Privacy
What we collect, who receives it, and what we cannot take back. Written from the code rather than from a template — the table of third parties is generated from the list the software actually talks to.
Last updated 24 September 2026 · Operated by Totym · hello@totym.io
What we store
Your email address, if you sign in with email or Google. It comes from Privy and is kept so an account survives a change of wallet.
Your wallet addresses, and whether each is one you brought or one created for you when you signed in without a wallet.
What you make — communities, posts, channels, lessons, images, and the gate settings that decide who gets in.
A membership record: the first time a wallet passes a community's gate here, and the last time it was seen doing so. This is how a community knows who its members are.
Product measurements, described below, which are deliberately narrower than is usual.
What we deliberately do not store
No IP addresses. Our hosting provider keeps request logs, as any host does, but nothing in our own database records one.
No full referrer. We keep the host somebody arrived from, never the whole URL, because a full referrer discloses the page they were reading.
No query strings. Paths are recorded without them: query strings carry tokens, email addresses and invite codes.
No fingerprinting. The visitor identifier is a random value we generate, stored in your browser. It identifies a browser, not a person, and it is never joined to anything off-site.
No advertising, no tracking pixels, no third-party analytics. There is no Google Analytics, no Meta pixel, and no session recording.
Who else receives it
Everything below is a service the software actually reaches. If we add one, this table has to change with it — an automated check fails otherwise.
| Service | Why | What reaches it |
|---|---|---|
| Privy | Sign-in and wallet linking | Your email address or Google account when you use one to sign in, and the wallet addresses you link. Privy holds the identity; Totym reads it back and stores the email address and wallet list. |
| Supabase | Database and file storage | Everything the product stores: your email address, your wallet addresses, the communities you create and their content, and a record of the first time each wallet passes a gate. |
| Vercel | Hosting | The ordinary contents of a web request, including your IP address, in server logs Vercel keeps. Totym does not store IP addresses itself. |
| Sentry | Error reporting | Server-side error reports. There is no Sentry initialisation in the browser bundle, so no client-side errors or session replays are collected. |
| Helius | Solana blockchain reads | Wallet addresses and token addresses, in order to ask the Solana network what a wallet holds. This is how a gate decision is made. |
| Alchemy | Ethereum, Base and Robinhood Chain reads | Wallet addresses and contract addresses, for the same reason as Helius. |
| Pinata (IPFS) | Image hosting for community and token artwork | The images you upload. IPFS is a public network and content on it is addressed by its hash, so an uploaded image is public and cannot reliably be deleted once it has been distributed. Do not upload anything you need withdrawn later. |
| MoonPay | Optional link to buy SOL | Nothing, unless you follow the Fund link — which opens MoonPay with your wallet address in the URL. Totym sends them nothing on its own. |
| DexScreener and Birdeye | Token prices and market data | Token addresses only. No personal data and no wallet addresses. |
| pump.fun and PONS | Token creation, when you launch a token | The transaction your wallet signs. Like all blockchain activity this is public and permanent by design, and it is not something Totym can undo. |
We do not sell personal data, and we do not share it for advertising.
Two things we cannot undo
This is the part most policies leave to the end, and it matters more here than anything else on this page.
Blockchain activity is permanent and public. A token you launch, a transaction your wallet signs, a payment you make — these live on a public ledger that nobody operates and nobody can edit. Deleting your Totym account does not remove them, because they were never ours to remove.
Images uploaded to IPFS are public and effectively permanent. Community and token artwork is stored on IPFS, a public network where content is addressed by its hash. Once an image has been distributed we cannot reliably withdraw it. Do not upload anything you may need taken back.
How long we keep it
A community you delete is hidden immediately, retained for 30 days so it can be recovered, and then permanently removed.
Account data is kept while the account exists. Write to us and we will remove it, subject to the two exceptions above.
Your requests
Write to hello@totym.io to see what we hold about you, correct it, or have it deleted. We answer from a person, not a ticketing system, so allow a few days.
Depending on where you live you may have stronger statutory rights than this page grants. Nothing here is intended to reduce them.
Children
Totym is not intended for anyone under 13, and we do not knowingly collect their data.
Changes
The date at the top is the last substantive revision. Material changes will be announced on the product itself rather than only here, because nobody re-reads a privacy policy.