Privacy Policy

What data Bad Place collects, why we are allowed to process it, who we share it with, and the rights you have over it.

Last updated: September 2026

Our Privacy Commitment

Bad Place is designed to hold as little about you as it can. We hold no private keys, seed phrases or key shares — not encrypted, not split, not at all. We do not sell your personal data, we do not run advertising trackers, and we do not build marketing profiles. What we do collect is listed below in full, with the legal basis for each use and the rights you have to challenge it. Your wallet, your keys, your privacy.

1. Who We Are and What This Notice Covers

This Privacy Notice explains how Cheese Art Labs L.L.C. (“Bad Place”, “we”, “us”) collects, uses, shares and retains personal data when you use the Bad Place website at badplace.io, the Bad Place mobile applications, our APIs, and the features built on them — including BadLine, Bad Street, BadEx, the Backroom, and token creation and trading.

Cheese Art Labs L.L.C. is the data controller for this processing. Our registered address is Ukshin Hoti 51, Prishtinë, Republic of Kosovo.

“Personal data” means information that identifies you or can reasonably be linked to you. Data that has been aggregated or irreversibly anonymised so that it can no longer be connected to you is not personal data and this Notice does not restrict our use of it.

This Notice does not cover third-party services you reach through Bad Place — external wallets, blockchain explorers, decentralised exchanges, or any site you open from a link posted by another user. Those operate under their own privacy terms. See section 22.

2. Data You Give Us

We collect the minimum needed to operate the platform. The following comes from you directly:
  • Email address — required to create an account and to receive one-time sign-in codes.
  • Profile information — username, display name, bio, avatar and banner images, and any links you choose to publish.
  • Wallet addresses — the public addresses you connect, link or generate. Public addresses only; never key material.
  • Content you create — tokens and their metadata, BadLine posts, replies, comments, uploaded images, AI prompts and AI-generated media, and community submissions.
  • Support and abuse correspondence — what you write to us, including reports you file about other users.
  • Verification material — where a feature requires it, such as proof of control of a social account or of a wallet.

We do not collect private keys, seed phrases or key shares of any kind; precise geolocation; contact lists or address books; biometric identifiers; or any special-category data such as health, religion, political opinion or sexual orientation. We do not ask for government identity documents, and you should never send them to us.

3. Data We Collect Automatically

When you use Bad Place, some information is generated by the act of using it. We collect:
  • IP address — recorded in server and security logs and used for rate limiting, abuse prevention and fraud detection.
  • Approximate country, derived from the IP address by our network provider. We do not derive city-level or precise location.
  • Device and client information — browser type and version, operating system, app version, screen and language settings, and time zone.
  • Request metadata — the endpoints you call, timestamps, response codes, referring page, and the session identifier attached to your requests.
  • Push notification token — on mobile, only if you grant notification permission.
  • Interaction signals — what you view, open, like (“cheers”), reply to and follow, used to rank your feed.

We do not fingerprint your device to track you across other websites, and we do not buy or receive behavioural data about you from data brokers or advertising networks.

4. Wallets and Key Material

We hold no key material of any kind. This is an architectural fact, not a policy promise — it is a property of how the product is built, and it cannot be quietly reversed by editing this page.
  • We never store private keys, seed phrases or partial key shares — not encrypted, not split, not at all.
  • On the web, the platform has no embedded custodial wallet: you connect an external browser wallet that you already control.
  • On mobile, your recovery phrase is generated on your device and kept in the device's secure storage. It never reaches our servers.
  • A wallet address shown on your profile is a link you chose to make and proved with a signature. A signature proves control; it grants us none.
  • Because we hold nothing, we cannot move your funds, freeze your wallet, reverse a transaction, or restore access if you lose your own backup.

Your account is an identity for social and platform features. It is not a wallet and it cannot spend your funds. Anyone who tells you that Bad Place support can recover a lost seed phrase is attempting to defraud you.

5. Accounts and Linked Services

Creating an account requires an email address. You may additionally link third-party accounts, each of which is optional unless stated otherwise.
  • Email — required to register, verify your account and sign in with a one-time code.
  • Two-factor authentication — if you enable it, we store the shared secret encrypted with a server-held key.
  • Google Sign-In — optional. We receive your email address, Google account identifier and profile picture.
  • Apple Sign-In — optional. We receive your Apple account identifier and the email address Apple releases to us. If you use Apple Private Relay, that address is a relay address and we never see your real one; we match your account on the Apple identifier, not the email.
  • X (Twitter) — optional, and required for certain social and reward features. We receive your public handle, profile picture and banner.
  • Push notifications — a device token, only if you allow notifications.

Linked accounts can be disconnected at any time from Settings. Disconnecting stops future collection from that service; it does not retroactively erase data already received, which is handled under the retention rules in section 16.

6. AI Features and Third-Party AI Processors

Several features generate or analyse images and text using AI models operated by third parties on our behalf. Using them is your choice.

What is sent: the prompt you write, the options you select, any reference image you upload, and — for ranking and recommendation features — the text of content you publish.

Who processes it. Each of the following acts as a processor for us and is contractually restricted to processing your data for our purposes only:

  • Google (Gemini) — image generation, prompt interpretation, and text embeddings used for feed ranking and interest matching.
  • Anthropic (Claude) — text generation and automated safety review of prompts and content.
  • xAI (Grok Imagine) — image generation and image editing in the Cook feature.
  • AtlasCloud — image generation and image editing in the Cook feature.
  • OpenAI — text embeddings, where configured as the embedding provider in place of Google.

Reference photographs you upload are used for generation and safety review and are not retained as source images after processing completes. Generated output that you keep is stored on our media infrastructure and linked to your account.

AI providers are added, removed and swapped as the product evolves. When that happens this section is updated, and material additions are announced under section 23. If you do not want your content processed this way, do not use the AI features — the rest of the platform works without them.

7. Automated Moderation and Automated Decisions

Content uploaded to Bad Place passes through automated safety systems before and after publication. You are entitled to know that this happens, what it can decide on its own, and how to contest it.
  • Every uploaded image is checked against known child sexual abuse material using the Canadian Centre for Child Protection's Project Arachnid service.
  • Text and images are screened by automated classifiers for the categories set out in our Acceptable Use Policy.
  • Automated signals also feed rate limiting, spam detection and anti-manipulation systems, which can throttle or temporarily restrict an account.

Where a decision is fully automated. Confirmed matches against known CSAM result in immediate permanent termination and, where the law requires it, a report to the competent authority. This is a deliberate exception: it is automated, it produces a legal effect for you, and there is no appeal. Every other enforcement outcome that permanently restricts an account — bans, content removals, reward disqualification — is subject to human review on request.

Your right to object. If an automated system has restricted your account, you may write to [email protected] to obtain human review, express your point of view, and contest the outcome. We will tell you the basis of the decision to the extent that doing so does not compromise the detection system itself.

Automated moderation is a filter, not an approval. Content that passes it has not been reviewed by a person and has not been declared lawful.

8. Legal Bases for Processing

Where the GDPR, the UK GDPR or an equivalent law applies to you, we process your personal data only where we have a lawful basis for doing so. Ours are:
  • Performance of a contract (Art. 6(1)(b)) — creating and running your account, displaying your content and holdings, executing the platform functions you ask for, and providing support. Without this data the service cannot be delivered.
  • Legitimate interests (Art. 6(1)(f)) — securing the platform, preventing fraud, abuse, spam and market manipulation, ranking your feed, measuring aggregate product usage, and defending legal claims. We have weighed these against your rights and you may object at any time under section 18.
  • Legal obligation (Art. 6(1)(c)) — retaining records we are required to keep, responding to valid legal process, operating the copyright notice-and-counter-notice procedure, and reporting child sexual abuse material.
  • Consent (Art. 6(1)(a)) — push notifications, optional linked accounts, and any use of the AI features. You may withdraw consent at any time; withdrawal does not affect processing carried out before it.
  • Substantial public interest and protection of vital interests — detecting and reporting child sexual abuse material and credible threats of violence.

9. How We Use Your Data

We use the data described above to:
  • Create, authenticate and secure your account
  • Provide platform functionality and display your content and activity
  • Show your transaction and position history
  • Rank and personalise your feed and recommendations
  • Calculate rewards, fees, referrals and distributions
  • Send service messages, security alerts and notifications you enabled
  • Detect and prevent fraud, abuse, spam and market manipulation
  • Enforce our Terms of Service and Acceptable Use Policy
  • Diagnose faults, measure aggregate usage and improve the product
  • Comply with legal obligations and respond to valid legal process
  • Establish, exercise or defend legal claims

We do not use your data for targeted advertising, sell it to third parties, build marketing profiles, or track you across other websites. We do not train our own models on your content, and we do not grant our AI processors the right to train their models on it.

10. How We Share Your Data

We share personal data only in the situations listed here:
  • Blockchain networks — transactions you submit are public by design. See section 11.
  • AI processors — Google, Anthropic, xAI, AtlasCloud and OpenAI, limited to the content you submit to AI features (section 6).
  • Child safety organisations — the Canadian Centre for Child Protection for CSAM detection, and competent authorities where a report is legally required.
  • Infrastructure and service providers — they act on our instructions under written terms. The ones that can see personal data are named here: Hetzner Online (server hosting, database and object storage, Germany), Cloudflare (content delivery, DNS, DDoS protection and inbound email routing), Resend (transactional email — sign-in codes, security notices) and Expo (push notification delivery to your device). Blockchain node providers receive the transactions and addresses we query on your behalf; they are not given your account data.
  • GIF searchKlipy, when you search for a GIF. Your search term and an internal account identifier are sent so Klipy can return and rate-limit results. Your IP address is not sent: the request is made by our server, not by your device, so Klipy never sees where you are connecting from.
  • Authentication providers — Google, Apple and X, limited to what is needed to authenticate you.
  • Legal authorities — where required by law or in response to valid legal process. Where we are permitted to notify you, we will.
  • Professional advisers — lawyers, auditors and insurers, bound by confidentiality.
  • Corporate transactions — in connection with a merger, acquisition, financing, reorganisation, sale of assets or insolvency, personal data may be transferred as part of the business. Any acquirer remains bound by this Notice for data collected under it, and we will notify you before your data becomes subject to a materially different privacy notice.

We never share wallet-to-identity mappings, key material of any kind (we hold none), your data for marketing or advertising purposes, or your data with data brokers.

11. Blockchain Data Is Public and Permanent

Bad Place settles activity on public blockchains, currently including BNB Chain, Base, Robinhood Chain, Ethereum and Solana. This has consequences for your privacy that no policy can undo, and you should understand them before you transact.
  • Every transaction — the addresses involved, amounts, timing and the contract called — is written to a public ledger that anyone in the world can read, index and archive.
  • These networks are decentralised and not operated by us. We cannot erase, edit, redact or alter anything recorded on them. Neither can anyone else.
  • If you publicly link a wallet address to your Bad Place profile, you are connecting your on-chain history to that profile for anyone who looks. That link is your choice; consider it carefully.
  • Third parties operate chain-analysis services that attempt to cluster addresses and attribute them to people. We do not participate in this and we do not sell them data, but we cannot prevent them from analysing public ledger data.

A request to erase your personal data reaches our off-chain systems only. On-chain records are outside the control of any party, including us.

13. International Transfers

Bad Place is operated globally and your personal data is processed in more than one country. Our primary application servers and databases are located in the European Union (Germany). Our content delivery, object storage and DDoS protection are provided by a global network with points of presence worldwide. Several of our processors — including the AI providers named in section 6 and the authentication providers named in section 5 — are established in the United States.

This means your personal data may be transferred to, stored in and processed in countries whose data protection laws differ from those of your own country, including countries that have not received an adequacy decision from the European Commission or the UK government.

Where we transfer personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical measures including encryption in transit and data minimisation. You may request a copy of the relevant transfer mechanism by writing to [email protected].

Blockchain data is a separate matter entirely: it is replicated to nodes worldwide with no controller and no transfer mechanism. See section 11.

14. Cookies, Local Storage and Analytics

We keep this deliberately small. Bad Place runs no advertising cookies, no cross-site tracking pixels, and no third-party marketing or advertising SDKs. We do not operate a third-party analytics product such as Google Analytics, and we do not combine anything stored on your device with third-party data for advertising or advertising measurement.

What we do use:

  • Strictly necessary — keeping you signed in, authenticating your requests, load balancing, and security and anti-abuse protections. These cannot be switched off without breaking the service, and no consent is required for them.
  • Functional — remembering your interface preferences, such as your chosen language, theme and selected chain.
  • Local storage on your device — your session token and, where you use the on-device wallet features, wallet material that stays on your device and is never transmitted to us.
  • Aggregate product measurement — derived from our own server logs, not from a third-party tracker.

How to control this. You can block or delete cookies and clear site storage through your browser settings; general guidance is available at allaboutcookies.org. If you block strictly necessary storage, you will not be able to sign in or transact. We honour Global Privacy Control signals where your browser sends them; because we do not sell or share personal data for advertising, there is nothing further for such a signal to switch off.

15. Security

We apply administrative, technical and physical safeguards proportionate to the risk, including:
  • TLS encryption for all traffic between you and our servers
  • No key material held at all — no private keys, seed phrases or key shares
  • Two-factor authentication secrets stored encrypted with a server key
  • Signature verification performed server-side; client-supplied amounts and eligibility claims are never trusted
  • Rate limiting and abuse controls on authentication and write paths
  • Access controls, least privilege and monitoring on production systems
  • Automated safety checks on uploaded content
  • Data minimisation and bounded retention

No system is perfectly secure. We cannot guarantee the security of data transmitted over the internet, and any transmission is at your own risk. Enable two-factor authentication, use an email address you control, and keep your seed phrase somewhere only you can reach.

If a breach occurs. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by Article 33 GDPR, and we will notify you directly without undue delay where the risk to you is high. If you believe you have found a vulnerability, report it to [email protected] rather than disclosing it publicly.

16. Data Retention

We keep personal data only as long as we need it for the purpose we collected it for, plus any period we are legally required to retain it.
  • Account data — until you delete your account, then removed or irreversibly anonymised within 90 days, except where an item below requires longer.
  • Content you publish — until you delete it or delete your account.
  • Server and security logs — 30 days.
  • Aggregate usage measurements — 12 months, after which they are retained only in a form that cannot be linked to you.
  • Reference photographs sent to AI providers — not retained as source images.
  • Consent and preference records — for as long as legally required, in order to prove what you consented to and when.
  • Copyright notices and counter-notices — for as long as legally required, including for repeat-infringer records.
  • Enforcement records — where an account was terminated for a zero-tolerance violation, the identifiers needed to prevent re-registration are retained indefinitely. Retaining them is the entire point of the ban.
  • Records needed to defend legal claims — until the relevant limitation period expires.
  • On-chain transaction history — permanent and outside our control.

17. Your Rights Over Your Data

Wherever you live, you can ask us to:
  • Access — tell you what personal data we hold about you and provide a copy.
  • Rectify — correct data that is inaccurate or incomplete.
  • Erase — delete your off-chain personal data and your account.
  • Port — export the data you gave us in a structured, machine-readable format.
  • Restrict or object — pause or stop processing that relies on our legitimate interests.
  • Withdraw consent — for anything you consented to, at any time.

How to exercise them. Write to [email protected] from the email address on your account and describe what you want. We may ask for information to verify your identity — we use it only to confirm who you are and delete it afterwards. We respond within 30 days and will tell you if we need a permitted extension. Exercising these rights is free unless a request is manifestly unfounded or excessive.

Limits we will be honest about. On-chain data cannot be deleted by anyone (section 11). We may decline erasure where we are legally required to retain something, where it is needed to establish or defend a legal claim, or where deletion would let a terminated account evade a zero-tolerance ban. Where we decline, we will tell you why.

18. Additional Rights — EEA, UK and Switzerland

If you are in the European Economic Area, the United Kingdom or Switzerland, the rights in section 17 are statutory rights under the GDPR, the UK GDPR and the Swiss FADP respectively, and you additionally have:
  • The right not to be subject to a decision based solely on automated processing which produces legal effects concerning you, and to obtain human intervention, express your point of view and contest the decision — see section 7.
  • The right to object at any time to processing based on our legitimate interests, on grounds relating to your particular situation.
  • The right to receive information about the safeguards applied to international transfers — see section 13.

The right to complain. If you believe we have not handled your personal data lawfully, we would rather you told us first at [email protected] — we investigate every complaint and tell you the outcome. But you do not have to come to us first. You may lodge a complaint directly with the data protection supervisory authority in the country where you live, where you work, or where you believe the infringement occurred. In the UK this is the Information Commissioner's Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner. A list of EEA authorities is published by the European Data Protection Board at edpb.europa.eu.

19. Additional Rights — California

If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you specific rights.

Categories we collect. In the past twelve months we have collected: identifiers (email address, account identifier, wallet address, IP address, device identifiers); commercial information (your transaction and position history); internet and network activity (your interactions with the platform); approximate geolocation at country level; audio, electronic or visual information (images you upload or generate); and inferences drawn from your activity for the purpose of ranking your feed. The sources, purposes and recipients for each are described in sections 3 to 11.

We do not sell or share your personal information as those terms are defined by the CCPA. We have not sold or shared personal information in the past twelve months, and we do not sell or share the personal information of minors under 16. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.

Your rights. You may request to know the categories and specific pieces of personal information we have collected, the sources, our purposes and the categories of recipients; request deletion; request correction; and opt out of sale or sharing (there is nothing to opt out of, but the right stands). You may use an authorised agent, who must provide written proof of authorisation.

No discrimination. We will not deny you service, charge you a different price, or provide a different level of quality because you exercised a privacy right. To make a request, write to [email protected]. We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days where necessary.

20. Additional Rights — Other Jurisdictions

Other data protection laws give you comparable rights, and we apply the same process described in section 17 to requests made under them.
  • Türkiye (KVKK) — you have the rights set out in Article 11 of Law No. 6698, including learning whether your data is processed, requesting correction or deletion, and objecting to results produced solely by automated analysis. You may apply to us directly and, if unsatisfied, complain to the Personal Data Protection Board (KVKK).
  • Brazil (LGPD) — confirmation of processing, access, correction, anonymisation or deletion, portability, information about data sharing, and the right to complain to the ANPD.
  • Canada (PIPEDA) — access to and correction of your personal information, and the right to complain to the Office of the Privacy Commissioner of Canada.
  • Other US states — where a state privacy law applies to you (including Virginia, Colorado, Connecticut, Utah and Texas), you have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and profiling, together with a right to appeal a refused request. We do not conduct targeted advertising, sale or profiling that produces legal effects.

If a right is available to you under a law not listed here, we will honour it. Write to [email protected] and tell us which law you are relying on.

21. Children

Bad Place is not directed to children. You must be at least 18 years old, or the age of legal majority in your jurisdiction if that is higher, to create an account or use the platform. We do not knowingly collect personal data from anyone under 18.

If we learn that we hold personal data collected from a person under 18, we delete it and terminate the account. If you are a parent or guardian and believe a child in your care has given us personal data, write to [email protected] and we will act promptly.

Sexualised depictions of minors are handled under a separate and absolute rule set out in our Acceptable Use Policy and section 7 above. That is not a privacy matter and it is not negotiable.

22. Third-Party Sites and Services

Bad Place links to and interoperates with services we do not control: external wallets, blockchain explorers, decentralised exchanges and aggregators, bridges, social platforms, and any website another user chooses to link to in a post or a token description.

We do not control these services and we are not responsible for their content, their security, or how they handle your data. Opening them takes you outside this Notice and into their own terms and privacy policies, which you should read. Displaying a link, a price feed or a token is not an endorsement of the operator behind it.

Take particular care with anything that asks you to sign a transaction or reveal a seed phrase. We will never ask you for a seed phrase, and no legitimate service will.

23. Changes to This Notice

We revise this Notice as the platform evolves, as we add or remove processors, and as legal requirements change. The current version is always published at this URL with the revision date shown at the top of the page.

Where a change is material — a new category of data, a new purpose, a new class of recipient, or a reduction in your rights — we will announce it in-app and by email before it takes effect, and where the law requires your consent we will ask for it rather than assume it. Non-material changes, such as clarifying wording or naming a replacement infrastructure provider, take effect on publication.

Continued use of Bad Place after a change takes effect constitutes acceptance of the updated Notice. If you do not accept it, stop using the platform and ask us to delete your account.

24. Contact Us

For any question about this Notice, to exercise your rights, or to complain about how we have handled your data:

If a message to an address above bounces, or goes unanswered for more than 72 hours, use our secondary channel, which runs on separate infrastructure: [email protected] for abuse, safety, copyright and security, and [email protected] for legal and data-protection matters. Please keep the original subject line.

By post: Cheese Art Labs L.L.C., Ukshin Hoti 51, Prishtinë, Republic of Kosovo.

We acknowledge privacy requests promptly and respond substantively within 30 days, or within the shorter period required by the law that applies to you. Complaints are investigated within a reasonable period proportionate to their complexity, and we tell you the outcome. You may also complain directly to your supervisory authority — section 18.

This Privacy Policy is published in English. Questions? Reach us at [email protected]. See also our Terms of Service, Acceptable Use Policy and Copyright & DMCA Policy.