Legal

Privacy policy

We collect very little. This policy is short because there is little to describe.

Version 1.0 · Effective July 16, 2026 · Operated by David Webb Studios

1. About this policy

TREADSTONE is a non-custodial token launchpad interface for Robinhood Chain, operated by David Webb Studios, an independent developer. This policy explains what happens to information when you use treadstone.finance. In it, "we" and "the Operator" mean David Webb Studios, and "the interface" means this website.

The interface is non-custodial. We do not hold your keys, your wallet, or your assets, and we cannot move them. There are no accounts here. You do not register, you do not give us an email address, and we do not ask you to verify your identity.

We collect very little, and this policy is short because there is little to describe. Where it says we do not do something, that is a statement about how the software is actually built, not an aspiration.

2. Information we collect

Wallet address. When you connect a wallet, the interface reads its public address so it can show your balances and build transactions for you to approve. A wallet address, or a blockchain transaction, may be personal information where it can be linked to an identifiable person. We treat it that way.

Server logs. Our host records ordinary technical information for every request: IP address, browser and device type, the page requested, referring page, and timing. This is inherent to serving a website and is used to operate and secure it.

Anything you type into a launch. A token's name, symbol, description, image, and links are chosen by you, submitted to a public blockchain, and permanently public. Do not put personal information in them.

Terms of Service acceptances. If you accept the Terms of Service by signing with your wallet, we store that acceptance as a legal audit record: your wallet address, the terms version, the exact message you signed, the signature, and the timestamp. The record exists so we can show, later, that a given wallet agreed to a given version of the Terms. It is stored with Supabase, our database provider, and is written only through our own server after your signature is verified.

Anonymous usage telemetry. We record a small set of product events (for example, a page was viewed, a launch was started, a claim succeeded) to understand which features are used and to spot faults. These events are aggregate and anonymous by design: they carry no wallet address, no IP address, no user agent, and no tracking identifier, and they cannot be tied back to you. They are stored with Supabase. You can see exactly what we do not attach to them in the next section.

Messages you send us. If you email us, we have your email address and whatever you wrote.

3. What we do not collect

We think the absences are the most useful part of this policy:

  • No third-party analytics, no session recording. We run no Google Analytics, no self-hosted analytics alternative, and no session recorder. The only usage measurement is our own event counter described above, which is anonymous by design.
  • No wallet addresses, IPs, or identifiers in telemetry. Our usage telemetry never carries your wallet address, your IP address, your user agent, or any tracking identifier. It cannot be linked to you or to your on-chain activity.
  • No advertising, no tracking pixels, no data brokers. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we run no targeted advertising.
  • No accounts, no passwords, no email signup, no KYC. There is nothing to breach.
  • No behavioural profile of you. We do not build one. The terms audit record is a single row proving a wallet accepted a version of the Terms, not a profile of your activity.

4. Blockchain information

Public blockchains are transparent and permanent by design. Wallet addresses, transactions, token launches, liquidity positions, fee claims, and contract interactions are visible to anyone through Robinhood Chain nodes, explorers, indexers, and other independent services.

We cannot edit, hide, reverse, or delete anything recorded on a public blockchain. Nobody can, including us. Disconnecting your wallet does not remove activity that already happened, and neither does a request to us.

Public blockchain data is also open to forensic analysis. Addresses that look anonymous can be linked back to a person, especially when on-chain activity is combined with information from elsewhere. This is a property of public blockchains generally, not of this interface.

5. Browser storage

No cookies. The interface sets no cookies at all: none for sessions, none for analytics, none for advertising.

Local storage. If you accept the Terms of Service by signing with your wallet, the record of that acceptance (the version, the signed message, the signature, and the timestamp) is cached in your own browser under a key containing your wallet address, so the interface can tell you have already accepted without asking your database provider each time. The same record is also stored server-side as the legal audit log described in Section 2. Clearing your browser storage removes only the local cache, not the server record. If the server is unreachable when you accept, the interface still works from the local cache and records the acceptance server-side on a later attempt.

6. Third-party services your browser contacts

Using the interface means your browser talks directly to services we do not control. They receive your IP address as a consequence, and their own terms and privacy policies apply:

  • Vercel, our hosting provider, which serves the site and keeps the request logs described above.
  • The Robinhood Chain RPC endpoint, which your browser queries to read chain state and broadcast the transactions you approve.
  • Your wallet, which is software you chose and installed. Browser-extension wallets, Coinbase Wallet, and WalletConnect are supported. WalletConnect additionally relays connection data through its own infrastructure when you use it.
  • DexScreener, queried for market data about tokens.
  • CoinGecko and IPFS gateways, from which token images are loaded.

We do not send them information about you beyond what making the request necessarily reveals, and a link or integration is not an endorsement.

One service your browser does not contact directly is Supabase, our database provider. It stores the Terms acceptance audit records and the anonymous usage telemetry described in Section 2. Only our own server writes to it, using a server-only key, so Supabase never receives your IP address from your browser.

7. How we use information

Only to run the thing: to operate, maintain, and secure the interface; to show you your own balances, positions, and claimable fees; to build the transactions you choose to approve; to diagnose faults and abuse; and to answer you if you write to us.

We do not use your information to profile you, to advertise to you, or to make automated decisions about you.

Where applicable law requires a legal basis to process personal information, we rely on processing that is necessary to provide the service you asked for, on our legitimate interest in operating and securing the interface, on your consent where we asked for it, and on compliance with legal obligations that apply to us.

We have deliberately not written this policy around one country's privacy statute. We are a single independent developer, not a company with a registered office, a data protection officer, or an appointed representative, and claiming otherwise would be untrue.

9. Retention

Server logs are kept only as long as they are useful for operating and securing the site, and are then discarded on our host's ordinary schedule. Email correspondence is kept as long as it is relevant.

Terms acceptance records are kept for as long as we may need them as legal evidence that a wallet agreed to a version of the Terms, which can be for the life of the interface and a reasonable period after. Anonymous usage telemetry is aggregate and, because it identifies no one, is retained as long as it is useful for understanding and improving the product.

Local storage stays on your device until you clear it. Public blockchain records last indefinitely and are outside our control and everyone else's.

10. Security

The site is served over HTTPS with a strict content security policy. Non-custodial design is the substantive protection here: we cannot lose your funds because we never hold them, and we cannot leak a password database because there is not one.

No system is perfectly secure. The most likely thing to hurt you here is not our server; it is a compromised wallet, a phishing site imitating this one, or a transaction you were persuaded to sign. Check the address bar and read what your wallet asks you to approve.

11. Your choices and rights

The things most within your control:

  • Browse without connecting. The interface is readable without a wallet.
  • Disconnect at any time, and clear your browser storage to remove the local cache of your acceptance. The server-side audit record of that acceptance remains, since it is our legal evidence that you agreed to the Terms.
  • Keep personal information out of token metadata, chat, and public links. Once it is on-chain it is permanent.
  • Use a separate wallet for activity you want to keep apart.

Depending on where you live, you may also have rights to access, correct, delete, or receive a copy of personal information, to object to or restrict processing, to withdraw consent, and to complain to your local data protection authority. To exercise any of these, email us at info@treadstone.finance and we will do what applicable law requires.

Two honest limits. We cannot alter or erase public blockchain records, for anybody. And because there are no accounts, we usually hold no off-chain personal information tied to you beyond server logs, so in most cases there is genuinely nothing for us to return, correct, or delete. We also cannot verify that an address belongs to you, so we will not disclose information on the basis of an address alone.

We will not discriminate against you for exercising a privacy right.

12. Children

The interface is not directed at children and is not for anyone under 18, or under the age of majority where you live. We do not knowingly collect information from children. If you believe a child has provided information, write to us and we will delete what we hold.

13. Changes to this policy

If this policy changes, the version and effective date at the top of this page change with it. Material changes will be announced through our official channels. Because the policy tracks what the software actually does, it changes when the software does.

14. Contact

Email info@treadstone.finance. It is the only support channel we operate. We will never ask for your seed phrase or private key, and we will never ask you to approve a transaction. Anyone who does is attacking you.