Legal

Privacy Policy

Last updated 2026-05-23.

What this policy covers

This policy explains what data Ponk collects when you use ponk.exchange, how that data is used, and what choices you have. Ponk is operated by Ponk. References to "we", "us", and "our" mean Ponk.

What we never collect

  • Your seed phrase, recovery phrase, or mnemonic.
  • Any private key for any wallet.
  • Your bank, card, or off-chain payment details.
  • Government identification, social security numbers, or KYC data.

We will never email, message, or otherwise contact you to ask for any of the above. Anyone claiming to be Ponk and asking for those is attempting to steal your funds.

What we collect

Wallet address. When you sign in by signing a wallet message, we store your public wallet address and link your activity in Ponk to it. This is required for the product to scope your data to you.

Agent and position data. The agents you create, the positions you import, the strategies you configure, the on-chain transactions you sign through Ponk, and the decisions your agents log are stored on our servers.

Technical telemetry. Standard server logs (IP address, user agent, request timestamps, request paths) for security and debugging. Cloudflare may collect edge-level traffic data per its own policy.

Session cookies. A signed session cookie keeps you logged in across requests. It is HttpOnly, Secure, and SameSite=Lax. It contains a session identifier; nothing about your funds or strategy.

What we do not store

Aside from the items above, we do not store private keys, seed phrases, personal identification documents, or off-chain payment methods. Transactions you sign are constructed by the server and handed to your wallet for signing; we receive the resulting signature and may store it for audit (signatures are public on chain anyway).

How we use the data

  • Operating the product (agent loops, recommendations, logs).
  • Surface notifications and pending actions to you.
  • Diagnose errors and improve reliability.
  • Detect and prevent abuse.
  • Comply with legal obligations.

Service providers

We rely on the following third parties to run the product:

  • Cloudflare for edge traffic delivery and DNS.
  • Helius for Solana RPC access. Solana queries are routed through Helius on the server side; your Helius API key is never exposed to your browser.
  • DigitalOcean for backend hosting.

We do not sell your data. We do not share your data with advertisers.

On-chain data is public

Solana is a public ledger. Once you sign a transaction, the contents are visible on chain forever. Ponk does not control on- chain visibility and cannot remove your transactions from Solana.

Data retention

We keep agent and position data for as long as you have an account with us, plus a reasonable period for backups and audit. Logs rotate on a shorter schedule (typically 30 days).

You can request deletion of your Ponk account data by emailing us (see Contact). On-chain history cannot be deleted by us.

Your choices

  • Sign out at any time from the Settings page.
  • Delete an agent at any time from the Agents page.
  • Request export or deletion of your account data by emailing us.
  • Stop using the service. Your funds remain accessible from your wallet regardless of whether you have access to ponk.exchange.

Children

The service is not directed to anyone under the age of majority in their jurisdiction. We do not knowingly collect data from such users.

Security

We take reasonable steps to protect server-side data: TLS in transit, encrypted storage at rest, scoped database access, and regular review of dependencies. No system is perfectly secure. If you discover a security issue, please report it to us privately at the email below before disclosing publicly.

Changes to this policy

We may update this policy. Material changes will be reflected by a new "Last updated" date at the top of this page. Continued use of the service after a change means you accept the updated policy.

Contact

Questions, deletion requests, or security disclosures can be sent to [email protected].

See also our Terms of Service.