Privacy Policy
What data Bad Place collects, why we are allowed to process it, who we share it with, and the rights you have over it.
Our Privacy Commitment
Bad Place is designed to hold as little about you as it can. We hold no private keys, seed phrases or key shares — not encrypted, not split, not at all. We do not sell your personal data, we do not run advertising trackers, and we do not build marketing profiles. What we do collect is listed below in full, with the legal basis for each use and the rights you have to challenge it. Your wallet, your keys, your privacy.
1. Who We Are and What This Notice Covers
Cheese Art Labs L.L.C. is the data controller for this processing. Our registered address is Ukshin Hoti 51, Prishtinë, Republic of Kosovo.
“Personal data” means information that identifies you or can reasonably be linked to you. Data that has been aggregated or irreversibly anonymised so that it can no longer be connected to you is not personal data and this Notice does not restrict our use of it.
This Notice does not cover third-party services you reach through Bad Place — external wallets, blockchain explorers, decentralised exchanges, or any site you open from a link posted by another user. Those operate under their own privacy terms. See section 22.
2. Data You Give Us
- Email address — required to create an account and to receive one-time sign-in codes.
- Profile information — username, display name, bio, avatar and banner images, and any links you choose to publish.
- Wallet addresses — the public addresses you connect, link or generate. Public addresses only; never key material.
- Content you create — tokens and their metadata, BadLine posts, replies, comments, uploaded images, AI prompts and AI-generated media, and community submissions.
- Support and abuse correspondence — what you write to us, including reports you file about other users.
- Verification material — where a feature requires it, such as proof of control of a social account or of a wallet.
We do not collect private keys, seed phrases or key shares of any kind; precise geolocation; contact lists or address books; biometric identifiers; or any special-category data such as health, religion, political opinion or sexual orientation. We do not ask for government identity documents, and you should never send them to us.
3. Data We Collect Automatically
- IP address — recorded in server and security logs and used for rate limiting, abuse prevention and fraud detection.
- Approximate country, derived from the IP address by our network provider. We do not derive city-level or precise location.
- Device and client information — browser type and version, operating system, app version, screen and language settings, and time zone.
- Request metadata — the endpoints you call, timestamps, response codes, referring page, and the session identifier attached to your requests.
- Push notification token — on mobile, only if you grant notification permission.
- Interaction signals — what you view, open, like (“cheers”), reply to and follow, used to rank your feed.
We do not fingerprint your device to track you across other websites, and we do not buy or receive behavioural data about you from data brokers or advertising networks.
4. Wallets and Key Material
- We never store private keys, seed phrases or partial key shares — not encrypted, not split, not at all.
- On the web, the platform has no embedded custodial wallet: you connect an external browser wallet that you already control.
- On mobile, your recovery phrase is generated on your device and kept in the device's secure storage. It never reaches our servers.
- A wallet address shown on your profile is a link you chose to make and proved with a signature. A signature proves control; it grants us none.
- Because we hold nothing, we cannot move your funds, freeze your wallet, reverse a transaction, or restore access if you lose your own backup.
Your account is an identity for social and platform features. It is not a wallet and it cannot spend your funds. Anyone who tells you that Bad Place support can recover a lost seed phrase is attempting to defraud you.
5. Accounts and Linked Services
- Email — required to register, verify your account and sign in with a one-time code.
- Two-factor authentication — if you enable it, we store the shared secret encrypted with a server-held key.
- Google Sign-In — optional. We receive your email address, Google account identifier and profile picture.
- Apple Sign-In — optional. We receive your Apple account identifier and the email address Apple releases to us. If you use Apple Private Relay, that address is a relay address and we never see your real one; we match your account on the Apple identifier, not the email.
- X (Twitter) — optional, and required for certain social and reward features. We receive your public handle, profile picture and banner.
- Push notifications — a device token, only if you allow notifications.
Linked accounts can be disconnected at any time from Settings. Disconnecting stops future collection from that service; it does not retroactively erase data already received, which is handled under the retention rules in section 16.
6. AI Features and Third-Party AI Processors
What is sent: the prompt you write, the options you select, any reference image you upload, and — for ranking and recommendation features — the text of content you publish.
Who processes it. Each of the following acts as a processor for us and is contractually restricted to processing your data for our purposes only:
- Google (Gemini) — image generation, prompt interpretation, and text embeddings used for feed ranking and interest matching.
- Anthropic (Claude) — text generation and automated safety review of prompts and content.
- xAI (Grok Imagine) — image generation and image editing in the Cook feature.
- AtlasCloud — image generation and image editing in the Cook feature.
- OpenAI — text embeddings, where configured as the embedding provider in place of Google.
Reference photographs you upload are used for generation and safety review and are not retained as source images after processing completes. Generated output that you keep is stored on our media infrastructure and linked to your account.
AI providers are added, removed and swapped as the product evolves. When that happens this section is updated, and material additions are announced under section 23. If you do not want your content processed this way, do not use the AI features — the rest of the platform works without them.
7. Automated Moderation and Automated Decisions
- Every uploaded image is checked against known child sexual abuse material using the Canadian Centre for Child Protection's Project Arachnid service.
- Text and images are screened by automated classifiers for the categories set out in our Acceptable Use Policy.
- Automated signals also feed rate limiting, spam detection and anti-manipulation systems, which can throttle or temporarily restrict an account.
Where a decision is fully automated. Confirmed matches against known CSAM result in immediate permanent termination and, where the law requires it, a report to the competent authority. This is a deliberate exception: it is automated, it produces a legal effect for you, and there is no appeal. Every other enforcement outcome that permanently restricts an account — bans, content removals, reward disqualification — is subject to human review on request.
Your right to object. If an automated system has restricted your account, you may write to [email protected] to obtain human review, express your point of view, and contest the outcome. We will tell you the basis of the decision to the extent that doing so does not compromise the detection system itself.
Automated moderation is a filter, not an approval. Content that passes it has not been reviewed by a person and has not been declared lawful.
8. Legal Bases for Processing
- Performance of a contract (Art. 6(1)(b)) — creating and running your account, displaying your content and holdings, executing the platform functions you ask for, and providing support. Without this data the service cannot be delivered.
- Legitimate interests (Art. 6(1)(f)) — securing the platform, preventing fraud, abuse, spam and market manipulation, ranking your feed, measuring aggregate product usage, and defending legal claims. We have weighed these against your rights and you may object at any time under section 18.
- Legal obligation (Art. 6(1)(c)) — retaining records we are required to keep, responding to valid legal process, operating the copyright notice-and-counter-notice procedure, and reporting child sexual abuse material.
- Consent (Art. 6(1)(a)) — push notifications, optional linked accounts, and any use of the AI features. You may withdraw consent at any time; withdrawal does not affect processing carried out before it.
- Substantial public interest and protection of vital interests — detecting and reporting child sexual abuse material and credible threats of violence.
9. How We Use Your Data
- Create, authenticate and secure your account
- Provide platform functionality and display your content and activity
- Show your transaction and position history
- Rank and personalise your feed and recommendations
- Calculate rewards, fees, referrals and distributions
- Send service messages, security alerts and notifications you enabled
- Detect and prevent fraud, abuse, spam and market manipulation
- Enforce our Terms of Service and Acceptable Use Policy
- Diagnose faults, measure aggregate usage and improve the product
- Comply with legal obligations and respond to valid legal process
- Establish, exercise or defend legal claims
We do not use your data for targeted advertising, sell it to third parties, build marketing profiles, or track you across other websites. We do not train our own models on your content, and we do not grant our AI processors the right to train their models on it.
10. How We Share Your Data
- Blockchain networks — transactions you submit are public by design. See section 11.
- AI processors — Google, Anthropic, xAI, AtlasCloud and OpenAI, limited to the content you submit to AI features (section 6).
- Child safety organisations — the Canadian Centre for Child Protection for CSAM detection, and competent authorities where a report is legally required.
- Infrastructure and service providers — they act on our instructions under written terms. The ones that can see personal data are named here: Hetzner Online (server hosting, database and object storage, Germany), Cloudflare (content delivery, DNS, DDoS protection and inbound email routing), Resend (transactional email — sign-in codes, security notices) and Expo (push notification delivery to your device). Blockchain node providers receive the transactions and addresses we query on your behalf; they are not given your account data.
- GIF search — Klipy, when you search for a GIF. Your search term and an internal account identifier are sent so Klipy can return and rate-limit results. Your IP address is not sent: the request is made by our server, not by your device, so Klipy never sees where you are connecting from.
- Authentication providers — Google, Apple and X, limited to what is needed to authenticate you.
- Legal authorities — where required by law or in response to valid legal process. Where we are permitted to notify you, we will.
- Professional advisers — lawyers, auditors and insurers, bound by confidentiality.
- Corporate transactions — in connection with a merger, acquisition, financing, reorganisation, sale of assets or insolvency, personal data may be transferred as part of the business. Any acquirer remains bound by this Notice for data collected under it, and we will notify you before your data becomes subject to a materially different privacy notice.
We never share wallet-to-identity mappings, key material of any kind (we hold none), your data for marketing or advertising purposes, or your data with data brokers.
11. Blockchain Data Is Public and Permanent
- Every transaction — the addresses involved, amounts, timing and the contract called — is written to a public ledger that anyone in the world can read, index and archive.
- These networks are decentralised and not operated by us. We cannot erase, edit, redact or alter anything recorded on them. Neither can anyone else.
- If you publicly link a wallet address to your Bad Place profile, you are connecting your on-chain history to that profile for anyone who looks. That link is your choice; consider it carefully.
- Third parties operate chain-analysis services that attempt to cluster addresses and attribute them to people. We do not participate in this and we do not sell them data, but we cannot prevent them from analysing public ledger data.
A request to erase your personal data reaches our off-chain systems only. On-chain records are outside the control of any party, including us.
12. Copyright Notices Are Forwarded
- A valid notice must contain your name, address, telephone number and email address — the law requires it.
- We forward the notice, including that identifying information, to the user whose content is affected. This is required and we cannot anonymise it.
- Counter-notices are forwarded the same way to the party who filed the original notice.
- We retain notices, counter-notices and the resulting actions for as long as legally required, including for our repeat-infringer records.
If you do not want your contact details passed to the other party, do not file a notice — there is no confidential route through this process. The full procedure is set out in our Copyright & DMCA Policy.
13. International Transfers
This means your personal data may be transferred to, stored in and processed in countries whose data protection laws differ from those of your own country, including countries that have not received an adequacy decision from the European Commission or the UK government.
Where we transfer personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical measures including encryption in transit and data minimisation. You may request a copy of the relevant transfer mechanism by writing to [email protected].
Blockchain data is a separate matter entirely: it is replicated to nodes worldwide with no controller and no transfer mechanism. See section 11.
15. Security
- TLS encryption for all traffic between you and our servers
- No key material held at all — no private keys, seed phrases or key shares
- Two-factor authentication secrets stored encrypted with a server key
- Signature verification performed server-side; client-supplied amounts and eligibility claims are never trusted
- Rate limiting and abuse controls on authentication and write paths
- Access controls, least privilege and monitoring on production systems
- Automated safety checks on uploaded content
- Data minimisation and bounded retention
No system is perfectly secure. We cannot guarantee the security of data transmitted over the internet, and any transmission is at your own risk. Enable two-factor authentication, use an email address you control, and keep your seed phrase somewhere only you can reach.
If a breach occurs. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by Article 33 GDPR, and we will notify you directly without undue delay where the risk to you is high. If you believe you have found a vulnerability, report it to [email protected] rather than disclosing it publicly.
16. Data Retention
- Account data — until you delete your account, then removed or irreversibly anonymised within 90 days, except where an item below requires longer.
- Content you publish — until you delete it or delete your account.
- Server and security logs — 30 days.
- Aggregate usage measurements — 12 months, after which they are retained only in a form that cannot be linked to you.
- Reference photographs sent to AI providers — not retained as source images.
- Consent and preference records — for as long as legally required, in order to prove what you consented to and when.
- Copyright notices and counter-notices — for as long as legally required, including for repeat-infringer records.
- Enforcement records — where an account was terminated for a zero-tolerance violation, the identifiers needed to prevent re-registration are retained indefinitely. Retaining them is the entire point of the ban.
- Records needed to defend legal claims — until the relevant limitation period expires.
- On-chain transaction history — permanent and outside our control.
17. Your Rights Over Your Data
- Access — tell you what personal data we hold about you and provide a copy.
- Rectify — correct data that is inaccurate or incomplete.
- Erase — delete your off-chain personal data and your account.
- Port — export the data you gave us in a structured, machine-readable format.
- Restrict or object — pause or stop processing that relies on our legitimate interests.
- Withdraw consent — for anything you consented to, at any time.
How to exercise them. Write to [email protected] from the email address on your account and describe what you want. We may ask for information to verify your identity — we use it only to confirm who you are and delete it afterwards. We respond within 30 days and will tell you if we need a permitted extension. Exercising these rights is free unless a request is manifestly unfounded or excessive.
Limits we will be honest about. On-chain data cannot be deleted by anyone (section 11). We may decline erasure where we are legally required to retain something, where it is needed to establish or defend a legal claim, or where deletion would let a terminated account evade a zero-tolerance ban. Where we decline, we will tell you why.
18. Additional Rights — EEA, UK and Switzerland
- The right not to be subject to a decision based solely on automated processing which produces legal effects concerning you, and to obtain human intervention, express your point of view and contest the decision — see section 7.
- The right to object at any time to processing based on our legitimate interests, on grounds relating to your particular situation.
- The right to receive information about the safeguards applied to international transfers — see section 13.
The right to complain. If you believe we have not handled your personal data lawfully, we would rather you told us first at [email protected] — we investigate every complaint and tell you the outcome. But you do not have to come to us first. You may lodge a complaint directly with the data protection supervisory authority in the country where you live, where you work, or where you believe the infringement occurred. In the UK this is the Information Commissioner's Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner. A list of EEA authorities is published by the European Data Protection Board at edpb.europa.eu.
19. Additional Rights — California
Categories we collect. In the past twelve months we have collected: identifiers (email address, account identifier, wallet address, IP address, device identifiers); commercial information (your transaction and position history); internet and network activity (your interactions with the platform); approximate geolocation at country level; audio, electronic or visual information (images you upload or generate); and inferences drawn from your activity for the purpose of ranking your feed. The sources, purposes and recipients for each are described in sections 3 to 11.
We do not sell or share your personal information as those terms are defined by the CCPA. We have not sold or shared personal information in the past twelve months, and we do not sell or share the personal information of minors under 16. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.
Your rights. You may request to know the categories and specific pieces of personal information we have collected, the sources, our purposes and the categories of recipients; request deletion; request correction; and opt out of sale or sharing (there is nothing to opt out of, but the right stands). You may use an authorised agent, who must provide written proof of authorisation.
No discrimination. We will not deny you service, charge you a different price, or provide a different level of quality because you exercised a privacy right. To make a request, write to [email protected]. We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days where necessary.
20. Additional Rights — Other Jurisdictions
- Türkiye (KVKK) — you have the rights set out in Article 11 of Law No. 6698, including learning whether your data is processed, requesting correction or deletion, and objecting to results produced solely by automated analysis. You may apply to us directly and, if unsatisfied, complain to the Personal Data Protection Board (KVKK).
- Brazil (LGPD) — confirmation of processing, access, correction, anonymisation or deletion, portability, information about data sharing, and the right to complain to the ANPD.
- Canada (PIPEDA) — access to and correction of your personal information, and the right to complain to the Office of the Privacy Commissioner of Canada.
- Other US states — where a state privacy law applies to you (including Virginia, Colorado, Connecticut, Utah and Texas), you have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and profiling, together with a right to appeal a refused request. We do not conduct targeted advertising, sale or profiling that produces legal effects.
If a right is available to you under a law not listed here, we will honour it. Write to [email protected] and tell us which law you are relying on.
21. Children
If we learn that we hold personal data collected from a person under 18, we delete it and terminate the account. If you are a parent or guardian and believe a child in your care has given us personal data, write to [email protected] and we will act promptly.
Sexualised depictions of minors are handled under a separate and absolute rule set out in our Acceptable Use Policy and section 7 above. That is not a privacy matter and it is not negotiable.
22. Third-Party Sites and Services
We do not control these services and we are not responsible for their content, their security, or how they handle your data. Opening them takes you outside this Notice and into their own terms and privacy policies, which you should read. Displaying a link, a price feed or a token is not an endorsement of the operator behind it.
Take particular care with anything that asks you to sign a transaction or reveal a seed phrase. We will never ask you for a seed phrase, and no legitimate service will.
23. Changes to This Notice
Where a change is material — a new category of data, a new purpose, a new class of recipient, or a reduction in your rights — we will announce it in-app and by email before it takes effect, and where the law requires your consent we will ask for it rather than assume it. Non-material changes, such as clarifying wording or naming a replacement infrastructure provider, take effect on publication.
Continued use of Bad Place after a change takes effect constitutes acceptance of the updated Notice. If you do not accept it, stop using the platform and ask us to delete your account.
24. Contact Us
- Privacy and data rights — [email protected]
- Abuse, safety, copyright and security reports — [email protected]
If a message to an address above bounces, or goes unanswered for more than 72 hours, use our secondary channel, which runs on separate infrastructure: [email protected] for abuse, safety, copyright and security, and [email protected] for legal and data-protection matters. Please keep the original subject line.
By post: Cheese Art Labs L.L.C., Ukshin Hoti 51, Prishtinë, Republic of Kosovo.
We acknowledge privacy requests promptly and respond substantively within 30 days, or within the shorter period required by the law that applies to you. Complaints are investigated within a reasonable period proportionate to their complexity, and we tell you the outcome. You may also complain directly to your supervisory authority — section 18.
This Privacy Policy is published in English. Questions? Reach us at [email protected]. See also our Terms of Service, Acceptable Use Policy and Copyright & DMCA Policy.