  • a JWT in local storage, issued after you sign in, which allows the Website to recognise you between page loads, expires after one day, and is removed when you disconnect your wallet or sign out;
  • a wallet-connection-state cookie set by the wallet library, which allows the Website to remember that you have a wallet connected;
  • a small set of UI preferences in local storage — purely cosmetic choices about how the Website displays things to you (for example, which art edition of the Hodler NFTs to show on certain pages). These preferences live in your browser, are not bound to your account on our server, and are not used for analytics or tracking.

The JWT and the wallet cookie are strictly necessary for the Website to function — you cannot sign in or have your wallet remembered across page loads without them. The UI preferences are saved only when you change a default display setting, so the Website can remember your choice on your next visit. Both categories — strictly necessary storage and user-interface customisation storage — are exempt from separate consent under Ukrainian law and Article 5(3) of the EU ePrivacy Directive, so we do not display a consent banner. We do not set any non-essential cookies; in particular, we have disabled the optional analytics features of the wallet library.

If you clear your browser storage, you will be signed out and the Website will forget your wallet connection on its next load.

8. Third parties we use

We rely on a small number of third-party services to make the Website work. We have grouped them by what kind of data, if any, reaches them.

Your wallet application

To use the Website you connect a self-custodial crypto wallet of your choice — for example MetaMask, Coinbase Wallet, Glyph, or any other wallet that supports the standard EIP-1193 interface or the WalletConnect protocol. Each wallet is software operated by a third party under its own terms and privacy policy. It is the wallet — not us — that holds your private keys, signs and broadcasts your transactions, and decides what telemetry, RPC endpoints, or analytics to use internally. We do not see what data your wallet collects or sends to its own servers, we do not control the infrastructure it uses, and we are not responsible for the wallet's handling of your data. Before connecting a wallet you do not already trust, you should read its own privacy policy.

Read-only blockchain infrastructure

We use blockchain data providers (for example, Alchemy) to read public on-chain information — token ownership, transfers, contract events. We query these providers with wallet addresses, which are themselves public on-chain identifiers. We do not send them any other data we hold about you: no Discord identifier, no X identifier, no Memories, no profile preferences, no session token, nothing about your account. If we add or change blockchain data providers in the future, this principle continues to apply.

Wallet connection protocol

When you connect a wallet to the Website, your wallet and the Website exchange messages through the WalletConnect protocol, which is operated by Reown and its relay infrastructure. We have disabled Reown's optional analytics feature, so we do not send behavioral telemetry to them. Reown may still see basic protocol-level information necessary to relay messages between your wallet and the Website.

X (when you link your X account)

If you choose to link X to your Crypto Hodlers profile, X receives the standard OAuth signals required to authenticate you, governed by X's own privacy policy. We receive, in return, the X account identifier we display on your profile.

Discord (when you link your Discord account, and via our Discord bot)

If you choose to link Discord, Discord receives the standard OAuth signals required to authenticate you, governed by Discord's own privacy policy. We receive your Discord account identifier and, via our Discord bot operating in our official server with standard server permissions, read public activity in that server in order to compute Memories and maintain roles.

Third-party marketplaces

When you buy, sell, or transfer a Hodler NFT through a third-party marketplace (for example, OpenSea), that marketplace is operated under its own terms and privacy policy. We are not a party to those transactions and have no control over what data those marketplaces collect.

Our hosting and infrastructure providers

We host the Website and our server on infrastructure located in the European Union and/or Ukraine. Hosting providers process data only as our processors and only to the extent necessary to run the service.

General principle for future providers

We may add or change service providers in the future. As a general principle, when we use third-party infrastructure we send only what is strictly necessary to perform the operation in question, and we do not share information we hold about you with parties who do not need it. If our practices ever change in a way that meaningfully affects your privacy, we will update this Policy.

9. International transfers

We host the Website and our server in the European Union and/or Ukraine, so the bulk of the data we process stays within the EU/EEA and Ukraine. Some of the third parties listed in Section 8 — including Alchemy, Reown, X, and Discord — are based in the United States or operate globally, which means that limited categories of data may be transferred outside the EU/EEA.

For those transfers we rely on the data-protection safeguards built into those providers' terms (most commonly the European Commission's Standard Contractual Clauses, together with the providers' own privacy programmes). We do not transfer to any third party more data than is necessary for the operation described in Section 8.

10. How long we keep data

We keep personal data for as long as we have a purpose to keep it, and no longer.

  • Active accounts: we keep your account record (linked wallets, profile preferences, optional linked identifiers) for as long as your account exists.
  • Disconnected wallets and removed links: if you remove a linked wallet, an X link, or a Discord link, we delete the corresponding identifier from your account record. Where required for security or audit purposes, we may keep a minimal record of the removal itself for a short period.
  • Account deletion: you can ask us to delete your account through the channels in Section 14. We will delete or anonymise your account record except where we are required by law to keep it. On-chain data associated with your wallet is, as explained in Section 6, outside our control.
  • Session tokens: JWT session tokens expire automatically after one day.
  • Challenges and nonces: single-use challenges and nonces issued during sign-in or wallet linking expire shortly after issuance.
  • Server logs: sanitized logs are kept for a limited period — typically no more than a few months — and are then rotated.
  • Gameplay and Memories records: we keep them for as long as your account exists, so your scores remain visible on public leaderboards and your Memories remain available to you and, where applicable, on your public profile. If you ask us to delete your account, the account and its aggregated records are deleted. We may still display on-chain ownership Memories for individual wallet addresses, but those are computed entirely from public blockchain data that anyone can read directly — they aggregate public information rather than expose anything we hold (see Section 6).

11. Security

We use industry-standard practices to keep the Website and our server secure. In particular:

  • sign-in is based on cryptographic signatures from your own wallet — we do not store passwords;
  • session tokens are stateless JWTs signed with RS256 (asymmetric RSA signing) and held only in your browser — we do not keep a server-side session record; when you disconnect your wallet or the token no longer matches the connected wallet, your browser clears the token and the session ends;
  • server logs are sanitized to mask sensitive values before they are written;
  • all data transfers between your browser and our server happen over HTTPS.

No service connected to the public internet is ever perfectly secure. If we become aware of a personal-data breach that meets the notification threshold under applicable law, we will notify the relevant supervisory authority and any affected users in line with our legal obligations.

12. Your rights

Subject to applicable law — primarily the Ukrainian Law "On Personal Data Protection" and, where you are in the EU/EEA, the GDPR — you have the following rights in relation to the personal data we hold about you:

  • Access — you can ask us what personal data we hold about you and obtain a copy of it.
  • Rectification — you can ask us to correct inaccurate or incomplete data.
  • Erasure — you can ask us to delete your account data, subject to the limits in Section 10 and the on-chain caveat in Section 6.
  • Restriction — you can ask us to restrict our processing in certain circumstances.
  • Portability — for data you have provided to us that we process on the basis of consent or contract, you can ask for it in a structured, machine-readable format.
  • Objection — you can object to processing based on our legitimate interests (Section 5).
  • Withdraw consent — for processing based on your consent (Discord linking, X linking), you can withdraw consent at any time by disconnecting the relevant account; withdrawal does not affect processing carried out before the withdrawal.
  • Lodge a complaint — you have the right to lodge a complaint with your local data-protection authority. In Ukraine, that is the Ukrainian Parliament Commissioner for Human Rights. In the EU/EEA, it is the supervisory authority of the member state where you live or where the alleged infringement took place.

To exercise any of these rights, contact us through the channels in Section 14. We will respond within the time limits set by applicable law, typically within thirty (30) days, and may extend that period where the request is complex.

Because we identify accounts by wallet ownership, we may ask you to confirm a request by signing a short message with the wallet associated with the account.

13. Children

The Website and the Hodler NFTs are intended for adults. As stated in Section 2 of the Terms, you must be at least 18 years old to use the Website. We do not knowingly process personal data of anyone under 18. If you believe a child has used the Website, contact us and we will investigate and, where appropriate, delete the data.

14. How to contact us

You can reach us:

  • by email at apxu@hodlerlab.com, with a clear subject line indicating that your message relates to privacy (for example, "Data access request");
  • through our official Discord server, linked from the Website footer.

For legal notices, including the formal dispute mechanism described in Section 21 of the Terms, please use the email address above.

15. Changes to this Policy

We may update this Policy from time to time. When we make a material change, we will update the "Last updated" date at the top of the page and, where reasonably practical, give notice through the Website or our official channels. Your continued use of the Website after a change takes effect means you accept the updated Policy. If you do not accept a change, your remedy is to stop using the Website and, if you wish, ask us to delete your account.