LEGAL / DRAFT FOR REVIEW

Privacy Policy

How the foundation application may handle wallet, verification, transaction, and operational information.

Last updated: September 4, 2026

Status: Draft for project-owner and legal review

1. Scope

This Privacy Policy describes how the Machine Bridge website may handle information when a user connects a wallet, confirms wallet ownership, views a Machine Profile, creates a Public Proof, submits an optional Boost, views Activity, or contacts the project.

The final production operator, legal entity, contact method, hosting configuration, analytics configuration, processors, retention periods and jurisdiction must be inserted only after they are verified.

2. Public blockchain data

Wallet addresses, transaction hashes, amounts, contract events, block numbers and timestamps recorded on a public network are public. They may be viewed, copied, indexed and correlated by third parties.

Machine Bridge does not control the underlying public ledger and generally cannot delete or alter public transactions.

3. Information the application may process

The foundation application may process:

  • connected wallet address;
  • readable ownership-verification message and signature;
  • nonce, issue time, expiry and consume status;
  • ownership verification result and time;
  • Machine Points ledger;
  • transaction hash and action type;
  • configured environment and contract used internally;
  • receipt, block and event verification results;
  • public Proof and Boost status;
  • request and security metadata needed for abuse prevention;
  • essential cookies or local storage used for session and pending-transaction recovery;
  • support information voluntarily submitted through a verified contact channel.

The application does not need to request:

  • private keys;
  • seed phrases;
  • wallet passwords;
  • arbitrary token approvals;
  • legal name;
  • home address;
  • government identifier;
  • unrelated full wallet history.

Machine Bridge will never ask a user to submit a seed phrase or private key.

4. Purposes

Information may be used to:

  • verify wallet ownership;
  • prevent replay and duplicate Points;
  • maintain the user's profile and ledger;
  • register and reconcile Public Proof and Boost transactions;
  • restore pending transaction state;
  • provide Account and Activity views;
  • protect the application, contract and users from abuse;
  • debug incidents;
  • comply with applicable obligations;
  • respond to support requests;
  • measure product reliability when approved analytics are enabled.

5. Legal bases and regional rights

The production operator must identify the legal bases applicable to its jurisdiction and users. Depending on context, these may include contract performance, legitimate interests, consent and legal obligations.

Users may have rights to request access, correction, deletion, restriction, objection, portability or withdrawal of consent for applicable off-chain information. These rights do not permit deletion of public-chain data that the operator cannot alter.

A verified privacy contact method must be published before production.

6. Cookies and local storage

The foundation may use:

  • essential session cookies;
  • CSRF or security tokens;
  • a pending transaction hash, wallet, action and submit time;
  • accessibility or theme preference when the supplied template already supports it.

Non-essential analytics or advertising cookies must not be enabled without an accurate consent and disclosure strategy where required.

Do not store private keys, seed phrases or deployment secrets in browser storage.

7. Service providers

Production may use providers for hosting, databases, wallet connectivity, RPC access, rate limiting, logging, security and analytics. The final Policy must list or accurately describe the providers actually used and link to their terms where appropriate.

Provider logs may include IP address and user-agent information. The project should minimize collection, use short retention, restrict access and hash or truncate data where practical.

8. Retention

Nonce records should be retained only as long as necessary for replay prevention, security and audit. Security logs, transaction reconciliation records and profile ledger entries should follow documented retention schedules.

Public transactions remain available according to the underlying ledger rather than this application's retention choices.

9. Sharing

Information may be shared:

  • with processors needed to operate the service;
  • when a user directs the wallet to submit a public transaction;
  • to investigate abuse or security incidents;
  • to comply with law or valid legal process;
  • in a business transfer subject to applicable safeguards.

Machine Bridge should not sell personal information or use wallet data for unrelated behavioral advertising without a separately reviewed policy and consent basis.

10. Security

The project should use encryption in transit, least-privilege access, secret management, database constraints, rate limits, deployment protections, dependency review, backups, incident response and monitoring.

No security measure eliminates all risk. Wallet software, user devices, providers, contracts and applications can fail or be compromised.

11. Children

The production operator must set and enforce an appropriate minimum age based on applicable law. The foundation product is not intentionally designed to collect information from children.

12. International transfers

Providers may process information in multiple countries. The production operator must disclose applicable transfer mechanisms and safeguards.

13. Changes

This Policy may change when the product, providers, law or operating entity changes. The current effective date should be displayed, and material changes should be communicated appropriately.

14. Contact

Display only a real, monitored and verified privacy contact method. Do not publish an invented contact email or company address.