DecentralProp privacy policy
Not yet reviewed by a lawyer. This document is published in draft so you can read it before you commit money, not because it is finished. No operating company has been formed and no governing law has been set, so parts of it name gaps rather than answers. It will be reissued once counsel has been through it. Questions: info@decentralprop.com
"DecentralProp," "we," "us," and "our" mean the DecentralProp project, which has not yet been incorporated as a company. This policy covers the trader terminal, backoffice-admin console, marketing site, and Telegram bot at decentralprop.com, trade.dprop.fun and admin.dprop.fun.
1. The short version
DecentralProp is a wallet-only platform — you don't give us a name, email, government ID, or bank account to trade. What we do collect is your wallet address, your trading activity within our simulated evaluation environment, and standard technical data any web service collects. Your evaluation and payout transactions settle on Solana, which is a public, permanent ledger outside our control — we explain what that means for your privacy below, because it's genuinely different from a typical fintech privacy policy.
2. What we collect
Wallet and identity. Your public wallet address. If you connect an external wallet (Phantom, Solflare, etc.), we never see or store your private key. If you use a platform-generated custodial wallet, your private key is stored encrypted at rest — see §6.
Account and trading data. Evaluation purchases, order history, positions, P&L, payout requests, and their on-chain settlement status. This is the core data needed to run your evaluation and pay you if you qualify.
Optional profile data. If you complete onboarding, an on-platform username, avatar, and linked Telegram or X handle, used for the leaderboard, referral program, and airdrop-points tracking. All optional — skipping onboarding doesn't block trading.
Technical data. IP address, browser/device metadata, and request logs, collected for security (rate limiting, abuse detection), debugging, and uptime monitoring. Retained per our data-retention schedule (§7).
What we do not collect. Government-issued ID, Social Security or tax ID numbers, bank account or card details, or biometric data. We removed our KYC requirement; wallet-only authentication is the front door to the entire platform. See the Geo/AML Decision Memo for why.
3. How we use it
- Operate your account: process evaluation purchases, run your simulated trading, compute payout eligibility, and execute on-chain settlement.
- Fraud and abuse prevention: our integrity engine analyzes trading patterns — including patterns that span multiple firms on the platform — to detect coordinated abuse (for example, hedged accounts designed to guarantee a payout regardless of market outcome). This cross-firm analysis is a stated, deliberate purpose, not a side effect; it's how we keep firm treasuries solvent for honest traders.
- Risk-engine inputs: your trading activity feeds the autonomous risk engine that sets each firm's live risk posture.
- Communications: transactional notifications (payout status, security alerts) and, if you opt in, product updates.
- Legal and security compliance: responding to lawful requests, enforcing our Terms, and protecting the platform from attack.
4. On-chain data is public and permanent — read this before you connect a wallet
Every evaluation purchase, settlement, and payout is a Solana transaction. Solana is a public blockchain: your wallet address, transaction amounts, and settlement outcomes are visible to anyone who looks, indefinitely, and cannot be edited or deleted by us or by you. If your wallet address is otherwise linked to your identity (an exchange KYC record, a public post, a doxxed handle), your trading activity on this platform is discoverable through that link. This is a structural property of the technology, not a choice we're making about how much to disclose — it's also the same property that makes our "the payout is enforced by code, not a promise" claim true. A traditional right to erasure does not apply to on-chain records; §8 explains what we can and can't delete.
5. Who we share data with
- Solana RPC providers — receive the transactions we submit on your behalf; they can see wallet addresses and transaction contents (this is inherent to using Solana, not a choice specific to us).
- Infrastructure providers (hosting, database, error monitoring) — process data on our behalf under standard processor terms.
- Telegram, if you link an account for recovery or bot features — governed by Telegram's own privacy terms for that surface.
- Analytics, if enabled on a given surface (disclosed via cookie/analytics banner where legally required — see §9).
- We do not sell your data. We do not share off-chain account data with third-party marketers.
- Firm operators see only aggregated or storefront-relevant data about their own firm's traders (order flow, payout status) needed to run their storefront — they do not receive your wallet's private key or data from other firms. See the Operator Terms of Service §3 for what operators can and cannot access or control.
6. Security
Custodial wallet private keys, where we generate one on your behalf, are encrypted at rest with keys separate from the database itself; we do not store them in plaintext. [Additional security-posture detail — SOC-type controls, encryption standards, incident-disclosure commitments — to be finalized alongside the Incident Response Plan.] No system is perfectly secure; see our Incident Response Plan for how we handle and disclose a breach if one occurs.
7. Retention
Operational logs (access logs, rate-limit counters, transient debug data) are pruned after 90 days. Account, trading, and payout records are retained for as long as your account is active and for a period after closure sufficient to meet tax, accounting, and dispute-resolution obligations [exact retention period pending counsel — likely 6–7 years for financial records in most jurisdictions]. On-chain settlement records are permanent and outside our retention control, per §4.
8. Your rights and their limits
Depending on your jurisdiction, you may have rights to access, correct, or request deletion of personal data we hold. We honor these for off-chain data we control — profile info, technical logs, support tickets. We cannot delete, alter, or "forget" on-chain transaction history; that data does not live in our systems, and no privacy request can reach a public blockchain. Where full erasure isn't possible, we'll delete what we can and explain what we can't. To make a request: info@decentralprop.com.
9. Cookies and analytics
The trader terminal and the operator console can load PostHog for product analytics. Both ask first: a banner appears on your first visit, and until you choose Accept the PostHog script is never fetched, so no analytics cookie exists and no request reaches a third party. Choosing Reject keeps it that way. Your answer is kept in this browser's local storage, not in a cookie, so we can stop asking. That record and your wallet session are strictly necessary and are not covered by consent, because neither site can function without them.
This marketing site (decentralprop.com) runs no analytics at all and loads no third-party scripts, which is why it shows no banner: there is nothing here to consent to.
10. Children
The platform is not directed at, and we do not knowingly collect data from, anyone under 18. If we learn a user is under 18, we'll close the account.
11. International transfers
The application and its database are hosted on Railway; on-chain data lives on Solana, which is globally replicated and permanent by design and is not something this project can localise, delete, or restrict by region. Formal data-residency and cross-border-transfer terms depend on where the operating company is incorporated, which has not been decided. They will be stated here when it is.
12. Changes to this policy
We'll post updates here with a revised date. Material changes affecting how we use previously collected data will be with more prominent notice (in-app banner or email, where we have one on file).
13. Contact
Open items for counsel: entity name/jurisdiction, exact retention periods per record type, international-transfer mechanism, cookie-consent implementation, and whether the cross-firm integrity-engine profiling described in §3 needs a more specific lawful-basis disclosure in GDPR-covered jurisdictions.
