Last updated:
Draft prepared by the PANDA team, not by a lawyer — treat this as a good-faith starting point, not final legal advice, until it's reviewed by qualified counsel in the relevant jurisdiction.
The short version: PANDA collects very little, because it doesn't need much to work. This page describes what the app actually does, not a generic template.
Wallet data and records. When you connect a wallet, PANDA reads its public address and, for the Portfolio page, your real token balances on Solana — public data, read live. PANDA also stores, tied to public wallet addresses: the log of trades you make through PANDA (coin, side, amounts, the SOL price at that moment, public transaction signature, time) and, for Portfolio, trades read back from your public on-chain history, marked as estimates; records of on-chain activity PANDA verified (launches, trades, fee distributions), which feed the Activity and Analytics pages; the sign-in challenges and sessions of wallets that sign in (wallet address, a random session id, issue and expiry times, and whether the session was revoked); a coin's creator wallet and fee split while a launch is being confirmed; and an audit trail of sensitive actions (wallet address, action, object, public signature, time). None of these records contains your IP address. PANDA never receives, requests, or stores your seed phrase or private key.
Where it is stored. Records live in a Postgres database hosted by Neon. Rate-limit counters and aggregated browser-security reports live in Upstash (Redis). Vercel runs the site; its functions, Neon's database and Upstash run in the United States (US East), so the data they process is transferred outside the European Union. Images and metadata you upload for a coin — and files of any feature that is not yet in the database — live in Vercel Blob, in Paris (France), at public addresses. During the move from file storage to the database, older copies of some records remain in Vercel Blob for a transition period and are then deleted.
How long. Sessions last 2 hours; expired sessions and sign-in challenges are deleted automatically (challenges a day after they expire, sessions a week after). Rate-limit counters expire with their window. Audit entries can't be edited or deleted — the database refuses it, by design, so history can't be rewritten. Trade, activity and launch records are kept for 5 years.
IP address. To protect the service from abuse, your IP address is used as a counter key in Upstash for the length of the rate-limit window only (normally one minute, up to one hour for a few actions), and then it expires. The hosting provider (Vercel) may also keep standard access logs, with IP addresses, for security and reliability. PANDA does not use them for tracking or marketing.
Cookies and local storage. See the Cookie Policy: one technical cookie, set only if you sign in, and no analytics, advertising or session-replay tools.
Third-party services. To show real data and build real transactions, your browser or PANDA's servers make requests to: Pump.fun (public API and coin images), GeckoTerminal and Dexscreener (market and pool data, prices, token names and logos), Jupiter (swap quotes and routing, and names, logos and prices of tokens in your wallet), RugCheck (a coin's risk indicator: PANDA's servers send it only the coin's address, your browser never connects to it, and the "View on RugCheck" link takes you to rugcheck.xyz, which has its own policies), a Solana RPC provider (reading balances, sending transactions — your browser talks to PANDA's own server, which calls the provider), the European Central Bank's euro reference rate through Frankfurter (currency conversion), and the public hosts where coin creators keep their images (your browser loads those directly, so those hosts see your IP address). These requests carry the technical information any web or API request does (for example the IP address, at network level). PANDA doesn't combine this with your wallet address or build a profile of you.
Stop Loss / Take Profit and Draw Your Trade. Only if you set one up, your wallet address, the order details and a Jupiter sign-in are sent to Jupiter's Trigger API and its vault provider Privy. PANDA also stores your strategies (prices, amounts, state, public transaction signatures) tied to your wallet address; the Jupiter session token is kept only in your browser's memory, and PANDA's server only forwards it to Jupiter, never storing it.
Holder rewards. PANDA keeps a record, in its database, of the rewards owed to and already paid to each wallet address, and of each automatic payout round.
Recruiters program. PANDA keeps, in its database: which wallet referred which (permanent, never changed) and when; each recruiter's own short code, if it has one; each invitee's daily trading-volume-vs-threshold record and the resulting active/inactive streak; a record of each recruiter commission payment it verified on-chain (amount, coin and transaction); which coins were launched through PANDA's own Create flow and by whom (used for the coin-page-as-recruiter-link feature and the "Launched on PANDA" showcase); which wallets are on the referred/legacy fee rate and since when; and Founder slot allocations (rank, reservation and mint status). This is what powers the /recruiters page's own stats and a wallet's tier and fee rate.