Privacy
Who. Operated by Subnet Metrics. Contact: hello@subnetmetrics.com, or reply to any email from us. Governing law: England and Wales. We are the data controller for what is described here.
What we hold, and why. For the free issue: your email, when you confirmed and the IP you confirmed from, kept as the record that consent existed; lawful basis, consent, withdrawn by the unsubscribe link in every email. For Pro: the same plus a Stripe customer id; lawful basis, the contract. For a tax pack: the order record (email, the coldkey(s) you gave us, what was bought, when, and any other-income figure you typed), and the chain history fetched for that coldkey while the pack is built; lawful basis, the contract. For the free exposure check: nothing, unless you enter an email, in which case the email only. We do not track email opens. The theme switch stores one value in your browser. If you allow optional analytics, PostHog receives public page paths, approved campaign labels, form-action events and verified purchase amounts, linked by a random visitor identifier. We do not send emails, wallet addresses, tax inputs, private URLs or form contents, and do not make screen recordings. The analytics identifier and your preference expire after 90 days. Withdraw consent using Analytics preferences on public pages; this stops collection and deletes queued events. Previously delivered events remain subject to the configured PostHog retention policy. PostHog processes these events in the EU cloud region; contact us to request deletion. Lawful basis: consent. Explore uses an essential sign-in cookie for subscriber access and stores the subnet numbers in your watchlist. Private sign-in links and sessions are stored as hashes. Short-lived hashed email and network identifiers limit sign-in requests.
Wallet evidence submissions store the subnet number, public wallet address, disclosure link and explanation in an internal review queue. We retain source excerpts and review notes as an evidence record; verified public information may support published coverage. The form uses an essential one-hour cookie and daily hashed network identifiers for abuse prevention. Rate-limit records are purged after two days during source monitoring. Do not submit secrets or personal information; contact us to correct or remove a submission.
For TAO purchases we keep the email, product, sending and receiving wallet addresses, USD price, TAO quote, payment amount, timestamps and transaction evidence to verify payment and provide the service. Transfers are public on Bittensor; the blockchain record cannot be deleted by us. Invoice and payment records are retained for accounting as described below.
For the API plan, we hold your email, Stripe customer and subscription identifiers, billing status and dates, key names, prefixes, creation/revocation dates and cryptographic hashes, and aggregate request counts per billing period. Complete API keys are shown once and are not stored. This supports access, billing and usage limits; lawful basis, the contract.
How long. Subscriber records for as long as you are subscribed, then the email alone so a resubscribe cannot be silently ignored. Coldkey history and pack files, 30 days after delivery, then deleted. Order records, six years, the period HMRC can ask about a sale. Explore sign-in links expire after 15 minutes (seven days for links in the Pro); sessions expire after 30 days. Expired records are purged when new links are issued. Request limits expire after an hour and are purged on the next request. Watchlists remain until you remove their entries or request deletion. API account, key and aggregate usage records remain until you request deletion; payment records needed for accounting follow the six-year retention period above.
Who else touches it. Stripe (payment; sees your email and card, we never see the card), Resend (email delivery), Railway (hosting and the database), PostHog (optional analytics, only with your consent), and Taostats (the chain index we read a coldkey's public history from, which receives the coldkey and nothing about you). TAO verification also reads public Bittensor RPC nodes. Coinbase provides the public TAO/USD quote; we send it no customer details. A coldkey is a public address; we treat it as personal data because it is yours. Some of these providers process data outside the UK under their standard contractual terms.
Your rights. To see what we hold, correct it, have it deleted, or object: email hello@subnetmetrics.com and it is done within a month. You can complain to the Information Commissioner's Office at ico.org.uk.