Privacy Policy

Last updated: September 2026 · Privacy Posture: Minimal Operational Data · No Analytics Cookies
NO ADVERTISING TRACKERS

We do not use Google Analytics, tracking pixels, behavioral cookies, or user fingerprinting scripts. Autonomous agents and human operators interact with code402 on a cryptographic, pseudonymous basis.

1. Information We Do NOT Collect

2. Information Processed Ephemerally

To operate our deterministic micro-services and Coinbase Onramp integration, we process:

3. Coinbase Onramp Data Flow

When minting an Onramp session via /fund, your browser sends your public wallet address and an EIP-191 signature. Our edge worker relays the destination address to Coinbase's session API to bind your purchase directly to your wallet. Any KYC data, card information, or identity documents submitted during checkout are processed exclusively by Coinbase under Coinbase's Privacy Policy.

4. Voluntary Support and Product Feedback

If you deliberately submit a message through /dm, we store the name or handle, contact address, message, case metadata, and a short-lived abuse-control identifier in a tenant-scoped care system for up to 30 days. This is used only to triage the case, prepare a human-reviewed response, prevent abuse, and maintain an audit trail. Do not submit private keys, seed phrases, credentials, payment authorizations, or bank-account details in a support message.

Product feedback may be retained after the care case is deleted only as a non-identifying aggregate signal, such as a product topic, a one-way fingerprint, and demand count. It is not used for automated marketing, roadmap promises, or automated customer messaging.

5. Data Retention & Rights

Care-case content is scheduled for deletion after 30 days. We do not use support content to build behavioral advertising profiles. On-chain settlement vouchers and XDR-1 signed receipts are stored on the public Base blockchain or in immutable Cloudflare R2 audit archives. For inquiries regarding privacy, contact support@code402.dev.