Devnet preview
This document covers Morfi's devnet (testnet) deployment. Devnet USDC has no monetary value and exists only for testing. Separate terms will be published when Morfi launches on Solana mainnet.
Last updated: 2026-06-04
This Privacy Policy explains how Morfi ("we", "us", "our") collects, uses, and shares information about you when you use the Morfi devnet preview (the "Service"). It applies to information collected through the Service, our marketing pages, and our communications with you.
The Service runs on Solana's devnet cluster. Activity that occurs on-chain — wallet addresses, trades, balances, claims, gifts, market proposals, boosts, and resolution outcomes — is recorded on a public blockchain and is, by design, visible to anyone.
Information you provide. When you sign up, you provide an email address (for one-time-password sign-in) or authorise an OAuth provider (Google, Apple, or X). When you complete onboarding, you provide a display name and a unique handle, and you may optionally provide an avatar, a short bio, a phone number (free-form, unverified), a country, your preferred language, currency, and theme, and topics of interest. If you connect a social provider after signup, we import the name, handle, and avatar reported by that provider. If you contact our support team or sign up for the mainnet-launch waitlist, we collect the contents of those communications and the email address you supply.
Information we collect automatically. When you use the Service, we automatically collect IP address, approximate geographic location derived from your IP (country / region), device type, browser, operating system, language, referring URL, pages and components viewed, click and form-interaction events, error events, and timestamps. We use first-party cookies, browser local storage, and similar technologies to support these features. As part of our analytics, our provider Statsig records session replays — anonymised reproductions of your interactions with the Service — which we use to debug issues and improve usability.
Information from third parties. We receive email and OIDC profile claims (name, picture, sub) from your chosen OAuth provider via our authentication provider Turnkey, public profile data from the X API when you connect your X account or send a gift to an X handle, and public on-chain data about Solana accounts, including wallet activity associated with you, from Solana RPC providers and our indexer.
On-chain information.Activity you take on the Service writes data to the Solana devnet blockchain. This data is permanent within devnet's retention horizon (devnet state may be wiped from time to time), public, and outside our control once written.
We use the information we collect to:
We share information with the third-party service providers listed below, each processing data on our behalf for the purposes described. These providers are based in the United States and other jurisdictions; where personal data is transferred internationally, we rely on appropriate safeguards as required.
We may also share information with:
We do not sell personal information for monetary consideration. Some advertising-related analytics or session-replay activity may qualify as "sharing" or "selling" under certain US state privacy laws; you can opt out as described below.
The following features publish information about you on the open web by default:
We do not currently offer a setting to make a profile private. If you do not want this information to be public, do not use the relevant features.
We set the following first-party cookies: NEXT_LOCALE (chosen language), DETECTED_CURRENCY (currency derived from IP), DETECTED_COUNTRY (country derived from IP), morfi_referral (referral code from a shared link), morfi_csrf (CSRF protection), and morfi_session (authentication and session management). We also store preferences and short-lived caches in browser local storage. Our service providers (Turnkey, Statsig, Better Stack, Intercom, Canny) set their own cookies and local-storage entries when their SDKs are loaded.
You can control cookies through your browser settings; disabling some cookies may affect Service functionality.
Depending on where you live, you may have the right to access, correct, delete, or port the personal information we hold about you, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. We may need to verify your identity before responding.
Information that has been recorded on the Solana blockchain cannot be deleted by us — it is permanent (within devnet's retention horizon) and public by design. We can only delete information that we hold in our own systems and the systems of our service providers.
If you are in the European Economic Area or the United Kingdom, our processing of your personal data is governed by the GDPR or UK GDPR. We rely on the following lawful bases: performance of a contract with you, our legitimate interests in operating and securing the Service, your consent (where required), and compliance with legal obligations.
You have the right to lodge a complaint with your local data-protection authority. When we transfer personal data outside the EEA or UK, we use appropriate safeguards such as Standard Contractual Clauses.
If you are a California resident, the California Consumer Privacy Act (CCPA / CPRA) gives you the right to know what personal information we collect, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information, and the right to limit the use of sensitive personal information. We will not discriminate against you for exercising these rights. To exercise any of these rights, contact us at privacy@morfi.markets.
We retain personal information for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. We may also retain information for as long as needed to operate the mainnet waitlist and notify you of the mainnet launch. Devnet on-chain activity may be retained on the Solana blockchain for as long as devnet state is preserved by Solana validators and is outside our control.
We use technical and organisational measures designed to protect personal information against loss, misuse, and unauthorised access. However, no system is perfectly secure, and we cannot guarantee the absolute security of any information. The Service's smart contracts have not been audited by an independent third-party security firm; you should not rely on the Service to safeguard anything of value during the devnet period.
The Service is not directed to children under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us and we will delete it.
We may update this Privacy Policy from time to time. The updated policy will be posted on this page with a new "last updated" date. Material changes will be communicated through the Service or via email where appropriate.
Privacy questions can be sent to privacy@morfi.markets.
The English version of this document is authoritative. If you have questions, contact us at legal@morfi.markets.