Privacy Policy

How we handle your data on the Bad Place platform

Last Updated: January 2025

Our Privacy Commitment

Bad Place is designed with privacy in mind. As a decentralized platform, we minimize data collection and never sell your personal information. Your wallet, your keys, your privacy.

1. Data We Collect

We collect the minimum needed to run the platform: • Email Address: required to create an account • Wallet Address: the public address you connect or link • Transaction Data: on-chain activity (public by design) • Content You Create: tokens, posts, comments, uploaded and AI-generated images • Usage Data: anonymous analytics for platform improvement • Device Information: browser type, OS, notification token (mobile, if permitted) • IP Address: temporarily, for security and abuse prevention We DO NOT collect: • Private keys, seed phrases or key shares (NEVER — we hold none) • Precise location • Contact lists or address books • Any data for advertising profiles

2. Wallets & Key Material

We hold no key material of any kind. This is an architectural fact, not a policy promise. • We NEVER store private keys, seed phrases or partial key shares — not encrypted, not split, not at all • On the web, the platform has no embedded wallet: you connect an external browser wallet you already control • On mobile, your recovery phrase is generated and kept on your device; it never reaches our servers • A wallet address shown on your profile is a link you chose to make, proven by a signature — it grants us no control • Because we hold nothing, we cannot move your funds, freeze your wallet or restore access if you lose your own backup Your account (email or Google) is an identity for social and platform features. It is not a wallet and cannot spend your funds.

3. Accounts & Linked Services

Creating an account requires an email address. You may also link third-party accounts. • Email: required to register, verify your account and sign in with a one-time code • Two-factor authentication: if you enable it, we store the secret encrypted with a server key • Google Sign-In: optional; we receive your email address, Google account ID and profile picture • X (Twitter): optional, required for some social features; we receive your public handle, profile picture and banner • Push notifications: on mobile, a device notification token if you allow notifications Linked accounts can be disconnected. Disconnecting stops future data collection from that service.

4. AI Features & Content Moderation

Some features generate images and text using AI models operated by third parties. • What is sent: the prompt you write, options you pick and any reference photo you upload • Who processes it: Google (image generation) and Anthropic (text and safety review) as processors on our behalf • Reference photos are used for generation and safety review only; we do not store the source photo • Generated results you keep are stored on our media storage and are linked to your account • Every uploaded image passes automated safety checks, including CSAM detection through the Canadian Centre for Child Protection's Project Arachnid • Confirmed child sexual abuse material is reported and the account permanently banned, as the law requires • Automated moderation is a filter, not an approval, and it is not a human review of your content If you do not want your content processed this way, do not use the AI features.

5. How We Use Your Data

We use collected data for: • Providing platform functionality • Displaying your transaction history • Preventing fraud and abuse • Improving user experience • Ensuring platform security • Complying with legal requirements We DO NOT use your data for: • Targeted advertising • Selling to third parties • Building marketing profiles • Tracking across other websites

6. Data Sharing

We may share data with: • Blockchain Networks: transactions are public by design • AI Processors: Google and Anthropic, only the content you submit to AI features • Child Safety: the Canadian Centre for Child Protection, for CSAM detection • Service Providers: hosting, storage and analytics (anonymized where possible) • Legal Authorities: if required by law or valid legal process We NEVER share: • Wallet-to-identity mappings • Key material of any kind (we hold none) • Your data for marketing or advertising purposes • Your data with data brokers

7. Copyright Notices

If you send us a copyright takedown notice or a counter-notice, that document is handled differently from ordinary support mail. • A valid notice must contain your name, address, phone number and email — the law requires it • We forward the notice, including that identifying information, to the user whose content is affected; this is required and we cannot anonymise it • Counter-notices are forwarded in the same way to the party who filed the original notice • We retain notices, counter-notices and the resulting actions as long as legally required, including for our repeat-infringer records If you do not want your contact details passed to the other party, do not file a notice — there is no confidential route through this process. The full procedure is set out in our Copyright & DMCA Policy.

8. Security Measures

We implement robust security measures: • SSL/TLS encryption for all communications • No key material held at all — no private keys, seed phrases or key shares • Two-factor secrets stored encrypted with a server key • Automated safety checks on uploaded content • Regular security audits • Minimal data retention • Access controls and monitoring However, no system is 100% secure. Turn on two-factor authentication and keep your seed phrase somewhere only you can reach.

9. Cookies & Local Storage

We use: • Essential Cookies: For platform functionality (session, preferences) • Local Storage: For wallet data (encrypted) and settings • Analytics: Anonymous usage statistics We DO NOT use: • Advertising cookies • Cross-site tracking • Third-party marketing pixels You can disable cookies, but some features may not work properly.

10. Your Rights

You have the right to: • Access: Request what data we have about your wallet • Deletion: Request deletion of off-chain data • Portability: Export your data • Objection: Opt-out of non-essential data processing Note: On-chain data (transactions, token creation) is permanent and cannot be deleted due to blockchain immutability. To exercise these rights, contact us through official channels.

11. Data Retention

• Transaction History: permanent (on-chain, outside our control) • Account Data: until you delete your account • Content You Publish: until you delete it or your account • Analytics Data: 12 months • Server Logs: 30 days • Reference Photos Sent to AI: not stored • Consent Records: kept as long as legally required You can request deletion of off-chain data at any time. On-chain data is immutable and cannot be deleted.

This Privacy Policy may be updated periodically. Continued use of the platform constitutes acceptance of any changes.