Privacy policy
Last updated: 6 October 2026
This policy explains what LOADED collects, why, who else sees it, and how long we keep it. It covers this website, the public API, the launch tools and the Telegram and X bots we run. There is no account to create: you connect a wallet, and we never see its private key or seed phrase. The one exception is the optional Google sign-in, where we create a wallet for you and keep its key encrypted (below).
What we collect#
- Wallet addresses and on-chain data. The public address you connect, its coin balances for LOADED coins, its pool position, and transaction signatures. This data is already public on Solana; we index it to show your portfolio, your score, your referrals, the holder lists and the vault logs.
- What you submit when launching. The name, ticker, description, links and image. They go to an AI model for moderation, are written to the chain at creation and cannot be removed from it, and the metadata document pump.fun reads is served publicly by LOADED (and on mainnet stored permanently on Arweave). Treat them as public. A description you type into the launch assistant is sent to the model and not stored beyond the request.
- Product analytics. First-party events (a page viewed, a quote shown, a deposit made) with a random per-tab session id kept in
sessionStorage, the connected wallet hashed with a salt that changes daily, and no cookies. Honoured:Do Not Trackturns it off entirely. We use it to count what works; nothing in it is sold or shared. - Referral and season ledgers. Which wallet referred which, and the hold-time, streak and league computed from public chain history for the seasons.
- Technical logs. IP address, user agent and request metadata, used for rate limiting, abuse detection and security.
- Google sign-in (only if you use it). Your Google account id and e-mail address (we ask Google for
openid emailonly: no name, photo or contacts); the Solana wallet we create for that account, with its private key encrypted (AES-256-GCM) under a key only the accounts service holds; your sign-in sessions; and a log of each sign-in, signature, key export and deletion with the IP address it came from. - Reports and correspondence. What you send us when you report a coin or e-mail us, including the contact details you give.
We do not collect names, e-mail addresses (unless you sign in with Google or write to us), card numbers, bank details, government identifiers, biometrics or precise location. There is no KYC. We run no third-party analytics or advertising trackers and show no ads.
Why we use it#
- To run the site: show the chain's state, build the transactions you sign, moderate launches, pay referrals, score seasons.
- To keep it safe: rate limiting, abuse detection, sybil checks on seasons and referrals, legal compliance.
- To show public activity: the feed, the boards, the vault logs, the holder lists, the leaderboards and the bots' posts display wallet addresses and amounts. All of it is already public on chain.
We do not sell personal data and do not use it to train models of our own.
Who else sees it#
- Solana RPC providers (Helius) and Solscan — on-chain reads and transaction broadcasts. Your browser talks to the chain through our read-only RPC proxy where the site is configured to, else to the public RPC directly; your wallet talks to its own RPC.
- pump.fun and PumpSwap — the program and pools your trades interact with. They see wallet addresses and amounts, as any chain interaction does, and pump.fun fetches a coin's public metadata document from us.
- Google — sign-in, if you choose it: Google learns that you signed in to LOADED, and sends us your account id and e-mail address.
- Anthropic, OpenAI, OpenRouter and Google — AI models for moderation, the launch assistant, narration and the analyst desk, under their API terms. Launch content and public coin numbers are sent; no wallet-identifying data beyond what is on chain.
- Pyth, Jupiter and CoinGecko — SOL/USD prices; they receive no user data.
- Arweave (ArDrive Turbo) — permanent storage of coin metadata and images on mainnet.
- Railway — hosting for the site, the indexer, the agent, the AI service and the accounts service (Google sign-in, encrypted keys).
- X and Telegram — only when the platform posts about a coin or a vault event; posts contain public chain information only.
- Authorities and claimants — when the law requires it, for example a valid DMCA notice, subpoena or court order.
Cookies and local storage#
No cookies, except for Google sign-in: the accounts service sets an http-only session cookie (7 days) and, during the sign-in round trip, a 10-minute cookie that ties Google's answer to your browser. The site keeps your wallet-adapter preference, a dismissed-notice flag and the analytics session id in your browser's local or session storage; clearing it clears them. On test clusters a throwaway burner wallet's key is kept in local storage of your browser alone and never sent to us.
How long we keep it#
- Indexed chain data, ledgers and season scores: for as long as LOADED operates; they are a copy of public history and document payouts.
- Product analytics: raw events 90 days, daily aggregates indefinitely; the wallet hash cannot be reversed after its day's salt is gone.
- Technical logs: 30 days, then deleted.
- Google accounts: the account, its e-mail and the encrypted key until you delete the account (wallet menu → Export key → Delete account, possible once the key is on your screen) or ask us to; sessions end after 7 days; the sign-in and signature log 2 years.
- Reports and correspondence: 2 years after the matter is closed.
Your choices and rights#
Depending on where you live you may have the right to access, correct, export or delete your personal data, or to object to some processing. E-mail the privacy address below, signing a message from the wallet concerned, and we will answer within 30 days. One honest limit: we cannot delete anything recorded on Solana or stored on Arweave, because none of it is ours to erase; we can stop showing a wallet's handle or hiding it from leaderboards. A Google account can export its key or delete itself from the wallet menu at any time.
Security#
We hold no user keys except for wallets created by Google sign-in. Those keys are encrypted at rest, decrypted only in memory to sign, and signed with only for what the policy in the terms allows. The platform keys that sign vault trades hold fee float only and can never withdraw user funds except through the admin's disclosed instructions, listed on the trust sheet. If we discover a breach affecting your data we will tell affected users and, where required, regulators.
Children#
LOADED is not for anyone under 18 and we do not knowingly collect data from children.
Changes#
The date at the top changes when this policy changes, and material changes are announced on @loadeddotfun.
Contact#
- Privacy and data requests: privacy@loaded.fun
- Abuse, impersonation and security reports (bug bounty): security@loaded.fun
- Copyright (DMCA) notices: dmca@loaded.fun