Jump to section

Privacy Policy

Last updated: May 4, 2026

Version: 1.0

This Privacy Policy explains how [Entity Name] ("we", "us", "our") handles personal data when you use the @nyone frontend at [domain]. It does not govern the @nyone protocol itself, which is decentralized and not operated by any party. See Section 0.2 for the distinction.

We built @nyone as a privacy-first product. The minimum data principle isn't marketing here; it's the architecture. We collect what is strictly necessary to make the frontend work, and we delete it when you leave.

If you do not agree with this Policy, do not use the frontend. You may also access the @nyone protocol through other interfaces or directly, in which case this Policy does not apply.

0.1 Who we are

[Entity Name] is a [legal form, e.g., foundation / association / LLC] organized under the laws of [jurisdiction]. We operate the @nyone frontend at [domain] and act as data controller for personal data processed through that frontend.

Contact: [privacy@nyone.example]
Address: [Entity address]

We are a small team. Requests are handled by humans. Response times are described in Section 0.8.

0.2 Protocol vs. frontend

This distinction matters and we want to be explicit about it.

The @nyone protocol is a set of smart contracts deployed on Base chain. The contracts are immutable and have no admin keys. No party, including us, can modify the protocol, censor transactions, freeze funds, or access funds held in the shielded pool. The protocol does not collect personal data in any conventional sense.

The @nyone frontend is the website and app we operate at [domain]. It calls the protocol on your behalf and provides features like account linking, send-by-handle, and unclaimed-send notifications. The frontend collects limited personal data to function, as described below.

You can use the protocol without our frontend. Other parties may operate alternative frontends. You may also interact with the protocol directly. This Policy applies only when you use the frontend we operate.

0.3 What we collect

We collect the minimum needed for the frontend to function:

Authentication data

  • Wallet addresses you connect
  • Linked social handles (e.g., X username) when you choose to link an account
  • Email address, if you sign in with email
  • Authentication tokens from third-party providers (X, Google, MetaMask) limited to what is required to verify your identity

Routing data

  • The mapping between your authentication methods (handle, email, wallet) and your @nyone address, so that sends to your handle reach you
  • Pending unclaimed-send state, until the send is claimed or canceled

Operational data

  • IP address, used transiently for security and rate-limiting; not retained tied to your identity beyond the periods in Section 0.6
  • Device type, browser type, operating system
  • Error logs and frontend telemetry needed to diagnose issues

Communications

  • Anything you send us when contacting support

We do not collect: government-issued IDs, biometric data, precise location data, behavioral profiles, or any special-category personal data under GDPR Article 9.

0.4 What we do not collect

To make our position explicit:

  • We never have access to your private keys or seed phrases
  • We do not track you across other websites
  • We do not sell, rent, or share data with advertisers or data brokers
  • We do not use your data to train AI or machine learning models
  • We do not run third-party advertising or marketing pixels on the frontend
  • We do not require KYC for standard use of the frontend

If we ever change any of these, the change will appear in this Policy with a clear changelog and advance notice.

0.5 Why we process data, and the legal basis

PurposeLegal basis (GDPR Art. 6)
Operating the frontend (authentication, routing, account linking)Contract performance (Art. 6(1)(b))
Security, rate-limiting, abuse preventionLegitimate interest (Art. 6(1)(f))
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))
Aggregated, non-identifying analytics for product improvementLegitimate interest (Art. 6(1)(f))

We do not run consent-based marketing communications at this time. If we ever do, they will be opt-in only and clearly labeled.

You can object to processing based on legitimate interest at any time. See Section 0.8.

0.6 How long we keep data

We keep data only as long as needed:

  • Authentication and routing data: retained while your account exists. Deleted within 24 hours of account deletion. Backups containing this data are purged within 30 days.
  • IP addresses and security logs: up to 90 days, then deleted or fully anonymized.
  • Error and telemetry logs: up to 90 days. Aggregated only, not tied to user identity beyond 7 days.
  • Support communications: up to 24 months after the issue is resolved.
  • Data we are legally required to retain: kept for the period required by applicable law (e.g., financial record-keeping obligations). We will not extend retention beyond what the law requires.

On-chain data is permanent and outside our control. Transactions on Base chain cannot be deleted by us or anyone else. The @nyone protocol uses zero-knowledge proofs and a shielded pool to keep transaction details private from public observers, but the encrypted on-chain data itself is permanent.

0.7 Who we share data with

We share data only with parties strictly necessary to operate the frontend:

  • Infrastructure providers (hosting, databases, monitoring): [list, e.g., Cloudflare, AWS, Supabase]. These providers process data on our instructions under data processing agreements.
  • Authentication providers: X (Twitter), Google, MetaMask, when you choose to sign in through them. Their handling of your data is governed by their own policies.
  • Legal authorities: when required by valid legal process. We will challenge overbroad or unlawful requests where we have grounds to do so.

We do not share data with advertisers, marketers, or data brokers.

International transfers, where they occur, are protected by Standard Contractual Clauses or equivalent mechanisms.

0.8 Your rights

Under GDPR and similar laws, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten"), subject to the legal retention exceptions in Section 0.6
  • Restrict processing
  • Object to processing based on legitimate interest
  • Portability — receive your data in a structured, machine-readable format
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with your local data protection authority

To exercise any right, email [privacy@nyone.example]. We will respond within 30 days. Most requests are handled within 7 days because we keep deliberately little data.

On-chain data cannot be erased. This is a property of public blockchains, not a limitation we can remove. The privacy-preserving design of the protocol means on-chain data does not directly reveal your identity, but the data itself is permanent.

0.9 Security

We implement technical and organizational measures appropriate to the risk:

  • TLS 1.3 for data in transit
  • Encryption at rest for stored personal data
  • Access controls and authentication for internal systems
  • Regular security review of the frontend codebase
  • Privacy-preserving cryptography (zero-knowledge proofs) at the protocol level
  • Incident response with notification to affected users and regulators within 72 hours of a confirmed breach, as required by GDPR Article 33

No system is perfectly secure. We cannot guarantee absolute security, but we treat your data with the care a privacy-first product requires.

1.0 Cookies and similar technologies

We use a minimal set:

  • Strictly necessary: session, authentication, security. Cannot be disabled.
  • Functional: remembers preferences (theme, language). Optional.
  • Aggregated analytics: privacy-respecting, no cross-site tracking, no advertising IDs. Off by default in jurisdictions where consent is required.

Manage preferences through our cookie banner or your browser settings.

1.1 Threat model and limits of privacy

We want users to have an accurate picture of what the privacy of @nyone does and does not cover.

The protocol's privacy depends on:

  • The cryptographic assumptions behind the zero-knowledge proofs (currently considered secure)
  • The size and behavior of the anonymity set in the shielded pool
  • User behavior, particularly at the deposit and withdrawal edges of the shielded pool, where on-chain links to known wallets are visible

The frontend's privacy depends on:

  • Our operational security
  • The minimal-data architecture described in this Policy
  • Real deletion of off-chain data on request

Risks we cannot eliminate:

  • On-chain data is permanent. Future advances in cryptography or computing could, in principle, weaken assumptions that protect today's transactions. We use current best-practice cryptography but make no claim of post-quantum security.
  • Frontend operators (us) can be subject to legal compulsion. The off-chain data we hold could be requested by authorities. The minimal-data architecture limits what we could be compelled to disclose.
  • Users who want stronger guarantees can interact with the protocol via alternative frontends or directly.

We will update this section as the threat model evolves.

1.2 Children

The frontend is not intended for individuals under 18. We do not knowingly collect data from children. If you believe we have, contact us and we will delete it.

1.3 International users

The frontend is operated from [jurisdiction]. If you access it from elsewhere, your data may be transferred to and processed in [jurisdiction]. Where data is shared with processors outside the EU, we use Standard Contractual Clauses or equivalent mechanisms.

1.4 Changes to this Policy

We may update this Policy. Material changes will be communicated via the frontend, by email where we have your address, and by a prominent notice. The "Last updated" date at the top reflects the most recent revision. We maintain a public changelog at [changelog URL] so you can see exactly what changed and when.

Continued use of the frontend after changes take effect constitutes acceptance of the updated Policy.

1.5 Contact

Email: [privacy@nyone.example]
Address: [Entity address]

For complaints, you can also contact your local EU data protection authority. A list is available at edpb.europa.eu.

Before publishing — placeholders to resolve

  • All [bracketed placeholders] need real values (entity name, domain, address, emails)
  • Confirm entity name, legal form, and jurisdiction (requires actual incorporation)
  • Verify the actual list of infrastructure providers (Section 0.7)
  • Confirm retention periods match what your systems actually do (Section 0.6)
  • Confirm legal-retention obligations with counsel, especially AML/financial record-keeping
  • Adjust the cookie section to match what you actually use
  • Build the changelog page referenced in Section 1.4
  • Have a privacy lawyer review — especially Sections 0.5, 0.6, 1.1, and the protocol/frontend distinction in 0.2