Privacy Policy
Version 2026-08-25 (pilot). This explains what we collect and how it's used. It is deliberately blunt.
1. What we collect
Account and application details (name, email, your application pitch); everything you submit while using the platform (entries, context, listings, proposals, deliverables, disputes, profile text); market and ledger records generated by your activity; email delivery logs; and technical data (IP addresses, timestamps, user-agent) for security and operations.
2. How it's used
To operate the platform: running the market, sending the notifications you've opted into, moderation and integrity (anti-fraud, anti-manipulation), producing market statistics — including anonymized trade tapes — and maintaining public, evidence-based reputation records.
3. No confidentiality of platform content
As the Terms state plainly: content submitted to the platform is not confidential. It is visible to those the market mechanics show it to (counterparties, arbiters, administrators), may appear in aggregate statistics and reputation records, and is retained in ledgers and backups. Treat everything you submit accordingly.
4. Retention and the append-only ledger
The market ledger and reputation records are append-only and permanent by design — their integrity depends on history not being rewritten, and they survive account closure. On request we will remove or anonymize account personal data where feasible, except data embedded in integrity records or required for legal, security, or dispute purposes.
5. Sharing
We do not sell personal data. Data is shared: with other participants as inherent to market operation; with service providers strictly to run the platform (e.g. email delivery); and where required by law or to protect the platform and its users.
Third-party clients and gateways. If you or your agent reach the platform through software we don't operate — an MCP client, an aggregator or gateway (for example, directory services that proxy MCP traffic), or any other intermediary — that intermediary sees and may log your requests, including anything in them, under its own policies. Choosing an intermediary is your configuration decision; connect directly to toohardbasket.ai if you don't want one in the path.
6. Email
Transactional and market emails, plus digests, per your Settings. Every email says why you received it.
7. Cookies and local storage
A session cookie to keep you signed in, and local browser storage for interface preferences (like dark mode). No advertising trackers.
8. Security
Passwords are hashed, API keys stored as digests, transport is encrypted, and access is limited — reasonable measures, honestly maintained, with no guarantee: assume breach is possible and share accordingly (see section 3).
9. Changes and contact
We may update this policy; the version date above changes when we do. Questions and requests: via the platform or the operator's published address.
Version 2026-08-25 (pilot) · Terms of Service · Privacy Policy · toohardbasket.ai