Local fork

DRAFT FOR LAWYER REVIEW. NOT LEGAL ADVICE. This document was drafted without legal counsel as a starting point for review by a qualified lawyer. It must not be published or relied on until it has been reviewed and approved. Text in [SQUARE BRACKETS] is a placeholder or an open decision. Paragraphs marked [DRAFTING NOTE] are notes to the reviewer and must be removed before publication. Sections marked [IF USED] describe processing the prototype does not do yet; keep them only if it is switched on before launch, and delete them otherwise.

Placeholders to fill: [ENTITY NAME], [ENTITY TYPE], [REGISTERED ADDRESS], [JURISDICTION OF INCORPORATION], [PRIVACY EMAIL], [SECURITY EMAIL], [EU REPRESENTATIVE], [UK REPRESENTATIVE], [LEAD SUPERVISORY AUTHORITY], [HOSTING PROVIDER], [HOST LOG RETENTION], [RPC PROVIDER], [ANALYTICS PROVIDER], [ERROR MONITORING PROVIDER], [DATABASE PROVIDER], [SCREENING PROVIDER], [SUPPORT CHANNEL], [ANNOUNCEMENTS CHANNEL], [EFFECTIVE DATE], and the retention periods marked [RETENTION: …].

Privacy Policy

Effective [EFFECTIVE DATE].

Doubt, at doubt.family, is operated by [ENTITY NAME]. This policy explains what information the Doubt website handles, which third parties receive it, our retention periods, and the rights you have over it.

The short version: there are no accounts, no names, no emails and no identity checks. The main thing Doubt sees is your wallet address, which it needs in order to show your balances and build your transactions. Your on-chain activity is recorded on a public ledger that nobody, including us, can edit or erase. Some third parties, especially the RPC node your browser talks to, see more than we do, and we say which ones below.


1. Who is responsible

[ENTITY NAME], a [ENTITY TYPE] organised under the laws of [JURISDICTION OF INCORPORATION], with its registered address at [REGISTERED ADDRESS], is the controller of the personal data described in this policy. You can reach us about anything in this policy at [PRIVACY EMAIL].

[If required: our representative in the European Union is [EU REPRESENTATIVE] and our representative in the United Kingdom is [UK REPRESENTATIVE].]

This policy covers the Doubt website and the servers that run it. It does not cover the smart contracts on Robinhood Chain, the chain itself, your wallet, or any third-party service, each of which is responsible for its own processing.

2. What we do not collect

  • No accounts. There is no sign-up, login, password or profile.
  • No identity checks. We do not ask for your name, email, phone number, date of birth, ID documents or selfie, and we do not run KYC.
  • No sensitive data. Doubt has no reason to handle data about your health, biometrics, ethnicity, religion or politics, and we do not seek it. Please do not send us any.
  • No sale of data. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
  • No advertising trackers. We do not use advertising pixels, retargeting, or advertising cookies.

3. Your wallet address

A wallet address is a pseudonym, not an anonymous identifier. We have no name to attach to it, but anyone who can link an address to you, for example because you used it on an exchange or posted it publicly, can then see its whole on-chain history. Under laws such as the GDPR, a wallet address can be personal data, and we treat it as such.

When you connect a wallet, the interface learns its public address. It uses the address to:

  • read your coin and USDG balances, your deposits, and your shorts from the chain;
  • show you your positions, debts, estimated fees and liquidation prices;
  • build the transactions and signature requests that you then approve in your wallet; and
  • [IF USED] check the address against sanctions or blocklists before allowing a Deposit or Open short.

The address is held in your browser while the page is open. Your wallet connection library may remember which wallet you last used (see section 8). The address leaves your browser in the places listed in section 5.

We never receive your private key or recovery phrase, and we will never ask for them.

4. On-chain data is public and permanent

Every Deposit, withdrawal, short, close, liquidation, approval and signature you send to Robinhood Chain is recorded on a public blockchain. That includes your address, the amounts, the coin, the time, and the Contracts you interacted with. Anyone can read it, copy it and analyse it, and block explorers, indexers and analytics firms do.

We do not control the blockchain. We cannot delete, change, hide or restrict anything recorded on it, and neither can anyone else. This is a real limit on your rights to erasure, rectification and restriction in section 16. What we can do is stop showing information in our interface and delete or restrict any off-chain copies we hold.

We read public on-chain data to run Doubt, for example to show market sizes, prices, positions and history. [We may run an indexer that stores a copy of public on-chain events, such as price readings and market activity, on our servers to power charts and history.] That data is already public, but it may include wallet addresses.

5. Where your information goes when you use Doubt

The RPC node. To read from and send to Robinhood Chain, your browser connects directly to an RPC node, which is [RPC PROVIDER / Robinhood Chain's public RPC endpoint unless configured otherwise]. Because your browser connects directly, that provider sees your IP address, browser user agent, wallet address, and every query the interface makes for you, as well as any transaction you broadcast. This is the largest disclosure that using Doubt causes, and the provider's own privacy policy governs it. Your wallet may also use its own RPC node when you sign.

Our servers. Some requests go through our own servers, which are hosted by [HOSTING PROVIDER]:

  • Token search. When you search for a token, your search text goes to our server, which looks it up with GeckoTerminal and checks the result on-chain. Your wallet address is not included.
  • Token logos and names. Logos and token details are fetched by our server from GeckoTerminal and, if GeckoTerminal has none, from DexScreener, and cached. Your browser loads the logo from our server, not from them, so they see our server's address, not yours, and they do not receive your wallet address.
  • Price history. Charts are served from our server using on-chain data.

Our host records standard request logs, including IP addresses, user agents, requested URLs, and timestamps, as any web host does. These logs are kept for [HOST LOG RETENTION] under the host's terms.

Your wallet. Your wallet app receives the transactions and messages you are asked to sign. Doubt currently offers browser-extension wallets (such as Rabby, MetaMask and Phantom) and Coinbase Wallet. Neither uses WalletConnect, and Doubt does not contact WalletConnect or Reown.

[IF USED] WalletConnect. WalletConnect is not offered at the moment. It is switched on only if we configure a WalletConnect (Reown) project ID. If we do, and you choose to connect using WalletConnect, the connection goes through a relay run by Reown, and loading the WalletConnect option may fetch code, images and configuration from Reown's servers, which may collect their own usage data. Browser-extension wallets still do not use WalletConnect.

[IF USED] Analytics. See section 6.

[IF USED] Error reports. See section 7.

[IF USED] Terms acceptance. See section 9.

6. Analytics [IF USED]

We use [ANALYTICS PROVIDER] to understand how people use Doubt, for example which pages are visited, which buttons are pressed, which errors occur, and roughly where visitors come from, so we can fix problems and improve the product. This data includes [page URLs, referrer, browser and device type, approximate country derived from IP address, and events such as "opened Open short panel"]. [We do not send your wallet address to our analytics provider. / We send a hashed wallet address to connect events from the same wallet.] [Our provider does not set cookies and does not store full IP addresses.] [Analytics cookies are only set if you consent, and you can withdraw consent at any time in [cookie settings].]

We do not use analytics data to identify you, to build advertising profiles, or to make decisions about you.

7. Error reports and diagnostics [IF USED]

When something in the interface breaks, we may record a report so we can fix it. A report can include the error message and stack trace, the page path, the app version, the browser type, the time, and, if the error happened during a transaction, the action you were attempting, the market, [your wallet address,] and the error returned by your wallet or the chain. [Reports are stored with [ERROR MONITORING PROVIDER / DATABASE PROVIDER].] We use them only to diagnose and fix problems, and we keep them for [RETENTION: e.g. 30 days].

8. Cookies and browser storage

We do not use advertising or tracking cookies. The interface and the wallet libraries it uses store a small amount of information in your browser's local storage so that it works properly, for example:

  • which wallet you last connected with, and whether you were connected, so it can reconnect you;
  • the selected network;
  • [IF USED] if WalletConnect is enabled and you use it, session data that keeps your wallet paired; and
  • [interface preferences such as theme, and whether you dismissed a notice].

[IF USED: [ANALYTICS PROVIDER] sets [describe cookies], only with your consent where the law requires it.]

This information stays in your browser and is not sent to us. You can remove it at any time by disconnecting your wallet or deleting doubt.family's site data in your browser settings. Strictly necessary storage does not need consent in most jurisdictions; if we add any storage that does, we will ask first.

Do Not Track and Global Privacy Control. We do not track you across other sites. [If we use analytics that the law treats as "sharing", we will honour Global Privacy Control signals.]

9. Terms acceptance record and location checks [IF USED]

Signed acceptance. Before your first Deposit or Open short, your wallet may be asked to sign a message confirming your acceptance of the Terms of Service and that you are outside the restricted jurisdictions. We store a record of that signature consisting of: your wallet address, the version of the terms, the time, the signed text, the signature, and [the two-letter country code of your connection]. [We do not store your IP address in this record.] We keep it to prove that you agreed to the terms and to establish, exercise or defend legal claims.

Location checks. To enforce the restrictions in the Terms of Service, our server may read the country associated with your connection, as reported by our host, when you try to Deposit or Open short, and refuse the action if it is in a restricted country. [We do not store the result.] This check is approximate, and it can be wrong.

Wallet screening. [We may check wallet addresses against public sanctions lists or a third-party screening service ([SCREENING PROVIDER]) and block addresses that appear on them.]

10. If you contact us

If you email us or contact us through [SUPPORT CHANNEL], we receive your email address or account handle, what you write, and any metadata your provider attaches. We use it to reply and to keep a record of what we said. We keep it for [RETENTION: e.g. up to 3 years after the matter is closed]. [SUPPORT CHANNEL] is run by a third party that holds your messages under its own policy. Never send anyone, including us, your private key or recovery phrase.

11. Why we use your information, and on what legal basis

Where the GDPR, UK GDPR, Swiss FADP or similar laws apply, we rely on these legal bases:

What we doLegal basis
Show your balances and positions and build your transactionsPerformance of a contract (providing the interface you asked to use), and our legitimate interest in operating it
Serve token search, logos, prices and chartsLegitimate interest in operating the interface
Host logs and security monitoringLegitimate interest in keeping the site secure and working
[IF USED] Analytics[Legitimate interest in improving Doubt / Consent, where cookies or similar technology require it]
[IF USED] Error reportsLegitimate interest in fixing problems
[IF USED] Terms acceptance record, location checks, wallet screeningLegitimate interest in enforcing our terms, managing legal and compliance risk, and establishing or defending legal claims; and legal obligation where sanctions or other laws require it
Replying to youLegitimate interest in answering you, or taking steps at your request
Responding to lawful requests from authoritiesLegal obligation

Where we rely on legitimate interests, we have weighed them against your rights and kept the data we use to a minimum. You can object (see section 16).

12. Who receives information

We do not sell personal data. Recipients fall into the categories below:

  • RPC node provider: [RPC PROVIDER]. Sees your IP address, user agent, wallet address and queries, as described in section 5.
  • Hosting provider: [HOSTING PROVIDER]. Runs the website and our server endpoints and keeps request logs.
  • Market data providers: GeckoTerminal (operated by CoinGecko) and DexScreener. Receive token search terms and token addresses from our server, but not your IP address or wallet address.
  • [IF USED] WalletConnect / Reown: not used unless we enable WalletConnect by configuring a Reown project ID, and then only if you choose to connect using WalletConnect.
  • [IF USED] Analytics provider: [ANALYTICS PROVIDER].
  • [IF USED] Error monitoring or database provider: [ERROR MONITORING PROVIDER], [DATABASE PROVIDER].
  • [IF USED] Wallet screening provider: [SCREENING PROVIDER].
  • Support platform: [SUPPORT CHANNEL], if you contact us through it.
  • Professional advisers, such as lawyers, auditors and accountants, under confidentiality.
  • A buyer or successor, if we are involved in a merger, acquisition, reorganisation or sale of assets, under confidentiality.
  • Authorities, such as regulators, courts and law enforcement, when we are legally required to, or when it is necessary to protect our rights, our users or others. We will check that a request is lawful and proportionate and, where we are allowed to, tell you about it.

Each third party handles your information under its own terms and privacy policy. We will update this list if our providers change.

13. International transfers

Our providers may process information in [the United States, the European Economic Area, and other countries]. Where information about people in the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK and Swiss equivalents, or another lawful transfer mechanism. You can ask us for more information about these safeguards at [PRIVACY EMAIL].

14. How long we keep information

InformationHow long
Wallet address in the pageUntil you close the tab or disconnect
Browser storageUntil you clear it or disconnect your wallet
Host request logs[HOST LOG RETENTION], on the host's schedule
Cached token logos and names[RETENTION: until refreshed; contains no personal data]
[IF USED] Indexed on-chain data[RETENTION: as long as needed to operate the interface]
[IF USED] Analytics[RETENTION: e.g. 12 months, aggregated after that]
[IF USED] Error reports[RETENTION: e.g. 30 days]
[IF USED] Terms acceptance records[RETENTION: e.g. the applicable limitation period plus one year after your last interaction], or longer if needed for a dispute or legal hold
Correspondence[RETENTION: e.g. up to 3 years after the matter is closed]
On-chain dataPermanently, outside our control and anyone else's

When a retention period ends, we delete the information or make it anonymous.

15. Security

We take reasonable technical and organisational measures to protect the information we hold, including encryption in transit, keeping secrets on the server rather than in the page you download, limiting what our server endpoints accept, and holding as little personal data as possible. No system is completely secure, and we cannot guarantee the security of information sent over the internet or held by third parties.

If we learn of a personal data breach that is likely to put people at risk, we will notify the relevant supervisory authority and, where the risk is high, the people affected, within the time limits the law requires (for example, within 72 hours under the GDPR where feasible).

To report a security vulnerability, write to [SECURITY EMAIL].

16. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and receive a copy, including in a portable format;
  • correct data that is inaccurate;
  • delete data we hold off-chain, where we have no overriding reason to keep it;
  • restrict how we use it;
  • object to processing based on our legitimate interests;
  • withdraw consent at any time, where we rely on consent, without affecting processing already done; and
  • complain to a data protection authority.

Please remember what these rights can reach. We hold very little, and on-chain data is outside anyone's control (section 4). We may need to keep some information, such as a terms acceptance record, to establish or defend legal claims or to comply with law, in which case we will restrict it rather than delete it and tell you why.

California and other US states. Doubt is not offered to US persons. If US state privacy laws nonetheless apply to you, you may have rights to know, access, correct and delete personal information, and to opt out of its sale or sharing. We do not sell or share personal information as those laws define it, and we will not discriminate against you for exercising your rights.

How to make a request. Write to [PRIVACY EMAIL]. Because we do not know your name, the only way we can check that a request comes from the owner of an address is to ask you to sign a message with that wallet. We aim to reply within one month. For complex requests the law may let us take up to two more months; if so, we will let you know. Requests are free unless they are clearly unfounded or excessive.

Complaints. You can complain to your local data protection authority, for example [LEAD SUPERVISORY AUTHORITY], the supervisory authority in your EU country, the UK Information Commissioner's Office, or the Swiss Federal Data Protection and Information Commissioner. We would appreciate the chance to deal with your concern first.

17. Automated decisions

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects on you, within the meaning of Article 22 GDPR. [IF USED: Location checks and wallet screening automatically block certain actions to comply with the law and our terms. If you think you have been blocked in error, write to [PRIVACY EMAIL] and a person will review it.]

Liquidations are carried out by the smart contracts according to their code, not by us processing your personal data.

18. Children

Doubt is only for adults aged 18 or over. We do not knowingly collect information from anyone under 18. If you think someone under 18 has sent us information, tell us at [PRIVACY EMAIL] and we will delete what we can.

19. Third-party sites and services

Doubt links to and relies on services we do not run, including Robinhood Chain, Uniswap, Pons, block explorers, GeckoTerminal, DexScreener, WalletConnect (only if enabled), your wallet provider, and [SUPPORT CHANNEL]. Their own privacy policies apply to them. We are not responsible for their practices, and we encourage you to read their policies.

20. Changes to this policy

We may update this policy. The current version and its effective date are always on this page. If we make a material change, for example adding a new kind of data or a new provider that receives personal data, we will say so on the site or through [ANNOUNCEMENTS CHANNEL] before it takes effect where we reasonably can.

21. Contact

[ENTITY NAME], [REGISTERED ADDRESS].

  • Privacy questions and requests: [PRIVACY EMAIL]
  • Security reports: [SECURITY EMAIL]
  • General help: [SUPPORT CHANNEL] (not for privacy requests; please use the email address so your request is recorded and the response times above apply)