Version 1.0. Effective from the date of publication.
1. Who is responsible
The controller of your personal data is the entity operating the CoFunders platform at app.cofunders.org ("CoFunders", "we").
For data protection questions, write to support@cofunders.org. The other ways to reach us are published on our contact page at https://cofunders.org/contact.
2. What we collect
2.1 You give us
| Data | Why |
|---|---|
| Email address or phone number | To create and secure your account |
| Display name, username, avatar | To show you to other users |
| Campaign content you write | To publish your campaign |
| Comments and messages | To run the social features |
| Support messages | To answer you |
2.2 Created when you use the platform
| Data | Why |
|---|---|
| Wallet addresses linked to your account | To send and receive funds |
| On-chain transactions you make through us | To show your history and calculate fees |
| Contributions, campaigns backed, amounts | To operate the service |
| Referral relationships | To attribute and pay referral rewards |
| Subscription tier and billing state | To apply the correct fee rate |
| Course progress, streaks, verification progress | To run those features |
2.3 Technical
| Data | Why |
|---|---|
| IP address, device and browser information | Security, abuse prevention, rate limiting |
| Error reports and diagnostics | To find and fix defects |
| Language preference | To show the right language |
2.4 What we deliberately do not collect
We do not collect your private keys or seed phrase. We cannot see them and cannot recover them for you.
We do not currently perform identity verification (KYC). This is a stated gap, not a privacy feature. If KYC is introduced, this policy will be updated and you will be asked to accept the new version.
3. On-chain data is public and permanent
This is the most important section of this policy.
Transactions you make through CoFunders are recorded on the Solana public blockchain. That means:
- the amounts, addresses, and timing are visible to anyone in the world;
- they are permanent;
- we cannot delete, alter, or hide them, not on request, not by court order, not ever;
- a wallet address is pseudonymous, not anonymous. Anyone who links an address to you can see everything that address has ever done.
Your right to erasure does not extend to the blockchain, because nobody controls it. We can delete what is in our database. We cannot delete what is on chain. Consider this before you transact.
4. Why we are allowed to process it (legal basis)
| Purpose | Basis under Article 6 GDPR |
|---|---|
| Providing the service you asked for | Performance of a contract |
| Security, fraud and abuse prevention | Legitimate interests |
| Keeping records the law requires | Legal obligation |
| Analytics and attribution beyond what is necessary | Consent, which you may withdraw |
| Marketing messages | Consent, which you may withdraw |
Where the basis is consent, you may withdraw it at any time without affecting processing already carried out.
5. Who else receives it
We use processors and third-party services. Each receives only what its function requires.
| Provider | Function | Data involved |
|---|---|---|
| Privy | Authentication and embedded wallets | Email/phone, wallet addresses |
| Supabase | Database and file storage | Account and platform data |
| Vercel | Application hosting | Request data, IP |
| Helius | Solana blockchain access | Wallet addresses, transactions |
| Sentry | Error monitoring | Diagnostics, technical identifiers |
| Upstash | Rate limiting | Technical identifiers |
| MoonPay, Coinbase Pay | Card purchase of crypto | Handled by them; they are separate controllers and their own terms apply |
| WalletConnect | External wallet connection | Wallet addresses |
Some providers are outside the EEA. Where they are, transfers rely on adequacy decisions or Standard Contractual Clauses.
We do not sell your personal data.
We disclose data to authorities where legally required, and to advisers, insurers, or an acquirer where necessary and lawful.
6. How long we keep it
- Account data: while your account exists, then deleted or anonymised.
- Transaction and fee records: as long as accounting and tax law requires, typically 10 years in Portugal, even after you close your account.
- Support messages: up to 3 years.
- Error diagnostics: up to 90 days.
- On-chain data: forever, and outside our control (section 3).
7. Your rights
Under GDPR you may request: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent.
To exercise these, use the Privacy and data screen in the platform, or contact us. We respond within one month.
You may complain to the Comissão Nacional de Proteção de Dados (CNPD) in Portugal, or to the authority where you live.
Two honest limits:
- We cannot erase on-chain data (section 3).
- We cannot erase records we are legally required to keep (section 6).
8. Security
We use encryption in transit, encryption of wallet material at rest, row-level access control in the database, and rate limiting.
No system is perfectly secure. We do not guarantee that our measures cannot be defeated. If a breach affects your rights, we will notify the CNPD within 72 hours and notify you where the law requires it.
9. Children
The platform is not for anyone under 18. We do not knowingly process data of children. If you believe a child has an account, contact us and we will remove it.
10. Automated decisions
We use automated rules for rate limiting and abuse detection, which can restrict an account. These are not decisions producing legal effects within the meaning of Article 22 GDPR, but you may contact us to have a restriction reviewed by a person.
11. Changes
We may update this policy. Where a change materially affects your rights, you will be notified in the platform and asked to accept the new version.