Last updated: September 11, 2026
1. Information we collect
- Account information you provide: name, contact details, and credentials.
- Transaction data: orders, settlement records, and wallet activity.
- Usage data: how you navigate the network, used to operate and improve it.
- Site analytics: CNXT web pages carry Google Analytics (Google LLC), which sets first-party _ga cookies and reports page views and a small set of named events — such as a press on the Add to Chrome link for $://THeXTeNSioN — to Google Analytics properties CNXT operates: one for the site as a whole, and a second one that receives only the $://THeXTeNSioN pages (the landing page and the mining console). In the EEA, the UK and Switzerland the tag defaults to its cookieless, consent-denied mode. The browser extension itself carries no analytics.
- Device and security signals needed to keep your account safe.
- A referral marker when you arrive through a partner link, set as a cookie by our affiliate-attribution provider so the referring partner can be credited.
2. How we use it
We use your information to operate the network: fulfill orders, settle payments, resolve identities, prevent fraud, provide support, and personalize what you see. We do not sell your personal information.
3. The identity layer
CNXT anchors entities — products, datasets, apps — to canonical GTIN identities. This identity graph describes things, not people. Your personal data is held separately and is never minted into a public identity anchor.
4. Sharing
- With sellers and Hubs only as needed to fulfill your orders.
- With service providers bound by confidentiality and data-protection terms.
- With our affiliate-attribution provider (PromoteKit): if you arrived through a partner link, your account email is shared after sign-in so the referring partner is credited for your sign-up and qualifying purchases.
- With our site-analytics provider (Google Analytics, Google LLC): page views and named events from CNXT web pages, under Google's data-processing terms. IP addresses are not logged or stored by Google Analytics 4. You can opt out with the Google Analytics opt-out browser add-on or by blocking the tag; the network works the same either way.
- When required by law or to protect the network and its users.
5. Your controls
- Access, correct, or export your data from Your Account.
- Request deletion, subject to records we must retain by law.
- Manage communication and personalization preferences at any time.
6. Retention & security
We keep personal data only as long as needed for the purposes above or as required by law, and we protect it with encryption in transit and at rest, access controls, and continuous monitoring.
7. THeoPeNAiDesK CNXTioNPaRTNeR — the ChatGPT connector
THeoPeNAiDesK CNXTioNPaRTNeR is CNXT's connector for ChatGPT: a Model Context Protocol resource served by this network at https://centralbanks.app/api/theopenaidesk/gptx, with CNXT itself as the OAuth authorization server. When you use it, your prompt and the tool call ChatGPT derives from it pass through OpenAI first — OpenAI's own terms and privacy policy govern that leg; CNXT receives the tool call, not your conversation.
Anonymous read tools process only the query or identifier needed to answer: curated public knowledge, the public machine census and network status, offer information, profitability scenarios, launch requirements, and public network discovery. Nothing from an anonymous read is stored against a person.
OAuth-scoped tools process: the access token in memory for authorization; the token's issuer, audience, lifetime, signature, subject, and scopes for verification; a keyed pseudonymous actor identifier derived from issuer and subject; and, for a connection request, its category, summary, requested items, approved HTTPS endpoint descriptions, optional opaque external reference, and idempotency key — together with timestamps, status, a payload hash, and a hash-chained audit event. The connector is designed not to store the access token or the raw OAuth subject.
Draftroom tools (available only where CNXT is the authorization server) additionally process, for the CNXT account behind the token, the campaign brief you give, the caller-supplied idempotency key, the generated copy and render references, allowance and spend accounting, and the network's policy decision. These are stored by CNXT Draftroom under that account exactly as a signed-in studio session would store them, and are readable back only by the same account.
- Do not send names, emails, phone numbers, payment-card or bank data, government identifiers, passwords, API keys, bearer tokens, OAuth client secrets, access or refresh tokens, MPP credentials, private agreements, signatures, medical information, or other sensitive personal data through the connector. Likely secrets and personal contact details are rejected automatically; automated detection is not a guarantee.
- Retention: connection-request content is kept for 365 days unless a different period is published on this page. Once a request is older than that, a bounded sweep — run at the next intake write or on operator demand — redacts its content (summary, requested items, endpoint descriptions, external reference) while the audit chain, which holds hashes and never content, keeps verifying. Idempotency records are keyed hashes and carry no content.
- Deletion: ask through Your Account or the Support page; the privacy team at $://THeCeNTRaLDesK actions it. What is removed is the request content and Draftroom drafts held under your account. What survives, and why: audit-chain entries (integrity hashes carrying no content) and any settlement entries, which are financial records the network has to keep.
- Money: the connector never creates a checkout, mints a payment credential, or moves treasury funds, and Stripe is not a processor for it. Where a deployment serves the premium dataset read, it debits the caller's own CNXT wallet at the per-call price disclosed before the call and appears in that wallet's own records; the connector as submitted to ChatGPT does not serve it.
- Security, as built: HTTPS only; OAuth resource and audience binding; token signature and lifetime validation; least-privilege scopes; principal pseudonymization; explicit write confirmation; idempotency; HMAC audit chaining; secret and personal-data rejection; HTTPS-only endpoint descriptions; output redaction; and strict separation from financial execution. No security measure is absolute.
8. Text messages from the CNXT desk line
$://THeCeNTRaLDesK operates a phone line, +1 (650) 307-5424, that receives calls and — once US carrier (10DLC) registration of the line completes — sends text replies. Texts are sent only to a mobile number whose holder opted in by submitting the consent form at /texts: an unchecked box with the full consent statement, recorded with the statement's version as displayed, the time, the page it came from, a keyed pseudonym of the submitting address, and the browser identifier. A submission made against a superseded statement is refused, not recorded.
What we send: replies to your own requests, the specific links you asked for, receipts for your own transactions, and notices about your own account. We do not send marketing campaigns or broadcast texts, and we do not text numbers from purchased, shared, or scraped lists.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Mobile numbers and text-messaging opt-in data are used only to deliver the messages described above and are processed by the telephony provider that carries the line, bound by its own confidentiality and data-protection terms. The consent record itself is kept as an append-only ledger — each opt-in and each opt-out is a new entry, never an edit — for as long as needed to prove consent under applicable law.
Opting out: reply STOP to any message, or use the unsubscribe form at /texts; reply HELP for help. A stop request is recorded the same way the consent was, and every send is checked against the newest record for the number before it leaves — an opt-out, or no record at all, refuses the message. The line does not send at all until its inbound STOP/HELP handler is connected; the /texts page shows that state. Message frequency varies and message and data rates may apply. Consent to texts is never a condition of any purchase.
9. Contact
Privacy requests can be raised through Your Account or through the channels on the Support page, and are handled by the privacy team at $://THeCeNTRaLDesK. This policy is provided for transparency and is not a substitute for independent legal advice.