betaPhenoTrade

What we can and can't see

Transparency

Most platforms describe privacy by listing what they promise not to do. Promises are worth less than architecture, so this page describes what PhenoTrade is actually able to see — including the parts that aren't flattering.

What we cannot read

  • Deal messages. Encrypted in your browser with a key derived between you and the other party. We store ciphertext. Handing over the database would hand over unreadable blobs.
  • Tracking numbers. Same encryption. We keep the carrier, the last four characters, and when it was logged — enough to prove a shipment happened, not enough to look up a name or address.
  • Your private key. It never leaves your device. We have no copy and cannot recover it for you, which is the trade-off that makes the rest of it true.

What we can see

  • Your email address, and the display name and shop details you chose to publish.
  • The deal graph: who opened a deal with whom, when, about which listing, and what the public price note said. Contents are encrypted; the fact of the conversation is not. This is the most sensitive thing we hold, and we're telling you rather than hoping you don't ask.
  • Your off-site contact channels, so we can reveal them to a counterparty when you accept a deal. You can see exactly who has viewed them from your shop settings.
  • Listing and receipt photos — with camera metadata stripped on upload.
  • Reputation records: confirmations, ratings, disputes.

Who else touches your data

We can only speak for our own design. These vendors run the infrastructure and keep their own logs, which we do not control:

  • Vercel hosts the site and records request logs, including IP addresses, for a limited retention period.
  • Neon hosts the database in the United States.
  • Resend sends verification and invite emails, and logs delivery status against your email address.

If your threat model includes your own network operator, use Tor or a VPN. We don't block either, and we never will.

Warrant canary

As of September 4, 2026, PhenoTrade has:

  • received no subpoenas, warrants, or court orders for member data;
  • received no national security letters or gag orders;
  • handed member data to no law enforcement agency;
  • been asked by no one to weaken, backdoor, or log around the encryption described above.

This statement is updated by hand — no script can sign it. If it is not renewed by November 1, 2026, or if it quietly disappears, draw your own conclusions. A canary only means something if you notice it stop singing, so this page will say so itself once the date passes. Next renewal due in 43 days.

What we ask of you

The platform can't protect you from what you publish. Don't put your address in a listing description, crop it out of receipt photos, and keep the sensitive details in the encrypted deal room rather than a public field.

See also the privacy policy, terms, and listing policy.

Transparency & canary · PhenoTrade