Privacy Policy
Summary: We store the account details you sign in with, the public addresses of your wallets, and the settings and on-chain activity for the coins and collections you launch. We never hold the keys to the wallet you sign in with, and fee wallet keys are held by Privy, not stored by us. We do not sell your data. Blockchain transactions are public and permanent, and we cannot delete them.
1. Who We Are
Floor is operated by Floor ("we", "us", "our"). This Privacy Policy explains what information we collect when you use the Floor website and app ("the Service"), how we use it, and who we share it with. By using the Service, you agree to the practices described in this Policy.
2. Information We Collect
Account information: You can browse public pages without an account. When you sign in by connecting a Solana wallet such as Phantom and signing a message, or with X through Privy, we receive and store:
- The public address of the wallet you sign in with
- If you use X: your Privy user identifier, X handle, display name, and profile picture URL
- The date, Terms version, IP address, and username recorded when you accept our Terms of Service
We do not store passwords or payment card details.
Wallets: For each fee wallet on your account we store its public address, an optional label, and its identifier in Privy. Private keys are held in Privy's secure enclave and are not stored in our database. Where Privy custody is not yet configured for an environment, a fee wallet may instead be an encrypted server wallet. For each collection we also store an encrypted minting key, used only to co-sign valid mints.
Coins, settings, and activity: For the coins and collections you launch, we store:
- Coin and collection addresses, collection settings (supply cap, price curve, burn share, royalty), and saved launch drafts, including the name, symbol, description, links, and images you upload
- Custom recipient lists you create (wallet addresses and amounts)
- Public coin page content you set (description, X, Telegram, and website links, and theme)
- Records of launches, mints, burns, fee claims, and payouts, including transaction signatures and wallet addresses
- Issue reports you submit (the coin, job, transaction, wallet, and your note)
- App preferences synced to your account, such as your active and hidden coins
Telegram alerts (optional): If you connect Telegram, we store your Telegram chat ID, Telegram username, and alert preference so our bot can message you. Disconnecting deletes these records.
X integration (optional): If you connect a coin's X developer app, we store its API credentials (encrypted), the X handle, and a log of the tweets the Service posts. When you scan X for supporters, we store public data about accounts that tweeted the coin's cashtag or contract address: X user ID, handle, tweet text, engagement counts, and follower count.
Reward claim links: When someone claims a reward through a coin's claim link, we store their X user ID and handle, verified by signing in with X, and the Solana address they submit.
Waitlist: If sign-up is closed and you join the waitlist, we store your X handle, IP address, and browser user-agent.
Technical data:
- IP addresses, used to enforce rate limits and prevent abuse
- Server logs of account actions such as sign-ins, wallet additions, and settings changes
- If a wallet feature fails, limited diagnostics (browser type, page, and error codes, never keys or tokens) to help us fix the problem
- A session cookie that keeps you signed in
3. How We Use Your Information
- To sign you in and operate your account
- To launch coins and collections, co-sign mints, and claim and route creator fees
- To show public coin pages and each coin's activity record
- To send Telegram alerts and post tweets you have enabled
- To enforce rate limits, prevent abuse, and investigate problems you report
- To keep a record of your acceptance of our Terms of Service
4. Public Information
Blockchain transactions are public. Launches, mints, burns, fee claims, and payouts are permanently visible on Solana. Public coin pages show each coin's activity to anyone, without an account. We cannot delete or change on-chain data.
5. Data Sharing and Third Parties
We do not sell, rent, or trade your personal information. We share data with these providers only as needed to run the Service:
- Privy (privy.io) - X sign-in and fee wallet custody in a secure enclave
- Phantom - the wallet you connect to sign in, launch, trade, and mint
- X (Twitter) - sign-in provider, and for the tweets and scans you enable
- Telegram - delivers the alerts you opt into
- Railway - hosting for our servers and database
- Cloudflare - CDN and DDoS protection (processes IP addresses and request metadata)
- Solana RPC providers, pump.fun, PumpPortal, Metaplex, Jupiter, GMGN, and DexScreener - blockchain and market data and transaction routing; they receive wallet and coin addresses, not your account details
- esm.sh and Google Fonts - deliver code libraries and fonts to your browser, which exposes your IP address to them
Each of these providers has its own privacy policy. We may disclose information if required by law, court order, or government authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Floor, our users, or the public.
6. Data Storage and Security
Account data and records are stored in a PostgreSQL database hosted on Railway. Data in transit is encrypted with HTTPS/TLS. Connected X credentials are encrypted at rest. Wallet private keys are held by Privy, not in our database. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
7. Data Retention
Account information, wallet records, coin settings, and activity records are kept while your account is active or until you ask us to delete them. Sessions expire after 30 days without activity. Some records, such as fee and payout ledgers and Terms acceptance records, may be kept longer where needed for accounting, security, or legal reasons. On-chain transactions are permanent and outside our control.
You may request deletion of your account and associated data at any time by contacting us. See Section 12.
8. Cookies and Local Storage
We use one session cookie to keep you signed in. It renews while you use the Service and expires after 30 days without activity. We do not use advertising cookies.
Your browser's local storage holds preferences and cached coin details (for example, recent coins and whether you finished the tour), plus the sign-in session tokens used by Privy. Some preferences are also synced to your account so they follow you across devices.
9. Children's Privacy
The Service is not directed at anyone under the legal age in their jurisdiction. We do not knowingly collect personal information from children. If you believe we have collected such information, contact us and we will delete it.
10. Your Rights
Depending on your location, you may have rights to access, correct, or delete the data we hold about you. To exercise them, contact us using the details in Section 12. We will respond within a reasonable timeframe. Data recorded on a blockchain cannot be changed or deleted.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. Signed-in users may be asked to review updated terms on their next visit. Continued use of the Service after an update means you accept the revised Policy.
12. Contact
For privacy questions, data deletion requests, or concerns about how your information is handled, contact us via @bulliebot on X/Twitter or email [email protected].