Privacy
Who. Operated by Subnet Metrics. Contact: hello@subnetmetrics.com, or reply to any email from us. Governing law: England and Wales. We are the data controller for what is described here.
What we hold, and why. For the free issue: your email, when you confirmed and the IP you confirmed from, kept as the record that consent existed; lawful basis, consent, withdrawn by the unsubscribe link in every email. For the paid feed: the same plus a Stripe customer id; lawful basis, the contract. For a tax pack: the order record (email, the coldkey(s) you gave us, what was bought, when, and any other-income figure you typed), and the chain history fetched for that coldkey while the pack is built; lawful basis, the contract. For the free exposure check: nothing, unless you enter an email, in which case the email only. We keep no opens, clicks, device data or analytics, and set no tracking cookies; the theme switch stores one value in your own browser. Explore uses an essential sign-in cookie for subscriber access and stores the subnet numbers in your watchlist. Private sign-in links and sessions are stored as hashes. Short-lived hashed email and network identifiers limit sign-in requests.
For the API plan, we hold your email, Stripe customer and subscription identifiers, billing status and dates, key names, prefixes, creation/revocation dates and cryptographic hashes, and aggregate request counts per billing period. Complete API keys are shown once and are not stored. This supports access, billing and usage limits; lawful basis, the contract.
How long. Subscriber records for as long as you are subscribed, then the email alone so a resubscribe cannot be silently ignored. Coldkey history and pack files, 30 days after delivery, then deleted. Order records, six years, the period HMRC can ask about a sale. Explore sign-in links expire after 15 minutes (seven days for links in the daily feed); sessions expire after 30 days. Expired records are purged when new links are issued. Request limits expire after an hour and are purged on the next request. Watchlists remain until you remove their entries or request deletion. API account, key and aggregate usage records remain until you request deletion; payment records needed for accounting follow the six-year retention period above.
Who else touches it. Stripe (payment; sees your email and card, we never see the card), Resend (email delivery), Railway (hosting and the database), and Taostats (the chain index we read a coldkey's public history from, which receives the coldkey and nothing about you). A coldkey is a public address; we treat it as personal data because it is yours. Some of these providers process data outside the UK under their standard contractual terms.
Your rights. To see what we hold, correct it, have it deleted, or object: email hello@subnetmetrics.com and it is done within a month. You can complain to the Information Commissioner's Office at ico.org.uk.