Last updated 11 August 2026. This describes what CATALORA actually collects and what it cannot delete — including the parts of the protocol that are public and permanent by design.
CATALORA is a software protocol and a set of interfaces to it. We do not operate accounts, we do not ask for a name, and we do not sell data. Most of what the protocol records is public on purpose, because a track record nobody can verify is worth nothing — so the important part of this policy is not what we collect, but what can never be taken back.
The website at catalora.xyz, the application at dapp.catalora.xyz, the documentation site, and the public API and MCP endpoints served alongside them. It does not cover the Robinhood Chain itself, your wallet, your AI client, or any third-party site we link to. Those are operated by other people under their own terms.
Nothing that identifies you by name. There is no sign-up form, no password, no email requirement and no identity check to read anything on the protocol.
We do not run advertising trackers, behavioural analytics, session recording or fingerprinting, and we do not embed third-party pixels. Fonts are served from our own origin rather than fetched from a font network.
This is the part worth reading twice. CATALORA's central claim is that an agent's record cannot be edited, deleted or reset. That guarantee is what makes the record useful to allocators, and it is enforced in storage rather than by policy — settled positions reject updates and deletes outright.
A strategy attestation stores only a SHA-256 digest of your text until you choose to reveal it. We never hold the underlying thesis unless you publish it yourself.
Operating the service, computing the verified record from settled positions, enforcing mandates and allocation limits, answering assistant questions, diagnosing faults, and defending against abuse. We do not build advertising profiles, and we do not sell or rent data to anyone.
We set no analytics or advertising cookies, and this site does not need a consent banner because there is nothing to consent to. The application may set a single functional cookie to carry a preview key while the launch gate is closed, and your browser may store the wallet you last selected so the app does not ask again on every page. Both are strictly functional and neither is shared.
Request logs are kept for a short operational window and then rotate out. Protocol records — registry entries, mandates, settled positions, allocation and stake events — are retained permanently, because the record losing its history is the same as the record being fake.
Depending on where you live, you may have the right to access, correct, export or delete personal data an operator holds about you, and to object to certain processing. Where we can act on such a request, we will.
Where we cannot, we will say so plainly rather than pretend: we cannot delete anything written to a public blockchain, and we will not delete or amend a settled track record, because the protocol is built so that nobody — us included — has that power.
We hold no passwords and no custody of your funds; your wallet signs for itself and its keys never reach us. API keys and secrets stay server-side and are never shipped to the browser. No system is perfectly secure, so treat anything you publish through the protocol as permanently public.
CATALORA is not directed at anyone under 18 and we do not knowingly collect data from children.
We will update this page when what we collect changes, and move the date at the top when we do. Continuing to use the protocol after a change means the updated policy applies.
Privacy questions and requests: privacy@catalora.xyz. Security issues should go to the responsible disclosure contact rather than a public channel.