Skip to content
Sherwood
Join the waitlist

Privacy Policy

Effective October 6, 2026

This Privacy Policy explains how Sherwood Labs, Inc. (“Sherwood Labs,” “we,” “us”), the company that builds and operates the Sherwood Protocol (“Sherwood”), collects, uses, and shares information when you use the sherwood.sh website and the Sherwood explorer (together, the “Services”). Sherwood is a non-custodial protocol for agentic finance: people deposit into onchain funds, AI agents manage strategies, and smart contracts enforce the rules.

We designed the Services to collect as little personal information as possible. You do not need an account to use the website or the explorer, we do not use third-party advertising, and we do not sell your personal information. If you join the waitlist to create a vault, we collect the information described in “Waitlist” below. We do not use cross-site tracking.

Information we process

Wallet address and onchain activity.When you connect a wallet, we process your public wallet address to show your balances, positions, and governance activity. Your keys stay in your wallet — connecting never shares them with us. Information recorded on public blockchains (deposits, withdrawals, votes) is public by nature and is not controlled by Sherwood. If you paste a wallet address into the waitlist, see “Waitlist” below.

Local data.The Services store settings — such as your theme and language — locally in your browser so pages load the way you left them. This data stays on your device. The waitlist also uses cookies, described in “Waitlist” below.

Analytics. We use Vercel Web Analytics, from our hosting provider Vercel, to count page views and a few product events, such as connecting a wallet, confirming a deposit or withdrawal, or casting a vote. It does not use cookies, and we do not record or replay your sessions.

Infrastructure logs. Like nearly every website, our hosting and RPC infrastructure processes technical data (such as IP addresses and request logs) to serve pages, read public chain data, and prevent abuse.

Waitlist

Creating a vault on Sherwood is by invitation at launch. If you join the waitlist at sherwood.sh/waitlist to apply, we collect the following:

Your X account.You sign in with X. X’s permission screen says Sherwood can read your posts; we read only your account id and handle, and we do not read or store your posts. We never post on your behalf.

Your email address. You confirm it with a six-digit code we send to it. We store the address as you typed it, along with a one-way hash of a standardized form of it, which we use to stop one inbox from joining twice. The code itself is stored only as a hash, expires after 10 minutes, and is deleted once it is used or after five wrong attempts. To limit abuse, we keep a record of each code we send (your X account ID, the email hash, and the time) for about an hour.

A wallet address. You paste the wallet address you would use to create a vault. You do not connect or sign with that wallet, and we cannot confirm that you control it.

Your agent harness. When you submit your wallet address, you choose from a fixed list which agent harness you run, and we record your choice.

Your IP address and the country and region it indicates. When you submit or change your wallet address, we record the IP address you submitted it from and the country and region it appears to come from, as reported by our hosting provider. We keep only the most recent ones. This is separate from the infrastructure logs described in “Information we process” above.

We keep one waitlist record per X account. It holds your X account ID and handle, your email address and its hash, the wallet address, the agent harness you chose, your IP address and the country and region it indicates, the times you signed up and joined, and the decision we make on your application.

Why we collect it. We use this information to review applications, decide which wallets Sherwood Labs sponsors to create a vault, and email you about your application and the waitlist. We use your IP address and the country and region it indicates to review applications for abuse and to help assess eligibility. The waitlist decides who may create vaults. It does not decide who may deposit.

Emails we send. Joining the waitlist means we email you about your application and the waitlist: the verification code, a confirmation once you join, notices about the status of your application, including a notice if your wallet is approved, and service notices about the waitlist and the launch. When you confirm your email address, we add it to the list we use to send you notices about your application and the waitlist. That list is held at Resend and is not used for marketing. We send these emails through Resend, which processes them on our behalf. We do not track whether you open them or which links you click. Status and service notices include a link to stop them, and you can use it at any time; stopping them does not remove you from the waitlist. The verification code and the confirmation are needed to run the waitlist, so they cannot be stopped.

Where it is held.Your waitlist record is stored in Sherwood Labs’ database, which is run by our hosting provider. Your email address is also held by Resend, the provider we use to send email.

If your wallet is approved. Approval is recorded onchain: a public transaction marks the wallet address as sponsored to create a vault. That transaction contains the wallet address. It does not contain your X account or your email address. Like all blockchain records, it is public and cannot be deleted.

Cookies. While you use the waitlist page, we set a cookie that keeps you signed in to the waitlist for up to 7 days, and a short-lived cookie that secures the X sign-in step. These cookies are needed for the waitlist to work. We do not use them for advertising or to track you across other sites.

Keeping and deleting your information. We keep your waitlist record until you ask us to delete it or until the waitlist closes, whichever comes first, unless we must keep it longer to comply with the law. Your IP address and the country and region it indicates are part of that record: they are kept with it and deleted with it. To have your waitlist record deleted and your email address removed from Resend, email support@sherwood.sh from the address you joined with. We cannot delete an onchain record of an approved wallet.

How we use information

  • To operate the Services and display public onchain data.
  • To review waitlist applications and decide which wallets Sherwood Labs sponsors to create a vault.
  • To email waitlist applicants about their application and the waitlist.
  • To secure, debug, and improve the Services and prevent abuse.

Sherwood does not provide personalized investment advice. The Services are informational tools, not a licensed financial advisor.

Service providers we share with

We rely on infrastructure vendors that process information only to provide the Services on our behalf: hosting providers that serve the website and run our database, blockchain RPC providers that read public onchain data, and Resend, which sends our email. If you join the waitlist, you sign in with X; X’s own privacy policy governs what X collects when you do. We may also disclose information if required by law or to protect the rights, safety, and security of our users and the Services.

Data retention and deletion

Apart from the waitlist, we do not maintain user accounts, so there is nothing to delete on our side beyond short-lived infrastructure logs. Waitlist records are kept and deleted as described in “Waitlist” above; to ask for deletion, email support@sherwood.sh. Local settings can be cleared through your browser at any time. Public blockchain records cannot be deleted by anyone, as they are not under our control.

Security

Your keys never touch our systems — transactions are signed in your own wallet. We use industry-standard measures (including encryption in transit) to protect the information we process. No method of transmission or storage is perfectly secure.

Children

The Services are not directed to children and are not intended for anyone under 18. We do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy from time to time. We will revise the “Effective” date above and, for material changes, take additional steps as required by law.

Contact

Questions about this policy or your data? Email contact@sherwood.sh.