Privacy
Last updated
In short
- You can read all of HEY without an account, a wallet or an email address.
- HEY counts page views with its own first-party beacon: no advertising or analytics cookie, no third-party analytics script, and nothing recorded under Do Not Track or Global Privacy Control.
- Wallet sign-in signs a message only. It sends no transaction and grants no approval.
- A $HEY holder check keeps the decision, not the balance.
- Your IP address reaches HEY’s raw server log, kept for at most two days. HEY’s own tables keep only hashed digests of it, never the address.
- HEY does not sell personal data.
See also the Terms.
This page covers HEY Research Lab at heyresearch.xyz: the website, the Research Terminal, the public API, the hosted MCP server and HEY’s Telegram bot and email. It describes what the code running the site does today.
When you read the site
The site is served through Cloudflare, which handles every request before it reaches HEY’s server. HEY’s web server then writes an access log: each request’s time, address, URL, status, browser and the page you came from. Credentials are removed before a line is written (API keys, the Telegram webhook secret, cookies, authorization headers, and the tokens in email-confirmation, unsubscribe, private-feed and GitHub sign-in addresses). The raw log is deleted after at most 48 hours.
Before that, HEY folds it into hourly counts by route, status and kind of browser or crawler, and a daily list of pages that were not found. Those tables hold no IP address and no browser string.
The application’s own logs record a request’s route, status and timing, not who made it. Rate limits, which stop one caller from overloading the site, count requests per address in the server’s memory and write nothing.
First-party analytics
On each page, a small script sends HEY a page view: the path, the host of the page you came from, any utm_ campaign labels in the address, a random id for the tab and whether this browser has visited before. The Research Terminal sends the same. A few controls also report, by name only, that they were used: a source, share, copy or related link on a project page, a Uniswap link, a step in a wallet flow. No address, amount or text you typed goes with them.
The server stores the path, the referring host (never the full address), the kind of device, the browser family, the country Cloudflare reports, and the campaign labels. It also stores two digests:
- a visitor digest, from a server secret, the day, your IP address and your browser string, which changes every day;
- a session digest of the tab id and the day.
Neither can be turned back into an address, and neither links one day to the next. Your IP address and browser string are not stored.
If your browser sends Do Not Track or Global Privacy Control, the page-view beacon records nothing. Known crawlers and HEY’s own traffic are not counted either.
Some product events are recorded by the server itself, not the beacon: a search (its words, lower-cased and trimmed, but never a contract address), a scan, a page not found. Under Do Not Track or Global Privacy Control these are still counted, but without the visitor digest.
Accounts and sign-in
An account is optional. It lets you follow projects, get alerts, claim a project, use an API key or use the Research Terminal.
- Wallet sign-in asks you to sign a standard sign-in message (ERC-4361) that says it moves no funds and grants no approval. It sends no transaction. HEY stores the address, a hash of the signature and a display name made from the shortened address.
- GitHub sign-in asks GitHub for your public profile only (
read:user). It asks for organisation membership (read:org) only while you are proving you own a project’s GitHub organisation. HEY stores your GitHub id, login, name, account creation date and public repository count. It does not ask for your email, and it never stores GitHub’s access token. - Sessions. A sign-in is recorded as a row with its method, start, expiry and last use. It holds no address and no browser details. Sessions last 30 days, and an ended session’s row is deleted 30 days later.
- HEY staff sign in to the console with an email address and a password, stored only as a salted hash.
What you keep in an account — followed projects, alerts, research boards, notes — is private to it unless you share it.
Linked wallets and $HEY checks
You can link one wallet to your account by signing a message. HEY keeps the address, a hash of the signature and when it was linked. An address belongs to one account at a time.
When HEY checks your linked wallet for a holding tier or for Research Terminal access, it reads the $HEY balance from the chain, decides, and keeps only the decision: the tier, whether the Terminal minimum was met, and the $HEY price and minimum it used. The balance, and any dollar value worked out from it, are not stored.
The one exception is the advisory funding vote: if you cast a ballot, HEY reads your linked wallet’s $HEY balance once at the closing block and stores it as that ballot’s weight. The ballot asks for that consent before it is cast.
If you pay for something in $HEY or another token, or put up a bond, your wallet sends the transfer. HEY records the transaction’s hash, the address it came from, the amount and what it was for. All of these are already public on the chain.
HEY has your email address only if you add one on the Watchlist. It then sends one confirmation link, valid for 24 hours, and nothing else until you confirm. After that it sends only the kinds you leave on: a claim verified, research you asked for, bounty payouts, alerts (at most one email an hour) and the weekly digest (off unless you turn it on).
Email is sent through Resend, which receives your address and the message. Every email has a one-click unsubscribe link that works without signing in. You can remove your address at any time. HEY adds no open or click tracking.
Telegram
If you link HEY’s Telegram bot to your account, HEY stores the chat id, your Telegram user id and when you linked it. It stores no message text, no username and no name. Telegram receives the messages the bot sends you, and your HEY display name when you confirm the link.
To unlink, use your account page, send /unlink to the bot, or block the bot. Each one deletes the link.
API, MCP and webhooks
For each call to the public API or the hosted MCP server, HEY records the route pattern (not the full address), the method, the status, the time taken and the response size. It also records the key and account, if a key was sent, and a digest of the caller that changes every day. Raw rows are kept for 90 days. An MCP client’s self-declared name and version are recorded too.
API keys are stored only as a hash. HEY shows a key once, when you create it.
A webhook stores the address you give it, its description, and the events and projects it follows. Its signing secret is derived when it is needed, not stored. Deliveries carry only the public change events /api/changes already serves, with no HEY credential. HEY keeps a delivery’s status and the first 256 bytes of your endpoint’s reply for 30 days.
What you submit
- Project submissions keep your account, what you entered, and a salted hash of your address for spam review.
- Claims keep the proof you chose: a DNS record, a file or meta tag on the site, GitHub administration, or a signature from the token’s launcher, owner or deployer. For a signature, HEY keeps the address and a hash of the signature.
- Owner updates and Scout research notes are published on the project’s page, labelled with how they were verified. A Scout handle is shown only if you choose one.
- Ask HEY questions are stored with your account. When the model layer is switched on, the question and HEY’s evidence lines for the project are sent to Anthropic to draft the answer. Nothing else about you is sent.
- Claim and submission attempts are counted against a salted hash of your address for 30 days, to stop abuse.
Who else receives data
Pages are rendered from HEY’s own database: showing you a page sends nothing about you to a data provider. These services do receive data:
- Cloudflare handles every request to the site.
- Project websites. Most logos load through HEY, but a logo on a host HEY does not proxy loads straight from the project’s own site, which then sees your request.
- GitHub, when you sign in with it.
- WalletConnect (Reown) and your wallet, when you open a wallet control or the sign-in page, and when you connect.
- A Robinhood Chain node, which HEY asks for the balance of a linked address, and to check a smart-account signature.
- Resend, for a confirmed email address.
- Telegram, when you link the bot.
- Anthropic, for an Ask HEY question, as above.
- Uniswap Labs, for an indicative quote. When a Research Terminal reader asks for a Uniswap quote, HEY sends Uniswap the token, the amount typed and a fixed placeholder in place of an address. Your address is never sent, and HEY stores no quote.
- Your own webhook endpoints, which receive public change events.
- Scans. A scan sends the contract address you entered to the chain, its explorer and the market and code sources HEY reads. It sends nothing about you.
Quotes are provided by the Uniswap Labs API. Using them is subject to Uniswap Labs’ Terms of Service and Privacy Policy. HEY sends Uniswap no reader address — every quote is asked with a fixed placeholder swapper — and stores no amount and no quote.
For Uniswap Labs’ own handling of the data, see its Privacy Policy. HEY does not sell, rent or trade personal data, and shows no advertising built on it.
How long HEY keeps it
- Raw web server log: at most 48 hours.
- Page views, product events and API request rows: 90 days. Daily and hourly totals built from them: 400 days.
- Sessions: 30 days, and the row 30 more days after it ends.
- Abuse counters for claims and submissions: 30 days.
- Webhook delivery records: 30 days.
- Your account and what you keep in it: until it is removed. Your email address: until you remove it.
Your choices
- Read without an account, a wallet or an email address.
- Turn on Do Not Track or Global Privacy Control, and the page-view beacon stops.
- On your account page: unlink your wallet or Telegram, revoke your API key, manage webhooks and sign out.
- Remove your email address, or switch off any kind of email, on the Watchlist or from any email’s unsubscribe link.
- Clear this site’s storage in your browser to remove everything listed under browser storage.
There is no self-serve way yet to remove an account entirely. To ask for that, or for a copy of what HEY holds about your account, write to [email protected].
Changes and contact
When this page changes, its date changes. The Terms cover using the site and its data. Questions: [email protected].