Legal

Privacy Policy

Last updated September 13, 2026

Hashly is a discovery platform for the Hedera ecosystem. This policy explains what information we handle when you browse Hashly or connect a wallet, what we use it for, and what you can ask us to do with it. Hashly is responsible for the personal data described here, and you can reach us at hashlyh@proton.me.

The short version

  • You sign in with a Hedera wallet. We never see or store your private keys or recovery phrase.
  • Votes, event check-ins, Ember grants and claims, and raffle entries and draws are written to public Hedera Consensus Service topics together with your account ID. Anyone can read them, and nobody can delete them, including us.
  • We don't sell your data and Hashly carries no advertising trackers. Visits are only measured if you accept analytics, and even then without cookies.

What we collect

Your wallet

When you connect, we receive your Hedera account ID and check a message you sign with it, so we know the account is yours. Your Hashly account is created around that ID.

Public data about your account

We read what anyone can read from the Hedera network and from NFT marketplaces: the NFTs and tokens your account holds and whether they are listed for sale. That decides your voting power, what you can stake, which raffles you can enter and what your museum shows.

What you choose to give us

  • An alias and a profile picture.
  • A HashWorld profile, if you create one, with the details you add to it, such as a name, country, X handle, bio and avatar.
  • Events you submit, projects you apply with (including a contact email and team member details), host requests, and the images you upload with them.
  • How you arrange your museum.

What you do on Hashly

Your votes, check-ins, missions, points and season progress, staking and Ember balance, raffle tickets, referral codes and, if you buy Premium, the transaction ID of the payment.

Technical data

  • Your IP address, used briefly to limit request rates and block abuse.
  • If you accept analytics, page views counted by Vercel Web Analytics without cookies: the page, the site that sent you, and your country, browser, operating system and device type.
  • If you accept analytics, page speed measurements from Vercel Speed Insights.

What your browser stores

Hashly uses no advertising or cross-site tracking cookies. What it keeps on your device is what the features you use need in order to work:

  • The auth-token cookie keeps you signed in for up to 24 hours.
  • hashly-auth-token and wallet-storage in local storage hold your session and your connected wallet.
  • theme, locale and sidebar-storage in local storage remember your theme, language and sidebar layout.
  • viewed:… entries in session storage stop an article view from being counted twice in one visit.
  • WalletConnect keeps the pairing with your wallet app in IndexedDB.
  • hashly-consent in local storage remembers whether you accepted or rejected analytics.

On your first visit Hashly asks whether you accept analytics. Until you accept, Vercel Web Analytics and Speed Insights don't load. You can change your answer at any time with Cookie settings at the bottom of every page.

You can also clear all of it from your browser settings. Doing so signs you out and disconnects your wallet.

Why we use it

  • To run Hashly: sign-in, voting, missions, seasons, staking, raffles, museums and Premium.
  • To check eligibility and voting power against your holdings.
  • To publish the records that let anyone verify votes and draws on Hedera.
  • To keep Hashly fair and secure, including rate limits and spotting abuse of votes and rewards.
  • To reply when you contact us.
  • If you accept analytics, to see in aggregate which pages people use and how fast they load.

If the EU or UK GDPR applies to you, we rely on our agreement with you (the Terms of Use) for most of this, on our legitimate interests for security and abuse prevention, and on your consent for analytics and for optional profile details. You can withdraw that consent at any time.

Public and permanent records

Some actions are recorded on the Hedera Consensus Service so that anyone can check them: votes (with the voting power and holdings behind them), event check-ins, Ember grants and claims, and raffle entries and draws. Each record includes your Hedera account ID and a timestamp. Hedera is a public ledger, so these records can't be edited or deleted by us or by anyone else, and a deletion request can't remove them.

Your alias, profile, museum, points and rankings are also visible to other people on Hashly.

Who else processes it

We don't sell or rent personal data. These providers process it for us to run Hashly:

  • Vercel: hosting, analytics and speed measurements.
  • Supabase: database and file storage.
  • Upstash: rate limiting.
  • WalletConnect (Reown): the connection between Hashly and your wallet app.

Hashly also reads public data and images from other services: the Hedera mirror node, SentX, Kabila, SaucerSwap and GeckoTerminal for market data, X for avatars and Spaces, and IPFS and Arweave gateways for NFT images. When your browser loads an image from one of them, that service receives your IP address under its own privacy policy.

Some of these providers process data in the United States or other countries outside your own. Where the law requires it, those transfers rely on safeguards such as the European Commission's standard contractual clauses.

How long we keep it

  • Account data stays while your account is active. If you ask us to delete it, we will, except for anything we have to keep to meet a legal obligation or to prevent fraud.
  • Records written to Hedera stay on the ledger permanently.
  • IP addresses used for rate limiting are kept only for a short period.
  • Analytics are aggregated and don't identify you.

Your rights

Depending on where you live, you can ask to access the personal data we hold about you, correct it, delete it, restrict or object to how we use it, or get a copy in a portable format. You can also withdraw your consent for optional profile details. Write to hashlyh@proton.me. Because accounts are wallets, we may ask you to sign a message with yours to confirm the request comes from its owner.

You also have the right to complain to your local data protection authority.

Children

Hashly is not meant for anyone under 18, and we don't knowingly collect data from them.

Changes

When this policy changes, the date at the top changes with it. For significant changes we also post a notice on Hashly.

Contact

Questions about this policy or your data: hashlyh@proton.me.