Privacy Policy
In short: NoFee collects only what it needs to run a passwordless trading terminal and launchpad: your email address (to send login codes), basic security logs (IP address, browser details, login times), the wallet addresses tied to your account, the public on-chain activity of those addresses, and anything you upload or send to us. Your email inbox is the single login factor, so protect it. We use functional browser storage only, with no advertising trackers, and we do not sell personal data. The keys of the wallet we create for you are held by us encrypted at rest and can be exported by you at any time. Blockchain transactions are public and permanent, so neither we nor anyone else can delete them. To ask questions or exercise your rights, email team@nofee.tax.
1.Who we are and what this policy covers
NoFee (nofee.tax) is a multichain trading terminal and token launchpad (the “Service”), operated by the NoFee team (the “Operator”, “we”, “us”). Where data-protection law applies to our processing, the Operator is the controller of the personal data described here. You can reach us at team@nofee.tax.
This policy explains what personal data we collect when you visit the website, create an account, trade, launch a token or contact us; why; who we share it with; how long we keep it; and your rights. It covers the nofee.tax website and application, the APIs behind it, the emails we send you and our support mailbox. It does not cover the blockchains, exchanges, launch venues, bridge providers, explorers or wallet software you interact with through or alongside the Service; those have their own privacy practices, which we do not control (sections 7 and 13).
Holding wallet keys for you (section 5) is a technical feature of the Service. It does not make NoFee a bank, broker, exchange, licensed custodian, investment adviser or fiduciary, and nothing in this policy is investment, legal or tax advice. Digital assets held through the Service are not deposits and are not insured.
Read this policy together with our Terms of Service and Risk Disclosure; capitalised terms not defined here have the meaning given in the Terms.
2.The data we collect and where it comes from
We keep the personal data we hold deliberately small. The table lists each category, typical examples and its source.
| Category | Examples | Source |
|---|---|---|
| Account data | Email address; the 6-digit login codes we send you (held only in hashed form); login timestamps; your acceptance of our legal documents (document version, timestamp, IP address and browser details). | You; generated by us at login. |
| Security and technical data | IP address, browser and device details (user agent), request timestamps, rate-limit counters, access and error logs. | Your browser, automatically; recorded by our servers and by Cloudflare at the edge. |
| Wallet data | The EVM and Solana addresses we create for you on first login; their private keys, held encrypted; the public address of any external wallet you connect. | Generated by us; you, for external wallets. |
| On-chain activity | Transactions, balances, holdings, trades, launches and Lucky Drop allocations, rewards and refunds associated with your addresses; the activity history and portfolio shown in your account. | Public blockchains, indexed by us and by third-party data providers. |
| Launch content | Token name, symbol, description, logo and links you submit when launching; for Solana launches with the optional vanity address, the new token mint keypair your browser sends to our launch service with the quote request. | You. |
| Support communications | Emails you send to team@nofee.tax, their content, attachments and metadata, and our replies. | You. |
What we do not collect
We do not currently perform identity verification (KYC), so we do not ask for your name, government identification, date of birth or address. We do not collect payment card or bank details, precise location, advertising identifiers or contact lists, and we run no advertising or cross-site analytics trackers. If the law or our risk assessment requires it in future, we may introduce identity or location checks; this policy will be updated first.
Personal data you include in a token description, an image or a support email is processed as part of that content. Never send us wallet private keys, seed phrases or login codes; we do not need them and will not ask for them.
3.Why we use your data and on what legal basis
We use personal data only for the purposes below. Where the law that applies to you requires a legal basis for processing, we rely on the basis shown next to each purpose.
| Purpose | What this involves | Legal basis |
|---|---|---|
| Providing the Service | Operating your account and NoFee wallet; sending login codes; quoting, submitting and tracking transactions; showing your activity and portfolio; publishing tokens you launch. | Performance of our contract with you (the Terms of Service). |
| Security, fraud and abuse prevention | Rate limiting; blocking automated abuse and denial-of-service attempts; investigating suspicious logins; protecting the wallets whose keys we hold. | Legitimate interest, shared with you, in keeping the Service and user funds secure. |
| Legal obligations and eligibility | Keeping required records; responding to lawful requests from courts and authorities; complying with sanctions and other applicable laws, which may include assessing from technical signals such as your IP address whether the Service may be offered in a location; retaining records needed for legal claims. | Compliance with a legal obligation; legitimate interest in defending claims and in offering the Service only where it is lawful. |
| Recording your acceptance | Storing the version, timestamp, IP address and browser details of your acceptance of the Terms, this policy and the Risk Disclosure. | Legitimate interest in evidencing the contract; legal obligation where applicable. |
| Operating and improving the platform | Diagnosing errors and measuring performance from technical logs and aggregated statistics. | Legitimate interest in running a reliable service. |
| Communicating with you | Login codes, security notices, notices of changes to our legal documents, and replies to support requests. | Performance of the contract; legitimate interest. Optional marketing emails would be sent only with your consent, which you may withdraw at any time. |
Automated processing
Automated rules rate-limit requests and block abusive-looking traffic based on technical signals such as request frequency and IP address, not on a profile of you; if you think you were blocked in error, email us and we will review it. The automated labels on token pages (“Verified”, “LP locked”, “Honeypot: clear”) are checks on token contracts and pools, not decisions about you and not endorsements of any token. We do not profile users for advertising or make automated decisions with legal or similarly significant effects on you.
4.On-chain data is public and permanent
Every blockchain the Service supports is a public ledger. Once a transaction is confirmed, the addresses, amounts, tokens and timing are visible to anyone, replicated across the network, and cannot be edited or removed by us or anyone else. This applies to trades, transfers, token launches, liquidity positions, Lucky Drop allocations, rewards and refunds, and every other transaction from an address associated with your account. NoFee reads this public data, indexes it and displays it in market pages, charts, transaction feeds, holder lists and your activity history; other explorers and analytics services index the same data independently. Assume that anything you do on-chain is permanently public.
What is not public is the link between an address and your email address. That link exists only in our systems. You can reveal it yourself, for example by posting your address on social media or reusing it with a service that knows who you are.
Launch content is public too: the name, symbol, description, logo and links you submit are published on-chain or to public metadata storage, and third parties may keep copies indefinitely.
For these reasons the rights to erasure and rectification (section 11) cannot be applied to on-chain data. We can delete the off-chain records we hold, such as your email address and its link to your addresses, but not the ledger.
5.Login codes, wallet keys and sessions
Passwordless login
There are no passwords. When you enter your email address we send a 6-digit code to it. The code expires after 10 minutes, can be used once, is invalidated after too many wrong attempts, and is held by us only in hashed form; we never log or display the plaintext code. Your inbox is the single factor of authentication: whoever can read email at that address can log in and control the wallet attached to your account. Protect your mailbox with a strong password and two-factor authentication, and never share a login code.
Because your email address is the only credential, we may be unable to verify you or restore access if you lose control of that mailbox. Keeping an exported copy of your wallet key in a safe place is the only way to guarantee that you can always reach your funds.
The wallet we create for you
On your first successful login we create an EVM wallet and a Solana wallet for you. The private keys are generated on our servers and stored encrypted at rest using AES-256-GCM. Depending on the network, transactions are signed either in your browser, using key material we return to it over an encrypted connection for the duration of the session and that is kept only in session storage cleared when the tab or browser closes, or inside our encrypted server-side custody boundary on the instruction you give through the interface. We do not send your keys to any third party. You can export the private key at any time with “Export key” and move your funds to any self-custody wallet; for some exports we may ask you to confirm with a fresh email code. Once exported, copies exist outside our systems and keeping them safe is your responsibility.
External wallets
If you connect an existing wallet, we receive only its public address and the signatures your wallet software produces. We never receive, request or store the private key of an external wallet.
Vanity token mint keys (Solana launches)
The optional vanity-address search for Solana launches runs inside your browser. When you request a launch quote using a found address, your browser sends the new token mint keypair to our launch service, which holds it with the pending launch record so it can create the token at that address. Our current implementation removes the mint secret from the record once the launch reaches a final state and clears expired quotes during routine clean-up; this describes how the application behaves and is not a guarantee of secure erasure from every memory copy, log or backup. This keypair identifies a new token mint; it is separate from, and must never be replaced with, the private key of any wallet you own.
7.Who receives your data
We do not sell personal data and do not share it with advertising networks or data brokers. We share data only with the recipients below, and only to the extent necessary.
| Recipient | Role | What they see |
|---|---|---|
| Cloudflare | Content delivery, DDoS protection and edge security in front of nofee.tax. | IP address, user agent and request metadata for every request; edge logs are kept under Cloudflare’s own rules. |
| Email delivery | Login codes and service notices, sent from the Operator’s own mail server. | Your email address and the email content, which also passes through your email provider’s systems. |
| Blockchain networks, RPC nodes and data providers | Quoting, simulating, submitting and indexing transactions; supplying prices, charts, holder data and token metadata. | Wallet addresses, transaction contents and queries about addresses and tokens, all public by nature. Many requests are made from our servers, but your browser also connects directly to public blockchain RPC endpoints to read balances and submit transactions, and those operators see your IP address and user agent. Token images are fetched through our own image proxy rather than by your browser. |
| Bridge and relay providers | Moving funds between chains when you use cross-chain funding or a cross-chain route. | Your source and destination addresses, the assets and amounts, and the related transactions. We do not control these providers; their own terms and privacy policies apply. |
| Launch venues and protocols | Creating tokens on NoFee’s own factory contracts or, on Solana, on Pump.fun through NoFee. | Your wallet address, the launch transaction and the token metadata you submit, which is published publicly. Pump.fun is a third-party venue with its own rules. |
| Advisers and successors | Lawyers, accountants and auditors bound by confidentiality; a successor if the Operator’s business is reorganised or transferred. | Only the data needed, under confidentiality. A successor is bound by this policy for data collected under it. |
| Courts and authorities | Where disclosure is legally required, or necessary to protect the rights, property or safety of the Operator, our users or others, or to enforce our Terms. | Only the data the lawful request or protective purpose requires. |
Where a recipient processes data on our behalf, such as an infrastructure provider, we require it to act only on our instructions and to protect the data. Blockchain networks, public RPC operators, decentralised protocols, bridge providers and launch venues are independent parties, not our processors, and we cannot instruct them.
8.International transfers
The Service is available globally and its infrastructure is distributed. Our servers, Cloudflare’s edge network, blockchain nodes and third-party data providers may be located in countries other than yours, with different data-protection laws. Public blockchains, by design, replicate data to nodes everywhere in the world.
Where the law that applies to you requires safeguards for transfers abroad, we rely on recognised mechanisms such as standard contractual clauses with our processors, together with the technical measures in section 10. Contact us for more information about the safeguards for a particular transfer.
9.How long we keep data
We keep personal data only as long as needed for the purposes in this policy, for security, to meet legal obligations and to operate the wallets whose keys we hold for users.
| Data | Retention |
|---|---|
| Email address and account record | While your account exists, plus a limited period after a deletion request to complete deletion safely, resolve any dispute and meet legal obligations. |
| Login codes | Held in memory, in hashed form only, until the code is used, expires after 10 minutes or is invalidated after too many wrong attempts; then discarded. The plaintext code is never stored or logged. |
| Security and technical logs | A limited period sufficient to detect and investigate abuse, then deleted or reduced to aggregated statistics that no longer identify you. |
| Wallet private keys | While the wallet exists in your account. Keys are deleted only after you have exported them or emptied the wallet (section 11). |
| Acceptance records | While your account exists, plus the period in which a claim relating to the contract could be brought. |
| Activity history | While your account exists. The underlying on-chain data is permanent and outside our control. |
| Launch content | Published permanently on-chain or to public storage. Our own copies are kept while the token is listed and as required for records. |
| Support communications | As long as needed to handle your request, plus a reasonable period as a record of what was agreed. |
We may keep specific data longer where the law requires it, where it is needed for legal claims, or where it has been anonymised so it no longer identifies you. Routine backups may hold copies for a limited time after deletion.
10.How we protect your data
We apply technical and organisational measures appropriate to the data we hold, including:
- Encryption in transit: all traffic between your browser and the Service is protected with TLS.
- Encryption at rest: wallet private keys are stored encrypted with AES-256-GCM.
- Hashed, single-use login codes that expire after 10 minutes and are invalidated after repeated wrong attempts.
- Rate limiting and abuse detection on login, quoting and transaction endpoints.
- Edge protection through Cloudflare against denial-of-service and automated attacks.
- Access controls restricting administrative access to production systems and key material to the people who need it.
- Data minimisation: we do not collect what we do not need, and we run no third-party trackers.
No system is perfectly secure, and we cannot guarantee that unauthorised access, loss or misuse will never occur. If we become aware of a breach affecting your personal data, we will notify you and any relevant authority where the law requires it. Our responsibility for any loss is governed by the Terms of Service.
What you can do
Your inbox is the key to your account: protect it with a strong, unique password and two-factor authentication, and never share a login code with anyone, including anyone claiming to work for NoFee. Consider exporting your wallet key and moving significant balances to a self-custody wallet you control. If you suspect your email or NoFee account has been compromised, secure your mailbox first and then contact us immediately.
11.Your rights and how to exercise them
Depending on where you live, you may have some or all of the following rights:
- Access: a copy of the personal data we hold about you and information about how we use it.
- Rectification: correction of inaccurate data; your email address can be changed by contacting us.
- Erasure: deletion of your personal data, subject to the wallet safety rule and the limits below.
- Restriction: limiting how we use your data in certain circumstances, for example while a dispute about accuracy is resolved.
- Portability: receiving the data you provided in a structured, machine-readable format. Your wallet key can be exported at any time, and your on-chain history is already available on any block explorer.
- Objection: objecting to processing based on our legitimate interests. We will stop unless we have compelling grounds, for example where the processing is essential to the security of the Service.
- Withdrawal of consent: where we rely on consent, you can withdraw it at any time without affecting earlier processing.
- Complaint: lodging a complaint with a data-protection supervisory authority, in particular where you live or work. We would welcome the chance to address your concern first.
How to exercise your rights
Email team@nofee.tax from the address registered to your account and tell us which right you want to exercise. To protect you, we verify that you control the account, usually by sending a code to your registered email, and we may decline a request we cannot verify. We respond without undue delay and within the time required by applicable law. Requests are free unless manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline as permitted by law.
Deleting your account and the wallet safety rule
We will not delete a wallet key while the wallet still holds funds. Deleting the key of a wallet that still contains assets would make them unrecoverable, and we will not take that step on the basis of an email alone. Before we delete your account, you must either export the private keys of your NoFee wallets with “Export key” or move all assets out of them. Once the wallets are exported or empty, we delete the keys, your email address, the link between your email and your addresses, and the other off-chain account data we hold, except records we must keep by law or for legal claims. Until then the account stays open. Deletion is irreversible: deleted keys cannot be recovered by us or anyone else, and assets sent to a deleted wallet afterwards are lost unless you kept an export, so secure your export before confirming.
Limits
On-chain data cannot be erased, corrected or restricted by anyone (section 4). We may retain data where the law requires it, for legal claims, or where necessary for security. If you object to security processing such as logging and rate limiting, we may be unable to keep providing the Service, because we cannot operate it safely without those measures.
12.Children
The Service is not intended for, and may not be used by, anyone under 18. We do not knowingly collect personal data from children. If you believe a person under 18 has created an account or given us personal data, contact us at team@nofee.tax and we will take appropriate steps, normally closing the account after the wallet safety rule in section 11 has been followed.
13.Third-party sites, venues and protocols
The Service links to and interacts with things we do not operate: block explorers, decentralised exchanges and pools, launch venues such as Pump.fun, Pons, Flap and DontBlink, bridge and relay providers, public RPC endpoints, external wallet software, and token project websites. Tokens launched on third-party launchpads are listed on NoFee for information only; a listing or an automated label is not an endorsement. When you follow a link or interact with one of these parties, its privacy practices apply and it may collect your IP address, wallet address and other data directly. We are not responsible for the data practices of third parties.
14.Changes to this policy
We may update this policy, for example when we add features, change providers or the law changes. The version string at the top of the page is the date of the current version. Updates are published at nofee.tax/legal/privacy.html, and when the version changes you will be asked to accept the current legal documents at your next login. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy. At each login we record the version of the legal documents you accepted, the timestamp, your IP address and browser details. If you do not agree with an update, stop using the Service and, if you wish, ask us to delete your account under section 11.
15.Governing law
This policy forms part of our Terms of Service. These Terms are governed by the laws of the jurisdiction in which the Operator is established, without regard to conflict-of-law principles, and any dispute shall be resolved in the competent courts of that jurisdiction unless mandatory consumer law provides otherwise. Nothing in this policy limits any right you have under the data-protection law that applies to you, including the right to complain to a supervisory authority.
16.Contact
For any question about this policy, to exercise your rights or to report a security concern, contact the Operator at team@nofee.tax. Please include the email address registered to your account and, for questions about a transaction, the network, token address and transaction identifier. Never include private keys, seed phrases or login codes in any message.