ONDA

Privacy

Last updated 2026-09-22

Draft — not ready to publish. Operator details are still placeholders and this text has not been reviewed by a lawyer. Set the NEXT_PUBLIC_LEGAL_* environment variables and get the wording checked before launch.

What we store

Your wallet address, and any display name and bio you choose to set.

The posts, replies, likes, reposts, follows and messages you create.

A record of trades initiated through the interface: wallet address, token, amounts, fee, transaction signature and status.

Product analytics events — the name of an action such as a completed sign-in or a started purchase, with your wallet address and a timestamp.

A session token in an httpOnly cookie, so you stay signed in.

What we never have

Private keys and seed phrases. We never ask for them and cannot use them.

We do not require an email address, a phone number or a real name to use the service.

Messages

Direct messages are stored on our server in plain text so they can be delivered and searched. They are not end-to-end encrypted, and an administrator with database access could read them. Do not send secrets through them.

If you explicitly choose to write a message on chain, it becomes permanent and publicly readable by anyone, forever, and cannot be deleted by us or by you.

Public by nature

Your wallet address, posts, follows and the on-chain activity shown on your profile are public. Blockchain data is public by design and we only read it — we do not create it and cannot remove it.

Deleting a post removes it from this service. It does not affect anything recorded on a blockchain.

Third parties

A Solana RPC provider receives wallet addresses in order to return balances and transaction history.

Jupiter receives token addresses and amounts in order to quote and build swaps.

These providers have their own privacy practices, which we do not control.

Retention and your rights

Analytics events are deleted after 90 days and notifications after 180 days. Posts and messages are kept until you delete them or ask us to.

To request access to or deletion of your data, write to [contact email] from a context that lets us verify control of the wallet.

[If you serve users in the EU, confirm your lawful basis, your data-processing agreements with the providers above, and whether a Data Protection Officer is required.]

Cookies

One cookie: the session token that keeps you signed in. It is httpOnly, same-site, and set only after you sign the authentication message.

No advertising or cross-site tracking cookies are set.