Skip to privacy notice
Legal · BoringDollars, Inc.

Privacy Notice

What information flows through iStreet, why it is used, and the choices available to you.

Last updated · Version 1.2

1. Who we are and what this covers

iStreet is operated by BoringDollars, Inc., a Delaware corporation. This notice covers istreet.io and the iStreet applications and APIs that link to it. Contact legal@istreet.io for privacy requests and hello@istreet.io for support.

This notice describes information used when you browse or choose an available feature. Describing a trading or wallet feature does not mean trading is open or that you are eligible. The Terms of Service govern access and product restrictions. Services are intended for adults aged 18 or over.

2. Website and API requests

Cloudflare hosts and delivers the site and API requests. Requests include an IP address, requested URL, browser and device headers and, where sent by your browser, a referrer. API requests also contain the information needed for the feature you use, such as a wallet address, selected asset or order. This information is processed to deliver pages, answer requests and support service operation.

Cloudflare can supply approximate country and region information derived from your IP address. Geographic access checks may use that information as described in the terms. IP location does not establish residence or US-person status. Contact support if you believe an access result is incorrect.

3. Wallet connection, email sign-in and orders

When you connect a wallet, the interface receives your selected public address and network. It uses iStreet APIs, your wallet provider and blockchain RPC providers to read balances, allowances and transaction history and to submit actions you authorize. These requests can disclose addresses, token contracts, transaction data and signed messages to the services handling them.

Portfolio history requests use Alchemy to discover indexed transfers and the configured blockchain RPC provider to check receipts and balances. These providers receive the queried wallet address, network and token contracts. To limit abuse, iStreet stores a hash of the wallet address and network, a random request identifier and request time in Cloudflare D1. This hash is pseudonymous, not anonymous; it does not prove wallet ownership.

Other provider-backed reads use shared request budgets to limit abuse. For these budgets, iStreet stores a hash derived from the connecting IP address supplied by Cloudflare, a random reservation identifier, a request-work credit amount and the reservation time. These records do not store the raw IP address or wallet balances. The IP-derived hash is pseudonymous, not anonymous, and users sharing an IP address also share a budget.

If you choose email sign-in, Coinbase Developer Platform receives your email address and verification code through its wallet SDK to authenticate you and create or recover an embedded wallet. The interface receives session and user information and associated wallet addresses. Coinbase handles that authentication and wallet service under its own terms and privacy practices. Email sign-in is optional; compatible external wallets are another connection method.

CoW quote requests send the selected network, wallet and receiver addresses, tokens, amount and order preferences through iStreet to CoW. Order submission sends the signed order, signature, quote identifier and partner-fee metadata; order history and cancellation requests send the corresponding addresses, order identifiers or signatures. This allows quoting, submission, status checks and cancellation requests. Orders and settlement information may be publicly accessible through protocol APIs and blockchains.

General signup acceptance

General signup acceptance is separate from trading eligibility. After you accept the Terms and acknowledge this Privacy Notice, iStreet can validate your Coinbase authentication token with Coinbase Developer Platform and check that the selected wallet belongs to the authenticated account. The token is processed for verification, not stored in the signup acceptance record; your verification code is not sent to iStreet. Coinbase's response can contain account information, but iStreet does not store its email fields or the full response in that record.

The general signup record in Cloudflare D1 contains a domain-separated hash of the authenticated Coinbase project and user identifier, the project identifier, wallet owner address, site origin, random challenge and receipt identifiers, Terms and Privacy versions and document hashes, acceptance and acknowledgment flags, and issuance, expiry and acceptance timestamps. The subject hash is pseudonymous, not anonymous. This record does not include a residency declaration, grant trading permission, or constitute consent to every processing use described here. A pending or unavailable acceptance service does not itself prevent wallet recovery, sends or logout.

Terms acceptance and eligibility declarations

When you sign an eligibility declaration, iStreet stores an acceptance record in Cloudflare D1: your wallet owner address, chain ID, site origin, nonce, exact declaration text, its SHA-256 message hash, signature and signature type, terms and eligibility-policy versions, and issuance, challenge-expiry and acceptance timestamps. The declaration records your assertions about residence, citizenship, location and acceptance of the terms; it is not independent proof of identity, location or eligibility, and is not KYC or sanctions screening.

Signature verification also records the verification block number and block hash, account-code hash and, where applicable, account type, delegated implementation address or factory address and factory-code hash. The configured chain RPC service receives the wallet address for account checks; smart-wallet verification can also send the signed-message digest, signature and factory-call data through read-only RPC simulation. That verification does not itself broadcast a transaction.

Temporary challenge records support replay protection and request limits. Eligibility sessions link to an acceptance using a SHA-256 hash of a random session token; the token itself is sent in a Secure, HttpOnly, SameSite=Strict cookie. These D1 acceptance and session tables do not store your IP address, geolocation, user-agent headers or identity documents. This does not mean hosting and RPC providers receive no technical request information.

Verification-attempt records contain a random attempt ID, challenge nonce, wallet owner address and attempt timestamp to limit repeated verification requests, including failed signatures or provider failures. These records do not contain signatures, IP addresses, location, raw session tokens or RPC endpoints.

Gas sponsorship and order coordination

If Ink sponsorship is enabled and you request it, iStreet stores your reviewed calls (target contracts or recipients, amounts and encoded call data), calls hash, wallet owner address, chain and origin, trade or exit purpose, acceptance reference where applicable, policy and controls hashes, exact intent message and signature, timestamps and processing state in Cloudflare D1. It also records prepared operation data and hashes, operation hash, provider call ID, status-read counters and sponsorship budget reservations. Reservations are accounting limits, not a statement of your balance or actual gas spent.

The Ink integration sends Alchemy the wallet address, network, reviewed calls and sponsorship policy identifier for preparation, and signed operation or delegation data for submission. Alchemy returns operation and status information. A random, opaque, single-use callback token accompanies preparation; D1 stores its hash, callback-consumption timestamp and operation-binding hash to check the callback. Separate exit sessions store a hash of the session token, owner, origin and timestamps, with the token in a Secure, HttpOnly, SameSite=Strict cookie. These sponsorship tables do not store IP addresses. Hashes linked to a wallet or request are not anonymous data.

When order coordination is enabled, iStreet maintains a durable CoW order journal in Cloudflare D1 containing the order identifier, owner address, chain ID, submission or observed status, and creation and update timestamps. It helps prevent duplicate or conflicting submissions across devices and tracks uncertain outcomes. This journal does not store order signatures; the signed order still goes to CoW as described above.

Sponsorship history recovery stores a challenge ID, wallet owner, origin, exact challenge message and creation, expiry and consumption timestamps. Its wallet-control signature is verified but not stored in the recovery tables. Recovery sessions store a token hash, owner, origin and timestamps; the token is held in a Secure, HttpOnly, SameSite=Strict cookie. Recovery also records per-intent read counters and coordination leases, operation hashes, observation outcomes and timestamps, and receipt evidence when available: transaction and block hashes and numbers, wallet owner, network, entry-point address, success result, gas cost and gas used, and finalized-block references. The configured recovery RPC service receives operation or transaction identifiers and chain-read requests. These records help investigate uncertain outcomes; recovery authentication grants history access, not permission to spend or retry an operation.

Base smart-account RPC, bundler and paymaster requests use the configured Coinbase service. Ink sponsorship uses Alchemy; CoW handles the quote and order flow on supported trading networks. Other wallet reads and transfers use the selected network’s configured RPC service or public fallback. Pimlico is listed for other planned network integrations, not as a recipient in the implemented Base or Ink sponsorship flow. Describing these integrations does not mean sponsorship or trading is enabled.

Wallet connections inside the Base App use the Farcaster Mini App SDK and the host’s wallet provider. The interface reads host context for layout and wallet access. That host and your chosen wallet have their own data practices. iStreet’s interface onboarding does not ask for identity documents. Do not send a seed phrase or private key to iStreet.

4. Waitlist and support

The marketing site embeds a GetWaitlist form for early-access registration. Information you submit, such as your email address and any other fields shown in the form, goes to GetWaitlist for the iStreet waitlist. Its externally hosted widget also receives browser requests when it loads, which can occur before you submit the form. Review the provider’s notice presented with its service before submitting.

If you email us, we receive your email address, message and any attachments through email services so we can respond to your request. Share only what is needed. A transaction hash or public wallet address can help investigate an issue, but can also link your identity to public activity. Contact support to ask to leave the waitlist or stop early-access communications.

5. Optional AI features

When you request an AI-generated basket, your prompt, weight cap and asset exclusions are processed by iStreet to prepare a request for the configured AI service: Amazon Bedrock through an iStreet proxy, or Cloudflare Workers AI. The model receives the prompt and allocation constraints. AI news analysis sends the selected company and retrieved headlines for analysis. Do not include identifying, confidential or sensitive information in a prompt.

The Bedrock integration derives a salted hash from the request IP address and sends it to the proxy for rate limiting. Its usage store records request counters associated with that identifier and aggregate usage limits. A hashed identifier is not a guarantee of anonymity. Provider logging, storage and other handling depend on the service and its configuration; this notice does not promise that prompts are never retained or used by a provider.

6. Analytics, cookies and browser storage

Pages that include iStreet’s analytics loader on istreet.io, app.istreet.io and miniapp.istreet.io load Cloudflare Web Analytics and, when configured, Google Analytics 4. They are used to understand visits, navigation and feature engagement. Analytics providers receive browser requests and associated technical information. Google Analytics may use cookies and identifiers; this is not a cookie-free service.

The iStreet Google Analytics integration sends page titles and paths, a limited app navigation category and the referring origin. Its page-view events omit URL query strings and asset or portfolio identifiers from app routes. It also reports waitlist opens and pitch-video playback events. The integration disables Google advertising signals and ad-personalization signals and does not explicitly attach wallet addresses, balances or portfolio prompts to these events. These limits describe iStreet’s event code, not every request or a guarantee about independent provider processing.

The app uses local storage in your browser for watchlists, saved and custom baskets, network preferences and order history. The Pro interface also stores recent and favorite markets. Wallet and authentication SDKs can use their own browser storage for sessions. Local storage is distinct from cookies and can persist after you close the browser or disconnect a wallet.

The app also caches bounded portfolio historical evidence per wallet, network and token pair: raw token-flow history pages and server-sealed checkpoints. This browser cache holds at most 4 saved snapshots and 2,000,000 UTF-8 bytes in total. Restoring saved history requires your explicit action and fresh server verification of the checkpoint before the app rebuilds the historical view; cached evidence alone is not a verified current balance or permission to trade.

The current iStreet analytics loader does not wait for a site consent choice and does not use Do Not Track or Global Privacy Control signals to disable analytics. You can use browser controls to block cookies or third-party requests and clear site storage; some features may stop working. Clearing storage does not delete information already sent to providers. Contact us about applicable privacy rights using the details below.

7. External services and international processing

The providers above receive data for hosting, analytics, authentication, waitlist registration, AI processing or the wallet and order actions described in this notice. The site also requests fonts from Google Fonts on some pages and company or token images from Logo.dev and issuer-hosted image services. Those direct browser requests disclose technical request information, including your IP address, to the resource host. Following a news, issuer, explorer or social link sends you to a separate service.

Providers operate under their own terms and privacy notices. Their processing locations and retention arrangements differ. Information sent to external services may be processed outside your country. This notice does not promise a particular storage country or transfer safeguard for every provider. Contact legal@istreet.io for information about the handling relevant to your request.

8. Retention and public records

Browser-saved preferences, baskets and order history have no automatic expiry in the app and remain until removed or cleared by you or your browser. Removing those local records does not cancel orders, revoke token approvals or erase provider records.

The portfolio history cache also persists after logout or wallet disconnection. It has no automatic deletion timer: saving newer snapshots can evict older entries to enforce the cache limits, and you or your browser can clear site storage. Checkpoint expiry can prevent restoration but does not delete the saved data. Clearing browser storage does not erase public blockchain records.

Portfolio-read rate-limit records older than 48 hours are deleted when a subsequent portfolio request runs the cleanup. Other provider-read budget records use the same 48-hour threshold and are cleaned up on a subsequent provider-budget reservation. This is request-triggered cleanup, not a guarantee of deletion exactly at 48 hours.

Eligibility challenges are valid for 5 minutes and eligibility sessions for 30 minutes. Expired sessions and older challenges are pruned when a new challenge is issued, not by a guaranteed deletion timer; logging out deletes the current eligibility session. Ink sponsorship intents are valid for up to 3 minutes, subject to earlier session or controls expiry, and separate exit-session cookies and authorization last 30 minutes. Expiration prevents further use; it does not imply that the underlying record has been deleted.

Verification attempts use a 15-minute rate-limit window; older attempt records are pruned on a later verification attempt, not automatically at the end of that window.

Sponsorship recovery challenges expire after 5 minutes and recovery sessions after 30 minutes. The current recovery code does not automatically delete challenge, session, read-counter or observation rows when authorization expires. Those stored records share the unresolved durable-record retention and deletion-workflow limitation below.

General signup challenges are valid for up to 5 minutes, or until the authentication token expires if sooner. Expired challenges outside the 15-minute issuance-limit window are pruned on a later challenge request. General signup receipts have no automatic deletion in the current implementation and do not become trading sessions.

Acceptance records, including general signup receipts, sponsorship intents and budget reservations, and the CoW order journal are durable records. The current implementation has no automatic deletion for these records or sponsorship exit-session rows. Eligibility acceptance records preserve the signed assertion; general signup receipts preserve Terms acceptance and Privacy acknowledgment. Reservations remain recorded even after failed or uncertain requests to support spending limits, and journal records support order reconciliation. A fixed retention period and deletion workflow for these durable records have not yet been established. This is an implementation limitation, not a promise or justification of indefinite retention. Contact legal@istreet.io about a particular record or request.

There is no single published retention period covering support correspondence, waitlist information, analytics, authentication records and infrastructure logs. Retention for these records depends on the relevant service and its settings. Contact us about a particular record or a deletion request; this notice does not promise immediate deletion or a fixed deletion deadline.

Public blockchain records generally cannot be changed or deleted by iStreet. Wallet addresses are pseudonymous, not necessarily anonymous, and can be linked to other information. Independent protocol and explorer records can remain accessible after you stop using iStreet.

9. Your choices and privacy requests

You can browse public pages without connecting a wallet, choose whether to use email sign-in, decline to join the waitlist and avoid optional AI features. Features requiring an address, order or prompt cannot work without that input. Disconnecting a wallet or signing out stops that interface session but does not erase earlier records or public transactions.

Depending on the law that applies to you and the processing involved, you may have rights to access, correct, delete or obtain a copy of personal information, restrict or object to processing, withdraw consent where processing relies on it, or opt out of certain uses. Send requests to legal@istreet.io. Describe the feature and information involved and how we can contact you. We may need information sufficient to verify your authority over the requested records; never send a private key or seed phrase.

Rights and exceptions depend on applicable law, and iStreet cannot erase public blockchain data or independently controlled provider records. You may also contact the relevant provider and your local data-protection authority. This notice does not waive any statutory rights or treat continued browsing as consent to every use of information.

10. Updates and contact

Revisions to this notice will appear here with an updated date. Check this page when using a new feature. Any notice or consent required by applicable law remains required.

Privacy and legal requests: legal@istreet.io.
Support and general questions: hello@istreet.io.

BoringDollars, Inc., a Delaware corporation
1111B S Governors Ave, Suite 95441
Dover, DE 19904, United States.