PumpFlarePumpFlare

Privacy Policy

How PumpFlare handles your data. Written to match what the software actually does — including the parts that are permanent and public.

Version 1.0 · Effective 25 September 2026

Two things you cannot undo

The blockchain is permanent and public. Every trade, token launch and transfer you make is recorded on Solana forever, by the network, not by us. Your wallet address is a pseudonym: if it is ever linked to your identity, your entire history becomes linkable too. We cannot delete anything from the blockchain.

IPFS uploads are permanent and public. Token images and metadata are published to IPFS, a distributed network. Once published, copies may persist indefinitely on machines we do not control. Never upload anything private.

1.Who is responsible for your data

1.1The controller responsible for your personal data is PumpFlare, the operator of https://pumpflare.fun.

1.2For any privacy question or to exercise your rights, contact us via Telegram (@pumpflaresupport). We answer within one month, as required by the GDPR.

1.3This policy covers https://pumpflare.fun and our API. It does not cover the Solana blockchain, your wallet provider, or third-party sites we link to.

2.What we collect, why, and on what legal basis

2.1We deliberately collect little. There is no account with a name, no password, and we never ask for an email address to use the Platform.

DataWhy we process itLegal basis (GDPR Art. 6)Retention
Wallet address (public key)Identifies your account, links your settings, watchlists, orders and rewardsContract (Art. 6(1)(b)) — needed to provide the service you asked forUntil you ask for deletion; see §6
Sign-in signature and one-time nonceProves you control the wallet, prevents impersonationContract; also legitimate interest in securing accounts (Art. 6(1)(f))Nonce: 5 minutes. Session: 7 days
IP addressRate limiting, abuse and fraud prevention, security loggingLegitimate interest (Art. 6(1)(f)) in keeping the service available and secureIn-memory, minutes; server logs up to 30 days
Trading activity you perform through us (orders, alerts, automation rules, paper trades)Executing what you asked for, showing your historyContractUntil deletion; see §6
Encrypted private keys of in-app wallets you generateSigning transactions you or your automation rules instructContract — you opt in by creating the walletUntil you delete the wallet; see §5
Profile you choose to add (display name, bio, avatar, links)Showing your public profileConsent (Art. 6(1)(a)) — entirely optionalUntil you remove it
X (Twitter) account ID and handle, if you connect oneVerified-launch badge, proving one X account per walletConsent — you initiate the connection and can disconnectUntil you disconnect
Telegram chat ID, if you link the botDelivering notifications you asked forConsentUntil you unlink
Web-push subscriptionDelivering browser notifications you asked forConsentUntil you revoke permission or it expires
Community posts, comments, reactions, uploaded imagesPublishing them, moderationContract and legitimate interest in moderating contentUntil you delete them, or removal on moderation
API keys and per-day request countsAuthenticating API access, enforcing quotas, billingContract; legitimate interest in preventing abuseKey until revoked; usage counters 12 months
Aggregate usage statisticsUnderstanding what to improveLegitimate interestAggregated, not linked to you individually

2.2Public blockchain data. We run an indexer that reads the Solana blockchain and stores trades, tokens and prices — including activity by wallets that have never used PumpFlare. This data is already public by design. We use it for charts, market data, trader statistics and our API. Legal basis: legitimate interest (Art. 6(1)(f)) in operating a market-data service. You can object — see §7.

2.3We do not collect special-category data, we do not run advertising profiling, and we do not sell personal data to anyone.

3.Cookies

3.1We use only strictly necessary cookies. There are no advertising, tracking or analytics cookies, which is why you are not asked for cookie consent — consent is not required for cookies that are essential to a service you requested.

CookiePurposeDurationType
pf_sessionProves you control the wallet you signed in with, so the server can authorise actions on your account. HttpOnly, SameSite=Lax.7 daysStrictly necessary
pf_adminAdministrator session for the internal admin panel. HttpOnly, SameSite=Lax.7 daysStrictly necessary

3.2We also use your browser's local storage to remember interface preferences (layout, sound, trade defaults). That never leaves your device and we cannot read it from our servers.

4.Who we share data with

4.1We use the third parties below to run the service. They receive only what they need for their function.

ProviderWhat it is used for
HeliusSolana RPC — reading chain state and broadcasting transactions
JupiterSwap routing for tokens that have graduated to an AMM
pump.funToken metadata and market statistics
BirdeyeHistorical price/OHLCV data
CoinGeckoSOL/USD reference price
Pinata / IPFSStorage of token images and metadata (public, permanent)
MuxLive video streaming
OpenAIAI-assisted token name/description suggestions
TelegramOptional notification delivery
X (Twitter)Optional account verification via OAuth
Tenor (Google)GIF search in community posts

4.2What this means in practice. When you load a page or send a transaction, your IP address is visible to the infrastructure providers handling that request (for example our RPC provider). When you view a chart, the mint address you are looking at is sent to our data providers. When you use AI name suggestions, the text you supply is sent to OpenAI.

4.3Some providers are outside the EEA, including in the United States. Transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, as applicable to each provider.

4.4We may disclose data where legally required — a valid court order, law-enforcement request or regulatory obligation — and where necessary to establish, exercise or defend legal claims. We will tell you unless we are legally prohibited from doing so.

4.5If the business is sold or merged, data may transfer to the acquirer, who will remain bound by a policy no less protective than this one.

5.Security, and the honest limits of it

5.1Private keys of in-app wallets are encrypted with AES-256-GCM before being written to the database, and are decrypted only in memory at the moment a transaction is signed. Sessions use signed, HttpOnly cookies. Access to production systems is restricted. Sensitive endpoints are authenticated and rate-limited.

5.2No system is perfectly secure, and we will not pretend otherwise. A key stored on a server is inherently more exposed than one held only by you. If you are not comfortable with that, do not use in-app wallets — connect your own wallet and sign each transaction instead.

5.3If a breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Art. 33–34.

5.4Found a vulnerability? Please report it via Telegram (@pumpflaresupport) before disclosing it publicly. We will not pursue legal action against good-faith researchers who avoid privacy violations, data destruction and service disruption.

6.How long we keep data

6.1Retention periods are in the table in §2. In general we keep account data while your account is in use, and delete or anonymise it on request.

6.2Some data outlives a deletion request: indexed public blockchain data (it is public and not sourced from you), records we must keep for accounting or legal-defence purposes, and content already published to IPFS or the blockchain.

6.3Server logs containing IP addresses are kept for up to 30 days for security purposes, then deleted.

7.Your rights

7.1Under the GDPR you have the right to: access your data; correct it; have it erased; restrict processing; object to processing based on legitimate interest; receive your data in a portable format; and withdraw consent at any time (without affecting processing already carried out).

7.2To exercise any of these, contact us via Telegram (@pumpflaresupport). To prevent someone else impersonating you, we may ask you to sign a message with the wallet in question — that is the only proof of ownership that exists for a pseudonymous account.

7.3Withdraw first. Deleting your account removes your in-app wallet records, including the encrypted keys. Export keys and withdraw balances before requesting deletion — afterwards we cannot recover them.

7.4We cannot erase data from the Solana blockchain or from IPFS. That is a property of those networks, not a choice we are making.

7.5You may lodge a complaint with your data-protection authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz); elsewhere in the EU, your national authority.

8.Automated decision-making

8.1We do not make decisions producing legal or similarly significant effects about you by automated means alone.

8.2Automation you configure — auto-snipe rules, limit orders, automation modes — executes automatically, but it acts on your instructions, not on a profile we built of you. Risk scores and launch analyses are informational and do not restrict your access.

9.Children

9.1The Platform is not for anyone under 18 and we do not knowingly process their data. If you believe a child has used the Platform, contact us and we will delete the data.

10.Changes to this policy

10.1We may update this policy. The version and effective date at the top of this page change with it, and we will announce material changes in the Platform. Where a change requires your consent, we will ask for it.

Contact

Data-protection requests and everything else: Telegram (@pumpflaresupport).

Twitter Alerts

View All Alerts