Privacy Policy
What robinhood.bio stores, why, and how you export or delete it. Short version: your wallet address is personal data, we keep as little as possible, and there are no tracking cookies.
1. Wallet addresses are personal data
A wallet address can identify a person, so we treat it as personal data. We store the address you sign in with, the addresses you add as display or recovery wallets, and the onchain statistics we derive from them. We do not link addresses to real-world identities and we never sell address data.
The legal basis for processing is the contract with you (running your page) and our legitimate interest in keeping the service safe (abuse prevention, link scanning, rate limiting).
2. What we store
For each account:
- your username, display name, bio, role, country/city (if you set them), theme and page layout;
- wallet addresses, chain ids, the time you verified them and the signature you used to prove ownership;
- server-side session records (a random id, the signing address, issue/expiry times and a hash of your browser's user agent - never the raw user agent);
- links, projects and the results of our safety scan for each link;
- a snapshot of public onchain statistics for your display wallet (transaction count, first/last activity, contract count, a sample of NFTs and token symbols). Balances are never shown unless you switch the balance tier on, and tokenized stock holdings are never shown at all;
- payment records: amount, method, the onchain transaction hash or the merchant-of-record order id. Card details never reach us;
- an optional recovery email, used only to reach you about your page and never shown on it;
- a salted hash of the IP address used to claim a name and to send reports (abuse prevention only).
3. Your public page
Everything on your page is public by design, including the share images and the text version served to command-line tools. Privacy switches in Settings remove fields entirely from the page, the share images and the API - hidden fields are not rendered as placeholders. You can also exclude your page from the Explore list and ask search engines not to index it.
Visitors of your page never trigger blockchain or explorer requests; pages read only the stored snapshot.
4. Cookieless analytics
We count page views per day without cookies and without storing IP addresses. Uniques are estimated from a daily salted hash that is discarded the next day. We do not use third-party analytics, advertising pixels or fingerprinting.
The only cookie we set is the session cookie after you sign in (httpOnly, 30 days) and, if you use a wallet library that stores connection state, its own cookie. Your theme preference is stored in your browser's local storage.
5. Service providers
We use a hosting provider, a managed Postgres database, an optional Redis cache for rate limits, an object store for uploaded images, blockchain data APIs for public onchain data, and a merchant of record for card payments. Each provider processes data only to provide its service to us. Uploaded photos are rebuilt from raw pixels, so camera metadata (including GPS) is removed.
6. Export and delete
Settings > Your data lets you download everything we store about you as JSON. Settings > Danger zone lets you release your username or delete your profile. Deleted profiles are hidden immediately and permanently erased after 30 days; during that time you can come back and restore them. Payment records are kept as long as accounting law requires.
Blockchain data is public and outside our control: deleting your page does not delete your onchain history.
7. Contact
Privacy requests: support@robinhood.bio. We answer within 30 days. If you are in the EEA or UK you can also complain to your local data protection authority.