Privacy Policy
This explains what UP9000 collects when you use our site, why, who else sees it, and what you can ask us to do about it. It covers the website and its APIs. It does not cover the blockchain itself, your wallet, or anyone else's site.
1. The short version
We have no accounts. There is no email address, no password, no name, and no identity check. You connect a wallet, sign a message to prove you control it, and that is the whole of "signing in".
We do not sell personal information, we do not share it for advertising, and we run no advertising or cross-site tracking on the site.
Most of what happens here happens on a public blockchain, where it is permanent and visible to everyone, forever. That part is outside our control.
2. Who we are
UP9000 operates the interface described in our Terms of Service and is the controller of the personal information described here.
We are not affiliated with, endorsed by, or connected to BNB Chain, Binance, PancakeSwap, or the issuer of any tokenized asset used as a quote asset, or to any of their subsidiaries. "BNB Smart Chain" is the network's own name and "PancakeSwap" is the exchange a graduated coin's pool is created in; we use both descriptively.
We are non-custodial: we do not control your wallet, hold your keys or assets, or make transactions for you.
3. What we collect
Wallet address. Your public address, when you connect a wallet, sign in, trade, launch, post, comment, or vote. A wallet address is pseudonymous, not anonymous. Where it can be linked to a person, whether by you, by us, or by anyone combining it with other data, we treat it as personal information.
Sign-in signatures. When you sign in we give your wallet a one-time random nonce and you sign a message containing it. We verify the signature to confirm you control the address, then discard the nonce. Signatures are used for authentication and message integrity only. We never ask for and never receive your private key or seed phrase.
Session cookie. One cookie, set after a successful sign-in, holding a session identifier. It is HttpOnly, Secure, host-scoped, and SameSite=Lax. It exists to keep you signed in. See section 7.
Content you post. Posts, comments, votes, any display name you set for your wallet, and moderation state (hidden, pinned, banned) with the reason recorded. Stored against your wallet address.
Images you upload. Token logos and post images, stored in object storage, along with a content hash, file type, size, upload time, and the wallet that uploaded them. We keep the hash so we can detect re-uploads of content we have already removed. Strip metadata from images before uploading if it matters to you; we may also strip it ourselves, but do not rely on that.
Token metadata you submit. Name, symbol, description, and social links attached to a launch. This is published, and the same data goes onchain in the launch transaction.
Server logs and request data. IP address, user agent, requested path, referrer, timestamps, response status and timing, and error diagnostics: for the site, for its APIs, and for the RPC proxy the site uses to read the chain. The RPC proxy sees your IP address and the requests your browser makes about the chain.
Rate-limit and abuse signals. Counters and short-lived records keyed to IP address and wallet address, so we can enforce posting limits, RPC-proxy limits, and bans, and so we can spot automated abuse.
Onchain data we index. Trades, launches, transfers, balances, duel events, and claims, read from the public chain, which we store and serve back in aggregate and per-wallet views. This data is public before we touch it.
If you write to us. Whatever you send, usually an email address and the contents of your message.
What we do not collect
No names, no passwords, no government ID, no KYC documents, no proof of address, no bank or card details, no phone number, no biometric data, no private keys, no seed phrases. We do not run third-party advertising or cross-site tracking scripts.
4. Where it comes from
From you (what you connect, sign, submit, upload, or send us); automatically from your browser and device when you make a request (IP, user agent, headers); from the public blockchain, via our indexer and our RPC provider; and from our infrastructure providers as part of delivering, protecting, and monitoring the service.
5. Why we use it
- To run the interface: to show you your holdings, claims, positions, and record, and to let you post, comment, and vote.
- To authenticate you: verifying a signature and keeping a session, so that a post is attributable to the wallet that wrote it.
- To read the chain on your behalf: proxying RPC requests so that provider credentials stay on our servers rather than in your browser.
- To enforce gates and limits: checking holdings or trading history where posting or voting requires them, and applying rate limits.
- To keep the service up and safe: debugging, performance monitoring, capacity planning, detecting and blocking abuse, spam, scraping, denial-of-service traffic, and manipulation.
- To moderate: reviewing reported content, hiding what breaches the Terms, banning wallets, and keeping a record of why.
- To handle your requests: answering support and rights requests.
- To comply with the law: meeting legal obligations and responding to lawful requests, and applying jurisdictional restrictions where required.
We do not use your information for advertising or for automated decision-making that produces legal effects about you.
6. Legal bases
Where a legal basis is required, we rely on: performance of a contract with you (running the interface you asked for, including sessions and boards); our legitimate interests (securing the service, preventing abuse and fraud, understanding performance, and defending claims), balanced against your rights; compliance with a legal obligation; and consent where consent is required and you have given it, which you may withdraw at any time.
7. Cookies and browser storage
We use one cookie: the session cookie described in section 3. It is strictly necessary, because without it you cannot stay signed in, and it is not used to profile you or to follow you across sites.
Your browser may also hold local settings such as theme or interface preferences, and your wallet software keeps its own connection state. That data stays on your device and is not sent to us as part of a tracking scheme.
We run no advertising cookies, no advertising pixels, and no cross-site or cross-context behavioural tracking. If we ever add analytics, we will name the provider here first and, where consent is required, ask for it.
You can clear browser storage and block cookies. If you block the session cookie you can still browse, but you will not be able to sign in or post.
8. The blockchain is public and permanent
Launching, trading, claiming, and every other onchain action is recorded on a public blockchain, linked to your wallet address, visible to anyone, and permanent.
We cannot edit, hide, reverse, anonymise, or delete anything recorded onchain. Nor can anyone else. Explorers, indexers, analytics firms, and archives copy that data independently of us and keep their own copies.
The token metadata you submit at launch, meaning the name, symbol, description and socials, goes onchain with the launch and is subject to the same permanence.
If you want to reduce what onchain activity reveals about you, that has to be decided before you transact, by how you use wallets and addresses. Nothing in this policy can undo it afterwards.
9. Who else sees your information
We do not sell personal information and we do not share it for cross-context behavioural advertising.
We share information with providers who help us run the service, and only for that purpose:
| Provider role | What they see |
|---|---|
| RPC and blockchain data provider | The chain requests our servers make, including ones proxied for your browser; our server's identity; and, in webhook delivery, our contract addresses |
| Network, CDN, DNS, and security provider (Cloudflare) | Every request to the site: IP address, user agent, headers, path, and TLS metadata, as traffic passes through their edge |
| Object storage (Cloudflare R2) | Images you upload, and requests for them |
| Hosting for our application and database | Everything the application stores, at rest on the host we operate |
| Email provider | Correspondence you send us |
We may also disclose information where we are legally required to, whether by a valid legal request, court order, or regulatory demand, or where we reasonably need to in order to investigate abuse, enforce the Terms, protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of the business, in which case this policy or an equivalent one continues to apply.
Wallets, explorers, and any site linked from a token page or a post are independent of us. What they collect is governed by their own policies.
10. International transfers
Our providers operate globally, so your information may be processed in countries other than yours, including countries whose data protection rules differ from your own. Where the law requires safeguards for such transfers, we use an approved mechanism, for example standard contractual clauses with the provider.
11. How long we keep it
| Data | Kept for |
|---|---|
| Server and RPC-proxy logs, including IP addresses | Retention depends on the logging settings of our hosting and security providers; no fixed deletion period is specified here |
| Rate-limit counters | Hours to days, only as long as the window they enforce |
| Session records and the session cookie | 7 days from sign-in, or until you sign out, whichever comes first |
| Sign-in nonces | 5 minutes, single use, then discarded |
| Posts, comments, votes, display names | Until you delete them or a moderator removes them; hidden content is retained with its reason while the account of it may still be needed |
| Uploaded images and their hashes | While the post or token page exists; hashes of removed content are kept longer so it cannot simply be re-uploaded |
| Ban and moderation records | While the ban is in force and for a reasonable period afterwards, so it can be enforced and explained |
| Correspondence with us | While needed to deal with the matter, and afterwards as needed for legal claims |
| Indexed onchain data | Indefinitely, because it is a copy of public chain data and rebuilding it is always possible from the chain |
We may keep information longer where we must for a legal obligation, or to establish, exercise, or defend a legal claim.
12. Your rights
Depending on where you live you may have the right to ask us to give you a copy of the personal information we hold about you, correct it, delete it, restrict or object to how we use it, port it, or withdraw a consent you gave. You may also have the right to complain to your data protection authority, and in some places to appeal our decision on a request.
Because we have no accounts, we will normally ask you to prove control of the wallet address concerned by signing a message we specify. We will not ask you for identity documents.
What we can actually do:
- Offchain content: we can delete or anonymise your posts, comments, votes, display name, and uploaded images.
- Logs: we can tell you what categories we hold, but logs are keyed to IP address and time, not to a wallet, so we usually cannot isolate "yours" without more information than we want to collect. Retention is described in section 11.
- Onchain data: we cannot delete it. We can remove our indexed copy from our own pages where the law requires, but the underlying records stay on the chain and in everyone else's copies. This is a limit of the technology, not a policy choice.
We do not charge for a request or treat you differently for making one. We will respond within the time your law allows.
13. Children
The interface is for adults. It is not directed to anyone under 18 and we do not knowingly collect information from anyone under 18. If we learn that we have, we will delete what we can.
14. Security
We use reasonable technical and organisational measures: encrypted transport, host-scoped HttpOnly Secure session cookies, single-use short-lived sign-in nonces, authorisation checked on every request rather than once at the door, a content security policy, rate limiting, credentials held only in server-side environment configuration and never exposed to the browser, dependency pinning, and access to production limited to the people who need it.
No system is completely secure. We cannot guarantee that information will never be intercepted, accessed, or disclosed, and nothing here is a warranty of security. Your wallet, your device, and your seed phrase are yours to protect; we can do nothing about a compromise there.
15. Test networks
Anything we run on a test network is for testing and may be reset or wiped without notice. Do not put anything into a test deployment that you would not want deleted, or published.
16. US state privacy disclosures
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws. We do not process sensitive personal information for the purpose of inferring characteristics about you. The categories we collect, why, who we disclose them to, and how long we keep them are in sections 3, 5, 9, and 11. Rights and how to exercise them are in section 12.
17. Changes
We may update this policy. The current version is always on the site. Where a change materially affects you, we will give prominent notice on the interface before it takes effect.
Also on this site: Terms of Service · Trust and contracts