Legal

Privacy Policy

Last updated: August 15, 2026.

What we collect

  • Wallet addresses. When you connect and sign a message, we store the public wallet address you verified. This is public blockchain data — the address itself reveals nothing private, and signing never gives us access to your funds or private key.
  • On-chain trading history. For a verified wallet, we ingest its historical swap activity from Zerion (a third-party blockchain data provider) to compute realized PnL, drawdown, and win rate. This is also public on-chain data, not something only we can see.
  • Profile information you provide. Display name, bio, and social links you choose to add — shown publicly on your verification page and storefront.
  • Purchase records. If you buy or sell a listing, we store who bought what, when, and the price — necessary to operate the marketplace and show "already owned" status correctly.
  • IP addresses, briefly. Sign-in attempts are rate-limited to prevent abuse; this logs an IP address and timestamp for that purpose only.
  • A session cookie. An httpOnly cookie that keeps you signed in, containing a signed reference to your account — not readable by JavaScript, not used for tracking or advertising.

What we deliberately don't collect

We don't have your private key, seed phrase, or any custody of your funds — a wallet signature proves ownership, it never authorizes a transaction. We don't ask you to create an account with an email and password. If you make or receive a real payment, Stripe collects your email directly as part of checkout for its own receipts — we reuse that same address once, via Resend, to send our own confirmation email, without storing it ourselves. We don't use advertising or third-party tracking cookies.

Payment information

We never see or store your card number. Payments are processed directly by Stripe, a PCI-compliant payment processor — we only ever store the identifiers Stripe gives us back (customer ID, subscription ID, transaction ID) to know what's active and what fee applied.

Third parties involved

  • Zerion — supplies on-chain transaction history for wallet verification.
  • Stripe — processes all real payments and subscriptions; see their own privacy policy for how they handle payment data.
  • Resend — sends real transactional emails on our behalf (purchase confirmations, sale notifications, refund confirmations), using the email address Stripe collected for that specific transaction.
  • Vercel and Supabase — host the application and database.

How long we keep data

Wallet history and tier data are recalculated nightly and kept for as long as your account exists, since the tier system depends on a trailing 365-day history. Purchase records are kept indefinitely as a transaction record. You can disconnect additional wallets yourself from your account page (your last remaining wallet, or any wallet with real trade history, can't be removed, since that would destroy audit data).

Your choices

You control what appears in your public profile (display name, bio, socials) directly from your account page. Wallet verification is opt-in and reversible by signing out; the underlying blockchain data itself, however, is public regardless of what we store.

Children's privacy

Tredecim isn't directed at children and isn't intended for use by anyone who can't legally hold a wallet, sign a binding message, or (where billing is involved) hold a Stripe account in their own name — see the eligibility section of the Terms of Service.

Contact

Questions about this policy, or a request to review or remove data associated with your account, should be directed to Tredecim directly.

See also the Terms of Service, Refund Policy, and Cookie Policy.