Privacy Policy
What This Covers
This Privacy Policy describes what information pumphood (this website, the pumphood smart contracts on Robinhood Chain, and any pumphood-operated API endpoints) collects, how we use it, and how you can control it. pumphood is operated as a non-custodial, open protocol; we collect the minimum data necessary to provide launching, fee distribution, and X-handle resolution features.
Information We Collect
- Wallet address — your connected EVM address (external or Privy-embedded), automatically read by the browser when you connect a wallet.
- X (Twitter) account data — username, display name, profile picture URL, and a stable subject (sub) identifier, obtained via Privy OAuth. Used to render @handle attribution and resolve handle-routed launches.
- Email address— only if you sign in via Privy email login. Stored by Privy; we don't maintain a separate copy.
- Token metadata — name, symbol, description, social links, and logo image you submit on launch. Pinned to IPFS via Pinata and indexed in Upstash Redis keyed to the token address.
- On-chain data — token launches, trades, fee collections, and vault claims are public by nature. We do not control or restrict access to this data.
- Server logs — standard request logs (IP, user-agent, path, status) retained briefly for debugging and abuse prevention. Not used for advertising or sold to third parties.
How We Use This Information
- Operate the Platform — launch tokens, route fees, resolve @handles
- Render attribution + transparency UI (deployer, fee recipient, profile pages)
- Cache token metadata for fast UI loads via Upstash Redis
- Prevent abuse + diagnose bugs via brief request log retention
What We Do NOT Do
- Sell personal data to third parties
- Run advertising / analytics trackers (no Google Analytics, no Facebook pixel)
- Custody your private keys — Privy embedded wallets are exportable and remain yours
- Maintain a public "handle → address" registry (resolution is per-request, not enumerable)
Third-Party Services + Data Sharing
The following services process your data on our behalf. Each has its own privacy policy:
- Privy (privy.io) — X OAuth, embedded wallet provisioning, session verification
- Pinata (pinata.cloud) — IPFS pinning for token logos + metadata
- Upstash (upstash.com) — Redis cache of metadata + response cache for /api/v1
- Vercel (vercel.com) — application hosting + serverless function execution
- RPC providers (e.g. Alchemy) — reading + writing to Robinhood Chain
Cookies + Local Storage
We use only essential cookies + browser storage required for authentication (Privy session token) and UI state. No third-party tracking cookies, no advertising IDs.
Data Security
We implement reasonable safeguards including encrypted transit (HTTPS), minimum-privilege server credentials, and rotation of administrative keys. However, no system is 100% secure. By using the Platform you accept the residual risk of breach beyond our control.
Your Rights
- Disconnect / delete your Privy account at any time via your account dashboard — this removes your @handle ↔ wallet linkage from our resolver
- Request export of any token metadata you submitted via the contact channels on this site
- On-chain data (launches, trades, claims) is immutable and cannot be removed retroactively
Children
The Platform is not directed at users under 18 and we do not knowingly collect data from minors. See the Terms of Service for the eligibility requirement.
Changes to This Policy
Material changes will be reflected in the "last updated" date at the top of this page.
Contact
Privacy questions can be directed through the contact channels listed on this site.
