Privacy policy
Last updated
This describes what we store, why we store it, and what we deliberately do not. It is written from the database schema, so each claim can be checked against the code.
Who we are
cats.fund operates this service and decides how the data described here is used. For anything in this policy — including a request to access, correct or delete your data — write toprivacy@cats.fund.
What we store
Your wallet address
Signing in proves control of a wallet using a signed message. We store the address and a session identifier. The address is your identity here: your evaluations, orders and certificates are all keyed to it.
A wallet address is public by design, and everything the contract records — accounts opened, verdicts, payouts claimed — is public on BNB Chain. We cannot make on-chain activity private, and neither can anyone else.
Your trading activity
Every order you submit is stored, along with the oracle price it filled against and the resulting position and fill. This is what makes a verdict reproducible: the same records replayed produce the same result, which is the basis on which we can be checked rather than believed.
Because verdicts are anchored on chain and must remain verifiable, this record is retained and is not deleted on request. See Your rights below.
Your display name
If you claim one, it is stored and — once a certificate is minted carrying it — written to the chain permanently. We cannot remove a name from an issued certificate.
Identity verification
Verification is performed by a third-party provider. They collect and hold your identity documents and the images captured during the check.
We do not store your documents. No identity document images, document numbers, dates of birth or addresses are kept in our database.
What we keep is the decision: whether verification was approved, the provider's own status for it, when it was granted, the provider's session reference, and whether a sanctions screening returned a match. That is the minimum an auditor asks for, and holding more would widen the harm of a breach without making the record more useful.
Technical records
We record request rate-limit counters keyed to IP address, and an audit log of privileged actions. Market data — candles and price ticks — is stored but is not about you.
Why we store it
- To provide the service. Sessions, orders, verdicts and certificates are the service.
- To meet legal obligations. Identity verification and sanctions screening are required before we release funds, and the records of those checks must be retained.
- To keep the service working and honest. Rate limits and audit logs exist to prevent abuse.
Who we share it with
- The identity verification provider, which receives your documents directly from you and returns a decision to us.
- Our infrastructure provider, which hosts the application and its database.
- Authorities, where we are legally required to disclose.
We do not sell your data, and we do not use it for advertising.
How long we keep it
Sign-in sessions expire after twelve hours. Verification and payout records are retained for as long as the law requires us to hold them, which is typically five years after the last transaction. Trading records supporting an on-chain verdict are retained indefinitely, because the verdict remains publicly verifiable and a record that could not be re-derived would make it uncheckable.
Your rights
Depending on where you live you may have rights to access, correct, or delete personal data, to object to processing, or to receive your data in a portable form. Write to privacy@cats.fundand we will respond within the time the law allows.
Two limits are worth stating plainly rather than discovering later.Data written to the chain cannot be deleted by us or by anyone else — that includes account records, verdicts, certificates and the display name on one. And records we are required to keep for anti-money laundering purposes cannot be deleted on request during their retention period.
Cookies
We set one cookie by default, which holds your sign-in session. It isHttpOnly, SameSite=Lax and, in production,Secure. We set no advertising cookies at all, and we do not sell or share what we measure with anyone for advertising.
We use Google Analytics to count visits and understand which pages people actually use. It runs in consent mode: until you accept, it stores nothing on your device and sets no cookie — it reports an anonymous, cookieless signal that we cannot tie to you or to a return visit. If you accept, it sets its own cookies to recognise a returning browser. You can decline, and change your mind later, from the banner; your choice is remembered on your device.
IP anonymisation is on, so Google receives a truncated address rather than the one you connected from. Analytics is not loaded at all on our partners' white-label domains.
Changes
If this policy changes materially we will say so before the change takes effect. The date at the top always reflects the current version.