Scope
This policy covers the Brc Exchange website, its APIs, and the data handled by them. It does not cover the blockchains themselves, your wallet software, or any third-party site you reach through a link — those are outside our control and governed by their own rules.
What we do not collect
We do not ask for, collect, or store:
- your name, email address, phone number, or postal address;
- government identification or any KYC documentation;
- date of birth, photographs, or biometric data;
- payment card or bank details;
- your seed phrase or private keys — under any circumstances, ever;
- any off-chain profile linking you to a real-world identity.
There is no account to register, no password to store, and no login to breach. We also do not run third-party advertising networks or cross-site behavioural tracking.
Wallet address
When you connect a wallet, the interface reads your public address in order to display your balances, positions, and history, and to prepare transactions for you to sign. A wallet address is a public identifier, not an identity, and we do not attempt to link it to a real-world person or to any off-chain data.
Connecting a wallet is not authenticated by a signature, so any record of a connection shows that an address was used from a browser — it is not proof that the owner of that address did so.
On-chain data is public and permanent
Blockchains are public by design. Your address, every transaction you send, every token you hold, every liquidity position you open, every bridge transfer and every market fill are recorded on public ledgers that anyone can read and that no one can edit or erase. This includes data displayed here, and it exists whether or not you ever use this interface.
We cannot delete, mask, or anonymise on-chain records, and neither can you. Anyone able to associate your address with your identity — for example through an exchange withdrawal or a public post — can then see your full on-chain history.
Server-side indexing of public activity
To show order books and trade history without hammering the chain, our servers index public on-chain events from the protocol contracts — offers, fills, claims, and transfers — keyed by the public addresses involved. This is a cache of data that is already public on the blockchain; it contains no off-chain personal information and is not combined with anything that could identify you.
RPC proxy
The interface talks to the Arc and Base networks through a same-origin proxy on our servers, so that upstream API keys never reach your browser. Requests passing through the proxy necessarily expose to our infrastructure the same things any RPC provider would see: your IP address, the addresses being queried, and the transactions being broadcast. Proxy logs are kept for security and debugging only and are not used to build profiles.
Data stored in your browser
The interface keeps a small amount of data in your browser's local storage. It stays on your device, is not sent to us as a profile, and can be removed at any time by clearing site data for this domain. It includes:
- which wallet you last connected, so the session can be restored;
- connection state used by the wallet-connection library;
- in-progress bridge jobs, so a transfer interrupted mid-flow can be resumed from where it stopped;
- any token contracts you imported manually into the swap list;
- interface preferences such as slippage settings or dismissed notices.
Clearing this data disconnects the interface and forgets resumable jobs. It never affects your funds — an interrupted bridge transfer can still be completed manually, because the attestation lives with Circle, not in your browser.
Cookies
The interface does not set advertising or analytics cookies. Any storage used is the local storage described above, which is required for the interface to function as expected rather than used to track you across sites.
Server logs
Our hosting and web servers may record standard technical information for each request — such as IP address, timestamp, requested path, response status, and browser and operating system strings. These logs exist for security, abuse prevention, and debugging. They are not used to build user profiles and are not combined with wallet addresses to identify individuals.
The relayer and keeper
The bridge relayer and the market keeper are services we run to submit certain transactions on your behalf (the final mint on Arc; offer reservations and claim relays). To do their job they necessarily process the public addresses and amounts involved in your transfers. They hold no personal data, cannot access your funds, and their operational logs are retained only as long as useful for security and debugging.
Third-party services
Some functions rely on third parties, each governed by its own privacy policy:
- Hosting and networking — serves the website and may log standard request data as described above.
- Wallet providers and connection libraries — your wallet extension or mobile app connects from your own device; some connection methods relay data through their own relay servers.
- Circle's APIs — Gateway balance and transfer requests and CCTP attestation lookups include the public addresses and transaction hashes involved.
- Blockchain RPC providers — upstream endpoints behind our proxy see the chain queries the proxy forwards.
- Block explorers — opened only when you click a link; from that point their policy applies.
We do not sell, rent, or trade your data to anyone, and we do not share it for advertising.
How we use data
Data handled by the interface is used only to:
- display market data, balances, quotes, order books, and history;
- prepare transactions for you to sign, and relay the ones we relay;
- keep the service available, performant, and secure;
- detect and mitigate abuse, spam, and attacks;
- understand aggregate usage in order to improve the interface.
We do not use it for profiling, credit scoring, or automated decisions about you.
Retention
Indexed on-chain activity is kept for as long as the interface operates, since its purpose is to show history. Server and proxy logs are kept only as long as useful for security and debugging. Browser storage is kept until you clear it. On-chain data is permanent and outside our control.
Security
We take reasonable measures to protect the systems we run, including transport encryption, server-side key storage for the relayer and keeper, and restricted administrative access. No system is perfectly secure. Because we never hold user funds or keys, a compromise of our systems could affect displayed data or site availability, but it cannot move your assets — escrow release in the market requires guardian-signed proofs no server of ours can forge.
Your choices and rights
You can at any time:
- disconnect your wallet;
- clear your browser's local storage for this site;
- use the interface without connecting a wallet, in read-only mode;
- use a different address to separate activity;
- stop using the interface entirely.
Depending on where you live, you may have rights to access, correct, or delete personal data held about you. Because we hold almost none, such a request would generally concern only server logs — contact us and we will address what is technically within our control. Requests to alter or erase blockchain records cannot be fulfilled by anyone.
Children
The interface is not intended for anyone below the legal age in their jurisdiction, and we do not knowingly collect data from children.
International transfers
The interface is served from infrastructure that may be located outside your country, and third-party providers may process requests in other jurisdictions. By using the interface you accept that technical data necessary to serve it may be processed in those locations.
Changes to this policy
We may update this policy. The "last updated" date at the top reflects the current version. Continued use of the interface after an update means you accept it.
Contact
Privacy questions can be sent to the project on X at @BRC_Exchange.