Privacy Policy
SolanaM is built local-first. This policy explains what stays on your device, what necessarily leaves it, and who sees what.
Last updated 5 August 2026
The short version
SolanaM does not run user accounts, does not operate a backend that stores your work, and does not sell data. Artwork you create or import is processed entirely in your browser. The only information that necessarily leaves your device is what any website receives when you load it, plus the blockchain requests needed to read balances and submit transactions you explicitly authorise.
No account, no profile
There is no sign-up, no email collection and no password. You are not asked to identify yourself to use the design studio or the tools. Connecting a wallet is optional and is only required to mint or to view on-chain balances.
Because there is no account, we hold no profile to export, correct or delete on your behalf — the data simply lives on your own device, under your control.
Data stored on your device
The app stores a small amount of data in your browser's local storage. It never leaves your device and is not transmitted to us:
- Preferences — theme, motion and density settings, your chosen RPC endpoint and commitment level, studio defaults such as canvas size, brush size and colour, and your notification toggles.
- Wallet connection state — kept by the wallet provider so it can reconnect you, if you enable auto-connect.
- Offline cache — a service worker caches pages and static assets so the app launches without a connection.
You can erase all of it at any time from Settings → Privacy & data, or by clearing site data in your browser.
Your artwork and files
Images you open, import, edit or export are read directly from disk by your browser and decoded on your own machine. They are not uploaded to a server, and we never see them. The same applies to files opened through the installed app's file handlers.
When you choose to mint, the metadata you have entered — name, symbol, description, traits and the artwork itself — is published to decentralised storage and referenced on-chain. That step is initiated only by you, and it is not reversible. See on-chain activity below.
Wallet connection
Wallet connection is handled by the Phantom embedded wallet SDK. When you connect, the app receives your public wallet address. It never receives your private key or seed phrase, and it cannot move funds or sign anything without your explicit approval in the wallet interface.
If you authenticate through Phantom using a Google or Apple sign-in option, that authentication happens with Phantom and the relevant identity provider — not with us. Their handling of your credentials is governed by their own privacy policies.
Third parties
Using a web application necessarily exposes your IP address and browser user-agent to the services that respond to your requests. For SolanaM those are:
- Our hosting provider — serves the pages and assets, and receives standard request metadata.
- Helius — the default Solana RPC provider. Reading a balance or submitting a transaction sends the request, and therefore your IP address and wallet address, to their endpoint. You may substitute your own provider in Settings.
- Phantom — handles wallet connection and signing when you choose to connect.
- Decentralised storage and explorers — contacted when NFT media is fetched, or when you follow a link to a block explorer.
We do not control these services and are not responsible for their practices. Each operates under its own privacy policy.
On-chain activity is public
Your wallet address, the tokens you mint, the metadata attached to them and every transaction you sign are recorded on a public ledger that anyone can read and index indefinitely. Treat a wallet address as a persistent public identifier, and avoid placing personal information in NFT names, descriptions or traits.
Your choices and rights
Because we hold no personal data about you, there is nothing on our side to request, correct or erase. You retain full control through your own device and wallet:
- Clear stored preferences and cached data from Settings, or via your browser.
- Disconnect your wallet at any time, or revoke the connection from the wallet itself.
- Route blockchain requests through an RPC provider of your choosing.
- Uninstall the app to remove its offline cache and file associations.
If you are in a jurisdiction with statutory data rights, such as the GDPR or CCPA, and believe we hold information about you, contact us and we will respond — though in practice the answer is usually that no such record exists.
Security
The site is served over HTTPS with HSTS, a strict Content-Security-Policy, and headers that block framing, MIME sniffing and cross-origin leakage. Files are processed locally, which removes an entire class of server-side breach risk.
No system is perfectly secure. Your wallet remains your responsibility: protect your seed phrase, verify every transaction before approving it, and be sceptical of any site — this one included — that asks you to sign something you do not understand.
Children's privacy
SolanaM is not directed at children under 13, and we do not knowingly collect information from them. The service involves digital assets and financial transactions, and is intended for users who are of legal age in their jurisdiction.
Changes to this policy
We may revise this policy as the platform evolves — particularly as deprecated integrations are replaced on the new infrastructure. Material changes will be reflected in the “last updated” date at the top of this page. Continuing to use the service after a revision constitutes acceptance of it.
This document describes current practice at solanam.com and is provided for transparency. It is not legal advice.