curve.

YOUR DATA ON CURVE

Privacy policy

What the service handles, what becomes public, and the choices available in your account.

1. Information the service handles

InformationExamples and purpose
Account detailsAutomatically assigned or chosen username, account identifier, creation time, sign-in wallet, and account preferences. Legacy records can also include previously configured receiving addresses.
Sign-in and securityWallet-verification challenges and session records. The owner's legacy recovery records can also contain password hashes and two-factor setup/recovery information. Your wallet's private key is not needed for wallet sign-in.
Public contentProfile picture, bio, username, token name, ticker, description, image, links, and the relationship between a creator profile and launched coins.
TransactionsLaunch reviews, reviewed quote-asset price references, bonding-curve targets and sale/migration allocations, selected reward modes, creator-fee and transfer-tax rates, signed transactions submitted through Curve, signatures, amounts, fee and reward records, status, recovery history, and records of approved fee or liquidity-policy upgrades. Upgrade records include the previous and updated settings, administrator identity, reason, time, public fee-wallet and administrator addresses, the selected protocol wallet, and confirmation reference.
Operational dataIP addresses used to handle requests and apply abuse limits; request metadata, error details, moderation records, and any logs maintained by the hosting infrastructure.

The normal account flow does not ask for a legal name or email address. Information you choose to put in a public profile or launch can still identify you.

2. What other people can see

Creator fees assigned to your wallet appear in a private section of your Launched tokens page after wallet sign-in. The assignment does not add the token to your public profile or change its original creator attribution. Payout addresses and transfers remain public on Solana, and Curve administrators can view and manage fee assignments.

Your creator username, bio, picture, publicly listed launches, and displayed market history are public. Usernames can be found through the search bar in the site header, and search results link to public creator profiles. Hidden and archived launches are excluded from public results. Solana wallet addresses, balances, transaction signatures, token holdings, transaction activity, and onchain fee or liquidity settings are public blockchain information. Connecting a username to a launch can make that activity easier to associate with you.

The public Analytics page reports aggregate launch counts, distinct original launch-wallet counts, trading volume, holder distributions, the number of distinct wallets paid holder rewards, and protocol buybacks and burns. Totals can include hidden and archived coins without publishing their names, private launch records, or creator identities in the analytics response. Confirmed protocol treasury receipt links lead to public Solana transactions. Analytics does not publish sign-in credentials, private keys, or administrative controls.

Launch images and metadata can be uploaded to public storage through Irys. They may remain accessible independently of Curve. Public profile and token images are also served from addressable URLs on the site. Avoid putting secrets or information you want to keep private in an image, bio, or token description.

3. Wallets and security

When you use an external wallet, your wallet app signs the login message or transaction. Curve receives the address, proof, and any transaction you submit; this does not require sending that wallet's private key to Curve.

Curve does not generate a personal wallet for new public accounts. Separate launch, fee-collection, buyback, and distribution wallets use service-managed signing keys stored encrypted. An approved legacy policy upgrade can create an additional protocol-fee wallet whose key is retained in the encrypted launch record; its address and confirmed onchain assignments are public. The optional automated protocol treasury uses a dedicated signing key stored encrypted, with saved revenue, conversion, purchase, burn and withdrawal records. Its operator can supply a dedicated wallet while retaining its backup and direct wallet access; Curve also has signing access to perform the enabled automation. Its public address and confirmed transactions are visible onchain. Previously generated owner wallets can remain in legacy recovery records. Curve controls these service-managed keys and uses them to perform the configured launch, fee, reward, recovery, and buyback operations. They are separate from your connected wallet’s private key.

Public accounts use wallet signatures without a password or authenticator code. The owner's legacy password path stores password hashes and supports two-factor authentication where enabled.

4. Cookies and browser data

Curve uses a relay-session cookie to keep you signed in. It is HTTP-only, so site scripts cannot read its value. Wallet verification uses a short-lived curve-wallet-proof cookie, which expires after five minutes. Blocking these cookies prevents the corresponding sign-in flows.

Your wallet app may keep its own connection and preference data. Clearing site data or signing out ends your browser access; disconnecting a wallet alone is not the same as signing out, deleting your Curve account, or stopping an already authorized onchain operation.

5. How information is used and shared

The service uses this information to operate accounts, display profiles and markets, prepare and track transactions, calculate rewards and fees, verify approved policy changes, recover pending operations, and prevent abuse. Authorized administrators can inspect relevant account and launch records for moderation and support.

Hosting and storage providers process the data needed to operate the site. RPC, market-data, routing, and blockchain services receive the addresses, queries, transaction data, or metadata needed for their part of an operation. Public transaction data is broadcast to Solana. An external link or embedded third-party view may expose your IP address and request information directly to that provider.

Records may also be disclosed when required by applicable law or necessary to investigate misuse and protect users or the service. Independent providers handle data under their own terms and may process it in other countries.

6. Retention and uploaded images

Account, launch, fee, treasury-automation, policy-upgrade, and transaction records are retained to operate accounts, reconcile activity, and investigate abuse. The application does not currently impose an automatic deletion date on account records or uploaded media. Infrastructure logs and backups can have separate retention periods.

You can replace or remove the picture shown on your profile. That changes the profile reference; it does not automatically erase the old uploaded file, cached copies, or any image already used in token metadata. Uploaded images currently have no automatic expiry.

Curve cannot erase confirmed Solana history or guarantee removal from permanent storage and third-party caches. Hidden coins and manually archived launch requests remain accessible in the private Archived tokens section. Archiving retains the launch and transaction records, recovery status, and archive-action history; it does not delete them. Hiding a coin removes it from public Curve listings and token pages.

7. Your choices

You can edit your public bio and picture, change your username once every 30 days, and manage the supported account settings. You can stop using the service, disconnect your external wallet, sign out, and clear browser data.

There is currently no self-service account-deletion tool. Depending on applicable law, you may have rights to access, correct, or request deletion of personal information. Nothing in this notice limits those rights, and deleting offchain information cannot remove a public blockchain transaction.

For privacy questions or to ask how to exercise applicable rights, contact @curvebond on X and ask for a private support channel. Do not post sensitive information publicly or send credentials, private keys, seed phrases, or recovery codes.

Updates to this notice will appear on this page with a revised effective date.