Privacy Policy

Effective September 27, 2026. Plain language, no fine-print games.

1. Who we are

Polgrape is a Polygon-native launchpad for meme tokens, NFTs and on-chain communities. For privacy questions or requests, contact [email protected].

2. What we collect

We collect only what the app needs to function:

  • Google sign-in identity. When you sign in with Google we receive your verified email address, name, profile photo and Google account identifier. We use them to identify your account and show your profile. We never see or store your Google password.
  • Wallet addresses. Addresses you connect, plus addresses and activity the app indexes from the public Polygon blockchain (tokens you launch, trades, NFT mints, creator locks).
  • Your profile’s embedded wallet. You can activate a real Polygon wallet address inside your Polgrape profile so you can receive and hold assets without installing anything. Activation is a paid membership step: you send exactly 10 POL from your own connected wallet to the platform treasury, and our backend verifies that payment on the blockchain (confirmed transaction, exact amount, correct recipient) before creating anything — without a verified payment no wallet is created. The 10 POL go to the platform treasury and fund the platform’s operation, keeping the system self-sustaining. This wallet is custodial: the private key is stored encrypted (AES-256-GCM) on our servers, and only our backend can decrypt it — solely to sign actions you request while signed in. You do not control this key directly; connect your own wallet for full self-custody.
  • Session data. A strictly-necessary httpOnly session cookie keeps you signed in (30 minutes of inactivity or 24 hours absolute, whichever comes first). No advertising or tracking cookies.

3. What we do NOT do

  • We do not sell, rent or trade your personal data. Ever.
  • We do not show ads and do not use advertising trackers.
  • We do not invent data: empty states stay empty, and balances shown are read live from the blockchain.

4. How we use your data

  • Operate your account: sign-in, profile, sessions, logout.
  • Display your launches, NFTs, collections and collaborations.
  • Prevent abuse (rate limits, replay protection on signatures).

5. Third parties

  • Google Identity Services — handles the sign-in flow; only the verified identity fields above reach us.
  • Supabase (database) — stores account, session and wallet records on infrastructure in the United States.
  • Polygon RPC providers — used to read on-chain balances and public blockchain data. No personal data is sent to them beyond the wallet addresses being queried.
  • Cloudflare — serves the site and the API.

6. Security

Embedded-wallet private keys are encrypted with AES-256-GCM; the encryption key lives only in server environment configuration, never in code or in the browser. Sessions are server-side records keyed by a random token stored in an httpOnly, Secure, SameSite=Lax cookie. No method is perfect, but we minimize what we keep: there are no demo users, no seed data, nothing fake in the database.

7. The blockchain is public

Anything recorded on the Polygon blockchain (token launches, trades, transfers) is public and immutable by design. We cannot delete or alter on-chain history. Think before you sign a transaction.

8. Your rights

You can sign out at any time from your profile. To request a copy or deletion of your off-chain account data (identity, sessions, custodial wallet record), email [email protected] from the address on your account. On-chain data cannot be deleted.

9. Changes

If this policy changes materially, we will update the date above. Continued use of the app after changes means you accept the updated policy.

Last updated: September 27, 2026