Privacy Policy

Effective date: July 18, 2026

This Privacy Policy explains what information V3R1 (“V3R1”, “we”, “us”) collects when you use v3r1.app and related services (the “Service”), how we use and share it, and the choices you have. It is part of our Terms of Service. By using the Service you agree to this policy. For any privacy request or question, contact captainv3r1@proton.me.

1. Information you provide

  • Account data: email address, username, and a password (stored only as a secure hash by our authentication provider). If you sign in with Google, we receive your email address and basic profile information from Google instead of a password.
  • Security data: if you enable two-factor authentication, your authenticator enrollment is held by our authentication provider, and recovery codes are stored only as one-way hashes. We never see or store your authenticator secrets or codes in readable form.
  • Wallet addresses: if you link a wallet, we store the address and a history of address changes. We never receive or store private keys or seed phrases.
  • Content: discussion posts, theories, replies, likes, market proposals, dispute reports, and anything else you submit.
  • Preferences: notification settings, and any referral code you enter at signup.
  • Correspondence: emails you send us, including support and privacy requests.

2. Information collected automatically

  • Usage and performance analytics via Vercel Web Analytics and Speed Insights. These are aggregated, privacy-respecting measurements (page views, referrers, device and browser class, performance timings) and do not use cross-site tracking cookies or build advertising profiles.
  • Google Analytics: we also use Google Analytics to understand how the Service is used (pages visited, approximate location, device and browser type). It sets first-party cookies (the _ga family, Section 4) to recognize returning visitors. We use it for usage measurement only, not for advertising, and we do not feed it your account identity.
  • Hosting and security logs: our infrastructure providers record standard server logs (such as IP address, user agent, and requested pages) used for delivery, rate limiting, security, and abuse prevention.
  • Marketing attribution: if you first arrive on a link that carries campaign or referral parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content, ref, gclid, fbclid), we save those values in a first-touch cookie and, if you sign up, record them with your profile so referrals and campaigns can be credited. No other browsing history is collected for this.
  • Email delivery records: which notification emails we sent you and their delivery status, used to prevent duplicates and respect your preferences.

3. Blockchain data is public

Trades, pledges, redemptions, refunds, and other on-chain actions are recorded on the public Base blockchain, permanently and outside our control. Wallet addresses and their full transaction history are publicly visible to anyone, and we (and third parties such as block explorers and analytics sites, including our public Dune dashboard) read, index, and display that public data. If you link a wallet to your V3R1 account or share your username alongside your address, your on-chain activity may become associable with your account or identity. Blockchain records cannot be edited or deleted by us or anyone.

4. Cookies and local storage

We use a small set of cookies and browser storage, none of them for advertising:

  • Authentication cookies (essential): keep you signed in; set by our authentication provider (Supabase).
  • v3r1_attr (attribution): first-touch marketing and referral parameters described in Section 2, stored as a small JSON value.
  • v3r1_oauth_intent (essential, expires in about 10 minutes): remembers whether you chose sign in or sign up when using Google, so accounts are not created by accident.
  • Wallet connection state (essential): the wallet library (wagmi) stores your last connection so your wallet reconnects smoothly.
  • _ga and _ga_* (analytics): first-party Google Analytics cookies that distinguish visitors so usage can be measured (Section 2).
  • Local storage kept on your device only and never sent to our servers: your favorites (v3r1_favs) and watchlist (v3r1_watch).

You can clear or block cookies in your browser; essential ones are required for sign-in and wallet features to work.

5. How we use information

  • to provide and operate the Service, including accounts, markets, and portfolios;
  • to mirror and display public blockchain activity (positions, leaderboards, derived statistics such as Character Scores);
  • to send transactional and notification emails according to your preferences. Security notifications (such as password changes or two-factor removal) are always sent. Optional categories have unsubscribe links and account toggles;
  • to credit referrals and operate the affiliate program;
  • to secure the Service: authentication, two-factor enforcement, rate limiting, fraud and abuse prevention, and debugging;
  • to comply with legal obligations and enforce our Terms;
  • to understand aggregate usage and improve the product.

We do not sell personal information, and we do not use it for targeted advertising.

6. Legal bases (EEA and UK users)

Where the GDPR or UK GDPR applies, we process personal data on these bases: performance of a contract (operating your account and the Service); legitimate interests (security, abuse prevention, aggregate analytics, referral attribution) balanced against your rights; consent where required (optional email categories); and legal obligation (compliance, responding to lawful requests).

7. How we share information

  • Service providers (processors) that host and run the Service on our behalf: Supabase (database and authentication), Vercel (hosting and the analytics described above), and Resend (email delivery). They process data under their own security and privacy commitments and our instructions.
  • Google, in two limited roles: to authenticate you if you choose Google sign-in, and as our analytics provider processing the usage data described in Section 2 (both governed by Google’s privacy policy).
  • The public: content you post, your username, public leaderboard entries, and all on-chain data (Section 3).
  • Legal and safety: we may disclose information to comply with law, lawful requests, or legal process, or to protect the rights, safety, and property of V3R1, our users, or others.
  • Business transfers: if the Service or its assets are transferred or reorganized, data may transfer with them under this policy’s protections.

8. Data retention

We keep account data while your account exists. Content you posted, email logs, security and attribution records are kept as long as needed for the purposes above, then deleted or anonymized. Some records may be retained longer where required for legal, security, dispute, or accounting reasons. Public blockchain data is permanent and outside any retention policy we could apply.

9. Security

We protect data with encryption in transit, hashed passwords and recovery codes, database row-level access controls, service-role isolation for sensitive tables, and optional two-factor authentication that the Service enforces at every login once enabled. No system is perfectly secure; protect your own credentials and wallet, and contact us immediately at captainv3r1@proton.me if you suspect unauthorized access.

10. Your rights and choices

  • Access, correction, export, deletion: you can change your username, email, and password in account settings. For a copy of your data or deletion of your account and associated personal data, email captainv3r1@proton.me from your account email. We verify and answer within the time required by applicable law.
  • Email: manage optional notifications in account settings or via the unsubscribe link in any optional email. Security emails cannot be disabled while you hold an account.
  • Cookies: see Section 4.
  • Limits: we cannot delete or alter blockchain records (Section 3), and we may retain what Section 8 describes. Deleting your account removes your profile and personal records from the app database; public on-chain history remains.
  • EEA/UK: you also have rights to object, restrict processing, and withdraw consent, and to complain to your local supervisory authority.
  • California: the CCPA/CPRA gives you rights to know, delete, correct, and to be free from discrimination for exercising them. We do not sell or share personal information as those terms are defined in the CPRA, and we do not use sensitive personal information beyond what is necessary to provide the Service.

11. International transfers

The Service is operated from the United States and our providers process data in the United States and other countries. Where required, transfers rely on appropriate safeguards such as standard contractual clauses implemented by our processors. By using the Service you understand your information will be processed in the United States.

12. Children

The Service is for adults. It is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it and close the account. If you believe a minor is using the Service, contact us.

13. Changes to this policy

We may update this policy from time to time. Material changes will be announced on the Service (and, where appropriate, by email) with an updated effective date. Your continued use of the Service after changes take effect means the updated policy applies.

14. Contact

Privacy questions and requests: captainv3r1@proton.me. Please write from the email address on your account so we can verify the request.

Also see the Terms of Service.