Two things you cannot undo
The blockchain is permanent and public. Every trade, token launch and transfer you make is recorded on Solana forever, by the network, not by us. Your wallet address is a pseudonym: if it is ever linked to your identity, your entire history becomes linkable too. We cannot delete anything from the blockchain.
IPFS uploads are permanent and public. Token images and metadata are published to IPFS, a distributed network. Once published, copies may persist indefinitely on machines we do not control. Never upload anything private.
1.Who is responsible for your data
1.1The controller responsible for your personal data is PumpFlare, the operator of https://pumpflare.fun.
1.2For any privacy question or to exercise your rights, contact us via Telegram (@pumpflaresupport). We answer within one month, as required by the GDPR.
1.3This policy covers https://pumpflare.fun and our API. It does not cover the Solana blockchain, your wallet provider, or third-party sites we link to.
2.What we collect, why, and on what legal basis
2.1We deliberately collect little. There is no account with a name, no password, and we never ask for an email address to use the Platform.
| Data | Why we process it | Legal basis (GDPR Art. 6) | Retention |
|---|---|---|---|
| Wallet address (public key) | Identifies your account, links your settings, watchlists, orders and rewards | Contract (Art. 6(1)(b)) — needed to provide the service you asked for | Until you ask for deletion; see §6 |
| Sign-in signature and one-time nonce | Proves you control the wallet, prevents impersonation | Contract; also legitimate interest in securing accounts (Art. 6(1)(f)) | Nonce: 5 minutes. Session: 7 days |
| IP address | Rate limiting, abuse and fraud prevention, security logging | Legitimate interest (Art. 6(1)(f)) in keeping the service available and secure | In-memory, minutes; server logs up to 30 days |
| Trading activity you perform through us (orders, alerts, automation rules, paper trades) | Executing what you asked for, showing your history | Contract | Until deletion; see §6 |
| Encrypted private keys of in-app wallets you generate | Signing transactions you or your automation rules instruct | Contract — you opt in by creating the wallet | Until you delete the wallet; see §5 |
| Profile you choose to add (display name, bio, avatar, links) | Showing your public profile | Consent (Art. 6(1)(a)) — entirely optional | Until you remove it |
| X (Twitter) account ID and handle, if you connect one | Verified-launch badge, proving one X account per wallet | Consent — you initiate the connection and can disconnect | Until you disconnect |
| Telegram chat ID, if you link the bot | Delivering notifications you asked for | Consent | Until you unlink |
| Web-push subscription | Delivering browser notifications you asked for | Consent | Until you revoke permission or it expires |
| Community posts, comments, reactions, uploaded images | Publishing them, moderation | Contract and legitimate interest in moderating content | Until you delete them, or removal on moderation |
| API keys and per-day request counts | Authenticating API access, enforcing quotas, billing | Contract; legitimate interest in preventing abuse | Key until revoked; usage counters 12 months |
| Aggregate usage statistics | Understanding what to improve | Legitimate interest | Aggregated, not linked to you individually |
2.2Public blockchain data. We run an indexer that reads the Solana blockchain and stores trades, tokens and prices — including activity by wallets that have never used PumpFlare. This data is already public by design. We use it for charts, market data, trader statistics and our API. Legal basis: legitimate interest (Art. 6(1)(f)) in operating a market-data service. You can object — see §7.
2.3We do not collect special-category data, we do not run advertising profiling, and we do not sell personal data to anyone.
5.Security, and the honest limits of it
5.1Private keys of in-app wallets are encrypted with AES-256-GCM before being written to the database, and are decrypted only in memory at the moment a transaction is signed. Sessions use signed, HttpOnly cookies. Access to production systems is restricted. Sensitive endpoints are authenticated and rate-limited.
5.2No system is perfectly secure, and we will not pretend otherwise. A key stored on a server is inherently more exposed than one held only by you. If you are not comfortable with that, do not use in-app wallets — connect your own wallet and sign each transaction instead.
5.3If a breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Art. 33–34.
5.4Found a vulnerability? Please report it via Telegram (@pumpflaresupport) before disclosing it publicly. We will not pursue legal action against good-faith researchers who avoid privacy violations, data destruction and service disruption.
6.How long we keep data
6.1Retention periods are in the table in §2. In general we keep account data while your account is in use, and delete or anonymise it on request.
6.2Some data outlives a deletion request: indexed public blockchain data (it is public and not sourced from you), records we must keep for accounting or legal-defence purposes, and content already published to IPFS or the blockchain.
6.3Server logs containing IP addresses are kept for up to 30 days for security purposes, then deleted.
7.Your rights
7.1Under the GDPR you have the right to: access your data; correct it; have it erased; restrict processing; object to processing based on legitimate interest; receive your data in a portable format; and withdraw consent at any time (without affecting processing already carried out).
7.2To exercise any of these, contact us via Telegram (@pumpflaresupport). To prevent someone else impersonating you, we may ask you to sign a message with the wallet in question — that is the only proof of ownership that exists for a pseudonymous account.
7.3Withdraw first. Deleting your account removes your in-app wallet records, including the encrypted keys. Export keys and withdraw balances before requesting deletion — afterwards we cannot recover them.
7.4We cannot erase data from the Solana blockchain or from IPFS. That is a property of those networks, not a choice we are making.
7.5You may lodge a complaint with your data-protection authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz); elsewhere in the EU, your national authority.
8.Automated decision-making
8.1We do not make decisions producing legal or similarly significant effects about you by automated means alone.
8.2Automation you configure — auto-snipe rules, limit orders, automation modes — executes automatically, but it acts on your instructions, not on a profile we built of you. Risk scores and launch analyses are informational and do not restrict your access.
9.Children
9.1The Platform is not for anyone under 18 and we do not knowingly process their data. If you believe a child has used the Platform, contact us and we will delete the data.
10.Changes to this policy
10.1We may update this policy. The version and effective date at the top of this page change with it, and we will announce material changes in the Platform. Where a change requires your consent, we will ask for it.
Contact
Data-protection requests and everything else: Telegram (@pumpflaresupport).