Privacy Policy
Last updated: 21 July 2026
Convenience translation — the German version at /datenschutz is the legally binding one.
1. Controller
Hubert Wolski, Steinböckengasse 6/2/10, 1140 Vienna, Austria, e-mail: office@tessera.at (see Imprint).
2. Core principle: data minimisation
Tessera is deliberately built so that as little personal data as possible is collected: registration works exclusively via passkey — no e-mail address, no password, no phone number. There is no tracking, no analytics cookies and no advertising.
3. Data we process
- Account data: decentralised identifier (DID), handle, public passkey keys and profile details you provide. Legal basis: performance of contract (Art. 6(1)(b) GDPR).
- Content data: posts, game scores, payment receipts (“zaps”) and other records you create — see section 4 on their public nature. Legal basis: Art. 6(1)(b) GDPR.
- Technical data: server logs (IP address, timestamp, requested resource) for operational security, automatically deleted after a short period. Session cookies that are technically required for login. Legal basis: legitimate interest in secure operation (Art. 6(1)(f) GDPR).
Your wallet keys are used exclusively on your devices and are held by the controller only in encrypted form that it cannot read.
4. Public nature of the federated network
Tessera is based on the open AT Protocol. Profile, handle and the records you create (including zap payment receipts) are public, cryptographically signed and may be replicated and stored permanently by third parties worldwide. Deletion on our systems cannot reach copies already made by third parties. Please keep this in mind before publishing content.
5. Recipients and third parties
- Hosting: Hetzner Online GmbH, Germany (servers in the EU, data processing agreement pursuant to Art. 28 GDPR).
- On-/off-ramp (optional): if you use wallet funding or withdrawal, the window of an independently responsible, regulated provider (e.g. Transak) opens — embedded on this page or in a new tab, depending on the provider. What you enter there goes to that provider directly; it performs the statutory identity verification (KYC) under its own responsibility. We receive no identity documents or payment data.
- Public infrastructures: payments run on public networks (e.g. Hyperliquid); transaction data created there is inherently public and cannot be deleted.
No data is shared beyond the above.
6. Retention
We store account data and records for as long as your account exists. After account deletion the data is removed from our systems; section 4 applies to copies already replicated. Log data is deleted automatically after a short period.
7. Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR) — contact see section 1. The AT Protocol additionally offers a complete export of your data. You may lodge a complaint with the Austrian Data Protection Authority (dsb.gv.at).