Privacy Policy
Last updated: September 7, 2026
This Policy explains how Amoeba Farm ("Amoeba," "we," "us," or "our") handles personal information in connection with our website, account services, hosted APIs, and supported market, oracle, and staking workflows.
Amoeba combines off-chain account services with public blockchain activity. An account can associate an email address or other identifying information with a wallet. Using a wallet therefore does not make your activity anonymous, and deleting an Amoeba account cannot erase independently maintained blockchain history.
1. Information we collect and process
1.1 Account and profile information. We process information you provide when creating or using an account, including your wallet address and provider, contact email, optional telephone number, username, display name, profile image, and account settings. The current external-wallet login flow requires a contact email; a telephone number is optional.
1.2 Authentication information. External-wallet login uses a challenge message and wallet signature to verify wallet control. Google sign-in is provided through Magic and associates a server-verified identity with the supported Solana wallet. We process the authentication tokens and proofs needed for verification, provider identifiers, verified email and wallet information, and related login events. We do not ask you to send a seed phrase or private key to an account or support form.
1.3 Session information. Persistent sessions include an account association, provider, hashed session-token record, creation and expiry times, revocation or last-seen information, browser user-agent information, and the IP address recorded for the session. Your browser receives cookies used to maintain the session and indicate that a session may be present.
1.4 Wallet and transaction information. We process public wallet addresses, requested balances and account state, transaction identifiers, signatures, prepared operations, submission status, and relevant blockchain records. Depending on the feature used, these records can concern option purchases or sales, auction bids, writer funding, Flat, close requests, staking, oracle bonds, rewards, votes, and settlement claims. Processing a signature for verification does not necessarily mean every signature is stored indefinitely.
1.5 Contributions and communications. We process the source definitions, URLs, archive references, values, timestamps, explanations, challenge material, and other evidence you submit, together with associated contribution and outcome records. We also process information you include in support requests, reports, feedback, or other communications with us.
1.6 Technical and preference information. Our services process information needed to deliver and protect them, such as request and error information, browser and device characteristics exposed by your connection, IP addresses, cookies, cached state, and saved preferences. An IP address can reveal an approximate location. For authenticated installed-app use, the application records the first and latest installed-app sightings. This is not access to the other applications or files on your device.
1.7 Information from other sources. We receive relevant information from your chosen wallet or identity provider, public blockchain infrastructure, and the public sources and archives used by the oracle. Where an enabled funding provider returns information about a transaction you initiated, we process the information necessary to support that flow. Third parties may independently collect additional information under their own policies.
2. How we use information
2.1 We use account, authentication, and session information to authenticate you, maintain your session, manage your profile, provide requested account features, and respond to support requests.
2.2 We use wallet, transaction, and operational information to retrieve balances and market state, prepare and validate requested operations, communicate with the applicable backend and blockchain infrastructure, report status, and reconcile what occurred. An API request or transaction submitted through Amoeba can be associated with the connection or account that made it.
2.3 We use oracle and contribution information to operate source selection, evidence review, updates, challenges, reward processes, and settlement records. This can require public inspection of submissions and their outcomes.
2.4 We use relevant information to detect misuse, investigate security incidents and manipulation, apply service restrictions, troubleshoot failures, maintain lawful records, and comply with applicable obligations. We may analyze service and market information to understand reliability and product performance. Public wallet information or a hashed identifier is not automatically anonymous data.
2.5 We do not treat your acceptance of the Terms, connection of a wallet, or use of a necessary login cookie as consent to unrelated advertising or other optional processing. Where a separate purpose requires additional notice or consent, that purpose must be addressed before the processing begins.
3. Public, on-chain, and archived information
3.1 Blockchain records can expose wallet addresses, token movements, balances, timestamps, program state, and activity relating to markets, staking, contributions, or voting. Other people can copy, analyze, and combine these records without using Amoeba.
3.2 Oracle source information, evidence references, challenges, outcomes, and settlement explanations may be displayed publicly or made available to the reviewers necessary for the applicable process. Do not put confidential material, unnecessary personal information, credentials, or private correspondence into a public evidence field.
3.3 An archive provider, source publisher, blockchain participant, or other independent recipient may retain a record after we remove it from a hosted display. We cannot promise to delete records controlled by independent parties or to reverse a finalized blockchain entry.
3.4 Account contact details and public protocol activity serve different functions. Your email address or telephone number is not a required public field of an ordinary market or oracle transaction, but we may hold the association between your account and wallet. Publishing the same information yourself can make that association visible to others.
3.5 Account compression, transaction hashes, and pseudonymous wallet identifiers do not by themselves provide anonymity or confidentiality. Privacy should not be inferred from a smaller account footprint or from data being represented cryptographically.
4. When information is shared
4.1 Service operation. We disclose information to providers as needed for the features you use, including application hosting, databases, object storage, security and operational support, identity and wallet services, and blockchain or RPC infrastructure. The relevant recipients and data depend on the enabled feature and configuration.
4.2 Identity and wallets. External wallet providers process the wallet interactions you initiate. Google sign-in uses Magic; the authentication and embedded-wallet services have their own data practices. Review the applicable provider's notice when choosing that login method.
4.3 Profile images. The current profile-image integration uses Cloudflare R2 object storage. Image uploads and delivery involve the storage service and, where configured, an image-serving domain or content-delivery service. Avoid including unnecessary identifying information or sensitive content in an uploaded image.
4.4 Blockchain requests. The application routes its supported chain reads through Amoeba's RPC gateway. The gateway and its upstream providers process the requests necessary to retrieve state or support the applicable transaction flow. A gateway does not make a wallet query anonymous to the infrastructure processing it.
4.5 Optional funding services. Stripe Crypto Onramp is a gated integration, not an assurance of current availability. When such a service is enabled and you choose it, the provider may collect identity, payment, compliance, device, and transaction information directly. We provide or receive the wallet and session information needed for the supported flow. Payment-provider approval, network support, and its own privacy terms remain separate from Amoeba account access.
4.6 Public processes, advice, and legal needs. We disclose public contribution and settlement information as described above. We may disclose relevant non-public information to professional advisers or authorized reviewers under appropriate confidentiality arrangements, or where reasonably necessary to comply with law, respond to lawful process, protect rights and security, or investigate fraud and other misuse. A public audit trail does not require publishing unrelated private account information.
4.7 Sale and changes in ownership. We do not sell personal information. A sale, merger, reorganization, or transfer of the business may involve information subject to applicable law and appropriate protections; any materially different use requires the notice or consent required by law. The meaning of selling or sharing under a particular privacy law may differ from the ordinary meaning of those words.
5. Cookies, browser storage, and installed-app features
5.1 The current account implementation uses ameba_session to authenticate a session and ameba_session_hint to support session-related interface behavior. It also uses browser storage and caches for preferences, wallet connection state, and application or market data. Some information remains only in your browser; information sent in a request is processed by the receiving service.
5.2 Session duration is configurable. Cookie expiry, signing out, clearing storage, and deletion of a server-side record are different events. Clearing a browser cache does not erase a submitted transaction, an account record, or an audit trail.
5.3 Third-party identity, embedded-wallet, image-delivery, or enabled funding components may use their own cookies and similar technologies. Their operation should be considered separately from Amoeba's necessary session cookies. Where consent or another choice is required for non-essential technology, that requirement is not replaced by this Policy.
5.4 You can control browser storage through your browser settings. Blocking necessary storage can prevent login or other functions from working. Installing the web application does not by itself authorize notifications, unrelated device access, or optional tracking.
6. Retention
6.1 We retain personal information for the period necessary for its disclosed purpose, taking account of an active account or request, outstanding transactions and claims, challenge and settlement requirements, security investigations, applicable legal obligations, and the need to establish or defend legal claims. Storage availability alone is not a reason to retain personal information.
6.2 Different records can have different retention periods. Profile information, login challenges, session records, support correspondence, uploaded images, operational logs, and market or contribution records do not necessarily expire together. A session's validity period is not a blanket retention period for all associated information.
6.3 Deletion requests are assessed against those specific needs and applicable rights. Where a record must be retained, we limit its use to the purpose supporting retention. When retention is no longer necessary, we delete or appropriately de-identify the information. Residual copies in backups are handled through the applicable backup and recovery process and are not retained for unrelated uses.
6.4 Independent public blockchain and archive records remain subject to Section 3. The inability to erase those records does not eliminate an obligation to consider deletion or restriction of personal information under our own control.
7. Security
7.1 We use measures intended to protect accounts and information, including authentication checks, session controls, and access restrictions. No security measure makes a service immune to compromise, misconfiguration, unauthorized disclosure, or a third-party failure.
7.2 Protect your devices, email and identity-provider access, wallet recovery arrangements, and every message or transaction you approve. Do not send passwords, private keys, recovery phrases, or active session tokens in a support request or public contribution.
7.3 Contact [email protected] if you believe personal information or an account has been compromised. Include enough detail to locate the issue without exposing additional secrets. Required notices concerning a personal-data incident will be handled under applicable law.
8. Your choices and privacy rights
8.1 You can choose whether to create an account, connect a wallet, submit public evidence, upload an image, or use an optional provider. Some account functions require specified information; for example, the current external-wallet login requires a contact email. Refusing necessary information may prevent that function from being provided.
8.2 Depending on the law that applies to you, you may have rights to obtain information about processing, access or correct personal information, receive a portable copy, request deletion or restriction, object to certain processing, withdraw consent, or appeal a denied request. We will assess requests under the applicable rules rather than treating every request as automatically available or automatically excluded.
8.3 Send requests to [email protected] with the subject "Privacy request." We may request information reasonably necessary to verify your identity or authority, but not your private key or recovery phrase. There is no need to publish a privacy request on-chain.
8.4 Updating a profile or disconnecting a wallet does not necessarily close an account or revoke previously granted token permissions. Account closure and wallet-approval management are separate actions. Ask us about information under our control; use your wallet's supported controls for wallet permissions.
8.5 Where applicable law gives you a right to opt out of the sale or sharing of personal information or of targeted advertising, you may send that request using the contact method above. This request method does not replace any additional opt-out control or preference-signal handling required by applicable law.
8.6 You may also have the right to complain to the relevant privacy regulator or supervisory authority. Exercising a legally protected privacy right will not result in unlawful discrimination. Necessary service limitations caused by missing required information remain distinct from retaliation for exercising a right.
9. Legal bases and international processing
9.1 Where applicable law requires a legal basis, we rely on performance of the relevant contract, or steps requested before entering it, for processing necessary to provide an account or user-requested service. We rely on legitimate interests for security, fraud prevention, and service reliability where that basis is legally available and does not override your protected rights and interests. We rely on compliance with applicable legal obligations for required records or disclosures, and on consent where required for an optional purpose. Consent can be withdrawn for future processing.
9.2 Those bases are purpose-specific. A public blockchain record does not give us unrestricted permission to link it to an identified person for an unrelated purpose. Withdrawal of consent does not automatically erase a transaction or information lawfully retained on another basis.
9.3 Information may be processed where the operator and its providers operate. Contact us for information about applicable locations, recipient roles, and international-transfer safeguards relevant to your data. We do not promise local-only storage or a particular transfer mechanism unless it is actually in place.
10. Children
10.1 Amoeba's account and financial participation features are intended for adults who meet the eligibility requirements in the Terms. They are not directed to children, and we do not knowingly seek children's personal information for those features.
10.2 Contact us if you believe a child has provided personal information. We will assess and address the record under applicable law, including any applicable deletion obligations.
11. Changes to this Policy
11.1 We may update this Policy when our services, providers, data practices, or legal requirements change. The updated date identifies the revision. Material changes will receive notice appropriate to the circumstances, and we will obtain additional consent where required.
11.2 An update does not authorize an undisclosed retroactive use of previously collected information where applicable law requires a separate basis, notice, or consent.
12. Contact
12.1 Privacy requests and questions: [email protected], subject "Privacy request."
12.2 Our ability to respond concerns information for which we are responsible. An independent wallet, identity provider, payment provider, source publisher, or archive service may need to handle a request concerning its own processing.
