Loading…
Loading…
Ourolens is a market terminal for Cardano, operated by Lock Jaw Disc Golf at ourolens.com. This page describes what the product actually stores and sends, field by field, because a vague privacy policy is worth nothing to the person reading it.
Two things up front, because they change how the rest of this reads. Ourolens runs no analytics, no advertising and no third-party trackers, and sets no cookies. And Ourolens never has your private keys and never holds your funds — there is no Ourolens-controlled address anywhere in the product.
Your account identifier is the stake key hash of the first wallet that signed in. That is a public value that already exists on the Cardano blockchain. We do not ask for your name, your address, your date of birth or a phone number, and there is nowhere to enter them.
There are four ways to sign in, and each stores something different:
Signing in with a second wallet links it to the same account; it does not create a new identity for it.
This is the whole list. If a field is not here, the product does not keep it.
| Field | Why it exists |
|---|---|
| Stake key hash | Your account identifier. It is the Firebase uid — the account is the stake key. |
| Bech32 stake address | Used to look up balances and delegation, and to show you which wallet you are signed in as. |
| Network | Mainnet or a testnet, so data is never mixed between them. |
| Receive address (addr1…) | Optional, one per linked wallet. Only stored if you use a feature that has to deliver ADA to you, such as a MoonPay purchase. Accepted only when its stake credential is one this account has already proved. |
| Display name | Whatever you type. Optional. |
| Watchlist | The assets you star, up to 200. |
| Currency setting | The fiat currency prices are shown in. |
| Alert email | Where price alerts are sent, if you ask for email alerts. |
| Verified sign-in email | Set if you signed in with an email link. |
| DRep delegation | Copied from the chain, where it is already public, so the governance pages can show who you delegate to. |
| Expo and FCM push tokens | Device handles for push notifications. Only present if you turn push on. |
| Membership tier | Free or paid, and which. |
| Usage credit balance and ledger | An append-only list of credit entries, each referencing a Cardano transaction hash. It is the audit trail for your bill. |
| Price alerts | The conditions you set and whether they have fired. |
| In-app notifications | The messages shown in the bell menu. |
| Passkey public keys | Public keys only. A passkey's secret half never leaves your device and Ourolens could not read it if it tried. |
| On-ramp order records | Five fields per order: status, amount, currency, the provider's order id, and a timestamp. Nothing else. |
The purpose of all of it is the same: to run the account you asked us to create and the features you turned on — that is, to perform the service you requested. Alert email and push tokens exist only because you asked for alerts. The credit ledger exists because a bill has to be checkable. Where a legal basis is required by law, ours is performance of that contract with you, and our legitimate interest in keeping the service secure and working; for optional extras such as email or push alerts, it is your consent, which you withdraw by turning them off.
| Party | What they receive |
|---|---|
| Google (Firebase / Google Cloud) | Hosting, sign-in, the database, server functions, logging and push delivery. Google sees the IP address of every visitor, as any host does. |
| Koios | A public Cardano API. When your balance or delegation is looked up, your bech32 stake address is sent to Koios. |
| MoonPay | Only if you buy ADA. See the MoonPay section below. |
| DexHunter | The swap widget is DexHunter's own component rendered inside our page. It connects to your wallet and talks to DexHunter directly — your addresses, balances and orders go to DexHunter, not through Ourolens. |
| Expo push service | Delivers notifications to the mobile app if you enable them. |
| IPFS gateways | Five public gateways serve NFT images. Your browser fetches them directly. See below — this one is worth reading. |
| CoinGecko | One logo image is loaded from CoinGecko by your browser. |
| Exchanges and providers we link to | Ordinary outbound links. Following one puts you on their site under their policy. |
NFT images are stored on IPFS, and Ourolens does not proxy them. Your own browser fetches each image from one of five public gateways: ipfs.blockfrost.dev, ipfs.io, dweb.link, w3s.link, gateway.pinata.cloud.
That means the operator of a gateway sees your IP address, and which NFTs are in the wallet you are viewing, because the image requests identify them. It happens on the portfolio, collection and NFT pages. Ourolens has no control over what those operators log or how long they keep it, and none of it passes through us.
If that matters to you, a VPN changes what they see of your network, and not opening the NFT pages avoids it entirely. The same is true of the single CoinGecko logo request.
Buying ADA is optional and nothing here applies unless you use it. When you start a purchase, Ourolens sends MoonPay three things: the destination wallet address, the dollar amount, and a reference identifier. That is the entire handover.
MoonPay's widget runs in an iframe on ourolens.com, and that iframe is granted camera and microphone permission because MoonPay's identity-document capture needs them. It is easy to read that as Ourolens asking for your ID. It is not.
The identity check is MoonPay's. The photographs of your documents and your face, and your card or bank details, go to MoonPay. They never reach Ourolens, are never stored by Ourolens, and Ourolens cannot see them — not the images, not the form fields, not the messages the widget exchanges with MoonPay.
MoonPay performs all identity verification, processes all payments, and is the counterparty to your purchase. It sends us a webhook when the order changes state. We keep five fields from it — status, amount, currency, MoonPay's order id, and the time — and discard the rest of the payload. No identity data, no payment data, no raw body, in the database or in logs. Ourolens takes no commission on your purchase.
What MoonPay does with your data is governed by MoonPay's own privacy policy, and its record-keeping is driven by financial regulation we have no say in. The same applies to any provider or exchange you reach from cashing out ADA.
No cookies. No tracking identifiers. What the site does keep, locally on your device:
localStorage — your theme colour, and a web-push registration token if you enabled push.sessionStorage — a flag that stops the service worker reloading the page in a loop.IndexedDB — the Firebase SDK keeps your signed-in session and an offline cache of data you have already loaded.Clearing site data for ourolens.com removes all of it and signs you out. It does not delete your account — see below for that.
Everything above is visible and editable in account settings: your display name, currency, alert email, alerts, watchlist, linked wallets, passkeys and notification settings.
Account settings also has delete your account. It deletes the account and all data associated with it: the account record, your alerts, your notifications, your saved passkeys, your credit ledger and your order history. It is not a request queue and it is not reversible.
Two things deletion cannot reach, and it would be dishonest not to say so:
If you would rather ask a person than press a button, or you want a copy of your data, email [[TO CONFIRM: support@ourolens.com]]. Depending on where you live you may also have rights to access, correct, port, restrict or object to processing, and to complain to your local data protection authority.
Account data is kept while the account exists, and goes when you delete it. Operational records — sign-in challenges, link codes, delivered notifications, logs — expire automatically and are short-lived by design. The five-field on-ramp order records are kept for about two years, because they are financial records of a purchase that took place. Nothing here is kept in order to build a profile of you; there is no profile to build.
Secrets — API keys, the MoonPay signing key, webhook keys — live in Google Secret Manager and are never sent to the browser. Wallet sign-in is a cryptographic signature check against your stake key, verified on the server and then thrown away. No private key, seed phrase or passkey secret is ever stored, transmitted or requested by Ourolens, and any page that asks you for one is not us.
No system is perfect. If you find something wrong, tell us at [[TO CONFIRM: support@ourolens.com]] before telling anyone else, and we will fix it and say what happened.
Ourolens is not for anyone under 18. We do not knowingly create accounts for under-18s. If you believe a child has an account here, email [[TO CONFIRM: support@ourolens.com]] and it will be deleted.
Ourolens runs on Google Cloud in the us-central1 region, in the United States. If you are outside the United States, using the site means your account data is stored there. The third parties listed above operate their own infrastructure in their own regions.
When this page changes, the date at the top changes with it. If a change is material — a new third party, a new category of data, a new purpose — it will be announced on the site before it takes effect, not slipped in. The concrete list above is the promise; keeping it accurate is the work.
Ourolens is operated by Lock Jaw Disc Golf, [[TO CONFIRM: legal entity name, suffix and jurisdiction of incorporation]], [[TO CONFIRM: registered address]]. Data protection questions, deletion help, or anything on this page: [[TO CONFIRM: support@ourolens.com]].