Request metadata
IP-derived rate-limit fingerprints and API key actor labels are processed server-side only. They are not joined to wallet addresses.
Pre-production placeholder. Will be replaced with counsel-reviewed language before public launch. The posture below describes how the product is currently architected.
IP-derived rate-limit fingerprints and API key actor labels are processed server-side only. They are not joined to wallet addresses.
NFT metadata, images, and traits hydrate from on-chain providers (Helius DAS) and are cached in our backend stores. Origin URLs are signed and proxied to prevent leaks.
Trading and team-console flows process public wallet addresses and signed actions only. We do not record private keys, signatures, or seed phrases — anywhere.
No third-party trackers. No advertising cookies. A single first-party session cookie holds CSRF state for trading actions.
Self-custody is the floor. We don't collect what we don't need. Email security@bidside.io for any data deletion or audit request.