Privacy Policy
01The short version
Stockboard is built so there is very little to have a privacy policy about. In plain terms:
- The website shows you information. It sets no cookies, runs no analytics, and stores nothing about you.
- The keyboard prototypes count keystrokes on your own device and send nothing anywhere. They never store or transmit what you type.
- The optional account page is the only place any personal detail is handled. It uses Privy to sign you in with an email address or a connected wallet, and only to sign you in.
- Rewards are not live, so no reward, balance, earning history or payout data exists.
- The keyboard and the account are separate and are never linked. Your key counts are never connected to your account.
02What this policy covers
This draft covers the parts of Stockboard that exist today:
- The Stockboard marketing website.
- The optional account and wallet sign-in page (
account.html, reached from the "Sign in" link). - The Stockboard keyboard prototype for Android.
- The Stockboard keyboard app for Windows, which is in development and not yet distributed.
It does not cover any rewards system, because none is active. It does not cover services you reach by leaving Stockboard, such as your own app store, wallet or email provider, which have their own policies.
03The marketing website
The website is a set of static information pages. It has no accounts, no forms and no waitlist. Stockboard sets no cookies on it, runs no analytics, and uses no advertising, tracking pixels or third-party trackers of any kind. It does not store anything about you in your browser.
To display its type, the site loads web fonts from Google Fonts. Like any request your browser makes to any server, this tells that provider your IP address and basic browser information as part of delivering the fonts. Stockboard does not add any tracking to this and receives nothing from it. See Google's privacy policy.
04The account and wallet page
The account page loads and runs only if you visit it and choose to sign in. Nothing on it runs on the homepage or in the keyboard apps.
- Sign-in through Privy. Stockboard uses Privy to sign you in with either an email address or a crypto wallet you connect. Privy processes that email or wallet address to authenticate you, and keeps you signed in by storing session data in your browser. Privy is an independent provider with its own terms; see Privy's privacy policy.
- The sign-in code is loaded from a CDN. When you open the account page, its sign-in code is fetched at runtime from the third-party network esm.sh. This is a normal request to serve that code.
- A non-custodial wallet. Signing in can create an embedded wallet on the Robinhood Chain that only you control. Stockboard never holds your keys or your funds, and this milestone does not buy, sell, fund or pay out anything.
- What is sent to Stockboard's own server. When you are signed in, the page may send your Privy access token to Stockboard's server endpoint /api/me. The server verifies the token to confirm who is signed in and, only if the operator has configured a server secret, looks up the wallet address Privy has on file so it can be shown back to you. Nothing else is sent. Nothing about your typing, your key counts or your devices is ever involved.
- Copying your address. The "copy address" button copies your wallet address to your device's clipboard. Nothing is transmitted by it.
Because rewards are not live, the account page today does no more than create and show a wallet. Stockboard holds nothing for you.
05The Android keyboard prototype
The Android prototype is built so that nothing you type can leave your phone or be recovered from it.
- No internet permission. The app requests no Android permissions at all, and it has no internet permission, so it cannot open a network connection. Nothing it records can be sent anywhere.
- It counts, it does not record text. The app counts eligible key presses on the device and stores only a small file of daily counts (numbers only) plus a running total, kept for a limited window. It stores no characters, words, messages, searches, app names, or timestamps finer than a day.
- Private input is excluded entirely. Password and private fields, and number, phone and date fields, are skipped with no tally at all, so nothing typed there is even counted.
- It never reads what is already on screen and writes nothing to device logs.
- No backup or transfer. The app is set so its counts are not copied off the device through cloud backup or device transfer.
In short, the Android prototype collects nothing about you and transmits nothing. It is a counter that lives on your phone.
06The Windows app
The Windows app is in development and is not distributed yet. As built, it has no networking and stores only local key counts (numbers only) in a file on your own PC. It transmits nothing.
One honest limitation: on Windows the app cannot detect a password field as reliably as the Android keyboard can, so the exclusion of private fields is best-effort there. Even so, only a local number is ever affected, and no count or anything else leaves your PC.
07Rewards are not active
Tokenized-stock rewards, per-key rates and payouts are not live. Every earning figure on the website is a demonstration, marked as such, and is not a rate or a promise. Because rewards are off:
- No reward balances, earning history, payout records or transaction data exist or are processed.
- No eligibility, identity-verification or location data is collected for rewards.
- Your key counts stay on your device and are not sent anywhere to be rewarded.
Turning on real rewards would require new data flows. None of them are built, and this policy will be revised to describe them plainly before any such data is collected.
08What Stockboard does not do
- It does not collect or store what you type.
- It sets no cookies of its own and runs no analytics or advertising trackers.
- It does not sell or share personal data, because, outside the optional Privy sign-in, it does not collect any.
- The keyboard apps and the account are never linked to each other.
09Service providers
The current build relies on these third parties, and only for the purposes described above:
- Privy: sign-in and the non-custodial wallet, on the account page only.
- esm.sh: delivers the account page's sign-in code at runtime.
- Google Fonts: delivers the web fonts used across the site.
- The hosting provider: serves the site and, as any web host does, processes standard server request logs to deliver and protect it. Stockboard adds no tracking on top of this.
10Your choices
- You can read the website and use the keyboard prototype without signing in and without any account.
- If you signed in, you can sign out at any time, and you can manage or request deletion of the account data Privy holds through Privy.
- The wallet the account creates is yours and non-custodial; Stockboard cannot access it.
11Children
Stockboard is a beta and is not directed to children. Outside the optional sign-in, it collects no personal data, so there is nothing about a visitor for it to gather.
12Changes and contact
This draft will change as the build changes, and it will be finalised and dated before launch. Material changes to how data is handled will be reflected here.
Contact for privacy questions: [privacy contact to be added before launch]. The operating entity and its contact details will be confirmed with counsel before this policy takes effect.