Last updated October 2, 2026
Privacy Policy
This policy explains what information Vrfy collects when you use vrfy.fun, why, and who it is shared with. Much of what happens on Vrfy is public by design, and this page says which parts.
1.What we collect
We collect only what the Service needs to work:
- Account details: your Solana wallet address or addresses; your email address if you sign in with email; and your GitHub and X usernames if you choose to link those accounts.
- Project information you submit: name, ticker, description, logo, website, product address, repository, X handle, program addresses and public commitments.
- Launch-support applications: your name, email, the project details you describe, team size, and any links you give us such as LinkedIn, Telegram, X or GitHub.
- Activity on the Service: projects you follow, questions you ask Ask Vrfy, and actions you take such as starting a review or building a transaction.
- Technical data: IP address, browser type and request logs, used to run the Service, prevent abuse and apply rate limits.
We do not collect your private keys, seed phrase or wallet password, and we cannot access them.
2.Public blockchain data
Launches and trades are transactions on the public Solana blockchain. Your wallet address, the tokens you create or trade, amounts and times are visible to everyone and are permanent. We read this public data to show charts, trades, holders and portfolio balances. We cannot edit or delete anything on the blockchain.
Token names, images and metadata are stored on IPFS, and each Build Receipt's hash is written to Solana. These are also public and permanent.
3.How we use it
- To provide the Service: sign you in, run reviews, build transactions for you to sign, show markets, and keep project pages up to date.
- To verify ownership of domains, repositories and accounts you say are yours.
- To contact you about your project, your application, or important changes to the Service.
- To keep the Service secure, investigate abuse and comply with the law.
- To understand how the Service is used so we can improve it.
We do not sell your personal information and we do not use it for third-party advertising.
4.Automated review of what you submit
When you start a review, automated agents process the project you submitted. Your public repository is cloned and built inside an isolated, temporary sandbox that is destroyed afterwards. Text from your website, product page and repository, and a screenshot of your product page, are sent to an AI model to produce the summaries shown on the receipt. The results, including scanner findings with file names and line numbers, are stored and shown publicly on your project's page.
5.Who we share it with
We use service providers to run Vrfy. Each receives only what it needs:
- Privy: sign-in, wallets and linked accounts.
- Supabase: our database and file storage.
- Vercel: hosting.
- Helius: access to the Solana network.
- Anthropic: AI models used in reviews and in Ask Vrfy.
- E2B: sandboxes in which repositories are built and product pages are opened.
- Pinata: storing token images and metadata on IPFS.
- Resend: sending email.
- Inngest: running background jobs.
- GitHub: reading public repository information.
- zauth: repository trust scores, where enabled. Only the repository address is sent.
We may also disclose information if the law requires it, to protect the rights and safety of users or the public, or as part of a merger, sale or reorganisation, in which case this policy continues to apply to it.
6.What is public
Project pages, Build Receipts, check results and evidence, development activity, changes, public commitments, the creator's wallet address and linked GitHub or X username are public once a project leaves draft. Drafts are visible only to you. Launch-support applications are visible only to our team.
7.Storage on your device
We do not use advertising or tracking cookies. Your sign-in session is kept in your browser by Privy. We also store small preferences in your browser, such as your choice of grid or table view and an unsaved launch form.
8.How long we keep it
We keep account and project information for as long as your account or project exists, and afterwards for as long as needed to meet legal obligations, resolve disputes and keep an accurate public record of launched projects. Request logs are kept for a short period. Information on the blockchain and IPFS is permanent and outside our control.
9.Your choices and rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, and to object to or restrict certain uses. To make a request, email us. We will respond within the time the law requires. We cannot delete on-chain or IPFS data, and we may keep the public record of a launched project.
You can unlink GitHub or X, or stop using the Service, at any time. You can delete a project that has not launched from its page.
10.Security and transfers
We use access controls, encryption in transit and reputable providers to protect information, but no system is completely secure. Our providers may process information in countries other than yours, including the United States, where data-protection laws may differ.
11.Children
The Service is not for anyone under 18, and we do not knowingly collect information from children.
12.Changes
We may update this policy. When we do, we change the date at the top of this page. If a change is significant we will make it clear on the Service.
Questions about this page: info@vrfy.fun