Privacy policy
[OPERATOR: lawyer review] Working draft for the Hashlock product as built. Fill in the operating entity and have it reviewed before production.
1. Who we are
Hashlock is operated by [OPERATOR: legal entity name] ("we", "us"). This policy covers the Hashlock website and app ("the Service").
2. What we never receive
- Your wallet's private key. Your wallet signs in your browser; only signatures and public addresses reach us.
- Your vault's 24 words, seed or one-time keys. They are made and used only in your browser's memory. They are never sent to us, logged or stored.
- Fee wallet keys. Fee wallets are held in Privy's secure enclave; we ask Privy to sign and never hold the key.
3. What we collect
- Account: the Solana address you sign in with (wallet sign-in), or, with X through Privy, your Privy identifier, X handle, display name and picture. The date, version and IP address when you accept the Terms.
- Vault (public data only): the vault's address, its owner address, its Merkle root and public seed, its height, the transaction that created it, and a count of one-time keys used (so a key is never reused). All of it is public on chain anyway.
- Coins and settings: coins you launch or route, their metadata and images, fee choices (sealed, fee wallet or agent), agent settings, pending launch steps and reminders, and records of launches, collections, claims, airdrops, buys and burns with their transaction signatures.
- Optional: Telegram chat ID and username if you connect alerts; issue reports you send.
- Technical: IP addresses for rate limits and abuse prevention, server logs of account actions, limited error diagnostics (never keys or tokens), and one session cookie.
4. How we use it
To sign you in, run the launches, vault steps and agent actions you choose, show public coin and vault pages, keep the fee ledger, send alerts you turn on, prevent abuse, investigate reported problems and record your acceptance of the Terms.
5. Public information
Blockchain transactions are public and permanent. Coin pages and vault pages show on-chain data, including a vault's holdings, its used one-time keys and the coins it launched, to anyone. We cannot change or delete on-chain data.
6. Who we share data with
We do not sell, rent or trade personal data. We share only what each provider needs:
- Privy: X sign-in and fee wallet custody
- X and Telegram: sign-in with X, alerts you opt into
- Railway: hosting and database
- Cloudflare: CDN and DDoS protection (IP addresses and request metadata)
- Solana RPC providers, pump.fun, Jupiter, GMGN and DexScreener: chain and market data and transaction routing (they see wallet and coin addresses, not your account)
- esm.sh and Google Fonts: deliver some code libraries and fonts to your browser, which exposes your IP address to them
We may disclose information when the law requires it or to protect the Service, its users or the public.
7. Storage and security
Data is stored in a PostgreSQL database hosted on Railway and sent over HTTPS. No storage or transmission is perfectly secure.
8. Retention and your rights
Account data is kept while your account is active or until you ask us to delete it; some ledger and Terms records may be kept longer for accounting, security or legal reasons. Sessions expire after 30 days without activity. Depending on where you live you may have rights to access, correct or delete your data: email us. On-chain data cannot be changed. Deleting your account does not affect your vault: it is yours on chain and only your 24 words move it. [OPERATOR: lawyer review]
9. Cookies and local storage
One session cookie keeps you signed in. Your browser's local storage keeps preferences such as theme, the last wallet you used and recent coins. Nothing about your vault key is ever written to local storage. No advertising cookies.
10. Children
The Service is not for anyone under the legal age where they live. Contact us if you think a child's data reached us and we will delete it.
11. Changes
We will update the date above when this policy changes.
12. Contact
Privacy questions and deletion requests: [email protected].