Last updated: 13 August 2026

Privacy policy.

What the Drafts.fun site and its rank checker collect, why, who else sees it, how long it lives, and how to get rid of it. Written to be read, not to be survived.

The short version
  • You can read this whole site without giving us anything. The rank checker is optional.
  • If you run it, we handle a Solana wallet address and a one-time ownership signature, or a small X profile, or both. Your choice.
  • The scan is read-only. We never request a transaction, never take custody, never touch funds, and never post as you.
  • The records that identify you live in encrypted cookies in your own browser. We do not keep a user database of them.
  • There are no advertising cookies and no cross-site tracking on this site, and we do not sell your personal information.
  • Clearing this site's cookies deletes your side of it. For anything else, email yo@drafts.fun.
01

Who we are

This site is operated by Drafts.fun, which is the controller of the personal data described here. In this policy, "Drafts.fun", "we", "us" and "our" mean Drafts.fun, and "you" means the person using the site.

One address handles questions, support, and every privacy request in this policy: yo@drafts.fun.

02

What this policy covers

This policy covers the Drafts.fun pre-launch website and the rank checker on it. It explains what that site handles about you.

It does not cover third-party services you reach from here, such as X or your own wallet software. Those have their own policies, and section 06 names the ones in the path.

Your use of the site is also governed by our Terms of Use.

03

What we collect and why

Browsing the site requires nothing from you. Everything below happens only if you choose to run the rank checker.

Solana wallet address and ownership signature

If you pick the wallet source, we handle your Solana wallet address, which is a public key, and a one-time signature of a plain-text challenge message that we show you in full before you sign. The signature exists to prove the wallet is yours. Together they let us score public on-chain signals for that address.

X profile

If you pick the X source, you sign in with X using OAuth 2.0 with PKCE. We receive your numeric user ID, username, display name, and profile image URL. The scopes we request are exactly tweet.read and users.read. We do not request offline.access. We call the X profile endpoint exactly once and then immediately revoke the access token. We use this to confirm which account you are and to score that account.

IP address

Your IP address is used for rate limiting, which protects the checker from automation and abuse, and it appears in ordinary hosting request logs kept by our hosting provider.

Scoring results

The output of a scan: a score, a rank label, a per-signal breakdown, a non-redeemable starting-balance figure, and the URL of a generated 1080 by 1080 image card. These are produced so we can show you your result and so you can share your card if you want to.

The waitlist field

The site shows a field where you can enter an email address to be told when a wave opens. That address is sent to our own server and stored in our own database, along with which form on the site you used, any campaign parameters that were in the URL you arrived on, and which shared rank card referred you if one did. It is not shared with anyone and no third party receives it. We do not send marketing mail and there is no mailing-list provider on this site; if either of those changes we will name the provider in this policy and update the last updated date before it goes live. Ask us to delete your address and we will, and it stays deleted unless you enter it again.

04

What we never do

  • We never ask you to sign a transaction, and never ask you to grant a token approval. The wallet scan is read-only.
  • We never take custody of your funds and never touch them. We hold no private keys and no seed phrases, and we will never ask you for either.
  • We never post as you on X, and we never read your posts, followers, likes, or Direct Messages.
  • We never keep a long-lived X access token. We do not request offline access, and the short-lived token is revoked immediately after a single profile call.
  • We never sell your personal information, and we never share it for cross-context behavioural advertising.
06

Who else receives data

We keep this list short deliberately. These are the services genuinely in the path, and what each one receives.

ServiceRoleWhat it receives
VercelHosting and content deliveryOrdinary request data, including your IP address, user agent, and the pages you request.
Drafts.fun scoring APIOur own service that produces the scoreYour wallet address, or your verified X username and user ID, depending on the source you chose.
ChainAwareScoring provider called by our APIThe wallet address being scored. Nothing beyond that.
WallchainScoring provider called by our APIThe wallet address or verified X username being scored. Nothing beyond that.
XSign-in, if you choose the X sourceThe sign-in request itself. X returns your ID, username, display name, and profile image URL to us.
Amazon CloudFrontServes your generated card imageThe image request, including your IP address and user agent.
Vercel BlobServes the marketing filmThe video request, including your IP address and user agent.
UpstashShort-lived shared store for rate limiting and resultsRate-limit counters keyed by your IP address, your network block, and a hashed session reference, plus a copy of a finished scoring result that carries no wallet address and no username.
NeonOur databaseEverything section 09 says is kept on our side and is not a cookie: a registered account with its linked wallet addresses and X handle, its rank cards, a waitlist address if you entered one, and the interaction events described in section 08. It is our own database and Neon runs it for us; the data is not theirs to use.

These providers act as our processors, or as independent controllers for their own infrastructure logs, and are bound by their own terms. We do not send them anything beyond what this table describes. We may also disclose data where the law requires it, or where it is necessary to protect the site, our rights, or the safety of others.

A small, named group of our own people can also see this data. We run an internal admin tool that lists registered accounts and shows, for each one, the Flex Score and rank, the linked wallet addresses, the linked X handle, the chosen drafter, and any rank cards that account has produced. Access is restricted to an explicit allow-list of X accounts, is granted only after signing in with X, is re-checked on every request so that removing someone takes effect immediately, and every sign-in, refusal, export, change, and deletion is recorded in an audit log that identifies who acted.

That tool can export the same information to a spreadsheet file, which our operators use for support and for understanding how the beta is being used. We are stating this plainly because it means your wallet address and X handle can leave our database and sit in a file on a company device. We do not sell that file, we do not give it to advertisers or data brokers, and it is covered by the same commitments as the rest of this policy. Exports are logged with the operator who ran them.

Operators can also correct and delete registrations. A deletion removes the account, its linked wallets, its linked X identity, and its stored rank cards, including the card images themselves, which are removed before the records are, so that a deleted account cannot leave a published picture behind.

07

Cookies

Every cookie this site sets is strictly necessary for the rank checker to work. They are all sealed with authenticated encryption, so the browser holding them cannot read or forge their contents, and all of them are HttpOnly, so scripts on the page cannot read them either. All are set with SameSite Lax, and with the Secure flag in production.

There are no advertising cookies, no cross-site tracking cookies, and no third-party analytics cookies on this site.

CookiePurposeContentsLifetime
dfc_sidSessionA generated identifier for your browser that ties the records below together. It is not linked to a name or an email address.180 days
dfc_xoX sign-in securityThe one-time PKCE verifier and state for an X sign-in in progress. Deleted the moment the sign-in is completed.10 minutes
dfc_xidVerified X identityYour X user ID, username, display name, profile image URL, and when it was verified.180 days
dfc_walVerified walletYour Solana wallet address and when ownership was verified.180 days
dfc_wchWallet ownership challengeThe exact challenge message awaiting your signature, and its expiry. Deleted as soon as it is used, so it can never be replayed.10 minutes
dfc_runCurrent scoring runA reference to the scan in progress or just completed, so a reload can find your result again.24 hours

You can delete these at any time through your browser settings. Deleting them ends your session, disconnects any verified account or wallet, and means a new scan starts from scratch. Blocking them entirely will stop the checker from working, but the rest of the site will still read normally.

Three more things are stored in your browser that are not cookies, and this section lists them because it is meant to be the complete account of what this site puts there. None of them is ever sent automatically the way a cookie is. They travel only in the body of the analytics request described in section 08, and only when that request is made.

KeyWhereContentsLifetime
df_vidlocalStorageA random identifier for this browser, so a repeat visit counts as one person rather than two. It is generated here and derived from nothing about you.180 days
df_sidsessionStorageA random identifier for this tab, so one visit can be read in order.Until the tab closes
df_srcsessionStorageWhich shared rank card link this visit arrived from, if it arrived from one, so we can tell whether sharing works.Until the tab closes

The checker itself also keeps a little scratch space in sessionStorage while you are using it: which source you chose, a reference to the scan in progress, and the link to your own rank card once one has been made. All of it is cleared when the tab closes, none of it is an identifier, and none of it is ever sent anywhere on its own.

Clearing this site’s storage in your browser settings removes all of the above. Removing the first three has no effect on the checker; removing the scratch space means a scan in progress starts again.

08

Analytics

We want to be precise here, because this is the part most policies overstate.

The site records interaction events, such as which section you scrolled to or which button you pressed, and sends them to our own server. As of the last updated date on this page, no third-party analytics tag is installed on this site, no advertising pixel is installed, and these events are not shared with anyone. They are stored in our own database and deleted after 90 days.

Those events are also built to carry no identifying data: they never include a wallet address, an X user ID, a username, a signature, a signed message, an email address, an invite code, or the query string of any page. The list of fields an event may carry is a fixed allow list in our source code, and anything not on it is discarded in your browser before the event is sent and again on our server when it arrives.

To count a visit rather than a page load, your browser stores two random identifiers: one in localStorage that lasts 180 days and identifies the browser, and one in sessionStorage that lasts until you close the tab. Neither is derived from anything about you, and clearing this site’s storage removes them.

If your browser sends a Global Privacy Control signal, we do not send these events at all.

If we add an analytics or tag-management provider later, we will name it in this policy and update the last updated date before or when it goes live.

09

How long data is kept

The rank checker does not write your identity records into a user database. The records that identify you live in the cookies described in section 07, which means they live in your browser, they expire on the schedule in that table, and you can delete them yourself at any time.

Data does exist on the server side, and here is all of it. One of these rows, the interaction events, is kept for longer than the rest and is described in full in section 08.

  • Rate-limit counters. Counts keyed by your IP address, your network block, and a hashed session reference. Kept for up to twice the length of the window they measure, which is up to 20 minutes for the short windows and up to 2 hours for the hourly budget, then they expire automatically.
  • A finished scoring result. So your card survives a page reload, a completed result is cached against a generated run identifier for 24 hours, matching the lifetime of the dfc_run cookie that points to it. This copy holds the score, rank, breakdown, balance figure, and card URL. It does not hold your wallet address, your X username, or your signature.
  • A waitlist address. If you entered an email address in the field described in section 03, that address is stored with the date you first entered it, the date you last did, how many times, which form you used, any campaign parameters from your arriving URL, and the shared card that referred you if one did. It is kept until a wave you can be invited to has opened and closed or until you ask us to delete it, whichever comes first.
  • Interaction events. Which buttons were pressed and which sections were reached, keyed to the random browser and tab identifiers described in section 08, and to a shortened one-way digest of your session and account when you have one. Kept for 90 days, then deleted automatically.
  • Hosting logs. Ordinary request logs kept by our hosting provider for their standard operational period, used for security and debugging.
  • Email you send us. If you write to yo@drafts.fun, we keep that correspondence for as long as needed to deal with it and to keep a record of how it was handled.

Third parties named in section 06, including the scoring providers, keep data according to their own retention rules, which we do not control.

10

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, to receive it in a portable form, to withdraw consent you previously gave, and to not be discriminated against for exercising any of these rights.

Two ways to use them.

  • Do it yourself, immediately.Disconnect your X account in the checker, and clear this site's cookies in your browser. Because the records that identify you live in those cookies, clearing them removes them. Nothing then links a future visit to a past one.
  • Ask us. Email yo@drafts.fun with what you want done. Tell us enough to find what you are asking about, such as the wallet address or X username you used, so we can act on the right record. We answer within the time the law that applies to you requires, and we do not charge for a reasonable request.

Because the checker holds no user database keyed to a name, there are cases where we genuinely cannot locate data about you beyond what your own browser holds. When that happens we will tell you plainly rather than ask you for more identifying information in order to find it.

If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your local data protection authority. We would rather you came to us first so we can put it right.

11

Children

This site is for people aged 18 or over, or the age of majority where you live if it is higher. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.

If you believe a person under 18 has used the checker, email yo@drafts.fun and we will delete what we can identify.

12

International transfers

The site runs on globally distributed infrastructure, and the providers named in section 06 operate in several countries, including the United States. That means data described in this policy may be processed outside the country you are in, including outside the European Economic Area and the United Kingdom.

Where such a transfer needs a safeguard under the law that applies to you, we rely on the mechanisms our providers put in place for it, such as standard contractual clauses in their data processing terms. If you want to know how a particular transfer is covered, ask us at yo@drafts.fun.

13

Security

Security decisions on this site were made to reduce what can go wrong rather than to add reassurance after the fact.

  • Every record the checker keeps is stored in an authenticated-encrypted cookie, so it cannot be read or tampered with by the browser holding it.
  • Those cookies are HttpOnly and SameSite Lax, and are marked Secure in production, so page scripts cannot read them and they travel only over HTTPS.
  • The wallet flow proves ownership with a single-use, expiring, plain-text challenge that is deleted the moment it is used, so a captured signature cannot be replayed.
  • The X flow uses OAuth 2.0 with PKCE, requests read scopes only, does not request offline access, and revokes the access token immediately after one profile call.
  • Rate limiting sits in front of scan submission to blunt automation and abuse.

No system is perfectly secure, and we cannot guarantee absolute security. Protecting your own wallet, keys and accounts remains yours. We will never ask you for a seed phrase or a private key, and any message that does is not from us.

14

Selling and advertising

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and comparable United States state privacy laws. We do not run advertising cookies or ad-tech pixels on this site.

There is therefore nothing to opt out of on this front today. If that ever changes, this policy will say so, and we will provide the opt-out mechanism the law requires before it does.

15

Changes to this policy

The site is pre-launch and still moving, so this policy will change. When it does, we update the "Last updated" date at the top of this page. The two changes this section previously said to watch for have now both happened, and both are written out where they belong rather than announced here: the waitlist field is connected to a real backend and section 03 says what it stores, and interaction events are now sent to our own server and section 08 says what they carry and for how long. Still no third-party analytics provider and still no advertising pixel; section 08 is where that will be named on the day it stops being true.

Continuing to use the site after an update means you accept the updated policy.

16

Contact

Privacy questions, access requests, deletion requests, and complaints all go to one place: yo@drafts.fun.

For the rules that govern using the site itself, see our Terms of Use.