Privacy policy
Last updated: [date]
This policy explains what data Quota collects, why, and what choices you have. We collect as little as we can: there are no accounts, emails or passwords.
1. Data we collect
- Wallet addresses. When you connect a wallet, sign in, launch a token, trade, or burn credits, the API sees your public wallet address. Wallet addresses and all transactions are public on the Solana blockchain.
- Sign-in sessions. When you sign in, we store a session token (hashed) linked to your wallet, its expiry, and the signed message.
- API keys. We store a hash and a short prefix of each key, its name, caps, creation and last-used times. We never store the full key.
- API usage logs. For every AI request we store the time, key, model, token counts, cost and status, to bill you and show your usage history. We do not store the content of your prompts or responses. The upstream AI provider processes your content under its own policy.
- Launch details. The name, symbol, image, description and links you submit for a token are published permanently to decentralized storage and the blockchain.
- Technical data. Our servers log IP addresses and request metadata for security and rate limiting, kept for a short period.
- Local storage. Your browser stores your theme preference and your session token. Nothing is used for advertising or cross-site tracking.
2. What we don't do
- We never take custody of your funds or see your private keys or seed phrase.
- We do not sell your data or use it for advertising.
3. Why we use it
To run the Service: authenticate you, credit burns to your balance, bill API usage, enforce caps and rate limits, prevent abuse, and show public statistics (such as fees claimed and credits distributed per token).
4. Who we share it with
- AI providers and routers (for example OpenRouter) receive the content of your API requests in order to answer them.
- Infrastructure providers (hosting, Solana RPC, decentralized storage) process data on our behalf.
- Authorities, when required by law.
5. Retention
Usage and billing records are kept as long as needed for accounting and abuse prevention. Expired sessions are deleted periodically. On-chain data and published token metadata cannot be deleted by anyone.
6. Your choices and rights
You can log out on every device at any time, and revoke API keys. Depending on where you live you may have rights to access, correct or delete your data; contact us at [contact email]. We cannot alter blockchain records.
7. Changes
We will post changes on this page with a new date. See also the terms of service.