Contents
Summary
- No accounts, names or email addresses for testing. Your identity is a random key kept in your browser.
- An email is stored only if you request HBM Enterprise access, and only to reply to you.
- Benchmark results are public by design. They carry no personal details.
- HBM does not store IP addresses. Rate limits count requests in server memory only; to cap rewards per network, a run keeps a salted hash of the address that changes every UTC day and cannot be reversed.
- Linking a wallet is optional and can be undone at any time.
- No advertising, no tracking cookies, no sale of data.
What a run stores
When you submit a run, HBM stores:
| Data | Example | Why |
|---|---|---|
| Measurements | Read, write, copy, random and sustain throughput, latency proxy, per-phase samples and traces, MEM Score | To show and rank your result |
| GPU details your browser reports | WebGPU vendor, architecture and description; WebGL renderer string | To place the run in a device class |
| Coarse browser and system | Chrome 140, Windows | To explain differences between browsers |
| Run context | Timing mode, duration, data moved, form factor you declared, validation flags | To validate the run |
| Operator hash | A 16-character hash of your key, shown as OP-XXXXXX | To group your runs and points |
| Time | When the run was submitted | Leaderboards and seasons |
For test runs, HBM does not store your full user agent, IP address, hardware serial numbers, precise location, name or email.
Your operator key
The first run creates a random 128-bit key in your browser. The server only ever stores the first 16 characters of its SHA-256 hash. The key itself travels over HTTPS with each submission and when you link a wallet, to prove it is yours, and is not stored. Anyone with your key can act as your operator, so treat the recovery key like a password.
What is public
Accepted runs appear on the leaderboards, in The Stack and on a share page: operator label, device class, measurements, MEM Score, MEMPRINT and date. Rejected runs are kept for review but not shown.
HBM Enterprise requests
If you request early access to HBM Enterprise, we store the work email, company, fleet size and note you submit, and the time. They are used only to reply to you about HBM Enterprise, are never sold or shared, and are deleted on request.
Rewards
Points are recorded as ledger entries (kind, points, season, a short note, time) against your operator hash.
When a weekly epoch closes, HBM stores each qualifying linked wallet's points, amount and Merkle proof, and publishes the epoch's root on Robinhood Chain. For Stock Token rewards, HBM stores the signed statement that you are not a US person, with its time and the country your request came from.
Linked wallets
Linking a wallet is optional. You sign a short message; signing sends no transaction and costs nothing. HBM stores your operator hash, the wallet address, the signature and the time of linking, and reads your $HBM balance from Robinhood Chain.
Wallet addresses and their activity are public on the blockchain. To remove the link, use Unlink on the Rewards page; the link record is deleted.
Token data
To show holders, trades and price charts for $HBM, HBM indexes public Robinhood Chain data: token transfers, trades, balances and the addresses involved. This data is already public on the blockchain.
Browser storage
HBM keeps a few entries in your browser's local storage. They never leave your device unless a feature above says so. Details are in the Cookie Policy.
| Key | Purpose |
|---|---|
mem.operator.v1 | Your random operator key: the identity your runs and points belong to. |
mem.runs.v1 | Your most recent runs on this device (up to 50), for quick access. |
mem.last.v1 | Your last result, to place your machine on the Economy ladder and calculator. |
privy:* | Your wallet sign-in session, kept by Privy (with privy-* cookies) only after you connect a wallet or log in. |
hbm.consent.v1 | Your choice about optional analytics. |
hbm.announce.* | Announcements you have dismissed. |
How data is used
To run the benchmark, validate and rank results, prevent abuse, compute rewards and show token information. HBM does not use data for advertising, does not build profiles and does not sell data.
Service providers
| Provider | Role | What it sees |
|---|---|---|
| Vercel | Hosting and content delivery | Request metadata such as IP addresses, to deliver and protect the service, under its own policy |
| Managed Postgres provider | Database | The data described above |
| Robinhood Chain RPC | Reading public chain data | Our servers relay your browser's token reads; if the relay is unavailable, your browser contacts the RPC directly |
| Coinbase and Kraken price APIs | ETH to USD prices | Server requests only; no personal data is sent |
| IPFS gateways | The token logo | Server requests only; no personal data is sent |
| Privy | Wallet sign-in and embedded wallets | Your login method (email or social account) and wallet address, when you choose to connect, under its own policy |
| Your wallet software | Signing and sending transactions | Governed by the wallet provider's own terms |
| Vercel Web Analytics | Optional, only with consent | Aggregated page views, without cookies |
Retention
- Runs, ledger entries and wallet links are kept while HBM operates, as part of the public record.
- Single-use run tickets are kept to stop replays.
- HBM Enterprise requests are kept until the conversation ends or you ask us to delete them.
- Rate limits count recent requests per address in server memory only; the counts are never written to the database.
- Browser storage stays on your device until you clear it.
Your choices and rights
You can clear HBM's browser storage at any time (your ledger stays reachable only through a saved recovery key), unlink a wallet, and decline analytics. Depending on where you live, you may also have the right to access, correct or delete data about you. Because HBM holds no names or emails, a request has to identify the runs or the operator concerned, for example with your recovery key.
Children
HBM is not directed to children and does not knowingly collect data from them.
Changes
We will update this policy when HBM changes what it stores. The date at the top shows the latest version.