ApeFax
APEFAX
CHECK BEFORE YOU APE
ApeFax · Privacy

Privacy Policy

Last updated 2026-07-17

§1Scope & principles

ApeFax is a non-custodial, primarily anonymous service. We collect the minimum information needed to operate the product and we do not sell personal data. Wallet addresses are pseudonymous; we treat them as personal information when combined with other identifiers (email, phone) you provide.

§2Information we collect

You provide:

  • Wallet address & SIWE proof: when you connect a wallet, we process the signed message and signature to verify wallet control. The signature is not kept in the account record after verification.
  • Email and/or phone: only if you join the launch waitlist or opt in to delivery/refund notifications. Either field alone is sufficient; both are never required.
  • Notification preferences: which categories (mainnet launch, MAYC support, etc.) you want to hear about.

We collect automatically:

  • Request metadata: the application and its hosting providers process the connecting IP address, user-agent string, referrer, and timestamps for security and abuse prevention. The application uses the connecting IP in a short-lived in-memory rate-limit window. Waitlist intake persists only a salted IP hash, not the raw IP.
  • On-chain data: transactions, ownership history, and marketplace events for the apes you query. This data is public on Ethereum.
  • Service telemetry: error logs, rate-limit counters, Core Web Vitals, and privacy-minimized aggregate product events. Product events record only a normalized route category and a limited event category such as report access state, unlock step, tool action, share outcome, search collection/result category, or error-boundary hit. They do not include raw search text, wallet addresses, token IDs, transaction hashes, email, phone, IP addresses, cookie values, or session identifiers.

We do not collect: private keys, seed phrases, government IDs, date of birth, social-security numbers, or credit-card numbers. We do not require a real name to use the service. We do not run third-party advertising or behavioral-tracking scripts.

§3How we use this information

We use the information above to:

  • Authenticate your wallet and tie unlocked Reports to your account.
  • Deliver Reports, refunds, and launch notifications you have opted into.
  • Prevent abuse, fraud, and unauthorized access (rate limiting, anomaly detection).
  • Measure aggregate product reliability and funnel completion without building user profiles.
  • Improve the scoring model and product. Improvements are based on aggregate patterns. We do not train models on data tied to a specific wallet's identifiable behavior.
  • Comply with legal obligations (tax records on payments, response to lawful process).

§4Cookies & storage

We use a small number of cookies to keep you signed in, remember your preferences, and route owner-preview traffic during pre-launch. We do not run third-party advertising cookies. The launch-preview cookie is set only when you visit a specific owner-preview URL.

Browser local storage may be used to cache a small amount of UI state (selected collection, last-viewed ape) for performance. None of this is transmitted to third parties.

§5How long we keep your data

  • Waitlist email/phone: until you unsubscribe or ask us to delete the contact record. We may retain the minimum suppression record needed to honor an unsubscribe and prevent an accidental send.
  • Wallet authentication records: SIWE nonces and signed-session cookies expire automatically. Account and wallet-link records remain while the account is active or until deletion is requested, except where limited records are needed for security, fraud prevention, or legal obligations.
  • Report snapshots tied to your wallet: while you keep the account so you can return to a paid Report. You may request deletion; payment and dispute records may remain separately where required.
  • Application and security logs: according to the operational and security settings of our hosting providers, then deleted or de-identified when they are no longer needed. We do not claim a fixed automated deletion window that the application cannot prove.
  • Rate-limit and intake identifiers: in-process IP-based rate-limit windows expire automatically. A salted intake-security hash may remain with its submission record until the record is deleted or de-identified.
  • Payment receipts: as long as needed for tax, accounting, fraud prevention, disputes, and other legal obligations.

§6Third parties we use

We share data with the following infrastructure providers only as needed to operate the service and under their applicable service terms. ApeFax does not sell personal data.

  • Supabase: primary database; stores waitlist entries, snapshots, and account records.
  • DigitalOcean: application hosting and edge logs.
  • Cloudflare: DNS and edge caching.
  • Sentry: privacy-minimized error reporting, aggregate product-event counters, and Core Web Vitals. Default personal-information collection is disabled.
  • Resend: transactional email delivery (waitlist receipts, launch notifications).
  • Twilio: transactional SMS delivery for users who opt in to phone notifications.
  • Bitquery, OpenSea, Alchemy, Etherscan, Dune, Gondi: read-only data sources for on-chain history, marketplace activity, trait and trade analytics, lending data, and ETH/USD pricing.
  • Wallet software (e.g. MetaMask, Rabby, Coinbase Wallet, WalletConnect): your chosen wallet connects from your own browser to sign messages and transactions. We never receive your keys and do not send these providers your contact information.

We do not share waitlist contacts with marketing partners. We do not run ad-network pixels.

§7Your rights

You may, at any time:

  • Access the personal data we hold for your wallet or contact.
  • Correct inaccurate information (e.g., update an email address).
  • Delete your waitlist entry or wallet-account record. On-chain transactions cannot be deleted; we can sever the link between them and your account.
  • Unsubscribe from email or SMS using the link in any message or by replying STOP to SMS.
  • Export a copy of your account data in a machine-readable format.

Requests: [email protected]. We respond within 30 days. The pre-filled request asks only for the wallet or contact record involved and the action you want; never send a private key or seed phrase.

§8International transfers

ApeFax is operated from the United States. If you access the service from outside the U.S., your information may be transferred to the U.S. and other locations where the providers listed above operate, subject to their applicable terms and legal safeguards. Contact us for current processor details.

§9Children

ApeFax is not intended for users under 18 and we do not knowingly collect personal information from children. If you believe a minor has provided information, contact us and we will delete it.

§10Security

We use TLS for all traffic, an HSTS header with the preload directive, and a Content Security Policy. Database access uses Row-Level Security; service-role credentials remain server-side and are not exposed to browser code. We do not store private keys or any signing material. No system is perfectly secure; report suspected vulnerabilities to [email protected].

§11Changes & contact

We may update this policy over time. Material changes will be announced on the site at least seven days before they take effect.

Privacy questions: [email protected].

Data minimalism. ApeFax reads public blockchains; it does not need to know who you are. If a feature can work without collecting personal information, it is built that way.