Important privacy facts
- A public wallet is pseudonymous, not anonymous. Wallet and transaction activity can often be linked to a person when combined with other information.
- Public blockchain records cannot ordinarily be deleted or changed by Capx.
- Launchpad processes wallet-linked intent signatures, token metadata, transaction requests and confirmation data when you use its connected features.
- Current Vercel Web Analytics is cookie-free, and Capx does not send wallet addresses in its analytics event properties.
- Where implemented, Google Analytics runs only after you allow optional analytics cookies. Capx does not send wallet addresses to Google Analytics.
- Capx does not sell personal data or use it for cross-context behavioural advertising.
Scope and who handles your data
This Privacy Notice applies to capx.ai, launchpad.capx.ai, terminal.capx.ai, Capx-operated APIs, and related Capx services (together, the Services). In this notice, “Capx,” “we,” “us,” and “our” mean the operator of the applicable Capx Service. For privacy-law purposes, that operator determines why and how personal data is processed and acts as the controller or data fiduciary where those concepts apply.
This notice does not govern an independent wallet, blockchain, validator, RPC provider, decentralized protocol, exchange, social network, model provider, or website merely because a Service connects or links to it. Those parties process data under their own notices. Open-source Casa software running only in your environment is under your control unless you choose to transmit information to a hosted or third-party service.
What “personal data” means
Personal data is information relating to an identified or identifiable person. Depending on context and applicable law, this can include an IP address, device or browser data, a public wallet address, a persistent identifier, activity linked to a wallet, or information inferred by combining public blockchain and off-chain records. Aggregated or irreversibly de-identified information is not personal data where applicable law treats it as anonymous.
Data we collect
The categories depend on how you use the Services and may include:
| Category | Examples |
|---|---|
| Wallet and authentication | Public wallet address, signed intent message, issue time, signature-validation result and request failures. Historical service records may include earlier authentication and session events. Capx never needs your seed phrase or private key. |
| Launch and transaction | Launch ID, creator wallet, project address, mint, prepared instructions, selected payment token, optional Dev Buy, setup and trade amounts, fees, transaction signatures, confirmation state, curve reserve and pool operations. Legacy records may include earlier contributions, allocations and refunds. |
| Creator and user content | Project name, symbol, description, images, website and social links, public company information, reports, support messages, and other material you submit or publish. |
| Website and device | IP address, request time, requested URL, referrer, browser, operating system, device type, language, approximate region, network and response data, error reports, and security events. |
| Usage and audit events | Pages and product surfaces used, token viewed, creation, setup or trading requests, wallet or token identifiers where relevant, request time, errors and security or support records. Exact fields depend on the service and action. |
| Public and third-party data | Public Solana records, token and liquidity data, market data, public company attestations, sanctions or fraud signals, and information returned by infrastructure or integration providers. |
Do not send Capx a seed phrase, private key, unnecessary identity document, financial account credential, health information, biometric information, or other sensitive information unless an official Capx interface expressly requests it for a lawful purpose.
Where data comes from
We receive data:
- directly from you when you connect a wallet, authenticate, transact, create content, submit a report, register a company, or contact us;
- automatically from your browser, device, wallet session, and use of a Service;
- from public blockchains, smart contracts, token programmes, liquidity protocols, indexers, RPC providers, and market-data services;
- from wallet and connection providers you choose to use; and
- from security, fraud-prevention, sanctions, hosting, monitoring, support, and compliance providers where permitted by law.
Why we process data
We process relevant data to:
- provide, operate, maintain, and improve the Services;
- authenticate wallets and maintain short-lived sessions;
- prepare, submit, reconcile, recover, display, and support Launchpad transactions;
- publish creator content and display public blockchain, market, and company information;
- measure aggregate usage, diagnose errors, and understand product performance;
- protect wallets, users, infrastructure, and the Services from fraud, abuse, manipulation, attacks, and prohibited activity;
- enforce the Terms of Service, investigate reports, and resolve disputes;
- comply with legal, sanctions, tax, accounting, audit, law-enforcement, and regulatory duties; and
- establish, exercise, or defend legal claims.
Legal bases
Where a law requires a legal basis, Capx relies on one or more of: your consent; steps requested by you and performance of a contract; compliance with a legal obligation; protection of vital interests; and legitimate interests such as operating and securing the Services, preventing fraud, maintaining records, improving products, and defending claims. We balance legitimate interests against your rights where required.
You may withdraw consent through the relevant control or by contacting us. Withdrawal does not affect earlier lawful processing and does not require deletion where another lawful basis applies, including transaction, security, tax, dispute, or immutable blockchain records.
Launchpad data
Current Launchpad creation and Casa-connection requests use a signed intent message containing the wallet, requested action and issue time. The service checks that signature without requesting a private key. A message signature does not itself move assets. Wallet transaction signatures separately authorize setup, creation or trading instructions.
The current wallet connection is held in memory and is dropped on disconnect, account change or reload. The current flow does not use the earlier browser bearer-session model. Requests can include creator metadata, image uploads, selected payment token, purchase amounts and transaction signatures. Public chain records, venue state, hosted media, infrastructure logs and operational records support the application.
Launchpad uses Solana RPC and market or venue providers, including Meteora for current markets, Raydium and Jupiter for supported legacy routes, and market-data services such as Codex. Providers can process request and public wallet or token information under their own notices. Earlier v1 records may remain under the retention purposes described below.
Public blockchains and permanent records
Solana and other public blockchains are distributed third-party networks. Wallet addresses, token holdings, transfers, programme interactions, transaction signatures, timestamps, and related data may be publicly visible and permanently replicated. Anyone may analyze those records and combine them with off-chain information to identify a wallet holder or infer activity.
Capx does not control a public blockchain and generally cannot erase, correct, restrict, or reverse information already recorded there. Deleting data from a Capx-controlled system does not delete a public blockchain record or copies independently held by others.
Terminal data
Terminal is a read-only research surface and does not require an account for normal browsing. It requests public Launchpad, blockchain, market, and Casa company information through Capx-operated and third-party services. Terminal infrastructure may process ordinary request and security data. A single-use Casa registration code is forwarded to the Casa service for redemption; Terminal does not keep the credential as an account password.
Public company pages may show company-authored briefs, diagrams, roadmaps, task plans, agent mandates, activity, attestations, collateral, artefact links and associated token information. Publishing makes that information available to anyone and it may be indexed, copied, or archived by third parties.
Casa and connected providers
Casa core runs locally in your own project. Building face.json, rendering a CAF disclosure, signing it and checking it locally do not themselves send the company brain to Capx. Model and tool integrations you use can independently transmit the files or context you provide to them.
The public repository also includes the optional capx/ integration. Initial binding is treated by that integration as go-public consent. For a bound brain, its guarded SessionEnd hook can render, sign and send new work, then publish an existing face.json. An unbound brain is a no-op. When there is no new attestation work, the current hook exits before the face step. Do not assume every later refresh prompts again.
Published company material and disclosed operating records can be visible on Terminal, indexed, copied or archived. The company face, selected public output folders and CAF disclosure are separate from the full private brain. Review their contents, connection settings and hook behavior before binding or publishing. Never include a private signing key in a public output directory.
Model providers, Git hosting, messaging tools and other integrations process data under their own terms. Review prompts, files, secrets, permissions and provider settings before enabling an integration.
Browser storage, cookies, and similar technology
Current Launchpad uses browser local storage for its Watchlist and pending-transaction recovery record. A pending record can include the public wallet, mint, payment-token or configuration identifier, transaction signature, purpose, time and validity information. It helps recover confirmation state after an interruption. These records are local conveniences, not authoritative chain state.
The wallet connection itself is held in memory in the current implementation. Clearing local storage removes local lists and recovery information but does not cancel or reverse a broadcast transaction. Other Capx surfaces can store preferences and analytics consent. Historical browser keys from earlier versions can remain until the browser or user removes them.
Wallet extensions, security services, hosting infrastructure and independent providers may use their own storage or cookies. Necessary request data can be used for routing, load balancing, fraud prevention and security. Those providers' notices govern their independent processing.
Current analytics
capx.ai uses Vercel Web Analytics for aggregate page measurement. Its cookie-free model does not provide Capx with an identifier designed to recognize a visitor across different websites or days. Data can include time, path, referrer, approximate region, browser, operating system and device type. Capx does not send wallet addresses in its analytics event properties.
The current Launchpad implementation does not include the earlier Vercel or Google Analytics client integration. This does not remove ordinary hosting, request, security, transaction or provider processing. Historical analytics and operational records remain subject to their applicable retention purposes.
Google Analytics and cross-domain measurement
Google Analytics is implemented on capx.ai and terminal.capx.ai only after a visitor allows optional analytics cookies. The Google tag does not load when analytics consent is declined. When allowed, Google Analytics uses first-party identifiers such as _ga and _ga_1885X58SGB to distinguish browsers and understand traffic between participating domains. The shared consent cookie does not imply that every Capx application loads the Google tag. Those cookies are configured to expire up to 12 months after the last relevant activity. Google Analytics can process the page path without its query string, referrer, campaign data, session activity, approximate location, browser, and device data.
You can deny analytics without losing necessary functionality. To withdraw a choice later, clear Capx site data or analytics cookies in your browser settings. Capx does not send seed phrases, private keys, signed transaction payloads, wallet addresses, authentication tokens, or Launchpad user-ID fields to Google Analytics. Advertising personalization, remarketing, Google Signals, and Google Ads integrations are disabled unless separately disclosed and lawfully enabled. Google Analytics user-level and event data follows the retention configured for the Analytics property; aggregate reporting may remain available for longer.
How data is disclosed
Capx may disclose relevant data to:
- hosting, cloud, database, media, analytics, monitoring, security, support, and infrastructure providers, including AWS, Vercel, and Google Analytics;
- wallets, WalletConnect, Solana RPC and validator infrastructure, indexers, Raydium, market-data services, and other providers needed for a requested feature;
- auditors, insurers, accountants, lawyers, and other professional advisers subject to appropriate duties;
- regulators, courts, tax authorities, law enforcement, sanctions authorities, and other persons when required or reasonably necessary to comply with law, protect rights or safety, investigate misconduct, or defend claims; and
- a successor or participant in a financing, reorganization, sale, merger, or transfer of a Service, subject to law and appropriate safeguards.
Capx does not sell personal data for money and does not share personal data for cross-context behavioural advertising. If that practice ever changes, Capx will provide any required notice and opt-out before the change begins.
Information you make public
Launch metadata, images, links, symbols, creator wallet associations, public company material, reports displayed by policy, attestations, and blockchain activity may be public. Public information can be viewed, searched, copied, indexed, archived, analyzed, or redistributed by anyone. Removing a listing from a Capx interface does not guarantee removal from blockchains, caches, search engines, archives, or copies held by third parties.
Retention
Capx retains data only for as long as reasonably necessary for the purposes described here, including providing a Service, securing the platform, completing and reconciling transactions, preserving audit evidence, resolving disputes, and satisfying legal, tax, accounting, sanctions, and regulatory duties. Retention depends on the record:
- browser preferences, Watchlist and pending-transaction values remain until the browser, user, or application removes or replaces them;
- the current Launchpad wallet connection is memory-only and ends on disconnect, account change or reload; historical service-side security records may remain;
- Vercel's temporary visitor hash resets after 24 hours; aggregate analytics data follows the configured provider retention;
- production application, network, and security logs may be retained for up to 12 months, and encrypted production database backups may be retained for up to 35 days;
- transaction, project, terms-acceptance, fraud, security, accounting, and dispute records may be retained for the life of the Service and longer where reasonably required; and
- protected audit and release evidence may be retained for up to seven years, while public blockchain records may persist indefinitely.
These periods are limits or operational expectations, not a promise that every record is kept for the full period. Capx may retain a minimal suppression, request, or proof record after fulfilling a deletion request when necessary to document compliance or prevent the data from being reintroduced.
International processing
The internet, public blockchains, and Capx service providers operate across jurisdictions. Data may therefore be processed outside your country, including where privacy laws differ. Where required, Capx uses an available lawful transfer mechanism and appropriate contractual, organizational, or technical safeguards. Public blockchain publication is inherently global and cannot be confined to one country by Capx.
Security
Capx uses measures designed to protect controlled data, including transport encryption, restrictive browser policies, access controls, network separation, encrypted storage and backups, monitoring, security logging, and protected audit evidence. Access is limited according to operational need. No system, transmission, wallet, blockchain, or storage method is completely secure, and Capx cannot guarantee that unauthorized access or loss will never occur.
You are responsible for securing your device, wallet, seed phrase, private keys, recovery method, browser profile, and connected providers. Capx will never ask you to disclose a seed phrase or private key.
Your privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to know or access personal data; obtain information about processing and recipients; correct inaccurate data; delete data; withdraw consent; object to or restrict processing; receive portable data; opt out of sale, sharing, targeted advertising, or qualifying profiling; nominate another person; appeal a refusal; and complain to a privacy regulator or data-protection board.
Submit a request to hello@capx.aiand identify the relevant Service. To protect users, Capx may ask you to verify control of the relevant wallet by signing a non-transaction message or to provide information reasonably necessary to locate the record. Never send a private key or seed phrase. Authorized agents may be asked for proof of authority.
Rights are not absolute. Capx may preserve information where required for blockchain integrity, transaction completion, legal compliance, security, fraud prevention, accounting, audit, dispute resolution, free expression, or legal claims. Capx cannot delete data controlled by independent third parties or alter a public blockchain.
Your choices
- You can browse capx.ai and Terminal without connecting a wallet.
- You can disconnect a wallet and clear Launchpad local and session storage through browser controls.
- You can decline an optional analytics consent request without losing strictly necessary functionality.
- You can decline to publish creator or company content, but content already made public may persist elsewhere.
- You can avoid an external integration or link if you do not accept that provider's privacy practices.
Certain operational, security, transaction, and terms-acceptance processing is necessary to use transactional features and cannot be disabled while still completing the requested transaction.
Children
The Services are not directed to anyone under 18, and Capx does not knowingly collect personal data from a child through the Services. If you believe a child submitted personal data, contact hello@capx.ai. Capx will take appropriate steps consistent with law, recognizing that public blockchain records may not be erasable.
Automated security and compliance controls
Capx systems may automatically validate transactions, apply rate limits, flag suspicious activity, restrict access, reconcile records, or route an event for review. These controls use wallet, transaction, device, network, and security signals as appropriate. Aggregate analytics is not used to make investment recommendations or decide token allocations. Where law grants a right concerning a qualifying solely automated decision, contact Capx to request available information or review.
Third-party services and links
Services may connect or link to wallets, WalletConnect, Solana, Raydium, RPC providers, GitHub, X, Telegram, Discord, model providers, market venues, and other services. Opening a link or using an integration can disclose ordinary request data and any information you choose to provide. Capx does not control an independent provider's collection, retention, security, or use. Review that provider's privacy notice before use.
Changes to this notice
Capx may update this notice as products, providers, analytics, retention, or law change. The date at the top identifies the current version. Where required, Capx will provide additional notice or seek consent before a material new use. Changes do not retroactively create consent where consent was legally required at the time of collection.
Contact and grievances
Send privacy questions, rights requests, complaints, consent withdrawals, and grievances to hello@capx.ai. Include the relevant Service, approximate date, and wallet or transaction signature where necessary to locate a record. Do not include a seed phrase, private key, or unrelated sensitive information.
Capx will respond within the period required by applicable law. You may also contact the competent privacy regulator or data-protection authority where you have that right. For service-use conditions, read the Terms of Service.
