1. Information processed in the browser
- Connected public wallet address, current chain, direct ENS name, ENS node, Registry/Name Wrapper ownership path, and wrapped-name expiry.
- A readable activation message and signature, terms/privacy versions, tier/profile, issue and expiry times, and a short-lived session record.
- The remembered club label, Money Machine plans, forecasts, lead files, proof-run records, drafts, and event history that you choose to store locally.
These records normally remain in sessionStorage, localStorage, IndexedDB, downloaded files, or browser memory on your device. Clear site data or use the reset/end-session controls to remove them.
2. Public blockchain data
Ethereum addresses, ENS names, ownership, transfers, expiry, resolver records, and transactions are public blockchain information. The site reads them to verify membership and display state. Blockchain data is not controlled or erasable by the Publisher.
3. Hosting and third parties
GitHub Pages, IPFS gateways/pinners, network providers, browsers, MetaMask, Ethereum RPC providers, email clients, and linked services may process IP addresses, device/browser details, requested resources, timing, diagnostics, wallet requests, and other technical data under their own policies. The Publisher does not control all third-party processing.
4. Optional high-touch request
The execution-request tool does not transmit information automatically. If you choose to download, email, publish, or otherwise send a request, the selected information leaves your device through the channel you choose. Do not include sensitive personal or customer data in the public/static tool.
5. Purposes and legal basis
Local processing supports authentication, security, entitlement, product operation, user-requested exports, fraud prevention, and legal acceptance. Any future off-device collection must identify its purposes, lawful basis, recipients, retention, safeguards, and choices before collection.
6. Data minimization and retention
The static application collects no central member database by default. Browser sessions expire after the configured period; local plans remain until you delete them. Operators adding forms, analytics, support systems, or hosting logs must adopt documented retention and deletion schedules and collect only what is necessary.
7. Consent and choices
Activation requires express agreement to the current legal versions. Optional contact and marketing consent must be separate. You may decline optional fields, end the session, clear local data, or refrain from sending any export. Withdrawal does not erase public blockchain/IPFS data or records lawfully retained for legal/security purposes.
8. Safeguards and incidents
Use secure devices, current software, phishing-resistant operational procedures, and appropriate organizational controls. An operator collecting personal information must maintain safeguards, incident response, breach records, and legally required notifications appropriate to sensitivity and applicable law.
9. Access, correction, portability, and complaints
For information actually controlled by the operator, applicable privacy law may grant access, correction, withdrawal, deletion, portability, and complaint rights subject to exceptions. Browser-local data can be exported or deleted directly by the user. Requests may be sent to the privacy contact below.
10. Privacy contact
Privacy lead / responsible person: the person designated by the operating entity. Public contact: secretariat@montreal.ai. Before production, the operator must publish the responsible person’s title and appropriate coordinates and complete a privacy-impact and cross-border assessment where required.