MINTREVOKE ← Back to MintRevoke

Effective 20 August 2026

Privacy notice

This notice explains the data used by the current MintRevoke website, its server endpoints and the third-party blockchain services required for the product to work.

1. Information MintRevoke does not request

MintRevoke does not require an account, legal name, email address, phone number or government identifier. It never asks for a seed phrase or private key. Never enter wallet recovery information into the site.

2. Wallet and blockchain data

When Phantom is connected, MintRevoke reads the selected public wallet address, SOL and token balances, token accounts, mint and freeze authorities, and relevant Raydium pool, reserve and LP information. Confirmed addresses, balances, mint and pool accounts, and transaction signatures are public on Solana.

3. Token forms and public IPFS

Token name, symbol, description, public wallet address, optional reference mint, image bytes, MIME type and original image filename are sent to the MintRevoke metadata endpoint. Pinata receives the image and filename as pin metadata. The public JSON identifies the submitted wallet as the metadata creator. The image and JSON are published to public IPFS before Phantom signs the mint transaction. Public IPFS content can be copied, cached and remain available even if the wallet transaction is later cancelled. Do not submit personal, confidential or unlawful content.

4. Data stored in your browser

MintRevoke uses local storage for the selected theme, up to 100 created-token records, up to 100 saved pool records and the display-only campaign countdown. Records can include mint, pool, vault and LP identifiers, public wallet addresses, transaction signatures, timestamps and selected seed amounts. This information is tied to that browser profile and is not a cross-device account or proof of ownership. It remains until the user clears site data, the browser evicts it or a newer record replaces the oldest one. Clearing site data does not remove confirmed blockchain transactions or public IPFS files.

5. Server requests and rate limiting

MintRevoke's server proxies allowlisted Solana RPC requests, including signed transaction submissions, and serves market, image and metadata endpoints. These requests include normal connection data such as an IP address and browser headers. IP addresses are used for abuse prevention and rate limiting; metadata-upload limits also use the submitted public wallet address. Metadata limit identifiers affect requests for ten minutes and are deleted from application memory within twenty minutes. Market and RPC limit identifiers affect requests for one minute and are deleted within two minutes. They can disappear sooner when the process restarts. Error details can be written to the hosting provider's technical logs; the provider's configured retention must be disclosed by the operator before public launch.

6. Infrastructure and third parties

Pinata processes public metadata uploads. Jupiter supplies public Mainnet market data and indexed images. Solana RPC and Raydium services are used to read, build, simulate, submit and confirm transactions. Phantom provides wallet access. Links can open Jupiter, Photon, Raydium, Solana Explorer or documentation in a new tab. When wallet inventory loads public off-chain metadata, the browser may contact the metadata host directly. The main page also loads Google Fonts. These third parties can receive ordinary connection data such as IP address and browser information under their own policies.

7. Analytics, cookies and advertising

The current MintRevoke code does not include an analytics package, advertising tracker or MintRevoke cookie. It does use the local-storage records described above. Linked and infrastructure providers may use their own storage or logging when their services are requested.

8. Security and your choices

No web interface can eliminate wallet or blockchain risk. Keep your device and wallet secure, inspect every Phantom request, avoid submitting personal content and clear MintRevoke site data if you no longer want the local history stored in that browser.

9. Legal bases where GDPR applies

Data needed to perform a user-requested paid metadata or transaction service may be processed because it is necessary to take requested steps or perform a contract. Limited connection and rate-limit data may be processed for the legitimate interests of securing the service, preventing abuse and maintaining reliable operation. Information may also be retained where necessary to comply with a legal obligation. The final operator must document these assessments and publish any materially different basis before launch.

10. Retention and public records

Browser retention and in-memory rate-limit periods are described above. Solana records generally remain for the lifetime of the public network. IPFS content remains available while pinned and may be retained by independent peers or gateways indefinitely. MintRevoke cannot rewrite confirmed Solana data or guarantee deletion of independent IPFS copies. Hosting, support, security, legal and accounting retention periods must be completed by the legal operator before public launch.

11. Sources, automated limits and international providers

Data comes from the user and browser, Phantom, public Solana and Raydium accounts, Jupiter and public metadata hosts. Wallet and content fields are required only for the transaction the user chooses. MintRevoke does not make decisions with legal or similarly significant effects, although automatic rate limits can temporarily reject requests. Infrastructure providers may process connection data outside the EEA. The operator must identify the actual host and RPC provider and document any adequacy decision, contractual safeguards or other transfer mechanism before public launch.

12. Controller, rights and complaints

Where GDPR applies and subject to its conditions, a person may request access, rectification, erasure, restriction or portability, object to processing, or withdraw consent where consent is used. The operator can act only on data it controls; it cannot rewrite Solana or guarantee deletion of copies retained by independent IPFS peers. The legal controller's full identity, geographic address, privacy contact and the competent supervisory authority must be published here before a public launch. If the Norwegian authority is competent, a person may complain to Datatilsynet.