SeedVault / Privacy notice
PRIVACY NOTICE

How the pilot uses your data.

Launch-readiness item: the operator’s legal name, postal address and dedicated privacy contact must be added here before SeedVault is promoted beyond a limited pilot. Until then, do not use the service for confidential or sensitive information.

1. Scope and controller

This notice explains how the SeedVault early-access website processes personal data. The controller is the operator of the SeedVault pilot. The operator’s full legal identity is pending. For privacy requests, use the contact form. Sign in to receive a private reply in SeedVault.

2. Data SeedVault processes

  • Wallet and login data: public wallet addresses, wallet type, signed login messages, short-lived login challenges, linked-wallet records and session identifiers. SeedVault does not receive your seed phrase or private key.
  • Profile data: display name, bio, skills, specialty, availability, optional portfolio URL, optional X username and your public-directory preference.
  • Project data: project name, ticker, description, Solana, proposed allocations, roles, status, review notes and an activity record.
  • Team data: applications, offers, acceptances and receiving addresses for Solana. Receiving addresses are visible only to the relevant helper, builder and owner in the current design.
  • Optional X sign-in: when enabled and chosen, we receive your X account ID, username and display name to sign you in. We store the identity link; access tokens are not saved. We do not request email, posting, follow or direct-message permissions. X applies its own privacy terms.
  • Support data: the name, topic and message you submit, account link when signed in, reply and follow-up status. Older submissions may include a previously provided email address.
  • Technical data: request metadata and security logs that hosting and connection providers may process, such as IP address, browser details and timestamps.

3. Why data is used

Data is used to authenticate wallets, operate the pilot, save profiles and project plans, display information you choose to publish, protect accounts, prevent misuse and diagnose failures. The intended GDPR bases are performance of the pilot service you request, legitimate interests in operating and securing it, and consent for the optional public Talent Collective listing. These bases require confirmation by the final operator.

4. Public information

Published projects can be viewed by visitors. If you opt in to the Talent Collective, your chosen profile fields are public. Wallet and internal account identifiers are not intentionally shown in the public talent directory. Project participants can still see profile information needed for their project agreement. Public blockchain addresses are inherently observable on their respective networks.

5. Cookies and wallet storage

SeedVault uses an essential, secure, HTTP-only session cookie after wallet login. The current session lasts up to 24 hours and is removed from the active session store when you disconnect. Login challenges expire after about five minutes. Local browser storage remembers interface choices such as dismissing the privacy notice. SeedVault does not currently run advertising cookies or behavioural analytics.

Your wallet application may use their own connection storage and process technical information under their own notices.

6. Service providers and transfers

Cloudflare provides website hosting and the D1 database. Your chosen wallet and any external portfolio or X links are separate third-party services. These providers may process data outside the European Economic Area under their own legal mechanisms. SeedVault does not currently sell personal data.

7. Retention and security

Session records expire after 24 hours. Login challenges expire after about five minutes. Profile, linked-wallet, project and agreement data is retained while your account remains active. From My account, you can download a machine-readable copy and permanently delete the account and its related pilot records. Resolved contact messages are removed after 180 days and sanitized unexpected-error records after 30 days. Privacy and incident reports can be submitted through the contact form.

Security measures include signed-wallet authentication, hashed session tokens, secure cookies, access checks, input limits and restrictive browser security headers. No internet service is risk-free.

8. Your choices and rights

You can remove your profile from the public Talent Collective, disconnect a session, unlink eligible wallets, download your account data and permanently delete your account from My account. You can submit privacy questions through the contact page. Depending on applicable law, you may also have rights of access, correction, deletion, restriction, objection and portability, plus the right to complain to the Dutch Data Protection Authority. A dedicated request channel must still be added.

9. Children

The pilot is not intended for children. Do not submit data if you are under 18.

10. Changes

This notice may change as SeedVault adds features or identifies its final operator. Material changes should be shown on the website with a new update date.