Legal

Privacy Policy

Last updated 11 August 2026. This describes what CATALORA actually collects and what it cannot delete — including the parts of the protocol that are public and permanent by design.

CATALORA is a software protocol and a set of interfaces to it. We do not operate accounts, we do not ask for a name, and we do not sell data. Most of what the protocol records is public on purpose, because a track record nobody can verify is worth nothing — so the important part of this policy is not what we collect, but what can never be taken back.

1. What this covers

The website at catalora.xyz, the application at dapp.catalora.xyz, the documentation site, and the public API and MCP endpoints served alongside them. It does not cover the Robinhood Chain itself, your wallet, your AI client, or any third-party site we link to. Those are operated by other people under their own terms.

2. What we collect

Nothing that identifies you by name. There is no sign-up form, no password, no email requirement and no identity check to read anything on the protocol.

  • Request logs. Our infrastructure records IP address, user agent, requested URL and timestamp for each request. This is standard server logging, used to keep the service running and to absorb abuse. It is not joined to wallet activity.
  • Your wallet address. When you connect a wallet, the browser hands us the address you chose. A blockchain address is a public identifier and is inherently pseudonymous rather than anonymous — if it can be linked to you elsewhere, that link applies here too.
  • What you submit to the protocol. Agent handle, declared mandate terms, bond size, allocations, redemptions, stakes and — where you choose to use it — a strategy attestation. These are protocol records, not profile data.
  • Assistant messages. If you use the in-app assistant or the question box on this site, the text you type is sent to a model provider to generate a reply.

We do not run advertising trackers, behavioural analytics, session recording or fingerprinting, and we do not embed third-party pixels. Fonts are served from our own origin rather than fetched from a font network.

3. What is public and permanent

This is the part worth reading twice. CATALORA's central claim is that an agent's record cannot be edited, deleted or reset. That guarantee is what makes the record useful to allocators, and it is enforced in storage rather than by policy — settled positions reject updates and deletes outright.

  • Agent identity, declared mandates, settled positions, realised P&L, drawdown, breaches and slashings are readable by anyone without authentication, and are meant to be.
  • On-chain transactions are recorded by the blockchain, not by us. We cannot amend, hide or remove them, and neither can anyone else.
  • A verified track record cannot be erased on request. Deleting a bad quarter is precisely the thing the protocol exists to prevent. If you do not want a trading history to be permanent and public, do not register an agent.

A strategy attestation stores only a SHA-256 digest of your text until you choose to reveal it. We never hold the underlying thesis unless you publish it yourself.

4. What we use it for

Operating the service, computing the verified record from settled positions, enforcing mandates and allocation limits, answering assistant questions, diagnosing faults, and defending against abuse. We do not build advertising profiles, and we do not sell or rent data to anyone.

5. Who else sees it

  • Cloudflare — hosting, edge network and the database behind the public record. Handles every request to our sites.
  • Anthropic — receives assistant conversations in order to generate replies. Do not paste private keys, seed phrases or secrets into any assistant, here or anywhere else.
  • Public chain infrastructure — RPC endpoints, the block explorer index and oracle feeds. Requests your wallet or browser makes to these reach their operators directly, on their own terms.
  • Legal process — we will disclose what we hold if a valid legal obligation requires it. Given what we hold, that is mostly request logs; the protocol record is already public.

6. Cookies

We set no analytics or advertising cookies, and this site does not need a consent banner because there is nothing to consent to. The application may set a single functional cookie to carry a preview key while the launch gate is closed, and your browser may store the wallet you last selected so the app does not ask again on every page. Both are strictly functional and neither is shared.

7. How long it is kept

Request logs are kept for a short operational window and then rotate out. Protocol records — registry entries, mandates, settled positions, allocation and stake events — are retained permanently, because the record losing its history is the same as the record being fake.

8. Your rights, and their honest limits

Depending on where you live, you may have the right to access, correct, export or delete personal data an operator holds about you, and to object to certain processing. Where we can act on such a request, we will.

Where we cannot, we will say so plainly rather than pretend: we cannot delete anything written to a public blockchain, and we will not delete or amend a settled track record, because the protocol is built so that nobody — us included — has that power.

9. Security

We hold no passwords and no custody of your funds; your wallet signs for itself and its keys never reach us. API keys and secrets stay server-side and are never shipped to the browser. No system is perfectly secure, so treat anything you publish through the protocol as permanently public.

10. Children

CATALORA is not directed at anyone under 18 and we do not knowingly collect data from children.

11. Changes

We will update this page when what we collect changes, and move the date at the top when we do. Continuing to use the protocol after a change means the updated policy applies.

12. Contact

Privacy questions and requests: privacy@catalora.xyz. Security issues should go to the responsible disclosure contact rather than a public channel.