What we collect, and why
| What | When | Why | Where it is kept |
|---|---|---|---|
| Your email address | Only if you submit the Desk waitlist form | To tell you when the Desk opens | Our own database server (Hetzner Online GmbH, Helsinki, Finland) |
| The page you signed up from, a short tag for which form you used, and (on the Desk page) which planned plan you picked | With the email | To know which page brought you and which plan interests you, so we can tell you about the right product. Picking a plan is not a purchase and nothing is charged | Same server, same row as your email |
| Your browser's user-agent string (browser and operating system) | With the email | To spot automated junk signups | Same server, same row |
| When you first and last signed up, and how many times | With the email | So signing up twice does not create two entries | Same server, same row |
| Aggregated, cookieless page-view and performance statistics | Every visit | To know which pages are read and how fast they load | Vercel Web Analytics and Speed Insights |
| Your wallet address and the signed sign-in message (Sign-In with Ethereum: domain, address, a one-time nonce, the time) | Only if you register for the Desk with a wallet | To prove you control the wallet and to be your account; there is no password | Our own database server (Hetzner, Helsinki), one row per wallet |
| The Desk registration form: what you run (a category), roughly how many agents, which plan you picked, an optional email, an optional note, and the version of the Terms you accepted and when | With the wallet, at registration | To shape the beta and to reach you about it if you gave an email | Same server, same row |
| A session token (your wallet address, plan, issue and expiry time, signed by us) | After a successful sign-in, for up to 30 days | So the Desk knows it is you without asking you to sign again | Your own browser's local storage only; we keep no copy |
| If you buy a Desk plan: the payment's transaction hash, the plan and its length, the amount, the paying address, the network and the Terms version | When a plan payment settles | To switch the plan on, to prove the purchase, and for refunds and accounting records the law requires us to keep | Our own database server (Hetzner, Helsinki). The payment itself is public on Base, and Coinbase Developer Platform receives the signed authorisation to settle it, under its own privacy policy |
| If you buy a single evidence pack (a check) instead of a plan: nothing beyond the request log below. We do not keep a record tying the pack to you | When you pay for a check | To deliver the pack you paid for | The payment itself is public on Base; Coinbase Developer Platform receives the signed authorisation to settle it, under its own privacy policy |
| Standard request logs (IP address, time, URL) | Every request | Security and keeping the site running | Vercel, our hosting provider, under its own retention rules |
We do not ask for your name, company or phone number, and no form has a field for them. We never ask for, receive or store a private key, seed phrase or password: signing in is a signature, not a secret. The wallet address you sign in with is public on the blockchain by nature; we do not link it to any other data we hold except the form you fill.
Why we are allowed to keep it: for the Desk registration, because it is necessary to provide the account you asked for (GDPR Article 6(1)(b)); for the waitlist, you ask us to, by submitting the form. That is consent under the EU General Data Protection Regulation (Article 6(1)(a)), and you can withdraw it at any time by writing to us. Withdrawing does not affect what happened before you did.
What the site stores in your own browser
No cookies. The site saves a few things in your browser's local storage so it remembers them next time:
- display preferences: the chart range you picked, whether you turned motion off, and whether you have already joined the waitlist;
- if you use the Desk: your session token (see above), the wallets this browser has signed in with, and your Desk data: the agents you watch, their allow-lists, your alert rules and the EIP-7702 delegation last seen on each watched agent, so a change can be flagged.
Your Desk data stays on your device. To draw an agent's card, the Desk asks our API for that agent's public record, as any visitor would, and sends your session token with it so a paid plan gets its full tier; we do not record which agents you look up. Clearing your browser's site data removes all of it, and the Desk's own Clear button removes the Desk data.
What we never do
- We do not sell, rent or share your email with anyone.
- We do not use it for advertising, and the site runs no advertising or cross-site tracking scripts.
- We do not combine a waitlist email with wallet addresses or on-chain activity. An email you type into the Desk registration form is kept in that wallet's row, because that is where you gave it.
- We do not load fonts, scripts or images from third parties while you read: everything is served from this site. If you choose to sign in with a Base Account, its sign-in window is Coinbase's (keys.coinbase.com), opened only when you pick it.
The data this site publishes is not about you
The graph itself is built from public blockchain records: agent registrations, wallet addresses and payments that anyone can read on-chain. We publish what those records show about software agents and their wallets. We do not try to find out who owns a wallet, and we never publish a person's name next to one. If you believe something we publish identifies you personally, write to us and we will look at it.
Who processes data for us
- Hetzner Online GmbH hosts the database server in Helsinki, Finland, where waitlist emails are stored.
- Vercel Inc. hosts the website and runs the form that passes your email to that server. Vercel is a US company, and it describes how it handles personal data in its own data processing terms.
- Coinbase Developer Platform verifies and settles USDC payments (Desk plans and evidence packs) from the authorisation your wallet signs. If you sign in with a Base Account, its window is Coinbase's own (keys.coinbase.com). Both work under Coinbase's privacy policy.
The data providers our collector reads from (blockchain nodes, price feeds, public registries) receive requests from our server, never from your browser and never with your data.
How long we keep it
Your email is kept until the Desk opens and you have heard from us, or until you ask us to delete it, whichever comes first. If you do not become a Desk user, we delete waitlist entries once the waitlist is closed.
Your rights
You can ask us at any time what we hold about you, to correct it, or to delete it. Write to agenticfinancegraph@proton.me from the address you signed up with, and we will do it and confirm. You also have the right to complain to your data protection authority.
Who is responsible
Agentic Finance Graph is run by its founder, a private individual, who decides what is collected and why (the data controller under the GDPR). No company has been registered for it yet; when one is, it becomes the controller and this notice will name it before that happens. Contact: agenticfinancegraph@proton.me.
Changes to this notice
If the site starts collecting anything new, this page is updated before that happens, and the date below changes.
Last updated 27 September 2026: named who is responsible, listed everything the Desk keeps in your browser, and added evidence-pack purchases and Coinbase as the payment processor.