Unpaid SonPrivacy notice · September 24, 2026

Privacy notice

Public research does not require an account. Guests and members can verify a wallet and purchase access. This page explains what those features save.

Browsing and sign-in

Hosting providers process network requests, including IP addresses, device information, and operational logs. We have not added advertising trackers or visitor analytics. The application uses short-lived hashed request identifiers for abuse limits.

A guest session creates a random profile identifier. Guest and account sessions use a secure, HTTP-only cookie that expires after seven days; the database stores a hash of its secret. Clearing cookies removes access to an unlinked guest session. You can recover a profile through a wallet you previously verified, or through an email account you created from that guest session.

Wallet sign-in uses a signed message and a one-use challenge that expires after five minutes. We store the public wallet address and verification/holder status. We never request your seed phrase or private key. A sign-in or ownership signature does not move funds.

When email, Google, or Apple sign-in is enabled, Supabase Auth processes the email and provider identity needed to authenticate you. Google or Apple also processes its own sign-in. Our application database stores the resulting identity identifier, not your email, password, or provider access token. For a new account, we may also save a name shared by your sign-in provider as your editable public display name. We do not import your wallet app’s private profile name or photo. The email provider delivers the sign-in link. Use only methods shown as available on the sign-in page.

Content, payments, and saved research

  • Community: chosen names, comments, signed calls, associated public wallet addresses, and timestamps are stored and displayed publicly. A signed call includes its message and signature. Do not publish sensitive personal information.
  • Payments: we save the order, plan, mint, amount, payer wallet, reference, transaction signature, and timing needed to verify and deliver purchases. Blockchain transfers are public. We do not collect card numbers or custody your wallet.
  • Position Watch: we save your mint, fixed USD scenario, thresholds, baseline, latest snapshot, and check results. Each watch keeps its most recent 10 snapshots for guests or 200 for accounts. You can remove a watch and its history from the site.
  • Other research: the market watchlist stays in browser local storage. Paid saved identity reports are stored under your guest profile or account. The one-off Investigator brief is computed on request.
  • Support: feedback, private founder messages, and payment/privacy requests, plus operator replies, are stored privately under your session or account. The site operator can review them. Never submit a seed phrase or private key.

Research agents

Agent names, token mints, research focuses, optional questions, source snapshots, AI summaries, run times, and source failures are saved privately under your profile. Guest profiles keep the latest 10 reports per agent; accounts keep 30. Deleting an agent removes its saved configuration and reports from the application database. Export is available in the research log.

When AI summaries are connected, we send the token mint, research focus, optional question, public source snapshots, and calculated changes to OpenAI. We do not include your sign-in email, wallet proof, payment records, or session secret. Do not put secrets or personal information in research questions. We request that API responses not be stored as retrievable response history; the provider may still retain data under its service and abuse-monitoring policies. Evidence mode does not send a request to OpenAI. Reports stay private unless you export or share them yourself.

Community moderation and ad creatives

We store submitted ad headlines and banner styles with their payment requests. Community reports store the reporting account identifier, post identifier, reason, and time for private operator review. Moderation records mark hidden posts; hiding a post does not erase its stored content. Automated checks run on submitted text for common abuse and scam patterns, without sending the text to an external AI moderation service. Records currently have no fixed automatic deletion period; use Support for a privacy request.

Referral links and rewards

Opening a valid referral link creates a secure, HTTP-only, first-party attribution cookie lasting 30 days. We store a hash of its random identifier and the referrer identifier; it is not a third-party advertising tracker. The first valid link remains active until expiry, and changing domains or clearing cookies can lose attribution. Expired referral visits are removed during the next completed monitor run.

Referral accounts save their fixed public payout wallet, share code, accepted terms version, purchase attribution, holder tier at checkout, commission amounts, review notes, and payout signatures. The operator can see payer and referrer wallets to review fraud and verify transfers. Referrers see their rewards and statuses but not the buyer’s account identity. Records are retained for reconciliation and disputes; no fixed automatic deletion period applies to reward or payout records. Blockchain transfers remain public. Use support for privacy requests.

Telegram and external data

If Telegram delivery is enabled and you choose to link your chat, we store its chat identifier and send the watched token and relevant change summary to Telegram. A linking code expires after ten minutes. Disconnect on the site or send /stop to the bot to remove the link. Telegram keeps delivered messages under its own policies.

DEX Screener supplies public token and pool information. Solana RPC supplies balance and transaction checks. These services receive the public addresses needed for a lookup. Token artwork may load from external image hosts. Hosting, authentication, email, and Telegram providers process the information required to run their services. Following external links takes you to those providers’ sites.

Owner service connections

The private operator panel stores configured authentication keys, Telegram bot credentials, and RPC connection details encrypted in the application database. The encryption key is stored separately as a hosting secret. Only the authorized operator can change connections; status responses do not return these credentials. The runtime decrypts them to contact the selected providers. SMTP and social-provider secrets entered in Supabase remain with that provider.

Retention and choices

We do not sell account records or wallet verification data. We retain account, support, payment, and public content records as needed to operate the service, reconcile purchases, and resolve requests. Session expiry prevents access even before expired rows are removed. Snapshot limits are enforced on checks; removal deletes a watch’s saved snapshots. Other records do not yet have a fixed automatic deletion period.

Use Support & privacy requests for access, correction, export, or deletion requests. Replies appear in that same session or account, so keep access until resolved. Requests are reviewed by the operator; automatic account deletion is not available. Clearing browser storage also removes the local market watchlist. The site cannot erase blockchain records or copies of public posts held by others.

Changes

This notice will be updated when data handling changes. The date above identifies this version.

← Back to market desk · Disclosures · Terms