Spread.
Solana

YOUR DATA

Privacy

Updated September 24, 2026.

Data the application stores

Spread stores public wallet addresses, token registrations, signed authentication messages, nonce hashes, configuration requests, and audit events. Wallet signatures are retained as verification evidence. Token registrations and reward records are publicly accessible.

Authentication

A secure, HTTP-only session cookie keeps you signed in for up to one hour. Authentication nonces expire after five minutes and can be consumed only once. The app never requests or stores wallet seed phrases or private keys.

Service providers

Cloudflare hosts the website and database and processes network requests. Solana RPC providers receive requests for public chain data; Helius is used if configured. Jupiter receives token discovery and quote requests. Your wallet provider handles wallet connection and signing. These providers have their own privacy policies.

Rate limiting and retention

A short-lived hash derived from the request IP and time window is used for rate limiting. The application does not install advertising trackers. Public blockchain data cannot be deleted from the blockchain. MVP audit and registration data currently remain stored until an operator removes them; automated retention and a dedicated privacy contact must be established before a live launch.