Privacy Policy
Last updated: 2026-07-30
1. Who we are
Dead Labs ("we," "us") operates decapination.xyz. This Privacy Policy describes how we handle personal information when you use our site and related services (the "Site"). Use of the Site is also governed by our Terms of Service.
Privacy questions or requests: decapinationnft@gmail.com. Correspondence address: Correspondence address available on request via the contact email below..
2. Scope
This policy applies to personal information we process through the Site, including when you browse without an account, create an account via Discord, link a wallet or social account, participate in ACID features, enter Black Market campaigns, submit a community survey or feedback form, or send a business inquiry through the hire page.
3. Information we collect
The categories below depend on how you use the Site. We aim to collect only what is reasonably needed for the purposes described in Section 5.
- Account and identity: Discord-derived name, email address, avatar image URL, internal user ID, and account role (for example, user or admin).
- Profile information: public handle, bio, and optional X (Twitter) handle or profile link that you provide or that we receive when you link X.
- Authentication and session data: session tokens, session expiry, IP address, and user agent stored with your session.
- OAuth tokens: access and refresh tokens for linked providers (Discord and, if you link it, X), stored to maintain your connection.
- Wallet data: Ethereum wallet addresses you link, chain ID, and primary-wallet flag. We do not collect private keys or seed phrases.
- Platform activity: ACID and XP balances, transaction history (amounts, kinds, reasons, and metadata), quest progress, daily check-in and streak records, referral codes and referral relationships, and leaderboard-related statistics.
- Black Market data: campaign entries, entry numbers, draw outcomes, prize assignments, and redemption or fulfillment status.
- Community survey and feedback responses: survey identifier, your linked user ID when signed in, answers you submit (including free text, choices, scales, and rankings), and submission time. Completing a survey may trigger a discretionary ACID grant recorded in your transaction history.
- Business hire inquiries: name, email address, service interest, message, and optional budget range and timeline that you submit on the hire page. These inquiries are delivered to the Operator via a Discord webhook and are not stored as long-term application database records on the Site.
- Administrative records: audit logs of admin actions and notes related to prize fulfillment, where applicable to your account.
- Referral attribution: an httpOnly cookie (decap_ref) may store a referral invite code for up to 30 days before you sign up.
- Technical and usage data: IP address, device and browser type, general location derived from IP, pages viewed, timestamps, and performance or error data. Our hosting provider (Vercel) processes requests and may log similar technical data.
- On-chain reads (not stored as your personal profile by default): when you use holder-gated or gallery features, we query a third-party indexer with your linked wallet addresses to read public NFT ownership for the Decapination collection.
4. Sources of information
We collect information directly from you (for example, profile edits, survey answers, and hire inquiries), automatically when you use the Site (for example, session and log data), from authentication providers (Discord and X), from your wallet software when you sign a SIWE message, from our database and background jobs, and from public blockchain indexer APIs.
5. How we use information
We use personal information to provide and secure the Site; authenticate users; link wallets; verify NFT holder eligibility; operate the ACID economy, quests, referrals, and leaderboards; run Black Market campaigns and fulfill prizes; run community surveys and grant related ACID rewards; respond to business hire inquiries; prevent fraud and abuse; measure performance; fix errors; comply with law; and respond to your requests.
We do not sell your personal information. We do not use your data to send marketing emails unless you opt in where required.
6. Legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies, we rely on appropriate bases such as:
Performance of a contract: providing accounts, ACID features, Black Market participation, and prize fulfillment.
Legitimate interests: security, fraud prevention, service improvement, and aggregated analytics, balanced against your rights.
Consent: where required for non-essential cookies, analytics, or session replay, and for optional account linking where applicable.
Legal obligation: where we must retain or disclose information to comply with law.
7. Cookies and similar technologies
We and our partners use cookies, local storage, and similar technologies as follows:
- Essential: Better Auth session cookies for sign-in and security.
- Functional: decap_ref referral cookie (httpOnly, up to 30 days) and wagmi cookie storage for wallet connector state.
- Analytics (non-essential, requires consent where required by law): Vercel Analytics, Vercel Speed Insights, and Google Analytics when NEXT_PUBLIC_GA_ID is configured.
- Diagnostics — Session Replay (non-essential, requires consent where required by law): sampled Sentry Session Replay when you accept analytics cookies.
- Diagnostics — error monitoring: Sentry error reporting and performance tracing may run to operate and secure the Site even when analytics cookies are declined; Session Replay does not.
8. Analytics and session replay
Vercel Analytics and Speed Insights measure traffic and performance. When configured, Google Analytics (Google LLC) processes pseudonymous usage data. These analytics tools load only when you have accepted analytics cookies (or where otherwise permitted).
We use Sentry (@sentry/nextjs) for error monitoring and performance tracing to keep the Site reliable and secure. That monitoring may operate independently of analytics-cookie consent. Session Replay may record visual reproductions of sessions only when you have accepted analytics cookies (or where otherwise permitted). Sampling rates are configured in our client Sentry setup. We configure Sentry with sendDefaultPii disabled and text/input masking enabled where supported.
We do not use Loglib or similar product-analytics SDKs on the Site today.
9. How we share information and subprocessors
We share personal information with service providers who assist us, including:
- Vercel — hosting, Analytics, and Speed Insights;
- Sentry — error reporting, performance tracing, and Session Replay;
- Google — Analytics (when enabled) and font delivery via Google Fonts;
- Discord — OAuth authentication, and delivery of hire-page business inquiries to the Operator via Discord webhook;
- X (Twitter) — optional account linking;
- WalletConnect — wallet connection infrastructure;
- Arcjet — bot detection and rate limiting (IP address processing);
- Inngest — background job orchestration;
- Hasura / indexer provider — NFT ownership queries using wallet addresses (server-side only);
- Database hosting — PostgreSQL provider used to store application data.
10. International transfers
If you access the Site from outside the country where our servers or subprocessors operate, your information may be processed in the United States or other jurisdictions. Where required, we use appropriate safeguards for international transfers, such as Standard Contractual Clauses or other mechanisms recognized under applicable law.
11. Retention
We retain information for as long as needed for the purposes described in this policy, including operating your account, fulfilling prizes, resolving disputes, and meeting legal obligations.
Indicative periods: account and profile data until you request deletion (subject to backup cycles); session data until expiry; ACID, Black Market, and survey response records for the life of the account and a reasonable period thereafter (including admin review of survey answers); hire inquiries retained in Operator Discord channels according to our operational practice rather than as Site database records; analytics and error logs per vendor defaults unless a longer period is required by law.
We cannot delete information recorded on public blockchains. Wallet addresses and on-chain ownership are public by nature.
12. Security
We implement technical and organizational measures designed to protect personal information, including encryption in transit, access controls for administrative tools, and server-side-only access to indexer credentials. We do not custody cryptocurrency private keys.
No method of transmission or storage is completely secure. You are responsible for securing your Discord account and wallet.
13. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, or export personal information, and to object to or restrict certain processing. California residents may have additional rights under the CCPA/CPRA. EEA/UK users may lodge a complaint with a supervisory authority.
To exercise rights, contact decapinationnft@gmail.com. We may verify your request. Account deletion is handled on request; some records may be retained where required by law.
14. Children, changes, and contact
The Site is not directed at children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. Contact us if you believe we have done so in error.
We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date. Material changes may also be communicated in-product where appropriate.
Privacy questions or requests: decapinationnft@gmail.com.