Privacy notice
This notice covers straycucks.com: its collab application, and signing in with a wallet on straycucks.com/me (your account, linked wallets and X account). It says who we are, what we hold, why, for how long, who else sees it, and what you can do about it. It does not cover the allowlist checker, except for what it learns from your sign-in (below).
Who we are
Stray Cucks is an independent NFT project on Robinhood Chain, run by one person: GM GN Repeat (by The Arson Dragon).
Privacy contact: legal@straycucks.com
What we collect when you apply
What you type: project name, contract address, creation transaction, project X handle, links, the page name you would like, what you want, the about text, your X handle, your role, and your contact with its kind (Discord, Telegram, X, email or other). Required: project name, what you want, where to reach you, your contact and the agreements. Everything else is optional.
Art you send, with its size, type, dimensions, frame count and a sha256 fingerprint. We do not keep the file name.
If you sign the optional project proof: your wallet address, the text you signed and the signature.
Your consents, with the version and fingerprint of each document and the time.
A keyed hash of your connection's IP address (for IPv6, of its /64 network). We never store the IP address itself. The key is a secret that we replace about every 30 days, so hashes made with an old key cannot be matched with new ones.
If you sign in with a wallet (straycucks.com/me)
We keep: an account id; when you confirmed you are 18 or older and the version of the notice you saw; the wallets you link, when, and how each proved it is yours; your sign-in sessions (when they started, when you were last here, which of your wallets made each one, and a keyed hash of the connection that changes every 30 days). We keep no signatures, no signed messages and no IP addresses.
If you link an X account we keep its X account number and username. With Sign in with X we also keep the X join date, follower count and verified type at that time. Sign in with X makes one read of your profile and gives the access back to X at once; we keep no X login or token. With the post method, the post id and the post data are kept while the check runs, 24 hours at most. Sign in with X runs a Cloudflare Turnstile spam check, which sees your IP address and browser details.
An X account you linked with Sign in with X can also log in to your account, with limited powers: it can look, download your data and use the allowlist checker, but it cannot change your wallets or X or delete the account. It can log in only after you linked or confirmed it while signed in with your first wallet, and Sign out everywhere from that wallet switches it off again. A log in with X lasts at most 7 days.
Your linked wallets are private. Anyone who has the key of one of your linked wallets can sign in to your account, so each sign-in shows only its own wallet in full, and only a sign-in with the first wallet you linked shows your X account.
For 30 days after a wallet or X account leaves an account (unlink or delete), we keep a keyed fingerprint of it (not the address or the X account) so it cannot join a different account at once. A wallet can always still sign in.
The allowlist checker (allowlist.straycucks.com) gets only a yes, no or unknown answer about whether your account holds a Stray Cuck. It never gets your account id, your wallets or your chairs.
If our data ever leaked, it would show which wallets belong to which X account. That is the most sensitive thing we hold, and the reason for the rules above.
Why: to run the account you ask for (sign-in, holder status, the X link you choose to make), and to stop abuse (connection hashes, rate limits, the 30-day fingerprints): our legitimate interest in keeping sign-in honest and working.
To check holdings we read our own index of Stray Cucks owners and, when it is behind, Robinhood Chain RPC providers, which receive your wallet addresses but not who you are. Sign in with X happens on X, under X's own terms.
How long: sessions end after 7 days without a visit and at most 30 days after sign-in. Your account, wallets and X link stay until you unlink them or delete your account. Rate limit counters expire within 2 days, and the ones named after your account or sessions are removed when you delete it.
On straycucks.com/me, Download my data gives you all of it as a JSON file, and Delete account removes your account at once.
Before you send
When you type a contract address, the form asks our server who owns that contract; the address goes to our server and to a Robinhood Chain RPC provider. When you press Sign, your wallet address and the contract are stored for 15 minutes with the signing request, then deleted.
What we add
Facts we read on chain about the contract you name: owner, deployer, first owner, factory, whether it is a clone, name, symbol and supply, and whether your signature matches the owner.
How many other contracts we know of that the signing wallet owns or deployed, including contracts named in other applications. We use this to spot launchpad owners who could sign for many projects.
The status of your application and its history, our decision and its reason, the result of the spam check, the id of our Discord message about your application, and our reviewer notes.
What we never collect
Real names on purpose, passwords, phone numbers, locations or government ids. Please do not put them in the form.
Why, and on what basis
To review your application and reply to you: these are steps you ask us to take before any agreement, and our legitimate interest in running collaborations.
To use the art you send: the art license you accept.
To check on chain who controls the contract you name, and to stop spam and abuse (IP hash, spam check, rate limits): our legitimate interest in keeping the application honest and working.
What is public
Nothing from your application is public. Your answer to "may we list you publicly" is stored as your wish; there is no public project page yet. If we build one, this notice will say what it shows before anything is published.
Who else processes it
Nobody buys or receives your data from us. Our providers: Cloudflare hosts this site and stores applications, and runs the Turnstile spam check on the form and the status page, which sees your IP address and browser details. Discord: the operator gets a private Discord message with the text of each application (art files are not sent). Robinhood Chain RPC providers receive the contract and wallet addresses we look up, not who you are.
Our home page loads its fonts from Google Fonts, which sees your IP address. The application form, the status page and these legal pages do not; they use fonts served by us.
Cloudflare and Discord may process data in the United States and other countries outside yours.
How long we keep it
Applications we have not decided within 6 months of the last status change are closed as expired.
Declined, withdrawn, expired or removed applications: art is deleted 30 days after the last status change, and the whole application 90 days after it.
Applications we mark as spam are deleted after 30 days.
Approved applications are kept while we work with the project. Your contact is deleted 12 months after the last status change. If we later remove the project, the rule for removed applications applies.
The IP hash is deleted 90 days after you apply. Signing requests are deleted after 15 minutes. Rate limit counters hold only hashes and expire within 2 days.
After a deletion we keep only the application id, the time and the id of our Discord message, until our checker has removed that message, and at most 12 months. After that, the id and the time alone for 7 more days, so a late copy of the application can still be found and deleted.
These deletions run automatically on our hosting provider, at least once a day. Removing or editing the Discord message is done by a checker on the operator's computer every few minutes while it is on; when it is off, the task waits and runs when it is back.
Your controls and rights
Your private status link lets you Download your application as a JSON file, Withdraw it, Delete it (the application and every art file, at once), and replace the link with a new one. When you delete it, our checker also removes the Discord message about it.
You can also ask us for a copy of your data, including our reviewer notes (they are not in the Download), and ask us to correct, delete or restrict it, or object to how we use it. Write to legal@straycucks.com. An application cannot be edited: to correct it, Delete it and apply again, or write to us.
You can also complain to the data protection authority where you live.
We do not keep a copy of your status link. If you lose it, write to legal@straycucks.com with your application reference, from the contact you gave in the application.
Security
Applications are stored privately with Cloudflare and only the operator can read them. A breach would reveal what you sent: your contact, handles, the wallet address if you signed, and your art. If that happens we will post a notice on this site and write to the contact you gave.
Blockchain note
Anything on chain, including transactions and signatures you broadcast, is public and permanent. Nobody can delete it. The project proof signature is not broadcast: it stays with your application and is deleted with it.