Who this notice covers
Community.fun is operated by the project owner. Use the support form for questions about the use of your data or to make a privacy request. The website is a community service. No financial product is offered through account registration.
What we collect
Member registration and member features remain locked before the Community token launch. No new email member accounts are accepted. Optional Phantom sign-in processes your public wallet address and signed proof of control. We store the address, a temporary challenge, expiry times and a hash of the session token. We do not store the full wallet signature or request private keys. Existing member records, if any, remain stored for support and privacy requests. The separate owner account stores its email, display name, password hash, recovery-code hash and consent record. Enquiry forms store the contact details, brief and optional campaign or referral identifiers you submit.
Why we use it
We use this information to operate your account, protect the service, moderate content, review contributions, respond to requests, and assess business enquiries. Marketing updates require a separate optional consent. We do not sell personal data or use your submissions to promise financial eligibility.
The public PFP maker
Public character choices and downloads are generated in your browser without a photo, email or wallet. Public designs are not uploaded or stored by the maker. Optional shared links contain only artwork choices in the URL fragment, not personal identifiers. Anyone with a design link can recreate the artwork. Optional wallet sign-in is a separate step. Premium exports remain locked; when available, an export will send the design code and selected finish to the server to check access and render the artwork. Our hosting provider still processes page and asset requests and associated network information.
What other people can see
The member space is unavailable while membership is locked. Existing private member records, owner credentials, and business enquiries are restricted to the service and authorized operators. A display name is not proof of identity. Public or commercial use of submitted creative work needs the separate permissions described in the terms.
Service providers and international processing
Cloudflare hosts the website, database, security services and any configured email routing. Phantom operates the wallet under its own privacy policy. PFP premium token-balance queries stay off before the Community token launch is configured. Future holder checks will send a public wallet address to the configured Solana RPC provider to read public blockchain data. Providers may process information in countries different from yours. External social services have their own privacy practices. We do not embed social tracking widgets.
Cookies and local storage
Essential secure cookies keep the owner logged in and bind an optional wallet challenge and session to your browser. Wallet cookies are HttpOnly, Secure and SameSite Strict. The challenge lasts five minutes and the wallet session one hour. A short-lived session value remembers an optional referral and campaign source during your visit. Cloudflare Turnstile loads on enquiry, support and owner access pages to prevent abuse, but not on the PFP maker or ordinary browsing pages. The site does not use advertising cookies. The maker does not save designs in local storage; keep a download or design link before leaving.
Retention
Wallet challenges expire after five minutes and wallet sessions after one hour. Disconnect revokes the server session when the sign-out request succeeds. A daily cleanup removes expired wallet records, normally within 24 hours; a challenge is retained while an active session still references it. Owner sessions expire after seven days. Rate-limit counters are cleared after expiration. Website enquiry records are retained for up to twelve months. Separately agreed client contracts or legally required business records are handled separately. Existing member data is preserved while access is locked; use support to request removal. Minimal non-content audit records may be retained for security. Provider backups may persist for their normal retention window.
Your choices
Use the support form to request a copy, correction, deletion, or withdrawal of any stored consent while member access is locked. We may need to verify the request before acting. Depending on your location, additional privacy rights may apply.
Children
This initial service is for adults aged 18 or older. Do not create an account or submit personal information if you are under 18.
Changes
Material changes will be reflected in a dated notice. New uses that require consent will ask for it separately.
Community usernames and pins
A username claim privately links a reserved site name to your wallet. Names require owner review before public use. Website pin requests require an approved name and at least 5,000,000 OTC, or Community tokens after its official launch. Balances are not combined. Each message needs owner approval. Read the identity and pin privacy notice for public fields, retention and removal requests.
Discord holder verification
Discord access uses a separate sign-in and token policy. When enabled, it stores the Discord account ID, display name, linked public wallet address and access check records. It uses a separate session lasting up to 24 hours and sends public wallet addresses to the Solana RPC provider for holdings checks. Read the Discord verification notice for retention, cookies and unlinking details.