Privacy Policy
Last updated: 16 July 2026
1. Scope
This policy explains what personal data Based Technologies Limited ("we", "us", "our") collects when you use the Based Alpha interface at alpha.based.one (the "Interface"), why we collect it, who we share it with, and what rights you have.
We are the data controller for the processing described here. Our contact details are in section 12.
This policy covers the Interface. It does not cover Robinhood Chain itself, your wallet provider, any decentralised exchange, or any third-party site linked from the Interface. Those are operated by others under their own policies.
2. The most important thing in this policy
Read this before anything else, because it is the part people underestimate.
Blockchain data is public, permanent, and outside our control. When you connect a wallet and transact, your wallet address, the transaction, its amount, its timing, and its counterparty are written to Robinhood Chain. That record is publicly readable by anyone in the world, forever. We did not put it there and we cannot remove it, edit it, or restrict access to it. Neither can you.
Wallet addresses are pseudonymous, not anonymous. Address activity can often be linked to a real identity through chain analysis, through exchange deposits and withdrawals, or through information you disclose elsewhere. Anyone who learns your address can see everything that address has ever done.
Where a wallet address can be linked to you, that address is personal data in some jurisdictions. Our obligations regarding it, including any obligation to erase it, apply only to data we hold in our own systems. They cannot extend to the public ledger, because we have no ability to act on it.
3. What we collect
Wallet and onchain data. Your wallet address when you connect it. Transactions you construct through the Interface. Public onchain state we read and index, including balances, token deployments, trades, and curve state.
Log and device data. IP address, user agent, browser and operating system, referring URL, pages viewed, timestamps, and session duration. Collected automatically when you load the Interface.
Usage data. Which features you use, what you search for, what you click, and error and diagnostic events.
Communications. If you contact us at compliance@based.one, we receive whatever you send, including your contact details and the contents of your message.
Creator-supplied content. If you deploy a token, the name, symbol, image, description, and links you supply. Understand that this content is written onchain or published on the Interface, or both. It is public by design.
Cookies and similar technologies. See section 7.
4. What we do not collect
We do not collect your name, government identification, date of birth, physical address, or payment card details, because the Interface has no account system and no fiat payment rail.
We do not currently perform sanctions screening, wallet risk scoring, or geo-blocking, and we do not use an analytics provider. If that changes, this policy will be updated before the change takes effect.
We never have access to your private keys or seed phrase. We cannot access your wallet. No one at Based Alpha will ever ask you for a private key or seed phrase, and any person who does is attempting to steal from you.
5. Why we process it, and on what basis
| What we do | Why | Lawful basis (where GDPR applies) |
|---|---|---|
| Display balances, curve state, and transaction history | To make the Interface function | Performance of a contract |
| Construct transactions for your wallet to sign | To make the Interface function | Performance of a contract |
| Log requests, monitor errors, rate limit | To keep the Interface available and secure | Legitimate interests |
| Analyse aggregate usage | To understand and improve the product | Legitimate interests |
| Investigate abuse, fraud, and manipulation | To protect users and the Protocol | Legitimate interests |
| Respond to you | To handle your enquiry | Legitimate interests |
| Respond to lawful requests from authorities | To comply with law | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights. You may object to that processing; see section 9.
6. Who we share it with
We do not sell your personal data. We do not share it for advertising or cross-context behavioural targeting.
We share it with:
Infrastructure providers who host and run the Interface on our behalf, including Vercel (hosting), Render (indexer hosting), and the public Robinhood Chain RPC endpoint. These act as processors under contract and may only process data on our instructions.
Authorities and legal parties where we are required by law to disclose, or where disclosure is necessary to establish, exercise, or defend legal claims.
An acquirer, in connection with a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply.
A current list of processors is available on request.
7. Cookies
We use strictly necessary cookies and similar local storage only. They keep your session and wallet connection working and cannot be disabled. We do not set analytics or advertising cookies.
Blocking cookies through your browser may break parts of the Interface.
8. How long we keep it
| Data | Retention |
|---|---|
| Server logs including IP | 90 days |
| Support correspondence | 24 months from resolution |
| Indexed onchain data | Indefinitely, because it mirrors a public permanent ledger |
We keep data longer where we are required to by law or where it is necessary for an ongoing legal claim.
9. Your rights
Subject to the jurisdiction that applies to you, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- have data erased;
- restrict or object to processing, including processing based on legitimate interests;
- receive your data in a portable format;
- withdraw consent, where processing relies on consent, without affecting prior processing;
- complain to a supervisory authority. If you are in Singapore, that is the Personal Data Protection Commission. If you are in the EEA, it is your local data protection authority. If you are in the UK, it is the Information Commissioner's Office.
To exercise any of these, contact compliance@based.one. We will respond within 30 days. We may need to verify that you control the wallet address in question, usually by asking you to sign a message.
The limit on erasure. We can delete data from our systems. We cannot delete anything from Robinhood Chain, and we cannot prevent third parties from independently indexing the public ledger. An erasure request reaches our databases and nothing beyond them.
10. International transfers
We and our processors operate outside your country of residence. Your data may be transferred to and processed in countries other than your own, including countries that do not provide an equivalent level of protection.
Where we transfer personal data out of the EEA or the UK, we rely on the transfer mechanisms available to us under applicable law, together with supplementary measures where required. Where we transfer out of Singapore, we ensure recipients are bound to a standard of protection comparable to the PDPA. Details are available on request.
11. Security, children, and changes
Security. We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and logging. No system is perfectly secure and we cannot guarantee absolute security. Your wallet security is entirely your responsibility.
Children. The Interface is not directed to and may not be used by anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact compliance@based.one and we will delete it.
Changes.We may update this policy. We will post the updated version here and change the "Last updated" date. Where changes are material we will give notice through the Interface before they take effect.
12. Contact
compliance@based.one
Based Technologies Limited, British Virgin Islands
See also our Terms of Use.