1. Who is responsible
[operator’s legal name and address] is the controller of the personal data described here. Write to us through the contact form.
2. Your wallet address is public
Using Levee means using a public blockchain. Your address, balances and every transaction you sign are visible to anyone and stay on the chain permanently. We cannot hide or delete them. Levee knows you only by that address: there is no sign-up, and we never ask for your name or email to use the app.
3. What the Levee API stores
- Ideas you post: your address, the text, market, side, the position it refers to, your signature, the time you signed it and the time we received it. Ideas are public.
- Points: your address, your total, and the activity it was counted from (kind, USD amount, a transaction, pool or order reference, the time). This is derived from public on-chain and venue activity.
- Perp set-up: your address, your Lighter account index, the order key’s index and public key, and whether it is bound. The order key itself is held, encrypted, by our signing service and is never shown to anyone.
- Request nonces: your address and a one-time number for each signed perp request, to stop a request being replayed.
- Practice perp accounts: only on a deployment that runs the simulated venue instead of Lighter, your address and the simulated balances and positions that go with it.
- The contact form: the name and the optional handle you give, your message, the time, and the IP address it came from (to deal with spam). When the operator has set one up, a copy of the name, handle, message and time - never the IP address - is also sent to the team’s notification channel, [notification service, to be named].
4. IP addresses
- Rate limits: the API counts requests per IP address to rate-limit writes and the contact form. Those counters are held only in the running server’s memory, count the last minute, and are never written to the database.
- Contact form: the IP address stored with your message is deleted automatically 30 days after the message arrives. The message itself stays (see section 9).
- Request logs: the API writes one log line per request - IP address, method, path (which can contain a wallet address), status, duration and a request id - to its hosting provider’s log store, kept for [log retention, to be confirmed with the hosting providers]. Our hosting providers also keep their own standard request logs for the same purpose.
5. What stays in your browser
Some choices are kept in your browser’s local storage and never sent to us: the light or dark theme, tour progress, that you accepted the risk notice, the authors you follow on Ideas, the address and alerts on the Alerts page, chart drawings, and which wallet you connected (so it reconnects on your next visit). Clearing your site data removes them. None of these are tracking cookies.
6. Analytics and error reports
If enabled on a deployment, Levee counts page views with a privacy-preserving analytics service that sets no cookies, does not follow you across sites and keeps no personal profile. If error reporting is enabled, a crash sends the error message and stack trace, the page path (without the query string) and the browser type - never your wallet address. Neither needs a cookie banner, and neither is used for advertising.
7. Services you talk to directly
Your browser also talks to services we do not run, under their own privacy terms: your wallet; the Robinhood Chain RPC provider, which sees your IP address and the addresses and transactions you look up; a wallet connection relay, if you connect a phone wallet by QR code; an email login provider, on builds that offer email login; and Lighter, for perp orders.
8. Why we use it
To run the features you ask for (posting ideas, counting points, routing perp orders, answering your message), to keep the service safe (rate limits, replay protection, spam), and to fix errors. We do not sell personal data, use it for advertising or build profiles. [legal bases, to be set by counsel]
9. How long we keep it
Two things are deleted automatically. Everything else is kept until someone deletes it by hand.
- Contact-form IP addresses: deleted automatically 30 days after the message arrives (a background job checks every 5 minutes).
- Request nonces: deleted automatically once their acceptance window (a few minutes) has passed.
- Contact messages (name, handle, message, time): kept, with no automatic deletion, until deleted by hand. [retention period for contact messages, to be set by counsel]
- Ideas and points: kept while Levee runs. We delete your ideas by hand if you ask.
- Perp set-up records: kept until you ask us to remove them, which we do by hand.
- Rate-limit counters: never stored; they live in memory and count only the last minute.
- Request logs: [log retention, to be confirmed with the hosting providers].
10. Your choices and rights
Depending on where you live, you may ask to see, correct or delete the personal data we hold, object to its use, or complain to a data protection authority. Ask through the contact form and give your address; we may ask you to sign a message to prove it is yours. We cannot change or delete data on the blockchain.
11. Where data is processed
The API and its database run with [hosting providers and regions]. Where data leaves your country, we rely on [transfer safeguards, to be set by counsel].
12. Children
Levee is not for anyone under 18, and we do not knowingly hold data about children.
13. Changes
We will update this page when what we store changes, and change the date at the top.