Legal
Privacy Policy
Last updated: 9 August 2026
1. Introduction and who we are
This Privacy Policy explains how MetaDAO LLC collects, uses, discloses and protects information about you when you access or use Backable, the Protocol, and our other Services. It is the "Privacy Policy" incorporated by reference into, and forming part of, our Terms of Service, and capitalized terms used but not defined here have the meanings given to them there.
For the purposes of applicable data protection law, the controller of your personal data is MetaDAO LLC, a decentralized autonomous organization limited liability company registered in the Republic of the Marshall Islands ("MetaDAO", "we", "us", "our"), with a mailing address of PO Box 852, Long Island Rd, Majuro, Marshall Islands MH 96960.
If you have any question about this Policy or how we handle your personal data, contact us at market.governed.civilization@metadao.fi.
2. Scope and application
This Policy applies to personal data we process about visitors to and users of the Services. It does not apply to the independent acts of Founders, other Users, third-party wallet providers, blockchain networks, or any third-party site or service you reach through a link on the Services, each of which operates under its own terms and privacy practices.
The Services are not offered to, and are not intended for, Restricted Persons or persons located in a Restricted Jurisdiction, as set out in the Terms of Service. Because the Services may lawfully be accessed by permitted users in the European Economic Area ("EEA") and the United Kingdom ("UK"), we treat the EU General Data Protection Regulation ("GDPR") and the UK GDPR as the governing data protection framework for this Policy. This Policy does not address United States state privacy laws.
3. Information we collect
-
Wallet and onchain information. When you connect a digital wallet, we receive your public wallet address and can observe the onchain transactions, balances, Token holdings, Raise participation and governance activity associated with it. This information is recorded permanently on public blockchains.
-
Session information. When you sign a message to establish a session, we set an authentication cookie tied to your wallet address. It is strictly necessary to operate features that act on your behalf — saving a draft Raise, posting in a raise chat, upvoting — and is not used for analytics or advertising.
-
Information you provide. Information you submit when creating a draft Raise or communicating with us, including project name and description, founder name and email address, website and social links, wallet addresses, budget and tokenomics parameters, uploaded images, transparency-filing disclosures, and any message content. Draft Raise content is stored so that you can return to it, and becomes public when you publish the Raise.
-
Information stored in your browser. Some preferences never reach us at all. Dismissed onboarding banners, favourited raises, and unpaid demo drafts are kept in your browser's local storage on your own device, and you can clear them at any time through your browser settings.
-
Device and usage information. Information automatically collected when you use the Services, such as IP address, device and browser type, operating system, language settings, referring pages, the pages and features you access, and the dates and times of your interactions.
-
Cookies and analytics data. Information collected through cookies and similar technologies and through our analytics providers, as described in sections 5 and 6.
-
Verification information. Where you verify control of a social account for a Raise, we process the public post you publish and the account handle it was published from. We do not receive credentials for, and never gain access to, that account.
-
Background and screening information. Where you apply to become, or engage with us as, a Founder or client, we (through an independent screening provider) may collect and process identity, eligibility, sanctions and background-screening information about you, which may include criminal-record or other sensitive information to the extent permitted by applicable law.
We do not knowingly collect special categories of personal data, and you should not submit such data through the Services. We do not collect or store your private keys or seed phrases, and we cannot recover them.
4. How we use your information and our lawful bases
We process personal data for the following purposes and on the following lawful bases under the GDPR and UK GDPR:
-
To provide and operate the Services (performance of a contract, or our legitimate interest in operating the Services where no contract exists), including enabling wallet connection, maintaining your session, storing your draft Raise, displaying onchain data, and facilitating your interaction with the Protocol.
-
To maintain security and integrity (legitimate interests, and compliance with legal obligations), including detecting and preventing fraud, abuse, market manipulation, governance attacks, sanctions evasion, and circumvention of access controls or geo-blocking. This includes rate-limiting abusive requests and declining sessions for wallet addresses we are required to block.
-
To verify eligibility and comply with law (compliance with legal obligations, and legitimate interests), including confirming you are not a Restricted Person and responding to lawful requests from authorities.
-
To screen prospective and current Founders and clients (compliance with legal obligations, including anti-money-laundering and sanctions requirements, and our legitimate interests in preventing fraud), as described in section 4.1.
-
To communicate with you (performance of a contract, or legitimate interests), including responding to enquiries.
-
To understand and improve the Services (consent, for non-essential analytics and cookies; otherwise legitimate interests), as described in sections 5 and 6.
-
To enforce our Terms and protect legal rights (legitimate interests, and establishment, exercise or defence of legal claims).
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. Where we rely on legitimate interests, you may object as described in section 12.
4.1 Background and eligibility screening
Consistent with the eligibility and anti-money-laundering requirements in our Terms of Service, we engage Groom Lake, an independent contractor, to provide network security services and to conduct background and eligibility screening on prospective and current Founders and clients. This screening may include identity verification, sanctions and watchlist checks, and, where permitted by applicable law, criminal-record and other background information.
Where we carry out such screening on individuals, we rely on our legitimate interests in preventing fraud, sanctions evasion and other unlawful activity, and on compliance with our legal obligations. We process any criminal-offence or otherwise sensitive information only to the extent, and subject to the additional conditions and safeguards, required by applicable law.
5. Cookies and similar technologies
We use cookies and similar technologies (including browser local storage) to operate the Services, remember your preferences, maintain security, and — with your consent — measure and analyze usage.
Strictly necessary cookies are required for the Services to function and do not require consent; your authentication session cookie is one of them. All other cookies, including analytics and performance cookies, are non-essential and are set only after you provide consent. You can withdraw or change your consent at any time through those controls or your browser settings.
6. Analytics
6.1 Purpose
We use analytics to understand how visitors and Users interact with the Services — which pages and features are used, how users navigate the interface, the performance and stability of the Services, and aggregate trends. We use these insights to maintain, troubleshoot, secure and improve the Services. We do not use analytics to make decisions producing legal or similarly significant effects about you.
6.2 Providers
We use the following analytics, performance-monitoring and infrastructure providers. Except where noted, each acts as our processor and processes personal data only on our instructions:
- PostHog — product analytics and error reporting. Records page and feature usage, navigation, interaction events and application errors, and may process IP address and device or browser characteristics. Session recording is disabled.
- Vercel — hosting and edge delivery of the interface. Generates server and access logs (including IP address) and may provide aggregate usage measurement.
- Cloudflare — content delivery, performance and security, including DDoS mitigation. Processes IP address and request metadata; this processing is largely strictly necessary to deliver and secure the Services.
- Northflank — application and infrastructure hosting for our backend services. Captures operational and server logs, which may include IP address.
The interface is built with the Next.js framework, which runs within our own hosting environment. It is software we operate rather than a separate recipient of your personal data.
6.3 Data collected
Depending on your consent and the provider, analytics may process: IP address (often truncated or pseudonymized), device and browser characteristics, operating system, approximate location derived from IP, referring and exit pages, pages and features viewed, interaction events, session duration, and similar usage metrics. Where the Services associate analytics events with your connected wallet address, that association is treated as personal data and processed in accordance with this Policy.
6.4 Lawful basis
For users in the EEA and UK, non-essential analytics are carried out only on the basis of your consent. You may decline analytics and continue to use the Services, and you may withdraw consent at any time. Where analytics are strictly necessary to secure or deliver the Services, we rely on our legitimate interests.
6.5 No re-identification or wallet deanonymization
Consistent with the prohibitions in our Terms of Service, we do not use analytics to deanonymize or re-identify any user from blockchain data, to build profiles that single out a specific individual from onchain activity, or to combine analytics data with wallet data for the purpose of identifying a natural person, except where strictly necessary to investigate fraud, abuse or a violation of the Terms, or to comply with a legal obligation.
6.6 Your controls
You can control analytics through our preference controls, your browser or device settings, and any opt-out mechanisms offered by our providers. Disabling analytics will not prevent you from using the core functions of the Services.
7. Onchain data and blockchain immutability
The Protocol operates on public blockchains. When you transact through the Services, information such as your wallet address, commitment amounts and timing, Token holdings, claims and governance activity is recorded on a public, decentralized ledger. As our Terms note, information recorded on the blockchain is not confidential.
Because public blockchains are immutable and are not controlled by us, onchain personal data cannot be altered, erased or made inaccessible on request, and your rights of erasure, rectification and restriction are necessarily limited with respect to data already written to the blockchain. We cannot reverse, modify or delete onchain transactions or records.
Anything you publish as part of a Raise — your project description, budget, team details, disclosures and images — is intended to be public and will be visible to anyone.
8. How we share information
We do not sell your personal data. We may share personal data with:
- Analytics, hosting and security providers identified in section 6, which process usage, performance, log and security data on our behalf as processors.
- Network security and screening provider. Groom Lake, as described in section 4.1, may receive identity, contact, eligibility and, where permitted by law, background-screening information.
- Entity formation provider. Where a Founder elects to form a legal entity through the Services, the information necessary to do so is passed to that provider, which acts as an independent controller under its own terms and is not a law firm.
- Other service providers and processors performing functions on our behalf under contractual confidentiality and data protection obligations.
- Blockchain networks and the public, by the inherent design of the Protocol, as described in section 7.
- Authorities and other parties where permitted or required, including to comply with applicable law, sanctions obligations or valid legal process, to enforce our Terms, or to protect the rights, safety and property of MetaDAO, our Users or others.
- Successors, in connection with a merger, acquisition, reorganization or sale of assets, subject to this Policy.
9. International data transfers
We and our service providers may process personal data in countries outside the EEA, the UK, or your country of residence, which may not provide the same level of data protection. Several of the providers we rely on are established in or process data in the United States. Where we transfer personal data to a provider outside the EEA or the UK, we put in place the European Commission's Standard Contractual Clauses and, for transfers subject to UK law, the UK International Data Transfer Addendum. You may request a copy of the safeguards we rely on by contacting us at the address in section 18.
10. Data retention
We retain personal data only for as long as necessary for the purposes set out in this Policy.
- Onchain data (wallet addresses, commitments, claims, Token holdings and governance activity): retained permanently on the relevant blockchain and outside our control.
- Published Raise content: retained for as long as the Raise is listed, so that Backers can review what they committed to after the fact.
- Unpublished draft content: retained while the draft is active and for a reasonable period afterwards, unless you ask us to delete it.
- Session cookies: for the duration of the session and its expiry period.
- Device, usage, server and security logs (including IP addresses, access logs and error telemetry): up to thirty (30) days, unless a longer period is necessary to investigate fraud, abuse or security incidents.
- Analytics data (where you have given consent): up to thirty (30) days from collection, or until you withdraw consent, whichever is earlier.
- Contact and enquiry communications: up to ninety (90) days from your last communication with us, or longer where required to establish, exercise or defend legal claims.
- Founder and client screening records: for the period required by applicable anti-money-laundering, sanctions and counter-terrorist-financing laws, typically five (5) years after the end of the relevant business relationship.
- Internal collaboration records: generally up to ninety (90) days, unless a longer period is required by law or for legal claims.
When retention periods expire, we delete or anonymize personal data unless we are required or permitted to retain it longer.
11. Data security
We implement technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse or alteration. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. Content you transmit may travel unencrypted across networks and may be posted on public blockchains. You are responsible for safeguarding your wallet, private keys, seed phrases and credentials; we do not store them and cannot recover them.
12. Your privacy rights
Subject to applicable law and the limitations described in this Policy, individuals in the EEA and UK have the following rights:
- Access — to obtain confirmation of whether we process your personal data and a copy of it.
- Rectification — to have inaccurate or incomplete personal data corrected.
- Erasure — to request deletion of your personal data in certain circumstances, subject to the blockchain limitations in section 7.
- Restriction and objection — to restrict or object to certain processing, including processing based on our legitimate interests.
- Portability — to receive certain personal data in a structured, commonly used, machine-readable format.
- Withdrawal of consent — to withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us at market.governed.civilization@metadao.fi. We may need to verify your identity, which for wallet-based interactions may include a cryptographic signature from the relevant wallet. You also have the right to lodge a complaint with a supervisory authority. Our supervisory authority for data protection is the Office of the Ombudsman of the Cayman Islands (5th Floor, Anderson Square, 64 Shedden Road, George Town, Grand Cayman). If you are in the EEA or the UK, you retain the right to lodge a complaint with the data protection authority of your country of residence or, in the UK, the Information Commissioner's Office.
13. Children's privacy
The Services are not directed to, and may not be used by, anyone under eighteen (18) years of age or the age of majority in their jurisdiction, whichever is higher. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take steps to delete it.
14. Third-party links and services
The Services may contain Third-Party Links and may interoperate with third-party wallets, blockchains, block explorers, exchanges and applications. We do not control and are not responsible for the privacy practices of those third parties. Following an outbound link — for example to a block explorer or a swap interface — takes you to a service with its own privacy terms, which you should review.
MetaDAO maintains community and support presences on third-party platforms and uses third-party collaboration tools for internal operations. Communications you send through public community channels are processed by those platforms as independent controllers under their own privacy terms.
15. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, except where necessary for security or fraud-prevention purposes or as otherwise permitted by law. The futarchy governance outcomes of the Protocol are market-driven and operate independently of MetaDAO.
16. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will take reasonable steps to notify you, such as by posting the updated Policy with a new "Last updated" date. Unlike the Terms of Service' change mechanism, material changes to this Policy will not be treated as effective immediately on posting where advance notice is required by applicable law.
17. Governing law and disputes
This Policy forms part of, and is governed by the same law as, the Terms of Service. It is governed by and construed in accordance with the internal laws of the Cayman Islands, and disputes arising under it are subject to the mandatory, binding arbitration provision in section 20.2 of the Terms of Service, to the extent permitted by applicable law.
Nothing in this section limits any non-waivable right you have under applicable data protection law. In particular, if you are in the EEA or the UK, your statutory rights to lodge a complaint with a supervisory authority and to an effective judicial remedy are not affected by the arbitration provision or the class-action waiver in the Terms of Service.
18. How to contact us
MetaDAO LLC
PO Box 852, Long Island Rd, Majuro, Marshall Islands MH 96960
Last updated 9 August 2026.
See also our Terms of Service.