Privacy Policy
Last updated 9 July 2026
A privacy protocol that is vague about its own data handling has not understood the assignment. This is what we collect, what we do not, and what a public chain records regardless of either.
What we collect
Hood USDB does not require an account, an email address or identity documents. Your wallet address is your identity. Using the platform, we hold:
- 01Wallet addresses you connect, and the signature nonces used to open a session. Signatures prove control of an address; they are not transactions and cannot move funds.
- 02Ledger records — your deposits, internal transfers, pay links, payment requests and withdrawals, with amounts, timestamps and counterparty accounts. This is the ledger; without it we cannot tell you what your balance is.
- 03An optional @username you choose, which is public by design, because being payable by name is the point of it.
- 04Agent records — agent names, scoped API key hashes, spending policies, and the spending log of every attempt with its outcome and reason.
- 05Optional reference labels you attach to a pay link, which may include a phone number or a note. These are labels you type for your own reference, not a delivery mechanism.
- 06Standard technical logs — IP address, user agent and request timestamps, retained for security and abuse prevention.
What we do not collect
- 01Private keys or seed phrases. Ever. Every deposit and withdrawal is signed in your own wallet.
- 02Identity documents, KYC records, or any government identifier.
- 03Payment card details or bank account numbers.
- 04The contents of anything you share off-platform, including where you sent a pay link.
What the chain records regardless
Some of what happens is on a public blockchain and is outside anyone's control, including ours. Be clear about which parts:
- 01A Public-level transfer is a normal on-chain token transfer, visible to anyone, permanently.
- 02A Partial-level deposit into the pool is visible on-chain. The spending that follows it is decoupled from your address, but the deposit itself is not private.
- 03A Full-level deposit is visible as a transfer from your wallet to a one-time holding address. What happens after that has no on-chain edge back to you.
- 04Internal transfers between Hood USDB accounts do not touch the chain at all and leave no on-chain record.
- 05Withdrawals appear on-chain as payments from the pooled reserve, which has no on-chain link to your deposit.
The trust assumption, stated plainly
Your balance sits in a pooled reserve that Hood USDB operates and is recorded on our ledger. Withdrawals are processed by our backend rather than claimed directly from a contract. That means we can see the ledger, and it means the confidentiality this platform provides is operational — privacy against on-chain observers — and not cryptographic. FHE-encrypted balances and an on-chain proof system are on the roadmap and are not shipped.
We would rather you weigh that than discover it. If it is not an acceptable assumption for what you are doing, it is not an acceptable assumption, and you should not use the Full level for it.
How we use it
Ledger records exist to operate the platform: computing balances, settling transfers, enforcing spending policies, honouring the seven-day pay-link refund, and calculating fees. Technical logs exist to keep the service up and to prevent abuse. We do not sell data, and we do not run advertising.
Disclosure
We disclose records where we are legally required to, and where it is necessary to protect the platform or its users from fraud or attack. We do not disclose voluntarily for any other reason. An adversary who obtains records from outside the chain — an exchange, a device, a legal order — is outside what routing and pooling can address, and we say so on the product pages as well as here.
Retention
Ledger records are retained for as long as they are needed to operate accounts and meet legal obligations, because a balance is a running total and cannot be computed from a truncated history. Technical logs are retained on a shorter, rolling basis. Agent API keys are stored as hashes; revoking a key takes effect immediately.
Your choices
- 01Choose the privacy level per payment. Public is fully visible and we call it that.
- 02Withdraw to a fresh address for a clean break — the receiving address has no history linking it to you.
- 03Use the balance-hide toggle when screen-sharing.
- 04Pause or delete an agent at any time; enforcement is instant.
- 05Do not attach a reference label to a pay link if you do not want us to hold one.
Contact
Questions about this policy can go to us on Twitter. The protocol settles on Robinhood Chain; the contract address and network reference are published in the docs.