1. Introduction
Phantotalk (“we,” “us,” or “our”) operates the Phantotalk web application and related services (collectively, the “Services”) available at phantotalk.com. This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you access or use our Services.
By using the Services, you consent to the data practices described in this Privacy Policy. If you do not agree, please do not access or use the Services.
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the “Last Updated” date above and, where required by law, by providing more prominent notice. We encourage you to review this policy periodically.
2. Information We Collect
2.1 Information You Provide Directly
- Wallet address: Your Solana public wallet address, obtained when you authenticate to the platform. This is your primary identifier. We never collect, request, or store private keys or seed phrases.
- Profile information: Display name and any optional profile details you choose to provide
- User content: Messages, trade calls, reactions, and other content you post in group chats or direct messages
- Settings & preferences: Alert preferences, watchlist selections, notification settings, and UI customizations
- Communications: Information you provide when contacting our support team
2.2 Information Collected Automatically
- Device & browser data: Device type, operating system, browser type and version
- Log data: IP address, access timestamps, pages visited, features used, and referring URLs
- Usage analytics: Interaction patterns, session duration, feature engagement, and performance metrics
- Authentication data: Session tokens and authentication timestamps
- Error & crash data: Technical error logs and diagnostic information to improve stability
2.3 Information from Public Blockchains
When you connect a wallet or when we verify token-gated group eligibility, we access publicly available on-chain data from the Solana blockchain, including token balances, NFT holdings, and transaction history associated with your public wallet address. This data is inherently public on the blockchain and is accessed solely to power platform features.
2.4 Third-Party Data
We receive token market data, pricing information, and safety analysis data from third-party blockchain data providers. This data is used to power token embeds, safety indicators, and market information features.
3. How We Use Your Information
- Authentication & account management: To verify your identity via wallet signature, maintain your session, and manage your account
- Service delivery: To operate real-time chat, direct messaging, call tracking, token radar, alerts, and all other platform features
- Reputation & leaderboards: To calculate and display call performance, accuracy scores, and reputation rankings
- Token-gating: To verify wallet eligibility for token-gated groups by checking on-chain token balances
- Notifications & alerts: To deliver price alerts, whale notifications, and other user-configured alerts
- Safety features: To surface rug check indicators and token safety information
- Platform improvement: To analyze usage patterns, diagnose bugs, and develop new features
- Security & integrity: To detect and prevent fraud, abuse, manipulation of reputation systems, and violation of our Terms
- Legal compliance: To comply with applicable laws, respond to legal process, and enforce our agreements
- Marketing communications: With your consent, to send you updates about new features and platform news. You may opt out at any time.
4. How We Share Your Information
4.1 Publicly Visible Information
The following information is visible to other users of the platform by default:
- Your display name and public wallet address (abbreviated)
- Your submitted trade calls and their outcomes
- Your reputation score, accuracy percentage, and earned badges
- Messages you post in public group chats
4.2 Service Providers
We share information with carefully selected third-party service providers who assist us in operating the Services. These providers are bound by contractual obligations to protect your data and may only use it for the specific purpose for which it was shared. Provider categories include:
- Cloud infrastructure and database hosting providers
- Blockchain data and real-time market data providers
- Error monitoring and performance analytics services
- Customer support tooling
- Email and push notification delivery services
4.3 Advertising Partners
We may use third-party advertising platforms (including social media platforms such as X/Twitter) to promote Phantotalk. These platforms may receive limited non-sensitive data (such as hashed identifiers or conversion events) to measure the effectiveness of advertising campaigns. We do not sell your personal data to advertisers.
We may use tracking pixels or similar technologies on our web pages for advertising measurement purposes. These tools are governed by the respective platform's privacy policy. You can opt out of interest-based advertising through your browser settings or platform-level controls (e.g., X ad preferences).
4.4 Legal Requirements & Safety
We may disclose your information where we reasonably believe disclosure is necessary to: (a) comply with any applicable law, regulation, or legal process; (b) protect the rights, property, or safety of Phantotalk, our users, or the public; or (c) detect, prevent, or address fraud, security, or technical issues.
4.5 Business Transfers
In the event of a merger, acquisition, financing, or sale of all or a portion of our business or assets, your information may be transferred as part of that transaction. We will notify you of any such change via a prominent notice on our platform.
5. Wallet & Blockchain Data
Phantotalk uses wallet-based authentication as its sole login method. Important points regarding wallet data:
- Your public wallet address is required to access the Services and forms your account identity
- We store only your public wallet address — never your private key, seed phrase, or any secret credentials
- We access on-chain token balance data solely to verify token-gated group eligibility and to display optional portfolio features
- You can link additional wallets or request account deletion at any time via Settings or by contacting support
- Blockchain transaction history is inherently public and permanent; we do not control what is recorded on-chain
6. Cookies & Tracking Technologies
We use cookies and similar technologies for the following purposes:
- Essential cookies: Required for authentication, session management, and security. Without these, the Services cannot function. These cannot be disabled.
- Analytics cookies: Help us understand how users interact with the platform so we can improve it. These collect aggregated, anonymized usage data.
- Preference cookies: Store your UI preferences such as theme and layout settings.
- Advertising measurement pixels: We may use conversion tracking tools from advertising platforms (including X/Twitter Pixel) to measure the effectiveness of our marketing campaigns. These tools may collect your IP address and browser information. They are governed by the respective platform's privacy policy.
You can control non-essential cookies through your browser settings. Note that disabling cookies may affect platform functionality. You can also opt out of interest-based advertising via the Digital Advertising Alliance (optout.aboutads.info) or your device settings.
7. Data Security
We implement industry-standard technical and organizational security measures to protect your personal data, including:
- Encrypted data transmission using TLS/HTTPS for all communications
- Cryptographic token-based authentication (PASETO) with expiration enforcement
- Rate limiting, bot detection, and DDoS mitigation
- Access controls limiting employee access to personal data on a need-to-know basis
- Regular security reviews and vulnerability assessments
Despite these measures, no security system is impenetrable. In the event of a data breach affecting your rights and freedoms, we will notify you and relevant authorities as required by applicable law.
8. Data Retention
- Account & profile data: Retained until you request account deletion
- Chat messages: Retained while your account is active; deleted upon account deletion request, or after 24 months of account inactivity
- Call tracking & reputation data: Retained indefinitely for platform accountability and leaderboard integrity, except where deletion is required by law
- Usage analytics: Aggregated data retained for up to 36 months; identifiable log data for up to 12 months
- Legal & compliance records: Retained for the period required by applicable law, typically 5–7 years
9. Your Rights & Choices
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to legal retention obligations)
- Data portability: Request your data in a structured, machine-readable format
- Restriction: Request that we restrict processing of your data in certain circumstances
- Objection: Object to processing based on legitimate interests or for direct marketing purposes
- Withdrawal of consent: Withdraw consent for consent-based processing at any time, without affecting the lawfulness of prior processing
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or as otherwise required by law). We may need to verify your identity before fulfilling your request.
10. Children's Privacy
The Services are not directed to or intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected data from a person under 18, we will take prompt steps to delete that information. If you believe we have collected data from a minor, please contact us at [email protected].
11. International Data Transfers
Phantotalk is operated from the United States. If you access the Services from outside the United States, your information may be transferred to and processed in the United States or other countries where data protection laws may differ from those in your jurisdiction. Where required by applicable law (such as GDPR), we implement appropriate safeguards for such transfers, including Standard Contractual Clauses approved by the European Commission.
12. Regional Provisions
12.1 European Economic Area, United Kingdom & Switzerland (GDPR / UK GDPR)
If you are located in the EEA, UK, or Switzerland, the following additional information applies:
- Legal bases for processing: We process your data on the bases of contract performance (to provide the Services), legitimate interests (platform security, fraud prevention, analytics), consent (marketing communications, non-essential cookies), and legal obligation
- Data controller: Phantotalk is the data controller for the personal data collected through the Services
- Supervisory authority: You have the right to lodge a complaint with your local data protection supervisory authority
12.2 California Residents (CCPA / CPRA)
California residents have the following additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- The right to know what personal information we collect, use, disclose, and sell
- The right to delete your personal information, subject to certain exceptions
- The right to correct inaccurate personal information
- The right to opt out of the sale or sharing of personal information — we do not sell personal information
- The right to limit use of sensitive personal information
- The right to non-discrimination for exercising your privacy rights
To exercise CCPA rights, contact us at [email protected] or submit a request through our support portal.
13. Third-Party Links & Services
The Services may contain links to or integrations with third-party websites and services (such as decentralized exchanges, blockchain explorers, or token information sites). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access. We are not responsible for the privacy practices or content of third parties.
14. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: