Skip to content
Privacy

We collect almost nothing, and we will tell you exactly what.

Galaxy Mind is an independent project, not a business built on your data. There are no ads, no ad networks, no data brokers, and nothing here is sold or shared for marketing. You can use the directory, every instrument, and every game without giving us anything at all.

Everything below describes the real system. If a feature is not listed, it does not collect anything.

Browsing the site

The site works without an account or login. We do not set advertising or cross-site tracking cookies.

We use Vercel Web Analytics and Speed Insights for aggregate page-view counts and page-performance timings. Vercel states these do not use cookies and do not track visitors across sites. We see totals and trends, not people.

Some vendor cards fall back to unavatar.io to fetch a profile picture we have not yet snapshotted ourselves. When that happens your browser makes a request to that third party, which will see your IP address as it would for any image on the web. Most avatars are served from our own domain specifically to avoid this.

If you subscribe to email alerts

We store your email address, your alert preferences, and (if you opt into portfolio-change alerts) a snapshot of the allocation inputs those alerts are diffed against. Email is delivered through Resend.

Subscriptions are double-opt-in: we send a confirmation link and store nothing durable until you click it. Every email carries a one-click unsubscribe, and you can change or drop any alert type at /prefs. Unsubscribing removes the contact.

We never sell, rent, or share the list, and we do not use it for anything but the alerts you asked for. Joining the USA fleet waitlist on /hashrate opts you into one extra channel: an email when a Galaxy Mind machine goes from none-open to open to rent. That is the only hashrate email. You can turn it off at /prefs.

If you enable browser push alerts

We store the push subscription your browser generates: an endpoint URL issued by your browser vendor and the keys needed to encrypt a message to it. That is what a push notification requires; it is not tied to an email address or a name. Turning the toggle off removes it.

If you link an X account in the arcade

Linking X is entirely optional. Every game works anonymously, and the leaderboards accept anonymous entries. If you do link, we store your X user ID, the @handle and profile image URL as they were at link time, and when you linked. Your session is an HttpOnly, signed cookie. We never receive your X password, and we cannot post as you.

Linked players also get cross-device save sync: game progress (records, unlocks, stats) stored against your X user ID so it follows your login.

Unlinking deletes all of it: the stored profile and the saved progress. That is the whole deletion story for the only personally-identifying data the arcade keeps.

Anonymous gameplay stats in CHOP

The arcade game CHOP sends two anonymous events: one when the game loads, and one when a run ends. They record how the game was played — the difficulty, how long the run lasted, hits and misses, the grade, and whether the block was finished or abandoned.

There is no identifier of any kind. No account, no cookie, no device ID, and never your arcade handle. Durations are rounded to five seconds and run counts are grouped into bands before anything leaves your device, and only the calendar day is recorded, not a timestamp. Two runs by one person are indistinguishable from two runs by two people — deliberately, because this measures the game and not the players.

It exists so the game can be improved by evidence rather than guesswork (where people quit, which difficulty they choose, whether the tutorial helps). Turn it off any time under Settings → Anonymous stats in the game; the game then sends nothing. Because the events carry no identifier, there is nothing to look up or delete afterwards.

If you submit a vendor

We store what you type into the form: the merchant's handle, name, description, category, and any optional details like country, website, or Lightning address, plus any note you add for the reviewer. This is business information intended for publication, and approved entries become part of the public directory.

The submit form requires an email address. We store it for up to 90 days and use it once, to tell you the outcome of your submission, whether it was listed or not. If the listing is accepted that message includes the verified-bitcoin badge for your shop. The address is deleted as soon as that message is sent, and it is never added to any mailing list. Operator-added listings (not submitted through the form) may have no address.

We do not store your IP address with the submission. Rejected submissions are kept briefly for audit and then expire.

Once a merchant is listed, a nightly job records whether their public shop and profile still resolve (gm:vendor:signals), queues changes for the operator (gm:vendor:review-queue, gm:vendor:review-notified), and may mark a quiet Nostr merchant dormant (vendor:dormant:*). A daily drip also records which public handles have already been drafted a badge DM for the operator to send (gm:badge-outreach:v2), so the same shop is not messaged twice, plus a short-lived flag for the public badge-launch post (gm:badge-launch:v1). Those records are keyed by the merchant's public handle, never by a visitor, and they never write the public verified-at date.

The form may be protected by Cloudflare Turnstile, a privacy-focused captcha, to keep out automated spam.

IP addresses

Some endpoints are rate-limited to keep floods and abuse from running up costs. That works by incrementing a short-lived counter keyed to your IP, which expires on its own within the rate-limit window. We do not log request histories against it, build profiles from it, or use it for analytics.

Data stored on your own device

Game saves, streaks, dismissed banners, and similar preferences live in your browser's local storage. They stay on your device unless you have linked X and enabled save sync, described above. Clearing your browser data clears them.

Arcade leaderboards are different: when you post a score, we store the culture handle you typed (or your linked X identity) and that score in a capped public board. That is how a leaderboard works. Unlinking X deletes the stored profile; an anonymous row stays until the board expires.

Who else touches the data

The full list of processors, and nothing beyond it: Vercel (hosting, analytics), Upstash (the key-value store holding the records above), Resend (email delivery), Cloudflare (captcha), and X (only if you choose to link an account).

Galaxy Mind never handles payments. We do not take orders, hold funds, or process transactions. When you buy from a merchant in the directory, that happens entirely between you and them. We have no payment details to lose.

Deleting your data

Email: unsubscribe from any message or at /prefs. Push: turn the toggle off. X identity and game saves: unlink in the arcade.

For anything else, or if you want confirmation that something is gone, message @GalaxyMind on X or on Nostr. It is one person reading them, so it will not be instant, but it will be honest.

Children

Galaxy Mind is not directed at children and we do not knowingly collect data from anyone under 13.

Changes

If this policy changes materially, the date below changes with it. There is no version where we quietly start collecting more than this page describes.

Last updated August 23, 2026