Privacy and storage notice
What the application processes, where browser preferences live and what is shared with service providers.
Last updated October 5, 2026. This policy is currently provided in English.
Operator and scope
Axiom Risk Group LLC operates The Book of Blocks. Contact info@axiomriskgroup.com about personal information, account access, corrections or deletion requests. This notice describes the application and its current service integrations; external websites and providers also publish their own notices.
Information you provide
An account uses an email address and authentication information through Supabase Auth, together with a profile and account permissions. The community workspace processes drafts, uploaded media, project claims, leadership evidence, review decisions, publication requests and support reports. Approved stories, contributor names, disclosures and approved public project profiles are displayed publicly; unpublished account records and drafts have separate access controls.
If you use a paid service, order records include the product and exact project, public payer and receiver wallet addresses, amount, transaction signature, status, review history and refund information. Solana transactions and their public memos are visible on the blockchain and cannot be erased by deleting a website account. Do not put personal information or secrets in a transfer memo.
Guide and classroom questions
The guide processes your question and recent conversation context to retrieve sources and prepare a reply. When the optional model service is configured and used, the application sends the question, recent messages and relevant retrieved material to OpenRouter and its selected model provider. The request asks for a route that denies data collection and supports zero data retention; this is a routing setting, not a promise that every infrastructure log, saved classroom or provider record is erased.
Guest conversations remain in the current page session, while signed-in confirmed accounts can save private classrooms in Supabase and delete those saved chats in the classroom. Guest requests use an opaque cookie and a daily keyed network identifier for question limits and abuse prevention; account requests also use the account identity. Provider and hosting systems may process request metadata. Do not use the classroom for sensitive or confidential information.
Cookies and device storage
Authentication and guest allowance use cookies. Local storage keeps theme, reading and logo animation preferences, a device watchlist and lesson progress. These device preferences are not an account-wide cloud backup. Clearing browser storage or blocking cookies can remove preferences, sign you out or affect classroom allowances. These features use storage to operate the requested service; third-party and hosting request processing also applies as described below.
Providers and requests
The deployed application uses Vercel for the frontend, Supabase for authentication, database, storage and realtime connections, and a Railway-hosted market worker. Configured email delivery providers handle account messages. OpenRouter and the selected model provider receive the AI inputs described above when that optional route is used. If MoonPay Commerce is offered for an order, its own service and privacy terms apply to the information it requests; it is not required for every supported wallet transfer.
Browser market connections can contact Binance, and wallet or explorer links open the provider you choose. The Dev Autographs contribution overlay loads the public report and can query its Railway-hosted registry to verify public signer records. Those requests expose normal network metadata such as your IP address to the receiving provider. Clicking source, project, social or portfolio links also connects you to external sites. Market and research suppliers provide information under their own terms.
The publication workflow can send approved article text to Microsoft Azure Translator to prepare cached translations. Reader language selections do not send classroom prompts to that translation service. Read-aloud uses your browser or operating system's speech-synthesis service; the voice you select may process the reading text through that provider.
Why information is used
Information is used to provide accounts, classroom replies and storage, assess and publish authorized contributions, verify and reconcile orders and refunds, operate market and research services, answer support requests and prevent abuse. Where applicable privacy law requires a legal basis, these activities rely on performing requested services, legitimate operational and security interests, legal obligations or consent where required. Public project submissions and blockchain transactions can reveal information beyond the account interface.
Retention, access and requests
We keep information as needed for the requested service, account administration, payment and refund records, abuse investigations and applicable legal obligations. There is no single retention period asserted for every record. Deleting a classroom removes its application record; backups, security records, public publications and legal or payment records may require separate handling. Blockchain records and third-party copies are outside our deletion control.
You can clear local browser preferences and delete saved classrooms through the available controls. Email info@axiomriskgroup.com to request access, correction, account deletion or other rights available under applicable law. We may need to verify that a request concerns your account before acting. Information may be processed in countries where our providers operate, including the United States; applicable transfer requirements and statutory rights still apply.
Access controls and transport protections reduce risk but do not make storage or transmission risk-free. Do not email passwords, confirmation links, private keys or recovery phrases. This notice will be updated when the service's processing materially changes.