01What is public by design
- Your wallet address and every transaction you sign are public on Solana.
- When you launch a coin, its name, ticker, description, links and image are uploaded to IPFS and referenced on-chain. That upload is public and permanent, even if we later hide the coin.
- Reward splits, their recipient wallets and percentages, and every payout are public on-chain.
- Your CALLED IT profile (username, display name, bio, picture, linked X handle), your theses and calls, and your call link stats are public on CALLED IT. Profile pictures and thesis images are stored by us, not on IPFS.
02What we collect
| Data | Why |
|---|---|
| Wallet address (and the wallet app name, like Phantom) | Your account. Proven by a signed message. Used to pay you your share of splits. |
| Profile you choose to add: username, display name, bio, picture | Shown publicly on your profile and posts. |
| Theses, calls, coins you launch, splits you create | The product itself. Public. |
| Optional X account: numeric X id, handle, display name, picture URL | To prove you own an X handle so creators can add you to a split by @handle. |
| Session records: a hash of your session token, a salted hash of your IP, timestamps | Keeping you signed in, and letting us revoke sessions. |
| First-party visitor id (random, in a cookie) | Counting unique visitors and call link traffic. |
| Salted IP and user-agent hashes on call link events | Detecting bots and fake traffic. |
| Analytics events (page views, button clicks, launch steps) | Understanding what works and fixing what breaks. |
| Error and security logs | Running the service safely. Secrets are scrubbed before anything is logged. |
We don't collect your email, phone number, real name, contacts, location, or anything from your wallet beyond its public address.
03Cookies
ci_vid: a random first-party visitor id. It lets us count unique visitors and attribute call link visits. It does not identify you personally and is never shared with ad networks.ci_sess: your sign-in session after you sign in with your wallet. HttpOnly, so page scripts can't read it.- Your browser also remembers which wallet app you last used (local storage), so it can reconnect.
There are no third-party cookies, pixels, fingerprinting scripts or ad trackers on CALLED IT. Our content security policy blocks third-party scripts entirely.
04Fraud checks on call links
Call link stats only matter if they're honest. For each call link event we store a salted SHA-256 hash of your IP address and of your browser's user-agent, a risk score and the reasons for it. We never store your raw IP address, and we don't fingerprint your device. These hashes are deleted after 90 days. Flagged traffic is excluded from public counts.
When a wallet that arrived through a call link buys the coin, we check the public on-chain transaction to count it as a verified buy. Attribution never affects payouts.
05Analytics
We run our own first-party analytics: page views, wallet connects, share and copy clicks, and launch funnel steps, tied to the random visitor id and, if you're signed in, your wallet address. Analytics events are deleted after 90 days. We don't use Google Analytics or any third-party analytics service.
06X account linking
Linking X is optional. It uses X's official OAuth login with read-only permission. We store your numeric X id, handle and display name, plus your X profile picture address if it's on X's own image server. The access token X gives us is used once to read who you are and then thrown away. We never store X tokens and can't post for you. You can unlink any time in Settings. Split shares already locked to your wallet stay yours after unlinking.
07Who we share data with
We don't sell or rent personal data. We use a few providers to run the service:
- Hosting and database providers that store the data described here.
- Solana RPC providers, which see the transactions we relay and the public addresses we look up.
- IPFS pinning (Pump.fun's uploader or Pinata), which receives coin metadata and images you choose to publish.
- Market data APIs (Pump.fun, DexScreener), which receive coin addresses only, never anything about you.
- X, only when you choose to link your account.
We may disclose data if the law requires it, or to protect users and the service from fraud or abuse.
08How long we keep it
| Data | Kept for |
|---|---|
| Call link events with IP and user-agent hashes | 90 days |
| Analytics events | 90 days |
| Security events | 180 days |
| Expired or revoked sessions | 7 days after they end |
| Profile, theses, calls, launches, aggregate call link totals | Until you delete them or ask us to |
| On-chain transactions and IPFS uploads | Forever. Not in our control. |
09Your choices and rights
- Edit your profile, change your picture or unlink X in Settings. Delete your own theses from the token page.
- You can ask us for a copy of your data, or to delete your account data held by CALLED IT. We can't delete anything on-chain or on IPFS.
- Depending on where you live (for example under the GDPR or CCPA), you may have extra rights to access, correct, delete or object to processing. Contact us and we'll handle it.
10Security
Sessions are server-side and stored only as hashes. Admin access needs a password and, in production, a one-time code, and every admin action is logged. Admins cannot move funds or change locked splits. No system is perfectly secure, so never share your seed phrase with anyone. We will never ask for it.
11Changes and contact
If we change this policy, we'll update the date at the top. For privacy requests, contact us on X at @calleditfun. CALLED IT is not meant for anyone under 18.