Privacy Policy version · September 10, 2026 · Version 2026-09-10
Privacy Policy
Brigid Forge LLC, a New Hampshire limited liability company based in Pelham, New Hampshire, operates Brigid Herald and is responsible for the personal information described in this policy.
Defined roles: A “Client” is a person or organization that requests or purchases Provider Services through Herald. A “Provider” is a person or organization that offers or performs those services. A user may act in either or both roles. This is a non-substantive terminology clarification and does not change any accepted right, obligation, fee, or deadline. Other capitalized terms have the meanings stated in the Terms of Service.
1. Scope
This policy applies to Herald’s websites, accounts, provider marketplace, bookings, messages, payment coordination, moderation, support, and related communications. Stripe and other third parties may separately control information they collect under their own notices.
2. Information we collect
Depending on how you use Herald, we collect:
- Identifiers and account data: name, login email, optional contact information, account identifiers, role, age-eligibility attestation, authentication status, avatar, workspace membership, and preferences. Herald does not request country during general account creation. When applicable, payment or payout country is collected or received during Stripe checkout or provider payout setup.
- Provider and project data: biographies, handles, services, pricing, audience metrics, platforms, chains, languages, regions, work samples, availability, verification evidence, project descriptions, websites, contract addresses, social links, applications, and moderation status. For connected X accounts, limited samples of public likes, reposts, replies, or quotes may be used to measure whether visible engagement is broad or concentrated. Herald converts participant account identifiers into one-way fingerprints and does not retain participant usernames, names, or post text in this analysis.
- Booking and commercial data: requests, offers, frozen terms, deliverables, dates, proof requirements, attachments, scheduled deliveries, fees, status history, cancellations, reviews, ratings, and dispute evidence.
- Project-token terms: chain and network, token mint or contract address, symbol and decimals, provider receiving wallet, quote source, liquidity and market inputs, USD price, agreement-time FMV, quote and acceptance timestamps, frozen gross and provider-net token quantities, checkpoint allocation, transaction hash or signature, confirmation and verification result, and any reported transfer problem.
- Communications: messages, attachments, support communications, reports, notification preferences, delivery events, and administrative access reasons.
- Payment and fraud data: Stripe customer, account, Checkout, Payment Intent, payment-method type, refund, transfer, reversal, and dispute identifiers; payment status; limited card fingerprints when a card or card wallet is used; Stripe-provided stablecoin network, wallet-transaction, or refund-reference details when applicable; fraud signals; and fee and reconciliation records. Herald does not receive complete card or bank-account numbers and does not receive crypto private keys or seed phrases.
- Wallet and blockchain data: optional and booking-required public wallet addresses, signatures, token balances, verification timestamps, public blockchain results, and BRIGID visibility eligibility. Herald never needs a seed phrase or private key.
- Technical and security data: IP address and approximate location derived from it, browser and device information, timestamps, authentication and security events, request logs, rate-limit records, and system audit data.
- Inferences and risk signals: account-integrity signals, linked-account indicators, repeated payment or transaction references, market-data anomalies, public-engagement concentration summaries, reputation summaries, moderation flags, and operational alerts. Material adverse marketplace actions receive human review.
3. Sources
We obtain information directly from you; from clients, providers, and workspace members involved in a booking; from Stripe and our service providers; from Jupiter, DEX Screener, public blockchain nodes, explorers, token contracts, and other public market or chain sources used for project-token quoting and verification; from public social profiles and public interactions; from devices and browsers; and from moderators, support personnel, fraud tools, or users who submit reports.
4. How and why we use information
We use information to create and secure accounts; publish approved listings; match projects and providers; operate conversations, opportunities, bookings, deliveries, reviews, and disputes; calculate and freeze project-token quantities and USD-denominated fees; verify wallet destinations and on-chain transfers; process and reconcile Stripe payments and provider payouts; verify providers and optional wallet eligibility; send transactional and requested notifications; detect fraud, manipulation, duplicate transaction identifiers, and abuse; enforce policies; preserve evidence; comply with law, tax, sanctions, and payment-network obligations; defend legal claims; and improve reliability and user experience.
Where a law requires a stated legal basis, we process information to perform contracts, comply with legal obligations, pursue legitimate interests in operating and protecting the marketplace, protect users and the public, and—withdrawing being available where required—based on consent for optional activities.
5. How information is disclosed
Approved profile information is visible to signed-in members, with limited featured previews available publicly. Booking parties and authorized workspace members can view the records assigned to them. Administrators may access information for vetting, support, security, fraud, disputes, legal compliance, and rights requests; sensitive transcript access is logged.
We disclose information as needed to service providers including Supabase, Stripe, hosting and infrastructure providers, transactional email providers, Google Workspace, security vendors, professional advisers, auditors, insurers, and authorities. We may disclose information in a merger, financing, reorganization, sale, or transfer, subject to appropriate protections. We may disclose information when reasonably necessary to comply with law, enforce agreements, protect rights or safety, or investigate fraud.
6. Sale, sharing, advertising, and analytics
Herald does not sell personal information for money and does not share personal information for cross-context behavioral advertising. Herald currently does not use third-party behavioral advertising or advertising cookies. If that changes, this policy and required choices will be updated before the new use begins. Essential browser storage is used to maintain authentication, security, interface state, and unsent form drafts.
7. Public information and blockchains
Provider listings, reviews, project opportunities, and information you intentionally publish may be copied or indexed by others. Public wallet addresses, token contracts or mints, transaction hashes or signatures, transferred quantities, timestamps, confirmations, and other blockchain information are independently available and cannot be deleted from the blockchain by Herald. Removing a wallet or booking record from public view does not erase public-chain history.
8. Retention
We retain information only as reasonably necessary for the purposes above. Account and active listing information is generally kept while the account is active. Non-transactional account content may be deleted or anonymized after an approved deletion request, subject to backups and legal exceptions. Booking, project-token quote, token quantity, wallet destination, on-chain transfer, transaction identifier, verification, payment, fee, tax, message, attachment, review, moderation, fraud, dispute, and audit records may be retained for up to seven years after the relevant transaction or longer when required for an active claim, chargeback, legal hold, tax obligation, sanctions review, or law-enforcement request. Public-chain data remains on the applicable blockchain independently of Herald. Security and operational logs are generally retained for up to two years unless needed for an investigation. Wallet-verification records may be retained while eligibility is active and for up to two years afterward to prevent abuse. Backups expire under their scheduled retention cycle.
9. Your choices and rights
You can update account, profile, and notification information in Settings. You can download available account data and request access, correction, deletion, or anonymization. Depending on your location, you may also have rights to portability, objection, restriction, appeal, opt out of sale or sharing, limit certain sensitive-information uses, and receive equal service when exercising rights.
Submit a request through Settings or email [email protected]. We may verify identity and authority before acting. An authorized agent may submit a request where applicable, but we may require proof of authorization and direct identity confirmation. If a request is denied, you may appeal by replying with “Privacy Appeal.” Active bookings and disputes must be resolved first, and information required for payments, taxes, security, fraud prevention, legal claims, or compliance may be restricted or anonymized instead of erased.
10. Security and incident response
Herald uses encrypted transport, row-level authorization, private attachment storage, signed links, MFA-protected administrative actions, access logging, webhook signatures, rate limits, access-controlled backups, and payment-provider controls. No online system is completely secure. Do not send passwords, seed phrases, private keys, or unnecessary sensitive information. We investigate suspected incidents and provide legally required notices.
11. International processing
Brigid Forge is based in the United States. Clients and providers may use Herald from countries and regions where the applicable Stripe payment or payout service is available and participation is lawful. Information may be processed in the United States and other countries where users and service providers operate. Those countries may have different privacy laws. Where required, we use approved contractual or legal transfer mechanisms.
12. Children
Herald is not intended for anyone under 18, and we do not knowingly permit minors to create accounts. Contact us if you believe a minor provided personal information.
13. Automated processing
Herald uses rules and signals to identify possible fraud, summarize public audience and engagement patterns, prioritize operational review, calculate reputation summaries, and enforce technical controls. Engagement concentration evidence is not a declaration that an audience is fake and does not independently determine provider approval, visibility, delivery acceptance, or payment. These signals do not independently make legal or similarly significant decisions. Administrators review material moderation, dispute, and account decisions. You may contact support to contest a decision.
14. Changes
We may update this policy as Herald, service providers, and legal requirements evolve. Material changes will receive a new version and appropriate notice. We will request acknowledgment or consent where legally required.
15. Contact
Brigid Forge LLC, Pelham, New Hampshire, United States. Privacy requests: [email protected]. General support: [email protected].
