Privacy
Mystery stores the information required to run whitelist campaigns and explain scores.
What is collected
Email address, verification timestamps, public wallet addresses, ownership-verification records, and normalized public chain activity returned by infrastructure providers. One-time codes are stored only as hashes.
Why
Email verifies a contact point. The wallet address is the whitelist credential. Chain activity is the input to the score. Project admins can see applicant emails because they operate the campaign.
How analysis works
Public chain data is fetched server-side through replaceable providers. Portfolio figures include the price timestamp and source. Missing prices stay missing. NFT figures are estimates when a methodology exists, and otherwise say value unavailable.
Retention and deletion
You can request deletion from settings. Confirmation removes the email, sessions, and the account’s link to wallet records. Transactions that already exist on a public network are not deleted from that network. Audit logs may retain an internal actor id.
Optional product email is not sent unless a specific notice, such as whitelist eligibility, is part of the service you used. Applying does not subscribe you to a marketing list.