PRIVACY POLICY
1. Who we are and what this policy covers
This policy explains what personal information DappHero Corp (DappHero, we, us) collects when you use the UAFC website and application (the Service), why we collect it, who we share it with, and what choices you have. DappHero is the data controller for the information described here, except where we say a third party is. This policy does not cover the practices of third parties you interact with through the Service, such as Privy, Robinhood Chain, bridges, or block explorers. The section on who we share information with names them.
2. Information we collect
Sign-in information. When you sign in through Privy, we receive an identifier for your Privy account and the sign-in method you chose. If you sign in with email, we receive your email address. If you sign in with Google, we receive the email address and basic profile identifier Google provides. If you connect an external wallet, we receive its public address. We do not receive passwords, private keys, or wallet recovery material. Wallet addresses. We collect the public address of the wallet you use, whether external or embedded, to show you your balance, bets, and claimable payouts. Bets and claims. We read your bets, pool positions, payouts, and refunds from the blockchain and from our indexer to display them to you. Eligibility confirmations. We record that you confirmed your age, accepted the Terms, confirmed you are not in a restricted region, and confirmed that you understand the experiment and its risks. Today this record is stored only in your browser, as described in the section on cookies and local storage. If we add server-side eligibility or location checks, we will record the result and the approximate location derived from your IP address. Chat messages. When live chat is enabled, we store the messages you send, the wallet or account that sent them, and the time. Technical information. Our hosting provider and our servers log your IP address, browser type, device type, requested pages, and timestamps for security and troubleshooting. Analytics and session replay. We use PostHog for product analytics, session replay, and error tracking. PostHog records specific events as you use the Service (for example sign-in, side selection, bet submission and confirmation, claim submission and confirmation, and video verification), each tagged with identifiers such as the fight or market involved. When you sign in, we identify your session to PostHog using your wallet address, which becomes your analytics identifier; this lets us connect your on-chain activity to your in-app behavior. PostHog also records a visual replay of your session (mouse movement, clicks, and page navigation) so we can diagnose problems; all form inputs are masked by default, and the bet amount field and wallet address elements are explicitly excluded from replay capture regardless of the default masking. We do not use PostHog for advertising, and we do not run separate advertising trackers. If an error occurs, PostHog records the error and relevant identifiers so we can diagnose it. PostHog is named as a processor in the section on who we share information with. Support correspondence. If you email us, we keep the email and our reply.
3. Player-made fighter descriptions
If you create a Player-made fighter, the description, name, and nickname you write are sent to a third-party AI model for content moderation, as described in the content policy in our Terms. The wallet address you create it from is kept by us with the description and is not sent to the model. We keep the description, the moderation outcome, and the compiled fields our model produces for moderation audit, whether or not the description is approved. We do not send your description to the video or image generators or to the Judge. The image and video generators only ever see the compiled text our model writes from it; the Judge only ever sees the finished Fight video.
4. Public blockchain data
Every bet, claim, and refund you make is a transaction on Robinhood Chain, a public blockchain. Your wallet address, the amounts, the Market, and the time are permanently visible to anyone, including through block explorers such as Blockscout, and DappHero cannot delete or change them. If your wallet address can be linked to you (for example through a name service, an exchange, or something you posted), your betting history can be linked to you as well. Do not use the Service if you are not comfortable with this.
5. Cookies and local storage
We do not set advertising or analytics cookies. We use your browser's local storage for: an eligibility flag recording that you completed the age, terms, region, and risk confirmation; a per-session flag recording that you dismissed the experiment banner; in demonstration mode, a mock data store holding simulated fights, bets, and balances; and sign-in state managed by Privy, which uses its own cookies and local storage to keep you signed in and, for embedded wallets, to hold a share of your wallet key on your device. You can clear these by clearing your browser's site data. Doing so signs you out and shows the eligibility screen again.
6. How we use information
We use the information above to: operate the Service and show you your bets and payouts; sign you in and keep your session; enforce eligibility, the Terms, and any location or sanctions restrictions; detect and prevent fraud, abuse, and manipulation; moderate chat; respond to support requests and disputes about results; keep the Service secure and diagnose problems; comply with law, including responding to lawful requests from authorities; and, if we add them, measure and improve the product. Where the GDPR or a similar law applies, our legal bases are performance of our contract with you (the Terms), our legitimate interests in running a secure and lawful service, compliance with legal obligations, and, where required, your consent.
7. Who we share information with
Privy (Horkos, LLC d/b/a Privy) provides sign-in and embedded wallets. Privy processes your email, Google identifier, and wallet information under its own policy (privy.io/privacy-policy) and a data processing agreement with us. PostHog provides product analytics, session replay, and error tracking as described above. PostHog processes the events, session replay data (with the masking described in section 2), and your wallet address as your analytics identifier, under its own policy and our configuration of its product. Robinhood Chain and RPC providers. When you place a bet or claim, your wallet address and transaction data are sent to the network through an RPC endpoint (by default rpc.mainnet.chain.robinhood.com) and become public. The app also reads chain data through these endpoints. Blockscout provides the block explorer the app links to; clicking an explorer link sends your request to Blockscout. Railway hosts the Service and processes server logs, including IP addresses, on our behalf. Video and AI providers generate Fights and judge them. They do not receive information about you. We may also share information with professional advisers, with law enforcement or regulators where required by law, in connection with a merger or sale of the business, and with a sanctions or wallet-screening provider if we add one. We do not sell personal information and do not share it for advertising.
8. Retention
We keep information for these periods as a matter of policy: Server logs, including IP addresses: 30 days. Chat messages: while the chat is available and for 90 days afterwards. Analytics events, session replay recordings, and error data held by PostHog: 90 days. Support correspondence and dispute records: 3 years. Sign-in records: while you have an account, and afterwards for as long as needed to enforce the Terms or comply with law. Blockchain data cannot be deleted by anyone, including us, and is permanent. Where a law requires us to keep something for longer than the periods above, we keep it for that period.
9. Security
We protect information with access controls, encrypted connections, and hosting-provider safeguards. Wallet keys are never held by DappHero. No system is completely secure, and you are responsible for protecting your email account, Google account, wallet, and devices.
10. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to delete it, to receive a copy in a portable format, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. To exercise a right, contact us at https://github.com/dennisonbertram/agent-wars/issues from the address you signed in with, or include your wallet address; we may ask for more information to verify the request. We cannot delete or alter data recorded on the blockchain. European Economic Area, United Kingdom, and Switzerland (GDPR). DappHero Corp is the controller for the information described in this policy, and the legal bases are the ones stated above. We have not appointed an EU or UK representative; if we become required to, we will name one here. You may complain to your local data protection authority. California (CCPA/CPRA). We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not discriminate against you for exercising your rights, and California residents may designate an authorised agent to make requests. We honour access and deletion requests from California residents whether or not we meet the statutory thresholds. Other jurisdictions. If the law where you live gives you rights over your personal information, contact us at https://github.com/dennisonbertram/agent-wars/issues and we will honour them to the extent they apply to us.
11. International transfers
DappHero and its providers process information in the United States and in other countries where they operate. Where the law requires safeguards for a transfer, we rely on the standard contractual clauses (or the equivalent mechanism) in our agreements with those providers.
12. Children
The Service is for adults only. We do not knowingly collect personal information from anyone under 18, and anyone under 18 may not use the Service. If you believe a minor has used the Service, email https://github.com/dennisonbertram/agent-wars/issues and we will remove the information we hold and block the account.
13. Changes to this policy
We may update this policy. We will post the new version in the app with a new Last Updated date and, for material changes, show a notice in the app. Continuing to use the Service after a change means you accept the updated policy.
14. Contact
DappHero Corp https://github.com/dennisonbertram/agent-wars/issues Use this channel for privacy questions, rights requests, and complaints.
Footnote: this policy was drafted by the operator and has not been reviewed by a lawyer. It describes what the Service actually does today. UAFC is an experiment, and this policy is published in the same spirit.