Skip to content
stonkhouse

Privacy

What this interface sees, and what it keeps

No controller has been named.No operating entity has been designated for this interface yet. This document is in force; the gap is published rather than filled with a placeholder.

This notice covers stonkhouse.fun (this site) and app.stonkhouse.fun (the dapp). It is written from the code, not from a template: each statement below was checked against the file that implements it. It does not cover your wallet, the chain, or any third-party site linked from here.

What we process

On stonkhouse.fun

  • This site sets no cookie, writes nothing to your browser's storage, runs no analytics, has no form and loads no third-party script. Its server may request public v2 contract cards and statistics from our indexer to render the landing; that request contains no visitor wallet address.
  • The server that answers the request is a Railway service. Railway records standard HTTP logs for it: your IP address, user agent, the path requested and the time. See Retention below.

On app.stonkhouse.fun

  • Your wallet address, once you connect. It is public chain data. The dapp reads public positions and market data from the chain and the Stonkhouse indexer. A position request sends your address to that indexer, and the request host may see your IP address. There is no username or password account.
  • Browser storage. The wallet library (wagmi) keeps, in your browser's localStorage under keys beginning wagmi., which connector you last used, the addresses and chain it was connected to, and a flag recording that you disconnected. This is what lets the page reconnect on your next visit. Notification settings may also use browser push state. We set no cookie; clearing site data removes local state.
  • The HTTP request. App and API requests reach services hosted for the product. Their hosts may record standard HTTP logs including IP address, user agent, path and time. Some API paths or queries contain a wallet address.
  • Optional notifications. If you enable Telegram, browser push or email alerts, the notifier stores your wallet address, channel, encrypted destination and alert preferences. A wallet signature authorizes each settings action. Telegram linking and email confirmation verify the destination; browser push uses the browser's push subscription. You can remove a subscription in settings or unsubscribe from email.

Where it goes

These are the services we run and the outside providers a request or alert may reach:

  • RPC providers. The dapp reads the chain from your browser, so your browser talks directly to rpc.mainnet.chain.robinhood.com (Robinhood) and, as a fallback, robinhood-rpc.publicnode.com (PublicNode). They see your IP address and every call the page makes, which includes your wallet address as call data once connected. We do not proxy those requests and cannot see them.
  • The Stonkhouse indexer. A service we run for markets, orders, positions, cost basis and settlement history. It stores addresses and values derived from public chain events. The app requests address-specific positions and history when you view an account; those requests can put the address in API and host logs.
  • The Stonkhouse notifier. A service we run for alerts you choose. It stores a wallet-linked subscription, alert preferences and a channel target encrypted at rest. Delivery uses Telegram, a browser push provider or the email provider for that channel, so the destination and message reach that provider. Notification delivery records are used for retries and deduplication.
  • Keeper and operating tools. Services we run may submit quote and order transactions. A running cranker may also submit settlement and redemption transactions; it has no exclusive privilege, and another caller can submit them when the contracts allow. These transactions appear on the public chain.
  • Hosting. Railway hosts the domains and services and keeps HTTP logs as described above.
  • The explorer. Links to Blockscout open in a new tab. Following one is a visit to their site under their terms.
  • Your wallet. Whatever your wallet extension sends to its own vendor is governed by that vendor, not by this notice.

What we do not do

  • No cookies, on either domain.
  • No analytics, no tracking pixel, no session replay, no third-party script.
  • No username or password account, marketing email list or know-your-customer process. Notification email is optional and used for the alerts you select.
  • No selling or sharing of wallet-linked notification details for advertising.

Where the GDPR or the UK GDPR applies, the basis for the processing described above is the legitimate interest in operating and securing the interface (Article 6(1)(f)) — the HTTP logs exist to keep the service running and to investigate abuse. Notifications are optional and start only after you choose a channel and authorize its subscription. Wallet balances and transactions are public chain data; notification destinations and preferences are information you provide to the notifier.

Your rights

If you are in the EU, the EEA or the UK, the GDPR and the UK GDPR give you rights over personal data about you. In plain words, you can:

  • ask what personal data is held about you and get a copy;
  • ask for it to be corrected if it is wrong;
  • ask for it to be deleted, where there is no reason to keep it;
  • ask for processing to be restricted, or object to it;
  • receive it in a portable form where it was provided by you;
  • complain to your data-protection authority.

Two honest limits. First, a wallet address and its transactions are on a public chain that nobody can edit; the rights above apply to what we hold, and we cannot delete a block. Second, our services may hold HTTP logs, indexer address records and any notification subscription you chose. A notification subscription can be removed through its settings or, for email, through the unsubscribe link.

Controller: not yet designated. No legal person has yet been named as the controller for the processing described here, and whether an EU or UK representative is required has not been decided. This line will name them when that is done.

Retention

  • HTTP logs are retained by Railway for as long as Railway retains them. We have not configured a retention period of our own, longer or shorter, and we do not export the logs anywhere.
  • The indexer keeps address-level figures for as long as the chain does, because it is a replay of the chain. Dropping and rebuilding it reproduces the same rows.
  • A notifier subscription stays until you delete it, even if delivery is disabled. Deleting it also removes its queued delivery records. Expired challenges and Telegram link tokens are purged; completed delivery records are purged after 30 days.
  • Browser storage written by the wallet library lasts until you clear it. We cannot clear it for you.

Security

The domains and services are served over TLS. There is no password account. Notification channel targets are encrypted at rest with AES-256-GCM and bound to the wallet and channel; the notifier logs ids and error codes rather than targets or signatures.

International transfers

The providers named above — Railway, the RPC providers, the explorer, and, if you enable alerts, Telegram, browser-push and email delivery providers — may process data in countries other than yours, including outside the EU and the UK. We have not put transfer safeguards of our own in place beyond what those providers publish; the only data that reaches them is what this page describes.

Children

Neither domain is directed at anyone under 18, and we do not knowingly process data about anyone under 18. The terms require users to be adults.

Changes to this notice

This notice is updated in place. Changes are published on this page; there is no separate notice.

Contact

Requests about personal data go to privacy@stonkhouse.fun. The terms are at /terms, the perimeter at /legal, and the dapp this notice describes is at app.stonkhouse.fun (opens in a new tab).