BetaLive on mainnet. Real money. Use at your own risk.

Legal

Privacy

Version 2026-09-02Updated 2026-09-02

1. The short version

Kommunity is built so that there is very little about you to lose. We store platform identifiers and a handle you choose. We do not ask for your name, your address, your date of birth or a document. We do not run advertising and we do not sell anything about you to anyone.

  • What identifies you: a handle you pick, a Telegram or Discord numeric id if you connect one, an identifier from our authentication partner, your public wallet addresses, and your locale.
  • What we never collect: your legal name, your postal address, your phone number, a scan of a document, your contacts, your location beyond a country code, and — under any circumstances — a private key or a seed phrase.
  • Analytics without personal data: our product analytics receives event names and internal identifiers only. No handle, no email address, no Telegram username, no wallet address is ever sent to it.
  • Your rights: download everything we hold about you, or close your account, from Your data below. Both are self-service and take effect immediately.

2. Who is responsible

Kommunity, operated from Switzerland, is the controller of the personal data described here. Questions, requests and complaints: privacy@kommunity.fun.

3.1 Account data

A handle, a locale, the identifier issued by our authentication partner, the Telegram or Discord numeric id of any account you connect, a Telegram username when Telegram supplies one, the version of the terms you accepted and when, and your two attestations (not a United States person, 18 or over).

We need this to give you an account, to attribute your trades and to prove you accepted the terms. Legal basis: performance of the contract, and our legal obligation to keep evidence of the attestations.

3.2 Wallets and trades

The public addresses of the wallets you register, and for every trade: the token, the direction, the amounts, the quote we showed you, the transaction signature, the status, the resulting position, the fee we collected and how it was allocated, and the payouts that settled it.

Solana is a public ledger: transactions, addresses and balances are public by design, worldwide and permanently, and neither we nor you can delete them. What we hold is our own record of the trades you made through us, which we need to execute them, to compute fees, to pay treasuries and cashback, and to keep accounts. Legal basis: performance of the contract, and our legal obligation to keep accounting records.

3.3 Sessions and security

A session cookie, the SHA-256 digest of the session token — never the token itself — the user agent and the IP address of the device that signed in, and a CSRF secret. We keep short-lived request logs carrying a request identifier and, for rate limiting and abuse prevention, an IP address.

Legal basis: our legitimate interest in keeping accounts and funds secure.

3.4 Notifications

If you turn them on: the identifier of the chat where the bot can reach you, a web push endpoint and its keys, or a device token from the mobile shell, plus your per-type preferences and quiet hours. Legal basis: your consent, withdrawable at any time by turning notifications off.

3.5 Product analytics

We use PostHog, hosted in the European Union, to understand whether the product works: how many people opened a trade link, how many completed a trade, where a flow breaks.

Events carry internal identifiers only. A distinct identifier is a Kommunity user id, a platform-prefixed numeric id, or a rotating pseudonymous value for signed-out visitors; it is never an email address, a handle, a Telegram username or a wallet address. Automatic capture of page content is switched off, so nothing on screen is collected incidentally. Legal basis: our legitimate interest in improving the service, balanced by holding no directly identifying data in the tool.

3.6 Error reporting

We use Sentry to receive stack traces when something breaks. Traces carry a request identifier and a service name. Our logging rules forbid message content, wallet balances, tokens and key material anywhere in a log line or an error report. Legal basis: legitimate interest in a working service.

3.7 Public content

Your handle, your receipts, your calls and your group memberships appear on public pages when you choose to make them public. Receipts show "a member" instead of your handle whenever you turn that off in your settings, and members appear on a group page only if they opt in.

4. Who receives data

We use a small number of processors, and each receives only what it needs.

WhoWhat they getWhere
Authentication and embedded wallet provideryour authentication identifier and login methodUnited States, under standard contractual clauses
Hosting and network providertraffic, IP addresses, request metadataEuropean Union
Product analytics (PostHog)event names, internal identifiers, no personal dataEuropean Union
Error reporting (Sentry)stack traces, request identifiersEuropean Union
Push delivery (browser push services, Google Firebase Cloud Messaging)a push endpoint or device token, and the notification textworldwide, depending on your device
Telegram and Discordthe message the bot sends youworldwide
Token data providersthe token address you look at, never who is lookingworldwide
Blockchain networkyour signed transaction — public and permanentworldwide

We disclose data to an authority only when a valid legal request compels us, and we tell you unless we are forbidden from doing so.

We do not sell personal data, we do not share it for advertising, and we do not profile you to make decisions with legal effects.

5. Your rights and how to use them

You can exercise the two that matter most without asking anyone.

  • Download everything. "Download my data" on this page returns a JSON file containing your account, your wallets, your trades, your positions, your fee ledger allocations, your payouts, your notifications and your share events. It is generated live from the database, not from a cache.
  • Delete your account. "Delete my account" on this page erases what identifies you: your handle becomes an anonymous marker, your Telegram and Discord ids and username are removed, the link to our authentication partner is replaced with a tombstone, your wallet rows are deleted, every session is revoked, every push registration and notification is deleted, and your flags are cleared. It takes effect immediately and cannot be undone.

Records of trades, fee allocations and payouts are kept, because they are accounting records we are required to hold and because a group's earnings cannot be recomputed without them. After deletion they are linked only to an anonymous identifier with nothing attached to it.

You also have the rights to access, rectification, restriction, objection and portability, and the right to lodge a complaint with a supervisory authority — the Federal Data Protection and Information Commissioner in Switzerland, or your local authority in the European Union. Write to privacy@kommunity.fun and we answer within thirty days.

6. How long we keep things

  • Account data: until you delete your account.
  • Trades, fee ledger and payouts: ten years from the transaction, as accounting records; anonymised as described above if you delete your account before then.
  • Sessions: thirty days, or until you sign out.
  • Notifications: ninety days.
  • Request logs: fourteen days.
  • Analytics events: twelve months.
  • Audit log: seven years. It is append-only by construction and records privileged actions, not what you traded.

7. Cookies and local storage

Kommunity sets no advertising and no third-party tracking cookies.

NamePurposeLifetime
kmm_sessionyour signed-in session, HttpOnly30 days
kmm_csrfprotects against cross-site request forgery30 days
kmm_localethe language you chose1 year
kmm_attrwhich call or referral brought you to a trade screen, HttpOnly — it decides who is paid24 hours

Our analytics tool stores an anonymous distinct identifier in your browser. The installed app stores a service-worker cache of the interface shell, never of any API response.

8. Security

We never hold your private keys. Session tokens are stored only as digests. Every mutating request is protected against cross-site request forgery, and every input is validated at the boundary. Secrets are held outside the codebase, containers run unprivileged, and backups are encrypted. The audit log cannot be modified or deleted, by anyone, including us.

If a breach affects your rights we notify the competent authority and, where required, you.

9. Children

Kommunity is for adults. You must be 18 or older, and you confirm it when you create an account. We do not knowingly hold data about anyone under 18; if we learn that we do, we delete it.

10. Changes

We publish a version and a date on this page. A material change raises the version of the Terms of service and asks you to accept the new text before you trade again.

11. Contact

privacy@kommunity.fun

    Privacy · Kommunity