1. Scope
This Privacy Policy explains how MIRADOR ("MIRADOR", "we", "us") handles information when you use the website at mirador.fun, its APIs and related services (the "Service"). It should be read together with our Terms of Service.
2. The short version
- We identify you by your Solana wallet address, which is already public on the blockchain.
- We never ask for, see or store private keys or seed phrases, and we never hold your funds.
- We use one strictly necessary cookie: a signed session token. No advertising or cross-site tracking cookies.
- Your calls, handle, points and rank are public by design. That is how the Arena works.
- We do not sell personal information.
3. What we collect
3.1 Information you provide
- Wallet address: when you connect a wallet and sign our login message.
- Signature: a signature over a one-time nonce, used once to verify wallet ownership. It authorizes nothing on-chain.
- Handle: an optional public display name you choose.
- Activity: calls you place (token, direction, horizon, optional note), tokens you add to your watchlist and on-demand scans you request.
- Correspondence: anything you send us by email.
3.2 Information collected automatically
- Technical logs: IP address, user agent, request path, timestamps and error data, collected by our hosting and infrastructure providers for security, rate limiting and debugging.
- On-chain data: your public $MIRA token balance, read from the Solana blockchain to compute your tier.
3.3 What we do not collect
We do not collect private keys, seed phrases, names, government IDs, phone numbers, payment card data or precise geolocation. We do not run third-party advertising trackers.
4. Public by design
Blockchain addresses and transactions are public and permanent. The Arena is a public competition: your wallet address (or handle), calls, scores, points, win rate, streak, tier and rank are displayed publicly and exposed through our public API. Do not choose a handle or write a call note that reveals information you want to keep private. Information that is already public on-chain cannot be made private by us.
5. How we use data
- To authenticate you and keep you signed in (performance of a contract).
- To operate the Arena: record, score and rank calls, and enforce per-tier limits (performance of a contract).
- To compute your tier from your public $MIRA balance (performance of a contract).
- To secure the Service, prevent abuse and rate-limit requests (legitimate interests).
- To debug, maintain and improve the Service (legitimate interests).
- To comply with legal obligations and respond to lawful requests (legal obligation).
Eye analyses are generated about tokens, not about you. Token metadata, not your personal data, is sent to our AI provider to produce them.
7. Third parties
We rely on the following providers. Each processes data under its own terms and privacy policy:
- Supabase: database and realtime infrastructure (stores profiles, calls, watchlists).
- Vercel: hosting and edge network (request logs).
- Reown (WalletConnect): wallet connection relay.
- Helius: Solana RPC (balance lookups for your public address).
- Google Gemini: AI model provider for Eye analyses (receives token data only).
- PumpPortal, pump.fun and DexScreener: public market data sources. The token chart is an embedded DexScreener frame, which loads directly from DexScreener and is subject to its policies.
We may disclose information if required by law, to protect the rights, property or safety of MIRADOR, our users or the public, or in connection with a merger, acquisition or sale of assets, in which case this policy continues to apply.
8. Retention
Profiles, calls and scores are retained while the Service operates because they form the public leaderboard history. Login nonces are single-use and short-lived. Technical logs are kept for a limited period by our infrastructure providers, typically no more than 30 days. Data that exists on the blockchain is permanent and outside our control.
9. Your rights
Depending on where you live (for example under the GDPR, UK GDPR or CCPA/CPRA), you may have the right to access, correct, delete or port your personal data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. You can remove your handle and watchlist at any time. To request deletion of your off-chain profile, email us from a channel where you can prove control of the wallet (we will ask you to sign a message). Scored calls may be anonymized rather than deleted to preserve leaderboard integrity. We do not sell or "share" personal information for cross-context behavioral advertising.
10. Security
Sessions are signed and HttpOnly; database writes go through server-side code only; access to production systems is restricted. No system is perfectly secure. Never share your seed phrase with anyone. MIRADOR will never ask for it.
11. Children
The Service is not directed to anyone under 18 (or the age of majority where you live). We do not knowingly collect data from minors. If you believe a minor has used the Service, contact us and we will remove associated off-chain data.
12. International transfers
Our providers may process data in the United States and other countries. Where required, transfers rely on appropriate safeguards such as standard contractual clauses offered by those providers.
13. Changes
We may update this policy as the Service evolves. Material changes will be announced on the site, and the effective date above will change. Continued use after an update means you accept the revised policy.
14. Contact
Questions or requests: legal@mirador.watch.