Settings

Account

    Settings

Resources

    DocumentationFeature board

Product

  • Markets
  • Proposals
  • Social
  • Road to Mainnet

Company

  • About
  • Learn
  • Documentation
  • Feature board

Legal

  • Terms of Service
  • Privacy Policy
  • Risk Disclosure

Social

  • X (Twitter)
  • Discord
  • Reddit
  • Instagram
  • Facebook
  • TikTok
  • Telegram
© 2026 Morfi. All rights reserved.
You're in demo mode. Support our journey to mainnet here.
Morfi
MarketsProposalsWinnersSocial
AllPoliticsSportsCryptoFinanceEconomicsTechnologyEntertainmentCultureMusicMemesGamingHealthScienceEnvironmentFoodWorldLawOther

Devnet preview

This document covers Morfi's devnet (testnet) deployment. Devnet USDC has no monetary value and exists only for testing. Separate terms will be published when Morfi launches on Solana mainnet.

Privacy Policy

Last updated: 2026-06-04

1. Introduction

This Privacy Policy explains how Morfi ("we", "us", "our") collects, uses, and shares information about you when you use the Morfi devnet preview (the "Service"). It applies to information collected through the Service, our marketing pages, and our communications with you.

The Service runs on Solana's devnet cluster. Activity that occurs on-chain — wallet addresses, trades, balances, claims, gifts, market proposals, boosts, and resolution outcomes — is recorded on a public blockchain and is, by design, visible to anyone.

2. Information we collect

Information you provide. When you sign up, you provide an email address (for one-time-password sign-in) or authorise an OAuth provider (Google, Apple, or X). When you complete onboarding, you provide a display name and a unique handle, and you may optionally provide an avatar, a short bio, a phone number (free-form, unverified), a country, your preferred language, currency, and theme, and topics of interest. If you connect a social provider after signup, we import the name, handle, and avatar reported by that provider. If you contact our support team or sign up for the mainnet-launch waitlist, we collect the contents of those communications and the email address you supply.

Information we collect automatically. When you use the Service, we automatically collect IP address, approximate geographic location derived from your IP (country / region), device type, browser, operating system, language, referring URL, pages and components viewed, click and form-interaction events, error events, and timestamps. We use first-party cookies, browser local storage, and similar technologies to support these features. As part of our analytics, our provider Statsig records session replays — anonymised reproductions of your interactions with the Service — which we use to debug issues and improve usability.

Information from third parties. We receive email and OIDC profile claims (name, picture, sub) from your chosen OAuth provider via our authentication provider Turnkey, public profile data from the X API when you connect your X account or send a gift to an X handle, and public on-chain data about Solana accounts, including wallet activity associated with you, from Solana RPC providers and our indexer.

On-chain information.Activity you take on the Service writes data to the Solana devnet blockchain. This data is permanent within devnet's retention horizon (devnet state may be wiped from time to time), public, and outside our control once written.

3. How we use information

We use the information we collect to:

  • create and authenticate your account, and provision your embedded wallet;
  • operate, maintain, secure, and improve the Service;
  • display your activity in public features such as profiles, portfolios, leaderboards, theses, and market trader lists;
  • process and record your activity on devnet markets;
  • communicate with you, including responding to support requests;
  • detect, investigate, and prevent fraudulent, abusive, or unlawful conduct, and to enforce our Terms of Service;
  • measure performance, run analytics, and understand how the Service is used;
  • send you transactional and product communications, and (with your consent where required) notify you about the mainnet launch;
  • comply with legal obligations and protect our rights and the rights of others.

4. Service providers we share information with

We share information with the third-party service providers listed below, each processing data on our behalf for the purposes described. These providers are based in the United States and other jurisdictions; where personal data is transferred internationally, we rely on appropriate safeguards as required.

  • Turnkey — authentication and embedded wallet provisioning. Turnkey holds the private keys to your embedded Solana wallet, and stores your email, OAuth identity, and OIDC profile data.
  • Vercel — hosting of the Morfi web application and edge processing of HTTP requests.
  • AWS ECS (Fargate) — hosting of our backend services (API, indexer, market maintainer, scheduled jobs) via AWS infrastructure-as-code.
  • AWS RDS PostgreSQL — managed PostgreSQL database for our application data (accounts, profiles, sessions, wallet linkages, mainnet waitlist signups, and related records).
  • Helius — Solana RPC and streaming endpoints used by our backend and frontend.
  • Statsig — product analytics, feature flagging, A/B testing, and session replay.
  • Better Stack (Logtail) — application logs, error monitoring, and OpenTelemetry traces for the frontend and backend.
  • Intercom — customer-support messenger. When you log in, we identify you to Intercom with your user ID, email, display name, account-creation date, and active wallet address so we can resume conversations.
  • Canny — public feedback and feature-request board. When you participate, we identify you to Canny with your user ID, email, display name, avatar URL, and account-creation date.
  • Pinata / IPFS — storage and pinning of public images (profile avatars, market images, and metadata). Content stored here is publicly accessible. Pins are tagged with creator pubkey and timestamp for tracking purposes.
  • Anthropic — AI text generation for proposal drafts and market insights via Claude (Haiku and Sonnet models).
  • Brave Search API — image search results for market research and content discovery.
  • fal.ai — optional AI image generation for market previews and custom content.
  • Sightengine — NSFW content moderation for user-generated images and uploads.
  • X (Twitter) — public profile lookups via the X API when you connect X or send a gift to an X handle. If you sign in with X, X also receives the standard OAuth sign-in signals.
  • Google, Apple — when you sign in with one of these providers, the provider receives standard OAuth sign-in signals.

5. Other sharing and disclosure

We may also share information with:

  • Other users and the public, to the extent that your wallet activity is recorded on the public Solana blockchain or appears in public features such as profiles, portfolios, leaderboards, theses, market trader lists, and gift permalinks (if you have enabled gift indexing);
  • Legal and regulatory authorities, when we are required to do so by law, court order, or other valid legal process, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others;
  • Successors in connection with a merger, acquisition, financing, reorganisation, or sale of assets.

We do not sell personal information for monetary consideration. Some advertising-related analytics or session-replay activity may qualify as "sharing" or "selling" under certain US state privacy laws; you can opt out as described below.

6. Public features

The following features publish information about you on the open web by default:

  • your profile page shows your handle, display name, avatar, bio, country, and aggregated activity statistics;
  • your portfolio page shows your active positions, profit and loss, trade history, and active wallet (linked from on-chain data);
  • social leaderboards, the trending feed, theses, replies, likes, and referral leaderboards display your handle, display name, avatar, and aggregated activity;
  • market pages show creator profiles and a list of recent traders.

We do not currently offer a setting to make a profile private. If you do not want this information to be public, do not use the relevant features.

7. Cookies and similar technologies

We set the following first-party cookies: NEXT_LOCALE (chosen language), DETECTED_CURRENCY (currency derived from IP), DETECTED_COUNTRY (country derived from IP), morfi_referral (referral code from a shared link), morfi_csrf (CSRF protection), and morfi_session (authentication and session management). We also store preferences and short-lived caches in browser local storage. Our service providers (Turnkey, Statsig, Better Stack, Intercom, Canny) set their own cookies and local-storage entries when their SDKs are loaded.

You can control cookies through your browser settings; disabling some cookies may affect Service functionality.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, or port the personal information we hold about you, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. We may need to verify your identity before responding.

Information that has been recorded on the Solana blockchain cannot be deleted by us — it is permanent (within devnet's retention horizon) and public by design. We can only delete information that we hold in our own systems and the systems of our service providers.

9. EEA / UK residents

If you are in the European Economic Area or the United Kingdom, our processing of your personal data is governed by the GDPR or UK GDPR. We rely on the following lawful bases: performance of a contract with you, our legitimate interests in operating and securing the Service, your consent (where required), and compliance with legal obligations.

You have the right to lodge a complaint with your local data-protection authority. When we transfer personal data outside the EEA or UK, we use appropriate safeguards such as Standard Contractual Clauses.

10. California residents

If you are a California resident, the California Consumer Privacy Act (CCPA / CPRA) gives you the right to know what personal information we collect, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information, and the right to limit the use of sensitive personal information. We will not discriminate against you for exercising these rights. To exercise any of these rights, contact us at privacy@morfi.markets.

11. Retention

We retain personal information for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. We may also retain information for as long as needed to operate the mainnet waitlist and notify you of the mainnet launch. Devnet on-chain activity may be retained on the Solana blockchain for as long as devnet state is preserved by Solana validators and is outside our control.

12. Security

We use technical and organisational measures designed to protect personal information against loss, misuse, and unauthorised access. However, no system is perfectly secure, and we cannot guarantee the absolute security of any information. The Service's smart contracts have not been audited by an independent third-party security firm; you should not rely on the Service to safeguard anything of value during the devnet period.

13. Children

The Service is not directed to children under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. The updated policy will be posted on this page with a new "last updated" date. Material changes will be communicated through the Service or via email where appropriate.

15. Contact

Privacy questions can be sent to privacy@morfi.markets.

The English version of this document is authoritative. If you have questions, contact us at legal@morfi.markets.