1 Scope
This notice describes the ELON Orbit website, token analyzers, wallet-based Pro account, research and content prototypes, CSV tool and development journal. See product status for availability and testing limits. Independent wallets, explorers, exchanges and social platforms have their own policies.
2 Information processed
Token analysis and wallet access
The basic analyzer accepts a public Solana mint address without wallet login. Pro uses your public wallet address, a signed login message and a session token. The application does not request a seed phrase or private key.
Credits and reports
Server records include wallet addresses, login challenges, credit balances, payment quotes and references, transaction signatures, purchase receipts, analysis request IDs, mint addresses, request status, timestamps and completed Pro reports. New payment quotes also retain a holder-discount snapshot: aggregate raw ELON balance for the signed-in wallet, RPC slot and check time, discount percent and base/final package price. The wallet address is sent to the configured Solana RPC provider to check eligibility. These records support login, discount eligibility, payment verification, duplicate-charge prevention and recovery.
Research, content and CSV
Research, Research Agent and Content Studio send the text and options you submit to the server and AI provider. Do not submit confidential information or personal information you are not entitled to share. Program planning forms process revenue, budgets, review checklists and partnership drafts in the browser and export files only when requested. The private grants preview stores applicant wallet addresses, proposal text and requested amounts, evidence links, timestamps, per-wallet test votes and self-reported outcomes. Enabled testers can see proposals, aggregate votes and outcomes, but not other voters’ addresses. No grant is approved or paid through this preview. These test records have no scheduled deletion workflow. The private agent-directory preview stores the registering wallet, tool metadata, revision and timestamps, plus rating values keyed by the signed-in reviewer wallet. Enabled testers can see metadata and aggregate ratings; reviewer addresses are not included in directory responses. Owners cannot self-rate; wallet identity does not prove a unique person. These records have no scheduled deletion yet. The developer comparison API receives the two snapshots submitted by an authenticated wallet and does not add comparison history. Bounty draft downloads are local. Choosing Submit voluntary work sends the task, description, public evidence URL and stable request ID to the server under your signed-in wallet. Only that wallet and authorized administrators can list the submission. Administrator decisions store reviewer wallet, reason, decision and timestamp and are visible to the submitting wallet. Pending submission content is temporarily kept in this tab’s sessionStorage to retry the same request; it is removed on confirmed completion or New draft. Server submission and review records currently have no scheduled deletion. Acceptance does not initiate a payment. The local workflow tool processes CSV batches and imported snapshot JSON in your browser. Explicit Pro export creates a minimal public snapshot without account or payment fields. Preparing research temporarily stores this snapshot in sessionStorage until the research page loads; sending it to AI requires pressing Run. CSV parsing and statistics run in your browser; the CSV tool does not upload the selected file.
Technical information
Infrastructure providers may process IP addresses, browser information, request times, errors and security logs. Wallet addresses and public blockchain information may be linkable to a person.
3 How information is used
Information is processed to authenticate wallet access, deliver requested tools, verify payments, maintain balances, prevent duplicate debits or credits, recover interrupted requests and troubleshoot the service. Public chain and market data support token reports; user-supplied text supports requested summaries or drafts.
4 Service providers and data recipients
The implementation uses Netlify for hosting and server records, Solana RPC or Helius for blockchain queries, DEX Screener and Raydium for market information, and OpenAI for AI output. Submitted mint addresses are sent to relevant data providers.
The Pro AI explanation uses selected token, holder, market and scoring evidence. The requester’s wallet identity, session token, credit balance and payment references are excluded from that AI input. Public holder addresses may remain in the evidence. Research, Research Agent and content tools send the text and options you submit to OpenAI.
AI requests use the application setting store: false. This does not promise zero provider retention: provider logging, abuse monitoring and other handling depend on their policies and configuration. External links open independently operated services.
Website feedback
Feedback is optional and does not require wallet login. We store the rating, full feedback text, optional contact details, page/report type, submission ID and timestamps. We do not automatically attach your wallet, payment records, mint address or login token. Please leave out passwords, recovery phrases and confidential information. Authorized administrators can read feedback and update its status. The full submission and any contact details you provide are also sent to the project administrators through Telegram; Telegram processes these messages under its own policies.
Daily rate-limit records contain a keyed hash derived from your IP address, submission identifiers and times. The raw IP is not stored in these feedback records; infrastructure providers may still retain technical logs. Feedback, notification status and rate-limit records currently have no scheduled deletion. To request removal of feedback, contact support with the submission details. Removing a website record does not automatically remove copies delivered to Telegram.
Support and administrator adjustments
Authorized administrators can record credit adjustments and payment resolutions. Audit records include customer and administrator public wallets, quantity, reason, request ID and, for payment resolution, quote and transaction identifiers. These records support accounting and duplicate-credit prevention and currently have no automatic deletion schedule.
You can review and copy support details before choosing to share them through Telegram. The export excludes login tokens, API keys and private keys. No message is sent automatically. Telegram processes messages under its own policies. An official-channel link is not a private support conversation; use a configured private contact for account support.
AI Assistant
The assistant is available to any signed-in wallet. Each independent question and optional context are sent to OpenAI; the application does not store those inputs or answers as conversation history. Provider and infrastructure handling still apply. The server retains daily UTC usage counts keyed by public wallet address to enforce 20 attempts per wallet and 200 project-wide. These usage records have no scheduled deletion yet. Failed AI attempts also count. Your wallet address and login token are not included in the AI prompt by the application. Any personal information you type into the question is part of the submitted text. Output stays on the page until cleared or navigated away from; copying is an explicit action.
5 Retention
The current implementation retains wallet credit and purchase records, payment quotes and claims, and analysis request records and completed reports in server storage. It does not yet have a scheduled deletion or report-expiry process. Records supporting duplicate-payment and duplicate-refund prevention must not be removed without a replacement safeguard.
Research, Research Agent and content tools do not add a separate application history of submitted text or generated drafts. Infrastructure logs and AI-provider handling are separate. Public blockchain transactions cannot be erased by ELON Orbit. A defined retention schedule and deletion workflow remain release-review items.
Mobile wallet returns
To return from Phantom to your browser, a pending request temporarily stores transport encryption keys, the Phantom connection session and, for payments, the existing Orbit login token in localStorage. Requests are accepted for ten minutes; completed or rejected requests are removed and stale records are cleared the next time the wallet flow performs cleanup. There is no background deletion timer. Callback data from Phantom is encrypted, and URL callback parameters are removed before continuing. Wallet seed phrases and wallet private signing keys are never requested. After returning, login state remains in tab-scoped sessionStorage. Prepared payment messages and their transaction signatures are retained by the server for retry and duplicate-payment protection.
Website usage measurement
We measure page views, approximate visits and clicks on predefined controls to understand how the website is used. A random identifier and cumulative counters are kept in this browser tab. A new visit starts after 30 minutes without tracked activity or at midnight UTC. Visits are not unique people. Multiple tabs, devices and wallet browser switches can count separately.
Only fixed page names, fixed action names, a date, counts and a broad referral category are sent to our Netlify endpoint. We do not send full referring URLs, URL query strings, entered text, wallet addresses, token addresses, file contents, feedback, payment details or login tokens with measurement requests. The random visit identifier is hashed on the server. A separate daily keyed IP hash is used for rate limiting; raw IP addresses are not saved in our analytics records. Hosting providers may process IP addresses and technical logs independently.
Measurement respects Do Not Track and Global Privacy Control. You may disable future measurement in this browser below; the choice is kept in localStorage. Previously counted events are not removed by opting out. Browser blocking, network failures, basic bot filtering and usage limits may reduce counts. Server-side daily aggregates, hashed visit counters and rate-limit records currently have no automatic deletion schedule. Only authorized project administrators can read the analytics dashboard.
7 Your choices and privacy requests
You can avoid wallet-based tools and use public project information without signing in. Clear browser storage or sign out to remove local access, noting that this does not remove server records or public transactions. Rights concerning personal information depend on applicable law.
A privacy request may need the relevant public wallet address to identify records. Never post identity documents, credentials or recovery phrases publicly. A dedicated private privacy-contact route and deletion procedure still need to be finalized before broader release.
8 Security and international processing
Reasonable technical and organizational measures are used for the current scope of the service, but no online system is completely secure. Service providers may process information in countries other than your own, subject to their safeguards and applicable law.
9 Children
The services are intended for adults aged 18 or older and are not directed to children. ELON Orbit does not knowingly request personal information from children.
10 Updates and contact
This policy may be updated when the product, providers, data practices, or legal requirements change. Privacy questions may be sent through the official Telegram channel at t.me/ELONOrbitOfficial. Do not send passwords, private keys, seed phrases, or authentication codes.