Cookie notice
Cookie notice
1. In brief
This site sets four cookies, all strictly necessary: one that keeps you signed in, and three that exist for the ten minutes it takes to connect an X account and are deleted the moment it finishes. There is no analytics cookie, no advertising cookie and no third-party cookie — nothing sets a cookie here except this site, and nothing we set is used to follow you. One flag also sits in your browser’s local storage to remember that you dismissed the notice.
The sections below are the binding text; this one is for orientation.
2. Why there is nothing to consent to
There is nothing here to consent to, which is why the notice at the bottom of the site has a single button and no “manage preferences” screen: there are no preferences to manage.
That is not because we set no cookies — we set four, listed in full below — but because every one of them is strictly necessary to do something you asked for. A cookie that keeps you signed in is what signing in means; a cookie that carries the security value for an X connection is what stops somebody else finishing that connection as you. Under the ePrivacy rules and the GDPR, cookies of that kind are exempt from consent. Anything that is not strictly necessary would require asking, and we set none — so the honest notice is still one button.
3. The cookies we set
All four are first-party, set by this site, and marked HttpOnly — meaning no script on the page can read them, including any script somebody managed to inject. None of them is readable by another site, and none is used to build a profile.
The sign-in session
- Name:
hood_session - Set when: you sign in by signing a message with your wallet
- Purpose: keeping you signed in. Without it the site cannot tell one request from another and you would be signed out on every page.
- Expires: 30 days, or immediately when you sign out
- Contains: a signed token naming your account and wallet address. Not your keys — this site never sees those and could do nothing with the cookie but recognise you.
The three X connection cookies
Set only if you press Connect X, and only for the round trip to x.com and back. The callback deletes all three, whether the connection succeeded, failed or you cancelled.
hood_x_state— a random value returned by X and compared against what we sent, so a connection cannot be completed by a request you did not start.hood_x_verifier— the secret half of the PKCE exchange. It never leaves this server, and without it the code X returns is worthless to anybody who intercepts it.hood_x_return— which page to send you back to afterwards.- Expire: 10 minutes, or the moment the connection finishes
4. What is stored outside a cookie
A single entry in your browser’s local storage — related to cookies, but not a cookie: local storage is never attached to a network request, so it is never transmitted anywhere.
- Key:
thehood.cookie-notice - Value:
dismissed - Set by: this site, first-party, when you dismiss the notice
- Purpose: not showing you the same notice on every page
- Expires: never — it persists until you clear your site data
- Contains: no identifier, no address, no timestamp, nothing about you
Because it is not a cookie and carries no personal data, it needs no consent under the ePrivacy rules or the GDPR — and neither do the four above, for the different reason given in section 2. The notice exists to tell you what is there, not to ask permission.
5. Tracking — what we do not do
- We do not run analytics of any kind — no Google Analytics, Plausible, Fathom, Vercel Analytics or self-hosted equivalent.
- We do not load advertising, retargeting or conversion pixels.
- We do not embed social widgets, chat widgets or session-replay tools. The Report a problem button is not one of those: it is our own code, it records nothing until you start it, it never captures your screen or your keystrokes, and it stores nothing on your device. See section 3 of the privacy notice.
- We do not fetch fonts, scripts or stylesheets from a third-party CDN. The interface uses the fonts already on your machine, so no request leaks your origin to a font host.
- We do not fingerprint you, or attempt to identify you across sites or visits.
6. Storage this site does not control
Your wallet extension keeps its own data — which sites it has authorised, which accounts, its own settings — under its own origin. This site cannot read it and does not set it. Manage that in the wallet, and revoke this site’s connection there if you want it gone.
Loading a project’s artwork fetches it from an IPFS gateway. The gateway may set its own cookies on its own domain, as any third-party host can, under its own policy.
7. Removing what is stored
Clear site data for thehood.markets in your browser’s settings, or use a private window. The stored flag disappears and the notice appears again on your next visit — that reappearance is how you can confirm it worked.
8. Changes to this notice
Adding anything that tracks you would be a material change. This page, the privacy notice and the on-site notice would all be updated before it took effect, and anything requiring consent would ask for it rather than assume it.
9. Contact
The Hood’s contracts are immutable, audited by Claude Fable 5. Nothing on this site is financial, investment, legal or tax advice.