Privacy Policy
Last updated: March 4, 2026
This policy explains what data FutarchyHub collects and what we do with it.
What we collect
Account data
- Nostr users: your public key and any profile metadata fetched from nostr relays (display name, picture, NIP-05 identifier).
- GitHub users: your GitHub user ID, username, avatar, and public organization memberships. We also generate and store an encrypted nostr keypair on your behalf.
- Google users: your Google user ID, name, email address, and profile picture. We also generate and store an encrypted nostr keypair on your behalf.
OAuth access tokens are stored encrypted.
Market activity
All market actions — trades, proposals, votes, deposits, withdrawals — are recorded in our database and published as signed nostr events to the market's relay. This means your market activity is verifiable by anyone with access to the relay.
Financial data
We store Lightning invoices, payment hashes, and transaction amounts for deposits and withdrawals. Token balances and share positions are tracked per market.
Cookies
We use a single session cookie (HMAC-signed, HttpOnly, Secure) to keep you logged in. No tracking cookies, no analytics, no third-party scripts.
What we don't collect
- We do not run analytics or tracking software.
- We do not sell or share your data with advertisers.
- We do not use third-party scripts that track you.
Data disclosure
We will not provide user data to any third party unless compelled by a court order.
Nostr relay
Market actions are published to each market's nostr relay. These events are cryptographically signed with your key and are designed to be publicly verifiable. Treat anything you do in a market as potentially public.
Server-held keys
If you sign in with GitHub or Google, we generate a nostr keypair for you. The private key is encrypted and stored on our server. If you want full control of your key, sign in with your own nostr key instead.
Data retention
We retain your data for as long as your account exists. Nostr events published to relays cannot be recalled. Ledger entries are retained permanently for audit purposes.
Data deletion
Contact us to request account deletion. We will remove your account data from our database. We cannot delete nostr events already published to relays or ledger entries required for market integrity.
Children
FutarchyHub is not for anyone under 18. If we learn a minor has created an account, we will delete it.
Changes
We may update this policy. Continued use after changes means you accept the new policy.
Contact
Questions: npub1hrsc5rld9qg7lms...