Privacy Policy
GrailSwap is wallet-based, so we collect very little — here is exactly what we hold, what is inherently public on-chain, and who processes it.
Last updated: July 7, 2026 · Draft — subject to legal review before public launch.
What we collect
- Wallet address. Your Solana public key is your account identifier. We never see or store your private key or seed phrase.
- Session cookie. A single httpOnly cookie keeps you signed in after you prove wallet ownership.
- Profile data you provide. Optional username, display preferences, privacy settings, wantlists, and showcase layouts.
- On-chain data. Your token holdings, trades, and settlement transactions live on the public Solana blockchain. This data is inherently public and permanent — anyone can read it with or without GrailSwap, and we cannot delete it.
- Sync metadata. When you sync your inventory, we store asset metadata returned by our RPC provider (Helius) and partner platform APIs — card details, grading attestations, and published values — plus sync job records and trade activity events.
We do not collect names, email addresses, physical addresses, or payment card details, and we run no advertising trackers.
What we do not do
We do not sell personal data. We do not share your data with third parties except the service providers below, who process it only to run GrailSwap, or where the law requires it.
Third-party services
GrailSwap runs on a small set of infrastructure providers, each of which may process data as part of providing its service:
- Supabase — database hosting (accounts, profiles, trades, sync records) and the realtime layer behind the trading floor.
- Vercel — application hosting; standard web server logs include IP addresses and request metadata.
- Helius — Solana RPC provider used to read on-chain data for inventory sync and settlement.
- Sentry — error monitoring, so we can diagnose crashes; error reports may include request context.
- Partner platform APIs (Collector Crypt, Phygitals) and card catalog / pricing sources — queried for asset attestations, published values, and reference prices. Requests may include the mints in your wallet.
Cookies and local storage
GrailSwap sets a single httpOnly session cookie to keep you signed in. There are no advertising or cross-site tracking cookies. Your browser's localStorage holds interface preferences (theme, design mode, dismissed prompts); it never leaves your device.
Data retention
Session records and sign-in nonces expire and are swept automatically. Trade, offer, and settlement records are retained as long as your account exists — they are the audit trail behind completed trades, which are also permanently recorded on-chain. Asset metadata snapshots are kept as an immutable verification history. Error reports are retained on Sentry's standard rolling window.
Your rights and contact
You can edit your profile and privacy settings (including inventory visibility) at any time from your profile page. You may request a copy of the data we hold about your wallet, or ask us to delete your off-chain account data, by contacting [contact email]. On-chain data cannot be deleted by anyone, including us. Depending on where you live, you may have additional rights under local data protection law; we honor requests to the extent the law provides.
This policy is maintained by [GrailSwap operating entity]. Material changes will be posted here with a new "last updated" date.
See also the Terms of Service.