PRIVACY & BROWSER STORAGE
Privacy policy
What the current arcade reads, stores locally and sends to service providers.
Who this notice covers
This notice describes the Stonk Arcade devnet website. The project contact is @stonkarcadefun. It explains the implemented data flow of this preview; wallet providers, hosting, RPC services, Solana and X have their own policies.
What the app handles and why
| Data | Purpose and handling |
|---|---|
| Public wallet address and token balances | Read after connection to display funds, build transactions and find your saved draws. Public addresses can be linked to public transaction history. |
| Transaction and receipt data | Used to submit approved transactions, confirm results, settle draws, recover interrupted actions and show claims. Broadcast transactions and receipts are public on Solana devnet. |
| IP address and request metadata | Requests reach our hosting service. The RPC gateway uses client IP information for in-process rate limiting; hosting and infrastructure providers may also process request and security logs. |
| Support information you choose to send | Used to investigate your request. Messages sent through X are handled on X and may include public wallet or transaction information you provide. |
The site does not ask for seed phrases or private keys. Signing happens in your wallet; the app receives the signed transaction for submission. It does not require an email account, password or identity-document upload.
What stays in your browser
| Storage | Contents and lifetime |
|---|---|
| arcade-theme-v2 | Your Pixel or Steel theme preference, until you change it or clear browser storage. Retired OG and Gacha preferences move to Steel. The old preview theme key is removed. |
| arcade-play-modes | Your Mix / Degen choice, for every collection and per collection, until you change it or clear browser storage. Without it the arcade starts in Degen. |
| arcade-wallet-name | The last selected wallet name for picker ordering; it does not authorise reconnection. Stored until replaced or cleared. |
| arcade-preparation-times | Up to 30 recent preparation timings, payment symbols and timestamps, used only for the timing card in this browser. Older entries are overwritten. |
| arcade-payout-v1:* | Public transaction signatures, validity bounds and action progress for purchases and claims. Kept until transaction reconciliation and a fresh account read; no signed bytes or private keys are stored. |
| arcade-referral | A referral code from a link you opened, until your wallet accepts it or you clear browser storage. |
| stonk-arcade-v1:* | Recovery records keyed by public wallet and pool: receipt address, nonce, transaction validity information and submission state. Cleared when resolved; legacy records can also clear after safe expiry checks. |
These preferences and recovery records use localStorage. Private operator sign-in uses a necessary session cookie that expires after 30 minutes; signing out clears it from the browser. The arcade code does not add advertising cookies, advertising pixels or behavioural analytics. Fonts are served from the site. Wallet software and linked third-party sites can make their own requests.
Services receiving requests
- Vercel hosts the site and server endpoints and may process hosting/security request logs.
- Upstash (through Vercel) stores the reward-points ledger: public wallet addresses, points, referral codes, which wallet referred which, and pending free pulls.
- The server sends Solana RPC requests to Helius, including relevant public addresses and signed transactions. Your browser uses the site’s RPC endpoint rather than receiving the private provider API key.
- Solana devnet stores broadcast transaction and account data. MagicBlock VRF requests and their randomness are on-chain.
- Your selected wallet handles connection and signing. Following the X link or a wallet/explorer link takes you to that provider.
Provider processing can occur in different countries. See Vercel’s privacy policy, Helius’s privacy policy and X’s privacy policy for their practices.
Retention and your controls
Browser preferences remain until replaced or cleared; recovery entries follow the rules above. In-process throttling and settlement maps are temporary server memory. The reward-points ledger keeps public wallet addresses, points and referral links while the devnet points feature runs, and will be reset before mainnet. The project has not published a fixed retention period for provider logs or messages received through X; do not assume those records are immediately deleted.
Disconnecting stops the app from using an active wallet connection but does not erase public transactions or local entries. You can clear this site’s browser storage yourself. Check pending transactions first so you do not discard useful local recovery information. Public blockchain records cannot be removed by deleting browser data.
Privacy questions and requests
Contact @stonkarcadefun to discuss access, correction, deletion or other privacy questions, and request a private channel before sharing sensitive details. Applicable privacy rights depend on the laws governing the processing; relevant regulators may also accept complaints. The project cannot erase public blockchain history or records independently controlled by another provider.
Something unclear? Reach us on X ↗