Terms of service
[OPERATOR: lawyer review] This whole document is a working draft written for the Hashlock product as built. Have counsel review it, fill in the operating entity and governing law, then bump the terms version on the server so signed-in users accept it again.
The short version
- Hashlock never holds your keys. Your Solana wallet signs your launches and trades. Your vault's key is a 24-word phrase made in your browser; it never reaches our servers.
- Nobody can recover a vault. If you lose the 24 words, what the vault holds cannot be moved by you, by us or by anyone. There is no reset.
- Every coin pays the flywheel. A share of each coin's creator fees (currently ) goes to one Hashlock platform wallet.
- Post-quantum has limits. The vault program checks a hash-based signature before anything leaves a vault. Your wallet, the fee payer, pump.fun's programs and Solana itself still use classical (Ed25519) cryptography. Section 5 says exactly what that means.
1. Acceptance
By using the Hashlock website and app ("the Service") you agree to these Terms. If you do not agree, do not use the Service. Continued use after an update means you accept the updated Terms.
2. What the Service is
The Service lets you launch coins on pump.fun with a dev buy, list and trade coins on a public board, and choose where a coin's creator fees go:
- Sealed: the creator share is paid to your post-quantum vault, and the dev buy is moved into it. Moving anything out needs a hash-based signature made from your 24 words and checked on chain by the vault program.
- Fee wallet: the creator share is paid to a Hashlock fee wallet held for your account in Privy (section 4).
- Agent: the creator share is paid to your fee wallet and the fee agent works it automatically (airdrops, buy and burn of the coin, liquidity). An agent-run coin is not sealed.
Anyone may also open a vault and seal tokens they hold. Coins on the Service are created permissionlessly by their launchers, not by Hashlock; listing a coin is not an endorsement or a check of any kind. The Service is operated by [OPERATOR: legal entity name] ("we", "us").
3. Eligibility
You may use the Service only if you are of legal age and permitted to do so where you live, and you are not subject to sanctions or located in a jurisdiction where using it is prohibited. You are responsible for checking that. [OPERATOR: lawyer review: restricted jurisdictions list]
4. Wallets and keys
- Your wallet. You sign in and sign transactions with your own Solana wallet (Phantom, Solflare, Backpack or any other Wallet Standard wallet), or sign in with X. Your wallet's keys stay in your wallet. Launches, trades, vault deposits and vault withdrawals are signed by your wallet in your browser.
- Fee wallets (Privy). If you choose the fee wallet or the agent, fees go to a wallet created for your account in Privy's secure enclave. Hashlock never stores its private key; it asks Privy to sign when you claim or when the agent works. Any system that signs on your behalf can fail or be compromised; you accept that risk for fee wallets.
- No private keys on our servers. We do not store, log or receive the private key of your wallet, your fee wallet or your vault.
5. Post-quantum vaults
A vault is an account of the Hashlock vault program on Solana. What it holds sits at the vault's owner address and can only be moved by a one-time hash-based signature (WOTS+ in an XMSS-style tree) that the program verifies on chain.
- The 24 words are the key. They are generated in your browser, shown once and never sent to us. Anyone who has them can move what the vault holds. We cannot see them, store them, reset them or recover them. If you lose them, the vault's contents are permanently out of reach. Write them on paper and keep them safe.
- Non-custodial. Hashlock cannot move, freeze or recover anything in your vault. We keep only public data about it (its address, root and a count of used one-time keys).
- One-time keys. A vault has 1,024 one-time keys; each withdrawal or record uses one. The site tracks them to avoid reuse, but signing two different messages with the same key weakens it. When the keys run out the vault can no longer move funds; move them to a new vault before that.
- What stays classical. Your wallet pays the network fee for every vault transaction and signs as the fee payer with Ed25519. A fee payer cannot change what a vault signature allows, but it can refuse to send. pump.fun's programs are controlled by pump.fun and use classical keys: fees are only behind the vault once they reach it. Solana's validators and consensus use classical cryptography.
- Who can change the vault program. A program that can still be upgraded could have its signature check replaced by whoever controls the upgrade. The current status, read from the chain: [OPERATOR: lawyer review: confirm this wording matches the deployed program before production.]
- If the Service is offline. A vault does not depend on the Service. The recovery page withdraws with only the 24 words, a Solana RPC and a wallet, and can be saved as a single file.
- Wallet-derived vaults. If you choose to derive a vault key from a wallet signature instead of 24 words, that vault is only as strong as your wallet's Ed25519 key. It is labelled not post-quantum.
- Unsupported tokens. Transfer-hook, non-transferable and frozen tokens cannot be withdrawn from a vault, so the Service refuses to seal them. Tokens with a permanent delegate can be moved by that delegate even from a vault; the Service warns you.
- "Post-quantum" describes the kind of signature used, not a guarantee. No system is unbreakable.
6. Fees
Every coin launched or routed through the Service locks a pump.fun fee-sharing configuration that pays a share of its creator fees, currently (shown before you launch), to one Hashlock platform wallet. Of what that wallet receives: The rest of the creator fees go to the destination you chose (vault, fee wallet or agent). The fee-sharing configuration is locked on chain and cannot be changed afterwards. [OPERATOR: confirm the live percentages and the agent claim fee before promotion]
Collecting a sealed coin's fees is permissionless: anyone may pay the small network fee to move the fees to every shareholder (the vault and the platform wallet). Solana network fees and rent are separate, paid by the wallet that signs, and never received by us.
7. Launches, trades and the agent
- Transactions are irreversible once confirmed. You are responsible for every parameter you approve in your wallet.
- A launch has more than one step (for a sealed coin: the launch and its vault record, then the fee split and the dev bag). Until the last step lands, the coin is live but its fee split or seal is not finished; the Service keeps reminding you until it is.
- The agent makes automatic decisions from market data that can be wrong, stale or late. It may delay, reduce or skip actions. Rewards, burns and prices are not guaranteed.
- Holder lists, balances and prices come from third parties and the chain and can be incomplete or wrong.
8. Availability and data
The Service depends on hosting, RPC providers, pump.fun, Privy and other third parties, any of which can be slow or unavailable. Data shown may be cached, delayed or wrong; check anything that matters on chain. If something looks wrong, email [email protected]. A report does not create a right to compensation.
9. Acceptable use
Use the Service lawfully and only with wallets, vaults and coins you control. Do not use it to defraud or mislead anyone, to get around rate limits or access controls, or to attack the Service or other users. We may restrict or end access for anyone who breaks these Terms.
10. Your responsibility
You are responsible for whether your use is lawful where you are, including tax, securities and money-transmission rules, and for any tax on launches, trades, fees and distributions.
11. Liability and warranties
The Service is provided as is and as available, without warranties of any kind. To the maximum extent the law allows, we are not liable for any indirect or consequential loss, or for any loss of funds, including funds in a vault whose words are lost, funds affected by third-party programs, or losses from outages, bugs or wrong data. Our total liability is limited to USD 10. You agree to indemnify us against claims arising from your use of the Service or your breach of these Terms. [OPERATOR: lawyer review]
12. Third parties
The Service uses or links to Privy, pump.fun, Jupiter, GMGN, DexScreener, X, Telegram, Solana RPC providers and wallet providers. Their terms and privacy policies apply to your use of them.
13. Intellectual property
The Hashlock name, design and code belong to [OPERATOR: legal entity name]. Coin names, symbols and images belong to their creators.
14. Governing law
[OPERATOR: lawyer review: governing law and venue]
15. Changes
We may change these Terms and will update the date above. Signed-in users may be asked to accept the new version.
16. Contact
Questions about these Terms: [email protected].