01 Who we are
Nutted is owned and operated by The Orderbook LLC, a limited liability company organized under the laws of the State of Wyoming, United States ("The Orderbook," "we," "us," or "our").
For the purposes of the EU and UK General Data Protection Regulation, The Orderbook LLC is the data controller of the personal data described in this policy. For the purposes of the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), The Orderbook LLC is the business that determines the purposes and means of processing.
You can reach us at any time at christoffer@theorderbook.xyz.
02 Scope of this policy
This policy applies to personal information we process through:
- the website at nutted.ai and any subdomain or successor domain we operate;
- the waitlist and any early-access, invite-code, or licence-activation flow;
- the Nutted agent, including where you interact with it through a third-party messaging platform such as Telegram; and
- email and other correspondence you send to us.
We refer to all of the above collectively as the "Services." This policy does not apply to any third-party website, exchange, broker, wallet, or platform that we do not control, even where we link to it or where our Services interoperate with it.
Nutted is a pre-launch product. The Services currently offered are limited, and the personal information we process today is correspondingly limited. As features launch, we will update this policy and revise the "Last updated" date above.
03 Information we collect
3.1 Information you give us directly
| Category | What it includes |
|---|---|
| Waitlist details | The email address you submit to join the waitlist, together with the date and time of submission. |
| Access credentials | Invite codes, early-access codes, and licence codes that you enter, and whether the attempt succeeded or failed. |
| Messaging identifiers | If you activate the agent through Telegram, your Telegram chat ID and Telegram username, and the date the licence was bound to your account. |
| Agent conversation content | The messages, prompts, questions, instructions, and any other content you send to the agent, together with the agent's responses. We retain a limited rolling history so the agent has conversational context. |
| Correspondence | The contents of emails and other messages you send us, including your email address, any name or signature you include, and any attachments. |
We do not require you to create an account with a name, postal address, or telephone number to join the waitlist. Please do not send us sensitive personal information — such as government identification numbers, financial account credentials, private keys, seed phrases, health information, or information revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or sexual orientation — unless we specifically request it. We will never ask you for a private key, seed phrase, or exchange password.
3.2 Information collected automatically
| Category | What it includes |
|---|---|
| Anti-abuse logs | When an invite or access code is submitted, we record the originating IP address, whether the attempt succeeded, and the timestamp. We use this solely to rate-limit and detect brute-force and automated abuse. |
| Server and hosting logs | Our hosting and backend providers generate standard technical logs, which may include IP address, user-agent string, browser and device type, operating system, referring page, requested URL, response status, and timestamp. |
| Diagnostic data | Error reports and performance information generated when something goes wrong, which may include the technical details above and the state of the page at the time of the error. |
We do not operate third-party advertising networks, advertising pixels, cross-site tracking tags, or data brokers on the Services.
3.3 Information from third parties
Where you choose to interact with the agent through a third-party messaging platform, that platform provides us with the identifiers necessary to route messages to you (for example, a Telegram chat ID and username). The platform's own handling of your data is governed by its privacy policy, not ours. We also receive aggregate technical and security information from our hosting and infrastructure providers.
3.4 Market and financial data
The Services process market, exchange, on-chain, and other financial data obtained from public and licensed sources. This data is generally not personal information about you. Where publicly available blockchain data is processed — for example, a wallet address you ask the agent to analyse — that information may in some circumstances be treated as personal data under applicable law. We process it only to respond to your request and for the purposes set out in section 5.
04 Local storage and similar technologies
The Services use your browser's local storage and session storage rather than advertising cookies. We currently store the following on your device:
| Key | Purpose and duration |
|---|---|
nutted_auth | Records that you have successfully entered a valid access code, so you are not asked to re-enter it on every page. Strictly necessary for the access-gated area to function. Persists until you clear your browser storage; the session-storage variant is cleared when you close the tab. |
nutted_waitlist | Records that you have already joined the waitlist from this browser, so the interface can show your status instead of prompting you again. Strictly necessary for that feature. Persists until you clear your browser storage. |
These entries are functional and are read only by the Nutted website itself. They are not used for advertising, profiling, or cross-site tracking. You can delete them at any time through your browser's settings for clearing site data; doing so may mean you are asked for your access code again.
Our pages load web fonts from Google Fonts and certain code libraries from public content delivery networks. When your browser requests those files, your IP address is necessarily disclosed to those providers so the file can be delivered. If you would prefer to avoid this, you may block those domains in your browser, though parts of the site may not display as intended.
Global Privacy Control. Because we do not sell or share personal information as those terms are defined under US state privacy laws, there is nothing for an opt-out preference signal to disable. We nonetheless honour the Global Privacy Control signal and will not treat a browser that transmits it as consenting to any future sale or sharing. We do not currently respond to legacy "Do Not Track" browser headers, as there is no common standard for them.
05 How we use information
We use personal information for the following purposes, and no others without telling you first:
- To operate the waitlist — to record your place, to prevent duplicate entries, and to contact you when early access becomes available.
- To provide the Services — to authenticate access codes, bind licences, route your messages to the agent, maintain conversational context, and return responses to you.
- To secure the Services — to rate-limit code submissions, detect and investigate brute-force attempts, fraud, abuse, and unauthorised access, and to protect the integrity of our systems.
- To improve the Services — to diagnose errors, measure reliability, understand which features are used, and develop and improve our models, prompts, and product. Where we use conversation content for improvement, we work with de-identified or aggregated data wherever it is practicable to do so.
- To communicate with you — to respond to your enquiries, send service and security announcements, and notify you of material changes to our terms or this policy.
- To send marketing — to tell you about launches, features, and offers, where you have signed up or where we are otherwise permitted to do so. Every marketing email includes an unsubscribe link.
- To comply with law — to meet legal, regulatory, tax, and accounting obligations, to respond to lawful requests, and to establish, exercise, or defend legal claims.
We do not use your personal information to make decisions that produce legal or similarly significant effects about you without human involvement. See section 16.
06 Legal bases (EEA, UK, Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under Article 6(1) of the GDPR and the UK GDPR:
| Purpose | Legal basis |
|---|---|
| Providing the Services you request, including waitlist registration and agent responses | Performance of a contract with you, or steps taken at your request prior to entering into a contract — Art. 6(1)(b). |
| Security, rate limiting, abuse prevention, and fraud detection | Our legitimate interests in protecting the Services, our users, and our business — Art. 6(1)(f). |
| Diagnostics, reliability, and product improvement | Our legitimate interests in operating and improving a functioning product — Art. 6(1)(f). |
| Marketing emails | Your consent, which you may withdraw at any time — Art. 6(1)(a); or our legitimate interests in marketing to existing contacts where permitted by law. |
| Compliance with legal obligations and defence of legal claims | Compliance with a legal obligation — Art. 6(1)(c) — and our legitimate interests in establishing, exercising, or defending legal claims — Art. 6(1)(f). |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your interests or fundamental rights and freedoms. You may ask us for further information about that assessment, and you have the right to object as described in section 15.
07 We do not sell your information
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising or targeted advertising, as those terms are defined under the CCPA and other US state privacy laws. We have not done so in the preceding twelve months. We do not sell the personal information of any consumer, including any consumer we know to be under sixteen years of age.
We do not rent, trade, or licence our waitlist to third parties. Disclosures we do make are limited to those set out in section 8.
08 When we disclose information
We disclose personal information only in the following circumstances:
- To service providers. To vendors and processors who perform services for us — hosting, database infrastructure, email delivery, messaging, analytics, and security — and who are contractually bound to process personal information only on our documented instructions, to keep it confidential, and to protect it appropriately. See section 9.
- For legal reasons. Where we believe in good faith that disclosure is reasonably necessary to comply with applicable law, regulation, subpoena, court order, or governmental or law enforcement request; to enforce our Terms of Service; or to detect, prevent, or address fraud, security, or technical issues.
- To protect rights and safety. Where we believe disclosure is reasonably necessary to protect the rights, property, or safety of The Orderbook, our users, or the public, including to prevent imminent harm.
- In a corporate transaction. In connection with a merger, acquisition, financing, reorganisation, sale of assets, bankruptcy, or similar transaction, personal information may be transferred to the successor or acquiring entity, subject to this policy or a materially equivalent successor policy. We will notify you of any such transfer that materially affects your rights.
- With your direction or consent. Where you ask us to, or otherwise consent to the disclosure.
- In aggregated or de-identified form. We may create and disclose aggregated, anonymised, or de-identified information that cannot reasonably be used to identify you. We maintain such information in de-identified form and will not attempt to re-identify it, except to test the effectiveness of our de-identification.
09 Service providers
We keep our vendor footprint deliberately small. As at the effective date of this policy, we rely on the following categories of provider:
| Provider | Function and data involved |
|---|---|
| Vercel | Website hosting and content delivery. Processes request logs including IP address and user-agent. United States and global edge network. |
| Supabase | Database and backend infrastructure. Stores waitlist emails, access-attempt logs, licence records, and agent conversation history. |
| Telegram | Third-party messaging platform, where you choose to use it to reach the agent. Handles delivery of your messages and provides your chat ID and username. Telegram is an independent controller of the data it holds about you. |
| Google Fonts | Web font delivery. Receives your IP address when your browser requests a font file. |
| Content delivery networks | Delivery of open-source front-end libraries. Receive your IP address when your browser requests a file. |
| Model and infrastructure providers | Where the agent uses third-party artificial intelligence models to generate a response, the content of your request may be transmitted to the relevant model provider for processing under contractual terms that restrict its use. |
We will keep this list current. If you would like the identity of any provider engaged after the effective date above, write to us and we will tell you.
10 International transfers
We are established in the United States, and our infrastructure and service providers are primarily located in the United States. If you access the Services from outside the United States, your personal information will be transferred to, stored in, and processed in the United States and potentially other countries whose data protection laws may differ from those of your own country.
Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on an appropriate safeguard under Chapter V of the GDPR — in most cases the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and supplementary technical and organisational measures where they are needed. Where a transfer is necessary for the performance of a contract with you or for the establishment, exercise, or defence of legal claims, we may instead rely on the corresponding derogation in Article 49.
You may request a copy of the relevant safeguards by writing to us at the address in section 20. We may redact commercial terms.
11 How long we keep information
We keep personal information only for as long as we need it for the purposes described in this policy, and then delete it or de-identify it. Our current retention practice is:
| Information | Retention period |
|---|---|
| Waitlist email addresses | Until the waitlist closes and early access has been distributed, or until you ask us to delete your entry, whichever comes first. |
| Access-attempt logs (IP address) | A short rolling window sufficient for rate limiting and abuse investigation — ordinarily no more than thirty days. |
| Licence and activation records | For the life of the licence and for a reasonable period afterwards to handle disputes, chargebacks, and legal or accounting obligations. |
| Agent conversation history | A limited rolling history for conversational context. Older messages are trimmed automatically. You may ask us to clear your history at any time. |
| Correspondence with us | For as long as needed to resolve your enquiry and for a reasonable period afterwards as a business record. |
| Server and diagnostic logs | The retention period applied by the relevant infrastructure provider, ordinarily measured in days or weeks. |
We may retain information for longer where we are required to do so by law, or where it is necessary to establish, exercise, or defend a legal claim, in which case we restrict our processing of it to that purpose.
12 Security
We take reasonable and appropriate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access. These measures currently include:
- encryption of data in transit using industry-standard TLS;
- row-level security on our database, configured so that the public cannot read the waitlist or any access, licence, or conversation table;
- server-side functions with defined privileges rather than direct public table access;
- rate limiting and monitoring of code-submission endpoints to resist brute-force attempts;
- a waitlist position function deliberately designed not to disclose the true number of signups; and
- restricting internal access to personal information to those who need it.
No method of transmission over the internet and no method of electronic storage is completely secure. While we work to protect your personal information, we cannot and do not guarantee its absolute security, and we cannot warrant that the Services will be free from unauthorised access. You are responsible for keeping any access code, invite code, or licence code confidential, and for the security of the device and messaging account you use to reach the agent.
If we become aware of a breach of security affecting your personal information, we will notify you and any relevant regulator where required to do so, and within the timeframes required by applicable law.
13 Your choices
- Leave the waitlist. Email us and we will remove your address.
- Unsubscribe from marketing. Use the unsubscribe link in any marketing email, or write to us. We will still send you necessary service and security messages relating to any account or licence you hold.
- Clear your local storage. Delete site data through your browser settings, as described in section 4.
- Clear your agent history. Ask us and we will delete the stored conversation context associated with your licence.
- Stop using the agent. You may block or delete the agent within your messaging platform at any time.
14 US state privacy rights
Depending on where you live, US state privacy law may give you the rights set out below. We extend these rights to all US residents as a matter of policy, regardless of whether your state has enacted a comprehensive privacy statute.
- Right to know and to access. To request confirmation of whether we process your personal information, and to obtain the specific pieces of personal information we hold, the categories collected, the sources, the business purpose, and the categories of third parties to whom it was disclosed.
- Right to delete. To request deletion of personal information we have collected from you, subject to the exceptions permitted by law.
- Right to correct. To request correction of inaccurate personal information, taking into account the nature of the information and the purposes of processing.
- Right to data portability. To receive a copy of your personal information in a portable and, to the extent technically feasible, readily usable format.
- Right to opt out of sale, sharing, and targeted advertising. We do not engage in any of these activities, so there is nothing to opt out of. Should this ever change, we will update this policy and provide a clear opt-out mechanism before doing so.
- Right to limit use of sensitive personal information. We do not collect or use sensitive personal information for the purposes that would trigger this right.
- Right to non-discrimination. We will not deny you services, charge you a different price, or provide you a different level of quality because you exercised a privacy right. We do not offer financial incentives in exchange for personal information.
- Right to opt out of profiling. We do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects.
Categories of personal information collected in the last twelve months
Under the CCPA's statutory categories, we have collected: identifiers (email address, IP address, messaging platform username and chat ID); internet or other electronic network activity information (server logs, diagnostic data, interaction with the Services); and other information you voluntarily provide (the content of your messages to the agent and your correspondence with us). We collect these from you directly, automatically through your use of the Services, and from the messaging platform you choose to use. We disclose them for business purposes to the categories of service provider listed in section 9.
How to exercise your rights
Email christoffer@theorderbook.xyz with the subject line "Privacy Request," and tell us which right you wish to exercise. We will acknowledge your request and respond within forty-five days, and may extend once by a further forty-five days where reasonably necessary, in which case we will tell you.
Verification. To protect your information, we must verify your identity before acting on a request. Ordinarily this means confirming that you control the email address associated with our records, or the messaging account bound to a licence. We may ask for additional information where a request is complex or high-risk. We will not use information you provide for verification for any other purpose.
Authorised agents. You may use an authorised agent to submit a request on your behalf. We will require written proof of the agent's authority and may require you to verify your own identity directly with us.
Appeals. If we decline your request, you may appeal by replying to our decision with the word "Appeal" and your reasons. We will respond to an appeal within the period required by your state's law, ordinarily forty-five or sixty days, and will explain our reasoning in writing. If your appeal is denied, you may contact your state Attorney General to lodge a complaint. California residents may also contact the California Privacy Protection Agency.
California "Shine the Light"
California Civil Code § 1798.83 permits California residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes.
Nevada residents
Nevada law permits residents to opt out of the sale of certain covered information. We do not sell covered information as defined by Nevada law, but you may submit a request to the address in section 20.
15 EEA, UK and Swiss rights
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights in relation to your personal data:
- Access — to obtain confirmation of whether we process your data and a copy of it.
- Rectification — to have inaccurate data corrected and incomplete data completed.
- Erasure — to have your data deleted where one of the grounds in Article 17 applies.
- Restriction — to have our processing restricted in the circumstances set out in Article 18.
- Portability — to receive data you provided to us in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
- Objection — to object at any time to processing based on our legitimate interests, on grounds relating to your particular situation. Where you object to processing for direct marketing, we will stop without qualification.
- Withdrawal of consent — to withdraw consent at any time where we rely on it, without affecting the lawfulness of processing carried out beforehand.
- Complaint — to lodge a complaint with your local supervisory authority. In the UK this is the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner. We would appreciate the chance to address your concern first.
We do not charge a fee to act on these rights unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act, and will explain why. We respond within one month, extendable by two further months for complex requests, and will tell you if we need the extension.
16 Automated processing
The Nutted agent is an automated system: it generates research, analysis, and output using artificial intelligence models. Its output is produced automatically and may be inaccurate, incomplete, or out of date.
We do not use automated processing to make decisions that produce legal effects concerning you or that similarly significantly affect you within the meaning of Article 22 of the GDPR. The agent does not decide whether you may access financial services, and does not evaluate your creditworthiness, employment, or eligibility for anything.
Output from the agent is information, not advice. It is not investment, financial, legal, tax, or accounting advice, and it is not a recommendation to buy or sell any asset. Any decision you take remains entirely your own. See our Terms of Service for the full position on risk.
17 Children
The Services are intended for adults. They are not directed to children, and we do not knowingly collect personal information from anyone under eighteen (18) years of age. You must be at least eighteen to join the waitlist or use the agent.
If you believe a child has provided us with personal information, contact us at christoffer@theorderbook.xyz and we will delete it promptly. Consistent with the Children's Online Privacy Protection Act, we do not knowingly collect personal information from children under thirteen, and we do not sell the personal information of consumers under sixteen.
18 Third-party links and platforms
The Services may link to, or interoperate with, websites, exchanges, messaging platforms, and applications that we do not operate. We are not responsible for the privacy practices or content of those third parties. Their collection and use of your information is governed by their own policies, which you should read before providing information to them.
19 Changes to this policy
We may update this policy from time to time to reflect changes in our practices, our product, or the law. When we do, we will revise the "Last updated" date at the top of this page and increment the version number.
If a change is material — for example, if we begin collecting a new category of personal information, or begin using it for a materially different purpose — we will provide prominent notice before the change takes effect, and where required by law we will seek your consent. Notice may be given by email to the address you gave us, or by a conspicuous notice on the Services. Your continued use of the Services after a change takes effect constitutes acceptance of the revised policy, to the extent permitted by applicable law.
We recommend you review this page periodically. Prior versions are available on request.
20 How to contact us
For any question, request, or complaint about this policy or our handling of your personal information, contact us:
- Entity
- The Orderbook LLC
- Formed in
- State of Wyoming, United States
- Product
- Nutted — nutted.ai
- Privacy contact
- christoffer@theorderbook.xyz
- Subject line
- Use "Privacy Request" so we can route it correctly.
- Response time
- We acknowledge requests promptly and respond within the period required by the law that applies to you.
This policy is governed by and construed in accordance with the laws of the State of Wyoming, without regard to its conflict-of-laws principles, except where the mandatory law of your place of residence provides otherwise. Nothing in this policy limits any right you have under a data protection law that applies to you and that cannot be waived by agreement.