Skip to content
CoFunders
Back to CoFunders

Privacy

CoFunders Privacy Policy

Version
1.0
Last reviewed

Version 1.0. Effective from the date of publication.


1. Who is responsible

The controller of your personal data is the entity operating the CoFunders platform at app.cofunders.org ("CoFunders", "we").

For data protection questions, write to support@cofunders.org. The other ways to reach us are published on our contact page at https://cofunders.org/contact.

2. What we collect

2.1 You give us

DataWhy
Email address or phone numberTo create and secure your account
Display name, username, avatarTo show you to other users
Campaign content you writeTo publish your campaign
Comments and messagesTo run the social features
Support messagesTo answer you

2.2 Created when you use the platform

DataWhy
Wallet addresses linked to your accountTo send and receive funds
On-chain transactions you make through usTo show your history and calculate fees
Contributions, campaigns backed, amountsTo operate the service
Referral relationshipsTo attribute and pay referral rewards
Subscription tier and billing stateTo apply the correct fee rate
Course progress, streaks, verification progressTo run those features

2.3 Technical

DataWhy
IP address, device and browser informationSecurity, abuse prevention, rate limiting
Error reports and diagnosticsTo find and fix defects
Language preferenceTo show the right language

2.4 What we deliberately do not collect

We do not collect your private keys or seed phrase. We cannot see them and cannot recover them for you.

We do not currently perform identity verification (KYC). This is a stated gap, not a privacy feature. If KYC is introduced, this policy will be updated and you will be asked to accept the new version.

3. On-chain data is public and permanent

This is the most important section of this policy.

Transactions you make through CoFunders are recorded on the Solana public blockchain. That means:

  • the amounts, addresses, and timing are visible to anyone in the world;
  • they are permanent;
  • we cannot delete, alter, or hide them, not on request, not by court order, not ever;
  • a wallet address is pseudonymous, not anonymous. Anyone who links an address to you can see everything that address has ever done.

Your right to erasure does not extend to the blockchain, because nobody controls it. We can delete what is in our database. We cannot delete what is on chain. Consider this before you transact.

4. Why we are allowed to process it (legal basis)

PurposeBasis under Article 6 GDPR
Providing the service you asked forPerformance of a contract
Security, fraud and abuse preventionLegitimate interests
Keeping records the law requiresLegal obligation
Analytics and attribution beyond what is necessaryConsent, which you may withdraw
Marketing messagesConsent, which you may withdraw

Where the basis is consent, you may withdraw it at any time without affecting processing already carried out.

5. Who else receives it

We use processors and third-party services. Each receives only what its function requires.

ProviderFunctionData involved
PrivyAuthentication and embedded walletsEmail/phone, wallet addresses
SupabaseDatabase and file storageAccount and platform data
VercelApplication hostingRequest data, IP
HeliusSolana blockchain accessWallet addresses, transactions
SentryError monitoringDiagnostics, technical identifiers
UpstashRate limitingTechnical identifiers
MoonPay, Coinbase PayCard purchase of cryptoHandled by them; they are separate controllers and their own terms apply
WalletConnectExternal wallet connectionWallet addresses

Some providers are outside the EEA. Where they are, transfers rely on adequacy decisions or Standard Contractual Clauses.

We do not sell your personal data.

We disclose data to authorities where legally required, and to advisers, insurers, or an acquirer where necessary and lawful.

6. How long we keep it

  • Account data: while your account exists, then deleted or anonymised.
  • Transaction and fee records: as long as accounting and tax law requires, typically 10 years in Portugal, even after you close your account.
  • Support messages: up to 3 years.
  • Error diagnostics: up to 90 days.
  • On-chain data: forever, and outside our control (section 3).

7. Your rights

Under GDPR you may request: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent.

To exercise these, use the Privacy and data screen in the platform, or contact us. We respond within one month.

You may complain to the Comissão Nacional de Proteção de Dados (CNPD) in Portugal, or to the authority where you live.

Two honest limits:

  1. We cannot erase on-chain data (section 3).
  2. We cannot erase records we are legally required to keep (section 6).

8. Security

We use encryption in transit, encryption of wallet material at rest, row-level access control in the database, and rate limiting.

No system is perfectly secure. We do not guarantee that our measures cannot be defeated. If a breach affects your rights, we will notify the CNPD within 72 hours and notify you where the law requires it.

9. Children

The platform is not for anyone under 18. We do not knowingly process data of children. If you believe a child has an account, contact us and we will remove it.

10. Automated decisions

We use automated rules for rate limiting and abuse detection, which can restrict an account. These are not decisions producing legal effects within the meaning of Article 22 GDPR, but you may contact us to have a restriction reviewed by a person.

11. Changes

We may update this policy. Where a change materially affects your rights, you will be notified in the platform and asked to accept the new version.