Privacy PolicyWallet-First PlatformUpdated 18 July 2026

Privacy acrosswallets, AI, and Web3.

This policy explains how KORAX handles website data, public wallet information, builder inputs, project publishing, deployment integrations, registry information, and launch activity.

KORAX never needs your seed phrase or private key.
Wallet addresses and blockchain activity may be publicly visible.
Builder inputs can be processed by configured AI and deployment providers.
Functional browser storage may keep project progress on your device.
KORAX official logoKORAX
Privacy Framework
Minimise • Protect • Explain
Processing Overview

What is processed and why.

The exact processing depends on the features you use and the providers configured in production.

ActivityDataPurposeLegal basisRetention
Website delivery and securityIP address, date and time, requested page, device/browser details, referrer, technical logsDeliver the website, prevent abuse, diagnose errors, maintain availability, and protect the platformLegitimate interests in secure and reliable operation; legal obligations where applicableNormally limited to the period required for security, troubleshooting, and legal obligations
Wallet connectionPublic wallet address, selected network, connection status, wallet-provider metadataConnect the user-selected wallet and display wallet-specific on-chain informationPerformance of requested platform functions and legitimate interests in providing wallet-based accessUsually processed for the active session; functional state may remain locally on the user's device
Blockchain interactionWallet address, transaction hash, token approvals, contract calls, balances, staking, claim, presale, and launch activityRead blockchain state, prepare transactions, show transaction status, and provide ecosystem functionsPerformance of requested platform functions; blockchain publication occurs through the user's signed transactionPublic blockchain records may remain permanently available and are not controlled by KORAX
AI builder toolsProject descriptions, prompts, configuration, branding direction, generated files, edit instructions, and technical metadataGenerate or revise project strategy, token configuration, website content, code, visuals, and deployment packagesPerformance of the user-requested builder service; consent where separately requiredAccording to the active feature, local browser storage, server security logs, and the configured provider's retention rules
GitHub and deployment integrationsOAuth identifiers, repository name, selected files, deployment configuration, provider responses, and status informationPublish generated project files and initiate user-requested deployment workflowsPerformance of the integration requested by the userAccording to the user's provider account, local project state, and limited security or troubleshooting logs
Public project registry and launchProject name, symbol, public wallet address, contract addresses, metadata, website/launch links, and on-chain timestampsPublish project information, enable discovery, and connect builder projects with launch infrastructurePerformance of the creator-requested publication and legitimate interests in operating the registryUntil removal from the hosted interface where available; public blockchain data may remain permanently accessible
Support and legal communicationEmail address, name if provided, message content, attachments, and communication metadataAnswer requests, investigate issues, protect rights, and meet legal obligationsContract or pre-contract steps, legitimate interests, consent, and legal obligations depending on the requestFor the period needed to resolve the request and satisfy applicable limitation or record-keeping periods
@

1. Privacy Contact

Privacy questions and data-protection requests can be sent through the official KORAX contact.

Privacy contact: contact@korax.fund.

Include enough information to identify and assess your request, but never include private keys, seed phrases, wallet passwords, API secrets, or recovery information.

2. Scope of this Policy

This policy covers the KORAX website and connected ecosystem functions.

This Privacy Policy explains how personal data may be processed when you visit the KORAX website, connect a wallet, interact with KRX interfaces, use presale, claim or staking functions, access AI builder tools, publish a project, connect GitHub, initiate deployment, browse the public registry, or use launch infrastructure.

It does not govern independent third-party websites, wallets, blockchain networks, repositories, hosting accounts, exchanges, or external project websites. Their own privacy notices apply.

3. Privacy Principles

KORAX aims to process only data reasonably needed for each function.

Data minimisation: avoid collecting information that is not needed for the requested function.

Purpose limitation: use information for the purpose described or another compatible and lawful purpose.

Transparency: explain the main categories, purposes, recipients, retention logic, and user rights.

Security: apply reasonable technical and organisational measures appropriate to the platform risk.

User control: wallet transactions remain subject to the user's own wallet confirmation.

No secret collection: KORAX never asks users to provide seed phrases or private keys.

4. Categories of Data

The data processed depends on the feature you choose to use.

Technical data: IP address, timestamps, browser and device information, request URLs, referrer, error and security logs.

Wallet data: public wallet address, network, balances, contract eligibility, transaction hashes, and public on-chain activity.

Project data: project name, token symbol, descriptions, branding, tokenomics, contract addresses, registry metadata, and public links.

Builder data: prompts, instructions, generated content, code packages, edit history, configuration, and deployment preferences.

Integration data: OAuth status, repository and deployment identifiers, provider responses, and user-selected publishing actions.

Communication data: email address, name where provided, support messages, attachments, and related correspondence.

Preference and local-state data: theme or functional settings, last-project state, access workflow state, and other necessary browser storage.

5. Sources of Data

Data may come directly from you, your wallet, public chains, or connected providers.

KORAX receives data when you enter information, connect a wallet, request AI generation, publish a repository, initiate a deployment, contact support, or otherwise use an interactive feature.

KORAX may also read publicly available blockchain information from BNB Chain through configured RPC services and may receive status information from wallet, repository, hosting, deployment, AI, and infrastructure providers used for a requested feature.

§

6. Purposes and Legal Bases

Processing must have a defined purpose and a lawful basis.

Depending on the function and context, KORAX may process personal data to perform a requested service, take steps before entering into a service relationship, comply with legal obligations, protect legitimate operational and security interests, or act on valid consent.

Where processing is based on consent, you may withdraw consent for the future. Withdrawal does not affect processing already carried out lawfully before withdrawal.

Where KORAX relies on legitimate interests, those interests may include secure website operation, fraud and abuse prevention, service improvement, error diagnosis, protection of legal claims, and operation of requested Web3 functionality.

7. Wallet Connections

Wallet providers handle keys; KORAX receives only public or connection-related information.

When you connect a wallet, the connection is handled through the selected wallet software and supporting connection libraries. KORAX may receive your public address, selected chain, connection status, and information required to prepare or display transactions.

KORAX does not receive or store your private key, seed phrase, wallet password, or recovery phrase. Never provide this information to KORAX staff, moderators, forms, AI tools, or support channels.

Disconnecting a wallet ends the active connection but does not erase data already published on a blockchain or retained by your wallet provider.

8. Public Blockchain Data

Blockchain transactions may be permanent, public, and independently analysable.

Public wallet addresses, token transfers, approvals, presale purchases, claims, staking positions, deployed contracts, project registration, launch activity, and transaction metadata may be visible to anyone through blockchain nodes and explorers.

Although a wallet address may appear pseudonymous, it can become personal data when linked or reasonably linkable to an individual.

KORAX cannot erase, correct, reverse, or restrict information independently recorded on a public blockchain. Requests concerning hosted off-chain information will be assessed separately from immutable on-chain records.

9. Website Hosting, Logs, and Security

Technical information may be processed to deliver and protect the website.

The hosting and network infrastructure may automatically process IP addresses, request times, requested resources, browser or device information, referrers, error details, and security signals.

These data may be used to deliver content, detect malicious activity, prevent abuse, investigate incidents, troubleshoot failures, and maintain platform availability.

Security logs are retained only for as long as reasonably necessary for those purposes and any applicable legal obligations. Exact periods may vary according to incident severity and the configured hosting provider.

10. Cookies and Browser Storage

Functional storage supports project continuity and integration workflows.

KORAX may use localStorage, sessionStorage, cookies, or similar browser technologies that are technically necessary to provide a user-requested function, maintain security, continue project workflows, remember local preferences, or complete OAuth and deployment integrations.

Functional browser storage can include the most recently generated project, deployment or launch identifiers, interface state, authentication state, and security values. Some information remains on your device until it expires or you clear browser data.

Non-essential analytics, advertising, profiling, or similar storage will not be activated without an appropriate consent mechanism where consent is legally required. If such tools are added, this policy and the consent interface must be updated before activation.

Clearing browser storage may remove locally saved project progress.

Blocking necessary storage may prevent login, publishing, deployment, or continuity features from working.

Third-party services may set their own storage on their domains under their own notices.

AI

11. AI Builder Processing

Builder prompts and project data may be sent to configured AI infrastructure.

When you request project analysis, website generation, visual generation, editing, or related AI functions, the information you submit may be transmitted to the configured AI service through KORAX server endpoints.

Inputs may include project descriptions, target audience, token configuration, branding instructions, website requirements, edit requests, and files or content you choose to provide.

Do not submit seed phrases, private keys, passwords, API secrets, confidential information, special-category personal data, or third-party personal data unless you have a lawful basis and the feature expressly supports that processing.

AI inputs and outputs may be logged temporarily for security, debugging, abuse prevention, and service reliability.

Provider-specific retention and training settings depend on the configured AI service and account configuration.

Generated content must be reviewed before publication or deployment.

GH

12. GitHub and Repository Publishing

GitHub data is processed only when you choose the publishing integration.

When you connect GitHub, KORAX may process OAuth identifiers, authentication state, account or organisation information made available by the granted scope, repository name, visibility choice, generated files, commit or publishing status, and provider responses.

The exact permissions are shown by GitHub during authorisation. You can revoke KORAX access through your GitHub account settings.

Files published to GitHub become subject to the repository visibility you select, your GitHub settings, and GitHub's own terms and privacy practices.

13. Hosting and Deployment Integrations

Deployment data is sent only when you request publication through a connected provider.

When you initiate deployment, KORAX may transmit project files, repository references, project names, configuration, environment-variable names, deployment instructions, and status data to the configured hosting or deployment provider.

Never place secret values directly inside generated public files. Review environment variables and repository visibility before publishing.

The deployment provider independently processes account, usage, security, billing, and hosting data under its own privacy notice.

14. Public Project Registry and Launch Data

Creators should expect approved project information to be public.

Project names, symbols, public owner wallets, token and contract addresses, metadata, public website links, launch identifiers, timestamps, and project status may be displayed in the KORAX public registry or launch interface.

Creators must not publish private personal information through project metadata unless they have a lawful basis and understand that registry or blockchain data may remain publicly accessible.

Removal from the hosted KORAX interface does not guarantee deletion from blockchain records, repositories, caches, archives, search engines, or third-party services.

15. Recipients and Service Providers

Data is shared only as needed for the chosen function, security, or legal compliance.

KORAX does not sell personal data. This does not prevent necessary transmission to providers used to deliver a feature or public disclosure caused by a user-authorised blockchain or publishing action.

Hosting, content-delivery, security, and infrastructure providers.

Wallet-connection providers and the wallet selected by the user.

BNB Chain nodes, RPC providers, smart contracts, validators, and blockchain explorers.

AI providers used by the selected builder function.

GitHub or another repository provider when publishing is requested.

Vercel or another hosting/deployment provider when deployment is requested.

Professional advisers, authorities, courts, or counterparties where required by law or necessary to protect legal rights.

Public visitors where a creator intentionally publishes project, registry, repository, website, or launch data.

16. International Data Transfers

Some technology providers may process information outside the EU or EEA.

Depending on the provider and feature, personal data may be processed in countries outside the European Union or European Economic Area.

Where GDPR transfer restrictions apply, the relevant transfer must rely on an available legal mechanism, such as an adequacy decision, approved standard contractual clauses, or another lawful safeguard.

Public blockchain data is globally distributed by design and may be accessed from jurisdictions worldwide.

17. Retention

Data is retained only for as long as required by its purpose or applicable law.

Retention depends on the category, purpose, provider, security need, and legal obligation. KORAX removes or anonymises off-chain personal data when it is no longer reasonably needed, unless continued retention is required or permitted by law.

Support correspondence and transaction-related records may be retained for applicable limitation, accounting, tax, fraud-prevention, or evidence periods.

Local browser data remains under your control and can normally be cleared through browser settings. Public blockchain data, public repositories, and third-party archives may remain available independently of KORAX.

18. Your Data-Protection Rights

Applicable law may give you rights over personal data controlled by KORAX.

Send privacy requests to contact@korax.fund. KORAX may request reasonable information to verify identity and prevent unauthorised disclosure.

Rights relating to data controlled by independent wallet, blockchain, GitHub, hosting, AI, or other providers must also be exercised directly with the relevant provider.

Erasure or rectification rights cannot force KORAX to alter immutable public blockchain records that it does not control.

Access: ask whether personal data concerning you is processed and request a copy.

Rectification: request correction of inaccurate or incomplete off-chain data.

Erasure: request deletion where the legal conditions are met.

Restriction: request limited processing in qualifying circumstances.

Portability: receive eligible data in a structured, commonly used, machine-readable format.

Objection: object to processing based on legitimate interests or direct marketing.

Consent withdrawal: withdraw consent for future processing where consent is the legal basis.

Complaint: lodge a complaint with a competent data-protection supervisory authority.

19. Automated Processing and Access Rules

Smart contracts may automatically apply transparent technical eligibility rules.

KORAX does not intentionally use personal data for solely automated decisions that produce legal or similarly significant effects on individuals.

Smart contracts and platform interfaces may automatically calculate staking eligibility, project slots, launch levels, contribution limits, token previews, or claim availability from wallet and contract state. These are technical execution rules for the requested Web3 service rather than an assessment of personal characteristics.

20. Security

KORAX applies reasonable safeguards, but no system is risk-free.

No website, AI system, smart contract, wallet, repository, hosting platform, or blockchain can guarantee absolute security. Users remain responsible for device security, wallet protection, transaction review, and safe handling of credentials.

Restricted access to operational systems and secrets.

Encrypted transport where supported.

Input validation, access checks, rate controls, logging, and incident investigation where appropriate.

Separation of public client configuration from private server credentials.

Review of provider permissions and minimisation of OAuth scopes.

Ongoing correction of identified vulnerabilities and dependency risks.

18+

21. Children

KORAX is not intended for children.

KORAX is intended for adults who can lawfully use blockchain and related services. KORAX does not knowingly seek personal data from children.

A parent or guardian who believes a child has submitted personal data may contact KORAX to request review and appropriate action.

22. Policy Changes

This policy will be updated when the platform or processing changes.

KORAX may update this Privacy Policy to reflect new features, providers, legal requirements, security practices, or processing operations.

The current version and last-updated date will be published on this page. Material changes will be communicated where legally required.

@

23. Privacy Contact

Use the official KORAX privacy contact for requests or questions.

Email: contact@korax.fund

Do not include private keys, seed phrases, wallet passwords, API secrets, or recovery information in any privacy request.

KORAX Privacy

Protect your wallet and control what you publish.

Never submit secrets to an AI tool, verify every integration, and remember that public blockchain data can remain visible permanently.