24h Vol
Tokens
ETH
Create

Privacy Policy

Most of what gord shows you is public blockchain data copied into a database so pages load quickly. Beyond that we collect very little. This page is organised by what we actually hold rather than by legal category, and it starts with the uncomfortable part: some of this is written to a public blockchain, where it is permanent and where nobody can delete it, ourselves included.

Wallet addresses, token addresses, trades, balances, fee accruals, locks and bindings are public facts on GIWA. Anyone can read them with or without gord. We index them so the site is fast. We did not create them and we cannot remove them.

Two of them are worth naming, because they involve you rather than a market:

The image a launcher uploads for a token is also referenced by a URL written into the token's on-chain record. The bytes are ours and we can stop serving them. The URL is not ours and stays where it is.

One Postgres database, run for us by our hosting provider. In it:

A dump of that database is taken nightly into a private bucket, and the fourteen most recent are kept.

Most of this never leaves your device. The cookies are the exception, and the list below names each one.

Fees designated to a social account are claimed by proving you manage it. There are two ways, and only one involves signing in.

Signing in with Google requests the https://www.googleapis.com/auth/youtube.readonly scope and uses it for exactly one call: channels.list with mine=true, to read back the id of the channel you manage. That single call is the whole proof. The access token serves it and is discarded, no refresh token is requested or stored, and we never read your videos, analytics, subscribers, comments, email or anything belonging to any other Google service.

Signing in with X requests users.read and tweet.read and calls /2/users/me once, to read back your numeric account id. Same shape: one call, token discarded, no refresh token.

You can revoke our access at any time at myaccount.google.com/permissions or in X's connected apps settings. Since we hold no refresh token, revoking takes effect immediately.

gord can instead generate a short phrase that names the payout wallet you want. On YouTube you put it in your channel description and we read the description of the channel being claimed. On X you post it and give us the link, and we check that your account wrote the post, because the phrase is public and anyone could otherwise post it from their own account. No sign-in, no token, no permission granted to us: both reads use public endpoints or our own API key, never your account. And because the phrase names the wallet, a phrase posted for one wallet cannot be reused to bind another.

A token image you upload is stored in an object bucket and served publicly, because a URL to it is written into the token's on-chain record. Files are named by the hash of their own bytes, so nothing about you is attached to one. The first time we see a given set of bytes they go to an automated classifier that scores them for nudity and gore, and we refuse the upload if it scores badly or, while the gate is armed, if the classifier cannot be reached at all. We remember only that a hash cleared, so the same image is not sent again. A bot check runs on the same endpoint. Link previews we fetch for a token's socials go through the same classifier before they are shown.

We use service providers. Each sees only what its job needs.

Most of these providers are outside the Republic of Korea, so using gord means the small amount of data described above crosses a border. Each entry above says what that provider sees. None of them receives more than that, and none of them receives it for any purpose except the job named. Where a data protection law requires the receiving country, the items transferred, the purpose and the retention period to be set out provider by provider, we will publish that alongside the operating entity's details rather than approximate it here.

We do not sell your data and we do not share it for advertising. We may disclose information where the law requires it.

Where a data protection law asks us to name a legal basis, these are the ones we rely on.

Where the law where you live gives you these rights, we honour them: access to the data we hold about you, correction of it, deletion of it, objection to a use of it, and a copy in a portable form. Write to privacy@gord.pro. We aim to answer within thirty days, and sooner where the law where you live sets a shorter deadline. We may need to check that the request is really yours, which for a wallet usually means a signature from it, and where a request is complicated or that check takes time we will tell you why it is taking longer. You can also complain to the data protection authority where you live, and you do not have to come to us first.

Two ordinary things need no request at all. Disconnect your wallet whenever you like: nothing here requires an account and nothing is waiting for you to log back in. Revoke our Google or X access from those platforms' own settings, and because we hold no refresh token it takes effect immediately.

Two limits on deleting off-chain data are worth naming rather than leaving you to find. Our nightly database backups keep the fourteen most recent dumps, so a record we delete today can still sit in a backup until the last dump holding it rolls off, about two weeks later; we use backups for nothing but restoring the service. And a cached social profile we clear is rebuilt the next time anybody looks that account up, because what causes the lookup is an on-chain designation we cannot remove. If you want a token here to stop carrying your account, the route is a takedown request to abuse@gord.pro, and even that reaches this interface rather than the chain.

gord is not directed to children and is not for anyone under 18. You must be 18 or older to use it, which is also a condition of the Terms of Service. We do not knowingly collect anything from a child. If you believe a child has given us something, write to privacy@gord.pro and we will delete what we hold, keeping in mind that anything already on chain is beyond deletion by anyone.

gord is operated from the Republic of Korea. The operating entity is being formed, and this page will name it, and the person responsible for privacy inside it, as soon as it exists. Until then the operator is the team that publishes this site, a privacy question reaches that team at the address below rather than a named officer, and these are the ways to reach it:

We aim to answer privacy requests and legal notices within thirty days, and sooner where the law where you live sets a shorter deadline. We are a small team rather than a support desk, and we would rather name a date we can keep.

If this policy changes, the date at the top changes with it, and that date is the notice. Material changes to how we handle Google user data will be described here before they take effect.