{"position":"No funds, no keys, no positions. What is stored is keyed to your address and listed below, table by table.","stored":[{"table":"users","what":"your address, the chain you signed in from, which wallet you used, an optional display name, first and last seen","why":"an address is the only account identifier there is; the wallet name is what lets the header say which wallet you used","readableBy":"anyone_with_the_database","retention":"until the account is deleted"},{"table":"sessions","what":"a SHA-256 hash of the session token, its expiry, your browser's user-agent, and a two-letter country code","why":"the hash lets a cookie be checked without the token being readable from the table; the country and user-agent are what lets you recognise a session as yours","readableBy":"anyone_with_the_database","retention":"thirty days"},{"table":"auth_nonces","what":"the sign-in message and its single-use nonce","why":"the server composes the message so the browser cannot substitute another domain; the nonce is burned before the signature is checked, so a replay finds nothing","readableBy":"anyone_with_the_database","retention":"minutes"},{"table":"watchlist","what":"the pools you starred","why":"the dashboard's first tab","readableBy":"anyone_with_the_database","retention":"until you unstar them"},{"table":"alerts","what":"the pool, the threshold, your webhook URL and its signing secret","why":"a webhook cannot be called without its URL, and the secret is what lets your receiver check the call came from here","readableBy":"anyone_with_the_database","retention":"until you delete it"},{"table":"alert_deliveries","what":"each webhook call: pool, horizon, status code, error text","why":"so a delivery that failed is visible to you rather than silently dropped","readableBy":"anyone_with_the_database","retention":"kept"},{"table":"api_keys","what":"a SHA-256 hash of each key, its first characters, its name, a request count, last used, revoked","why":"the hash lets a key be checked without being readable; revoked keys stay so the audit trail does","readableBy":"anyone_with_the_database","retention":"kept"},{"table":"api_key_usage","what":"how many requests each key made per UTC day","why":"it is the figure a metered read would bill from, and the /usage page","readableBy":"anyone_with_the_database","retention":"kept"},{"table":"checkpoints","what":"your address as submitter of a checkpoint","why":"off-chain a checkpoint carries no storage proof, so who submitted it is the only provenance it has","readableBy":"anyone_with_the_database","retention":"kept"},{"table":"challenges","what":"your address as opener of a challenge","why":"a record only its author can audit is not a record — the opener is part of what is published","readableBy":"anyone_with_the_database","retention":"kept"},{"table":"ingest_runs","what":"your address as the key that started a run","why":"the /runs page attributes each run to the key that started it","readableBy":"anyone_with_the_database","retention":"kept"},{"table":"liquidity_requests","what":"your address as the key that posted a request","why":"provenance — an ask nobody made must not read as sourced","readableBy":"anyone_with_the_database","retention":"kept"}],"neverStored":[{"what":"a private key, a seed phrase, or a signature that can move funds","because":"impossible by construction — sign-in is a plain-text signature, a swap is signed by your wallet against Uniswap's router"},{"what":"your balances, holdings, positions or trades","because":"decided against — the swap panel reads one balance to check you hold enough, and keeps nothing"},{"what":"the swap quotes you ask for, or the address you ask them from","because":"decided against — answered from the chain, no table for it"},{"what":"your conversations with the assistant","because":"decided against — each request carries its own turns; nothing is written back"},{"what":"your IP address","because":"decided against at this layer — only a country code, on the session row; see the edge note"},{"what":"an email, a phone number, a name","because":"there is no field for one"}],"thirdParties":[{"name":"Anthropic","sees":"the assistant conversation. Not your address: the model is not told who is asking, though a tool result can carry whether a pool is on your watchlist.","when":"only while you use /assistant"},{"name":"Uniswap's router and the pools it routes through","sees":"the swap, on chain, from your address","when":"only when you sign a swap"},{"name":"The wallet you connect","sees":"an address, a text signature, and — for a swap — a transaction you approve","when":"on sign-in and on a swap"},{"name":"Your webhook receiver","sees":"the alert payload you configured it to receive","when":"when an alert fires"}],"swap":{"request":"Two tokens, an amount, and your address so the calldata can name you as recipient. Answered, not stored.","counterparty":"The approval is to Uniswap's router, never to Cleaton, for exactly this amount. Wallet → router → wallet; Cleaton is not a party and cannot redirect it.","afterwards":"The swap is public on chain, like any swap. Cleaton reads pools, not addresses; a block explorer attributes it to you, as it does every trade."},"edge":"Cleaton runs on Cloudflare Workers. The edge sees what every edge sees — your IP address, your requests — under Cloudflare's terms. This covers what Cleaton's code stores, not the layer beneath it.","note":"Every row names a table in the migrations; a test fails if a reader-keyed table exists that is not listed here."}