Draft · development preview

Privacy policy

How the XFriends preview handles wallet information, swaps, conversations and saved experiences. This is a draft, not a finalized launch notice.

Draft updated 30 September 2026

1. Scope and operator

XFriends is a Rokusho project based in the Netherlands. This notice covers the XFriends website and its available features, including wallet verification, token swaps, character customization, conversations and contact requests. It does not describe independent blockchain networks or third parties as services controlled by XFriends. The registered operator's name, business address, registration number and public privacy contact remain unconfirmed and must be published before public launch. In this draft, ‘we’ refers to the project team. Our terms of service are available at /terms.

2. Wallet and public blockchain information

Connecting and verifying a wallet provides its public address, network, signed login proof and session information. The login signature proves control of the address; it does not authorize a transfer. To show balances, ownership and transaction status, the server sends relevant wallet addresses, token or collection identifiers and transaction signatures to the configured Solana RPC and asset-indexing providers. Public addresses, holdings and transaction history can identify a person when combined with other information; public availability does not make them anonymous. We never need your seed phrase or wallet private key.

3. Swap information and recipients

The current swap integration uses Jupiter on Solana mainnet. Token searches send your search text to Jupiter through our server. Quote requests send your verified wallet address, input and output token mint addresses, amount and slippage setting. If you approve a swap, the server receives the signed transaction and sends it with the provider request identifier to Jupiter for execution. Transaction signatures are sent to the configured Solana RPC provider to check confirmation. Jupiter and the underlying transaction infrastructure process routing and execution information; confirmed transactions expose addresses, assets, amounts and fees on the public blockchain. Our server mediates these API calls, but that is not an anonymity guarantee. A signed transaction can authorize asset movement; treat it as sensitive until it expires or settles.

4. Cookies and browser storage

The essential HTTP-only xf-wallet-challenge cookie lasts up to five minutes and xf-wallet-session lasts up to one hour. They support wallet verification and authenticated features. Outfits, avatar preferences and sound or appearance settings can be stored in localStorage until you remove them. Saved looks stay in localStorage while you are signed out. When you are signed in and server storage is configured, up to six saved looks are stored on the server, scoped to your verified wallet like saved drafts, and looks already on the device are moved there; removing a look deletes it from the server, and signing out removes the account copy from the browser. The swap screen stores the quote, authorization, signed transaction and result in sessionStorage so a pending transaction can be checked after a reload. Its recovery reader accepts receipts only within approximately one day of quote expiry; that check does not automatically erase the stored data. Session storage normally ends with the browser tab session, subject to browser restoration behavior. Clearing storage can remove your local recovery receipt but cannot cancel a submitted swap. Wallet connection software may also maintain its own session storage. Blocking essential storage may prevent sign-in, saved preferences or swap submission.

5. Saved characters, encounters and memory

Where configured, private saved character drafts, fictional encounters and memory notes are stored on the server, using Supabase or a development-only local store. Records are scoped to your verified wallet and the relevant character; hashed scope identifiers are pseudonymous, not anonymous. Saved context and memory may be supplied to the AI provider when you request a reply. Clearing browser storage or disconnecting your wallet does not delete these server records. Use the available memory and saved-experience controls to remove records, or request deletion of information controlled by the operator. No automatic retention or backup deletion schedule has yet been approved.

6. Conversations, connected AI accounts and voice

An initial character greeting is authored content. Live replies require configured services and wallet verification. The standard chat flow sends your submitted conversation, character instructions and applicable saved memories or encounters to the configured AI provider; its default integration is Anthropic. Where agent chat is enabled, the selected connected ChatGPT or Claude service receives the conversation context needed for your request. The agent runtime can retain messages, provider selections, run and approval records, and connection credentials in encrypted server storage. Resetting an agent conversation clears its current stored message history, but is not a guarantee of deletion from providers, logs or backups. Disconnecting a provider removes the local connection; if remote revocation cannot be confirmed, remove access through the provider's account settings. Requested voice playback sends reply text to ElevenLabs. The current voice endpoint generates speech from text, rather than collecting a microphone recording. Do not submit wallet secrets, sensitive personal information or other people's private information.

7. Optional integrations and external services

WalletConnect connections use Reown AppKit when configured. Connection providers and your wallet application may process addresses, session metadata and device or network information under their own notices. The current AppKit configuration enables event analytics for the Reown dashboard, including wallet connection activity. Providers may also maintain operational logs. Opening a fiat purchase flow takes you to a third-party onramp experience. That provider may request identity documents, contact or payment information directly under its own terms and privacy policy; XFriends does not collect those fields through the current contact or swap endpoints. Optional agent tools, computer workspaces and Telegram connections can process the messages, files, connection credentials and activity you provide or authorize. Review the integration and its recipient before connecting or approving a tool action.

8. Contact and technical information

The contact form asks for a name, reply email and message. When configured, Mailgun delivers these to the team's receiving mailbox; application contact-message records are not stored separately. Mailgun click and open tracking is disabled for these submissions. Mailgun and the mailbox may retain delivery and correspondence records. Requests to the website and third-party infrastructure necessarily expose technical information such as IP addresses, browser information, request paths, timestamps and errors to the receiving systems. The host's logging and retention settings have not yet been confirmed. Abuse controls also use temporary request counters, including wallet-scoped counters. This draft makes no promise that infrastructure never processes or stores IP addresses.

9. Purposes and proposed legal bases

We process information to provide features you request, authenticate access, display public holdings, obtain swap quotes, submit approved transactions, generate requested replies, retain selected private experiences and answer inquiries. The proposed basis for processing objectively necessary to a requested service is performance of a contract or steps you request before a contract. Security, abuse prevention and ordinary support may rely on legitimate interests in protecting users and operating the service, subject to necessity, balancing and your right to object. A legal obligation is a basis only where an applicable obligation actually requires the processing. Optional marketing or non-essential tracking requires the applicable consent arrangements before being enabled; agreement to these terms or continued website use is not blanket privacy consent. The operator must validate the purpose-by-purpose legal basis before launch.

10. Sharing and provider responsibilities

Information is shared as needed with the providers for features you use: Jupiter, configured Solana RPC and indexing services, Reown or WalletConnect, configured AI providers, ElevenLabs, Supabase or other approved private infrastructure, Mailgun and the receiving mailbox. Hosting, security and authorized operational support can also process necessary information. Some recipients act as processors for the operator and others independently determine how they process data; those roles and agreements remain to be confirmed. Information may also be disclosed where law requires it, where necessary and lawful to address a security incident or legal claim, or as part of a business transfer subject to applicable protections and notice. The current application does not implement sale of personal information or advertising audience sharing. This is not a representation about all independent providers' practices.

11. International transfers and retention

Providers and public blockchain participants may be outside the European Economic Area. Before public launch, the operator must identify the actual provider entities, processing locations and transfer arrangements, and establish any required adequacy decision or appropriate safeguards, such as standard contractual clauses with any necessary additional measures. Those arrangements are not confirmed by this draft. Apart from the cookie and browser-storage behavior described above, exact retention periods for private records, agent credentials, correspondence, provider requests, logs and backups remain unresolved. The launch notice must specify periods or meaningful criteria and an operational deletion process. Data should be retained only as necessary for its stated purpose or an applicable legal requirement; no unimplemented automatic deletion deadline is promised here.

12. Choices and privacy rights

You may choose not to connect a wallet, request a swap, use AI or voice, connect an integration or submit a contact request; the corresponding feature may then be unavailable. Depending on applicable law and the processing, you may request access, correction, erasure, restriction and portability, object to processing, and withdraw consent without affecting earlier lawful processing. We may need proportionate proof of identity or wallet control to protect your information, but never your seed phrase or wallet private key. GDPR requests are normally answered within one month; lawful extensions require an explanation. You can complain to the Dutch Autoriteit Persoonsgegevens or another competent supervisory authority. Where California or other regional privacy laws apply, their applicable access, deletion, correction, opt-out, authorized-agent and non-discrimination protections remain available. A public contact that works independently of wallet access must be confirmed before launch; the /contact form can be used only while configured and available.

13. Public records, security and automated features

XFriends cannot edit or erase records maintained by an independent public blockchain. Off-chain records controlled by the operator remain subject to applicable rights even if they refer to public transactions. Wallet verification, access checks, bounded requests and encrypted agent storage help protect relevant information, but cannot guarantee security of every system, wallet or provider. AI personality scores, fictional responses and automated route quotes are not a promise of a legally significant automated decision about you. Any future automated eligibility or screening decisions require their own assessment and appropriate notice. Disconnecting a wallet does not revoke a transaction you have already signed.

14. Age, updates and contact

Wallet transactions and connected AI services under these draft terms are intended for adults aged at least 18 who can legally use them. If you believe a child submitted personal information, contact the team through the available contact channel. We will update this notice when the actual processing changes, show the revision date, and provide appropriate notice of material changes. A policy update does not itself obtain consent for a new purpose. Operator identity, an accessible privacy email, retention and transfer details remain launch requirements, rather than facts established by this draft.

Contact the team