Privacy Policy
What Backer collects, why, who handles it for us, and the choices you have.
Draft status
This policy describes Backer as it will run at launch, including accounts, which are still being added. Today the site is a prototype.
Who is responsible
The operator of Backer is responsible for the personal information described here. Its legal name, mailing address and an email address for privacy requests will be published here before launch.
When you visit
Vercel hosts Backer. When you visit, Vercel receives your IP address, browser details and the pages you request, and keeps request logs.
We use the country and region that Vercel works out from your IP address to block access from restricted places.
To stop the report form from being flooded, we count how often each connection sends it. The count is kept against a one-way hash of your IP address, never the address itself, and it is deleted within a day.
If a page fails to load in your browser, the site sends the error, the page it happened on (without any query string), and the version of the site to our request logs so the fault can be fixed. Our server passes the same report to Sentry, the error-tracking service we use; your browser does not contact Sentry, so Sentry does not receive your IP address. The report does not include your wallet address, anything you typed, or anything else about you.
Your browser keeps your answers to the entry notice and the cookie banner. The Cookie Policy explains this storage.
If you allow analytics, Vercel Web Analytics records each page view with the page address, referrer, country, browser, operating system and device type. It sets no cookies. Vercel says it tells visits apart using a hash of the request that it discards after 24 hours.
When you sign in
Sign-in and embedded wallets are provided by Privy. Depending on how you sign in, Privy handles your email address or the details of your social account, and it creates and manages your embedded wallet under its own privacy policy.
Backer receives your Privy account identifier, your wallet addresses, and the email address or social account linked to your sign-in. Backer does not receive your private keys.
Other people never see your Privy account identifier. Where the site points to your account, such as on your profile page or in someone's messages, it uses a separate random id that we create for your account and that reveals nothing else about it.
What you publish
Your profile, meaning your handle, display name, bio, avatar and links, is public.
Your profile has its own public page at your handle, which also shows how many accounts follow you, your posts and your price for a message. It does not show your email address, your wallet addresses (unless you choose to link one, as the next paragraph says) or who follows you.
You can choose to link a wallet you launched tokens from to your profile. Nothing is linked until you choose it, one wallet at a time, and we link only a wallet on your own account. Once linked, anyone can see that the wallet belongs to your profile: the page of every token launched from it shows your handle, a link to your profile and when you last posted, and anyone can look the wallet up. What that wallet has done on its blockchain is already public, and the link lets anyone tie it to you. You can unlink it in your profile at any time; we then remove the link at once, though a page may show it for up to 20 seconds more. We cannot remove copies other people made while it was public.
Tokens you create are public, including their name, ticker and image. The name, the ticker and a link to the token's details are also written to a public blockchain.
Profiles and uploaded token images are stored with Supabase.
Your posts are public. Your direct messages are stored with Supabase and shown only to the two people in the conversation; Backer can read them to review a report, enforce the Terms or answer a legal request. For a paid message we keep the id of the payment transaction and of its escrow deposit, both public on their blockchain, with the message, whether the trader replied in time, and a record of who you blocked and what you reported.
Blockchain data
Wallet addresses and transactions are public on their blockchains. Backer reads that public data to show balances, trades and positions. Anything written to a blockchain cannot be changed or deleted by Backer or by anyone else.
Notices you send
If you send a takedown or impersonation notice, we collect your name, email address, any mailing address or phone number you give, whether you own the rights or act for the owner, the work you describe, what you say infringes it, your statements and your typed signature. We may share your name, email address and notice with the person whose content you reported.
Card and wallet payments
When card, Apple Pay or Google Pay buying is available, the payment provider will collect your payment details and any identity documents it requires, under its own terms and privacy policy. Backer does not collect card numbers or identity documents.
How we use information
To run Backer: signing you in, showing profiles and tokens, and displaying market information.
To block restricted regions, prevent abuse and protect the site and its users.
To handle notices, enforce our terms and meet legal obligations.
To measure how the site is used, only if you allow analytics.
We do not sell personal information and do not use it for targeted advertising.
Legal bases in the EEA and the UK
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases: performing our agreement with you for sign-in, profiles and tokens; our legitimate interest in protecting the site and its users; compliance with legal obligations, including sanctions; and your consent for analytics, which you can withdraw at any time.
Who handles information for us
Vercel hosts the site, keeps request logs and, if you allow it, runs analytics. Privy runs sign-in and embedded wallets. Supabase stores profiles and uploaded images. Sentry receives the error reports described above.
To show chain volume figures and the real markets, our server requests them from DeFiLlama and GeckoTerminal. Those requests carry no personal information about you.
When you search for, open or trade a token launched elsewhere, your browser asks Jupiter, LI.FI and GoPlus directly for the token's details, its safety checks and a quote, and sends a Solana trade through a public Solana network provider. They receive your IP address and, for a quote or a trade, your wallet address, and handle it under their own privacy policies. Backer's server is not involved in these requests.
Before the site sends a transaction for your wallet, or delivers a paid message, our server checks the wallet address against sanctions lists: for an EVM wallet it reads Chainalysis's public sanctions oracle through public blockchain network providers, and for a Solana wallet, once this check is switched on, it asks Chainalysis's sanctions screening service. Only the wallet address is sent, not your name or IP address. The result is kept in the server's memory for up to ten minutes and is not stored. A wallet on a sanctions list cannot send transactions through the site or pay for a message.
We may also disclose information when the law requires it, to protect people or the site, or as part of a sale or reorganization of the business.
Where information is processed
Our providers may process information in the United States and other countries. How transfers from the EEA and the UK are protected will be described here before launch.
How long we keep it
Retention periods for each kind of information will be published here before launch.
Your entry notice and cookie choices stay in your browser until you clear them. Information written to a blockchain stays there permanently.
Your rights
Depending on where you live, you may have the right to know what personal information we hold, to get a copy, to correct it, to delete it, to object to or limit some uses, and to withdraw consent. You will not be treated differently for using these rights.
The email address for privacy requests will be published here before launch. We may need to confirm who you are before acting on a request. We cannot delete information from a blockchain.
If you are in the EEA or the UK, you can also complain to your data protection authority.
Do Not Track
Backer does not track you across other websites, and analytics load only if you allow them. The site does not change how it works in response to Do Not Track signals.
Children
Backer is only for people 18 and older, and we do not knowingly collect information from anyone younger. If we learn that an account belongs to someone under 18, we will close it and delete the information we hold about them, apart from what is on a blockchain.
Protecting information
We use reasonable measures to protect personal information, but no system is fully protected. If a breach affects your information, we will tell you where the law requires.
Changes to this policy
We will post changes on this page with a new date, and tell you on the site before a material change takes effect.