thesis

Privacy

Last updated 23 September 2026

This notice describes what thesis does with information about you. It is short because the product currently does very little with it. Where a section says we do not do something, that is a statement about the software as it is built today, not an aspiration.

1.What we collect

Wallet identity. There is no account database. Wallet sign-in sets a single cookie named thesis_session that records the public wallet address that proved control, the provider, and the session expiry. It expires after thirty days.

No private keys. The pad asks the wallet to sign a one-time, domain-bound message. It never receives a private key or seed phrase, and signing the login message cannot move funds.

Server logs. Whoever hosts the site will keep ordinary web logs โ€” IP address, user agent, the page requested and when. That is a property of running a web server, not a choice we made about you.

2.Who else sees your requests

Market data is fetched by our server, not your browser, so these providers do not see you. They see us asking about coins:

  • Jupiter โ€” prices, holders, concentration and organic scores for Solana coins.
  • DexScreener โ€” prices, liquidity and trade counts across every chain we carry.
  • GeckoTerminal โ€” candles.

Coin logos are served from our own domain because they were downloaded at build time. Loading a page does not call out to arweave, IPFS or anyone else, so nobody learns which coin you were looking at.

3.Cookies and tracking

The session cookie described above, plus local browser storage for draft and published theses, payout wallet addresses and useful votes. Thesis data stays on this device in the prototype; it is not uploaded to us. No analytics, pixels, fingerprinting or advertising network follows you to another site.

Because we do not track you anywhere, a Do Not Track header changes nothing about what we do โ€” we were not going to do it either way.

4.Sharing and selling

We do not sell information about you, share it for advertising, or pass it to a data broker. There is no information to sell.

5.Security

The session cookie is httpOnly and sameSite=lax, so page scripts cannot read it and another site cannot cause it to be sent.

The login challenge expires after five minutes and is deleted after one attempt, which prevents replay. This prototype has not had an external security audit and does not take custody of wallet funds.

6.Children

thesis is not for anyone under 18. We do not knowingly collect information from children, and given the section above, we do not knowingly collect information from anyone.

7.Your rights

Depending on where you live you may have the right to see, correct, export or delete information a company holds about you, and to object to how it is used.

You can exercise the deletion right yourself, immediately, by clearing cookies for this site. That removes everything we hold. If you want confirmation of that in writing, ask and you will get it.

8.Changes

If the product starts doing something this notice does not describe โ€” persistent accounts, transaction submission, custody or analytics โ€” this notice gets rewritten before that ships. The date at the top is the honest one.

9.Contact

Contact details will be published before the public launch. See also the terms.