cubes.fun
Documentation

Privacy policy

How cubes.fun handles account information, browser storage and wallet activity.

Last updated

On this page

1. Scope and operator

This notice covers cubes.fun and its application services, including authentication, support, collectible previews and the wallet interface. The legal entity and registered address of the operator have not yet been finalized. In this notice, ‘we’ and ‘us’ refer to that operator, not to Dynamic, Abstract or a token issuer.

The existing contact address is dev@hood.rich. It is retained while the cubes.fun operator and contact details are being confirmed. This notice does not cover the independent practices of services you connect to through the application.

Paid cube settlement and physical redemption are not active in this release. Wallet swaps, when available and confirmed by you, use real assets. A demo opening does not create a purchase, inventory entitlement, token reward or shipping right.

2. Information we process

The information processed depends on the features and sign-in method you use. You provide some information directly; authentication providers supply verified sign-in information; wallet and blockchain services supply public account and transaction information.

The current application does not ask you to submit payment-card numbers, bank-account numbers, government identification, date of birth or a shipping address. Please do not include those details, recovery phrases or private keys in support messages. If a future feature needs additional information, its collection and use must be explained before you provide it.

  • Account information: an internal account ID, the authentication provider and its environment-scoped user identifier, an email address and verification status when supplied by the provider, an optional display name, account role and account status.
  • Authentication and security information: sign-in/session records, expiry and revocation records, hashed application session tokens and rate-limit identifiers derived from request or account information. When a separate password-testing mode is enabled, it processes your email and password and stores a salted password hash; those accounts are unverified preview identities.
  • Application activity: saved preview orders and reveals, item records, points and daily claims, historical battle, market and auction records, action identifiers, timestamps and support tickets, including messages and staff replies.
  • Wallet information: the address you connect or request information about, chain, token amounts, balances, quotes, allowances, public transaction hashes, transaction contents and confirmation status needed for wallet actions and recovery.
  • Technical information: IP address, browser/device and request information processed by hosting, authentication and RPC infrastructure, plus the browser storage described below. An address can be linked to your activity and is not necessarily anonymous.

3. Why we use information

We use information to provide the features you request, authenticate access, retrieve your saved records, show balances and transaction status, calculate requested swap quotes, respond to support requests and communicate about your account or the service.

We also use information to prevent duplicate actions, investigate errors, enforce access controls, limit abusive requests, protect users and the service, resolve disputes and meet applicable legal obligations. A support request may be reviewed by authorized administrators.

Providing the required sign-in or transaction information is necessary to use the corresponding feature. You may browse public material and use local demos without creating an account. We do not treat using a wallet or signing in as permission to send marketing messages.

4. Providers and disclosure

Dynamic supplies authentication and wallet connection, and Abstract Global Wallet supplies the connected smart-wallet experience. The application sends the authentication token to its own server for verification and records the account fields described above. Provider authentication, security challenges and wallet interfaces also operate under their own notices.

Hosting and database providers process application requests and stored account, activity and support records. The deployment uses Vercel hosting and a separately configured PostgreSQL database. RPC providers process blockchain queries; some wallet and session requests go directly from your browser to those providers. Public image or content hosts may receive requests when their resources are displayed.

We may disclose relevant information to service providers working on our behalf, professional advisers, authorities where required by law, or others where necessary to protect rights, investigate fraud or respond to legal process. Information may also be disclosed at your direction or in connection with a business transfer, subject to applicable law.

Public activity views may show pseudonymous participant labels, account identifiers, item listings, bids, results and points. The public application responses do not include account email addresses. These labels and identifiers should not be treated as a guarantee of anonymity.

5. Public blockchain records and session keys

If you submit an approval, swap or session-permission transaction, its address, contents and outcome may become publicly visible on Abstract. Others can copy and analyze public blockchain data. Removing an application account or local record does not remove blockchain records or reverse a transaction.

The application does not ask you to disclose the private key or recovery phrase for your main wallet. Optional swap sessions create a separate scoped signer in the current browser's memory. The current implementation does not send that session private key to our APIs or store it in localStorage, sessionStorage or the application database. Public permission details and transaction-recovery metadata are stored locally; the permission itself is recorded on-chain when authorized.

Logging out or closing a tab can discard the local signer, but does not revoke an on-chain grant. Revocation requires an appropriate wallet transaction and confirmation. Your wallet and authentication providers may have their own credential and recovery arrangements; review their notices separately.

6. Cookies and browser storage

The application uses a host-only, HttpOnly, Secure, SameSite session cookie to recognize an authenticated account. Its current absolute lifetime is seven days; signing out revokes the application session and clears the cookie. Provider sessions can have different lifetimes.

Browser storage also remembers interface preferences, short-lived sign-in redirect intent, pending-action identifiers, and wallet transaction and public session-permission recovery details. A pending-action identifier is paired with a payload digest rather than a stored copy of your support message. Wallet recovery records can contain an address, amount, transaction data, hash and status.

Interface preferences and unresolved recovery records may remain until they are cleared or completed. Provider SDKs may use additional storage under their own policies. Blocking or clearing storage can prevent login or remove the information needed to safely recover a pending action; check transaction status before retrying.

Local demo results are generated in your browser and are not saved as orders or sent to the opening/settlement API. Loading the page, catalog and images still generates ordinary web requests.

7. Retention and security

Account, activity, support and security records are retained for operating the service, investigating problems, resolving disputes and meeting applicable obligations. The current application does not implement a universal automatic deletion schedule. Cookie or quote expiry does not mean that the corresponding database, provider or blockchain record has been deleted. A category-specific retention schedule and provider retention details still require confirmation.

The implementation uses access controls, hashed application session tokens, request verification and protected database connections. No website, provider or device can be guaranteed secure. Do not share credentials or recovery phrases, and notify support if you suspect unauthorized access. This notice does not promise that every provider or every stored field uses a particular encryption scheme.

8. International processing

Hosting, authentication, database and blockchain infrastructure may process information outside your country, including in the United States, where privacy protections may differ. Public blockchain records can be accessed worldwide. Provider processing locations and any required transfer safeguards must be assessed for the jurisdictions where the service is offered; we do not claim certification under a particular transfer framework.

9. Your choices and rights

You can choose not to connect a wallet, decline a wallet request, sign out, adjust browser storage settings or contact us about your information. Declining or removing required information can make the relevant feature unavailable. Disconnecting the application is not the same as revoking a wallet allowance or session permission.

Depending on the law that applies to you, you may have rights to access, correct, delete or obtain a copy of personal information, restrict or object to processing, withdraw consent where processing relies on consent, or complain to a competent privacy authority. Contact dev@hood.rich to make a request. We may need proportionate information to verify that a request concerns your account; never send a private key or recovery phrase.

Some records may need to be retained for legal or security reasons. We cannot delete independently maintained public blockchain records. There is no self-service account-deletion tool in this release; contacting support starts a request and does not itself guarantee that every record can be removed.

10. Age restrictions

The service is intended for people who are at least 18 and meet any higher local age requirement. It is not directed to children. Do not register or submit personal information if you do not meet that requirement. Contact us if you believe a child has provided information so that the matter can be investigated. This restriction is not a claim that age verification has been implemented.

11. Changes and contact

We may update this notice as the service changes, including before introducing additional personal-data collection. The date above identifies the version. Where applicable law requires additional notice or consent, changing this page alone does not replace that requirement.

For privacy questions, rights requests or general support, use the existing contact below. The cubes.fun operator identity, registered address and final contact information remain to be confirmed.

Your wallet

ETH & USDC.e on Abstract

Sign in to connect your Abstract wallet.

Spending permissions

Sign in with Abstract Global Wallet to set optional spending limits.

Sign in