Back to home

Privacy Policy

Last updated: 23 July 2026

This Privacy Policy explains how BlockPhi (“BlockPhi”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you visit the BlockPhi website, terminal, and analytics dashboard, subscribe to our newsletter, use member access, engage with our community, or otherwise interact with us (collectively, the “Services”).

1. Who we are and how to contact us

BlockPhi is a macro-crypto analytics firm operating the Services. For the purposes of the EU and UK General Data Protection Regulation (“GDPR”), BlockPhi acts as the data controller of personal data processed through the Services, except where a third party acts as an independent controller under its own privacy policy.

For any question about this Privacy Policy or about your personal data, contact contact@blockphi.com.

2. Scope of this Privacy Policy

This Privacy Policy applies to the BlockPhi website, terminal, analytics dashboard, newsletter, member access, and related communications. It does not replace the privacy policies of third-party services such as Whop, Substack, or Discord that you choose to use. Those parties may process personal data for their own purposes under their own terms and privacy policies.

3. Personal data we collect

3.1 Information you provide directly

  • Email address — provided when you sign up for the newsletter or terminal access. This is the only directly identifying personal data we collect at signup.
  • Newsletter consent preference — a value indicating whether you opted in to receive our newsletter. This is recorded as an explicit, affirmative action; the opt-in is unchecked by default.
  • Membership and account data — where you purchase premium access, your Whop account identifiers, membership tier, and membership status. Whop and its payment providers handle payment-card details; BlockPhi does not receive or store payment-card details.
  • Community data — if you join our community on Discord, your Discord identifier and activity are processed by Discord under its own policy.
  • Correspondence and feedback — the content of any message, support request, testimonial, or feedback you choose to send us.

3.2 Information collected automatically

  • Hashed IP address — at newsletter signup your IP address is irreversibly hashed using SHA-256 before storage. We do not store your raw IP address. The hash is retained solely for abuse prevention and compliance record-keeping.
  • Source attribution — which part of the site you signed up from (for example, a modal or the footer). This is non-identifying and used to understand how people reach us.
  • Technical and security data — standard server-log information such as IP address, user-agent, requested URL, referrer, and timestamps, processed transiently by our hosting provider for security, reliability, and abuse prevention.
  • Authentication data — if you use premium features, short-lived session tokens stored in secure, httpOnly cookies (see Section 6).

We do not use advertising pixels, cross-site tracking, device fingerprinting, or third-party analytics cookies on the Services.

4. How we use personal data

  • Provide and administer the Services, including managing newsletter signups and, for premium members, verifying membership through Whop and granting access to gated features.
  • Send the newsletter containing market insights and product updates, only if you have explicitly opted in.
  • Security and abuse prevention, including detecting and preventing fraudulent or abusive signups and protecting the Services.
  • Improve the Services based on aggregate, non-identifying signup and usage patterns.
  • Communicate with you, including responding to enquiries and sending service or security notices relating to your account.
  • Legal and business administration, including complying with legal, tax, and regulatory obligations and protecting legal rights.

5. Legal bases for processing

Where the GDPR applies, we process personal data on one or more of the following legal bases:

  • Consent — for newsletter communications. You provide explicit consent by checking the newsletter opt-in. You may withdraw this consent at any time without affecting the lawfulness of prior processing.
  • Performance of a contract — for processing your email and Whop membership data to create and manage your access to the Services.
  • Legitimate interests — for abuse prevention (hashed IP storage), security, and service improvement (source attribution and aggregate usage), provided those interests are not overridden by your rights and freedoms.
  • Legal obligations — where processing is necessary to comply with tax, accounting, or other legal requirements.

6. Cookies

We use only strictly necessary cookies required for the Services to function. We do not use tracking, analytics, or advertising cookies, so no cookie consent banner is required.

  • Authentication cookies — secure, httpOnly session tokens (whop_access_token, whop_refresh_token, and their expiry/state) for logged-in premium members. These are strictly necessary and do not require consent under the GDPR.
  • OAuth state cookies — short-lived tokens used during the Whop login process for security (CSRF protection and the sign-in return path). These expire within minutes.

Embedded components you actively use, such as the Whop checkout, may set their own cookies within their own context under Whop’s privacy policy.

7. How we share personal data

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We use the following third-party processors to operate the Services:

  • Supabase — database hosting (stores your email, newsletter consent preference, and hashed IP).
  • Vercel — website hosting and serverless functions.
  • Whop — membership management, authentication, and payment processing for premium features.
  • Substack — newsletter delivery, for users who opted in. Your email is shared with Substack via periodic manual export; there is no automated API connection.
  • Discord — the community platform, if you choose to join.

We may also disclose personal data where required by law, court order, or lawful government request, or where reasonably necessary to protect the rights, safety, or property of BlockPhi, our users, or others; and in connection with a merger, acquisition, or sale of assets.

8. Third-party services and independent controllers

Whop, Substack, and Discord may act as independent controllers for the personal data they process under their own privacy policies and settings. BlockPhi is not responsible for the privacy practices of an independent third party.

9. International data transfers

BlockPhi operates from the European Union, but some service providers process data in the United States or other countries outside the European Economic Area, the United Kingdom, or Switzerland. Where required, international transfers are based on an adequacy decision, the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism. You may contact us for further information about the safeguards relevant to a transfer of your personal data.

10. Data retention

  • Email and consent data are retained for as long as your account or subscription is active. If you request deletion, we will remove your data within 30 days.
  • Hashed IP data is retained for up to 12 months for abuse prevention, after which it is purged.
  • Membership records may be retained for the period needed to meet tax, accounting, and legal obligations.
  • Server and security logs are retained by our hosting provider for a limited period for security and reliability.

We may retain anonymised or aggregated information that can no longer reasonably identify you for longer periods.

11. Your rights under European and UK data-protection law

Subject to applicable law, you may have the right to:

  • Access the personal data we hold about you and obtain information about its processing.
  • Rectification of inaccurate or incomplete personal data.
  • Erasureof your personal data (“right to be forgotten”).
  • Restriction of certain processing.
  • Object to processing based on legitimate interests and to direct marketing. Where you object to direct marketing, we will stop using your personal data for that purpose.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
  • Complain to your local Data Protection Authority or the supervisory authority in the country of your habitual residence, place of work, or the place of the alleged infringement.

To exercise any of these rights, contact contact@blockphi.com. We will respond within the period required by applicable law — under the GDPR, generally within one month.

12. California and other United States privacy rights

Where applicable United States privacy law, including the California Consumer Privacy Act as amended, applies to BlockPhi, residents may have rights to know or access personal information, request deletion or correction, and receive equal service when exercising privacy rights. BlockPhi does not sell personal information and does not share it for cross-context behavioural advertising. To submit a request, email contact@blockphi.com.

13. Marketing communications

We send the newsletter only where you have opted in. You can unsubscribe using the link in any newsletter email or by emailing contact@blockphi.com. We may still send non-marketing communications necessary to administer your account, access, or security.

14. Children's privacy

The Services are intended only for persons aged 18 or older. We do not knowingly collect personal data from children. If you believe that a child has provided personal data to us, contact contact@blockphi.com and we will take appropriate steps to investigate and delete the information where required.

15. Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), SHA-256 hashing of IP addresses, httpOnly cookie flags, server-side secret management, and row-level security on our database. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

16. Personal-data breaches

If a personal-data breach occurs, we will assess the risk and make any notification to supervisory authorities or affected individuals required by applicable law. Where the GDPR applies and a breach is likely to result in a risk to individuals’ rights and freedoms, the competent supervisory authority will be notified without undue delay and, where feasible, within 72 hours after we become aware of it.

17. Automated decision-making

BlockPhi does not make decisions based solely on automated processing that produce legal or similarly significant effects on you. Certain access-control functions are automated, such as verifying your Whop membership status, but these do not have such effects.

18. Third-party links and embedded content

The Services may link to or embed third-party content, such as the Whop checkout, the Substack newsletter, our Discord community, or external videos and articles. When you follow a link or use an embedded feature, that third party may collect personal data under its own privacy policy. Review the relevant third-party policy before providing information or using the feature.

19. Nothing here is investment advice

All content on the Services is educational and informational only. Nothing is financial, investment, legal, or tax advice. Past performance is not indicative of future results. Do your own research and consult a qualified professional before making investment decisions. See our Terms of Service for the investment-risk disclosures.

20. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Changes become effective when posted, with a new “Last updated” date. If we make material changes to how we handle personal data, we will notify affected users by email where possible.

21. Contact

For privacy-related enquiries, data-access requests, or to exercise your GDPR rights, email contact@blockphi.com.

BlockPhi. All rights reserved.