← about

privacy policy

Last updated: July 16, 2026

This Privacy Policy explains how the operator of wave.baby (the "Operator", "we", "us"), available at wave.baby (the "Platform"), processes personal data. The Operator is the data controller. For information about the legal entity acting as controller, contact us at the address in Section 10; we respond to any legitimate request.

We designed the Platform to work without accounts, emails, or personal profiles: you interact through a self-custodied wallet. We still process a limited amount of personal data, described below.

1. Data we process

Wallet data. Your public Solana wallet address, the tokens created with it, and related on-chain activity that we index (fees, market data).

Creation data. The content you submit when creating a token: drawings (as raw stroke data), text, prompts, selections, and for some editions audio recordings; the resulting media and metadata; your creation attestation (the confirmation you give before signing) with its timestamp.

Technical data. IP address, approximate country derived from IP, browser and device information, and server logs. IP-derived country is used to enforce geographic restrictions; IP addresses are used to rate-limit media generation.

Usage analytics. Behavioral usage data collected through analytics tools (currently Mixpanel) — pages viewed, interactions, approximate location, device information — used to understand and improve the Platform.

Error data. Technical error reports collected through Sentry (may include IP address and device information).

Correspondence. Anything you send to our contact address.

We do not collect names, emails (unless you email us), or government identifiers. We do not sell personal data, and we do not use it for third-party advertising.

2. Purposes and legal bases

ProcessingPurposeLegal basis (GDPR)
Geographic enforcement (IP country checks, blocking logs)Enforce jurisdiction restrictions, sanctions complianceLegal obligation; legitimate interest
Creation attestations + creation logsProve rule acceptance, defend legal claimsLegitimate interest; legal obligation
Creation data processing and publicationProvide the service (create the token you request)Contract
Rate limiting, anti-abuse, security logsProtect the PlatformLegitimate interest
Token indexing, fee and market data displayProvide the serviceContract; legitimate interest
Analytics (Mixpanel)Understand and improve the PlatformConsent where required; otherwise legitimate interest
Error monitoring (Sentry)ReliabilityLegitimate interest
CorrespondenceRespond to youLegitimate interest

3. Public and permanent by design: blockchain and IPFS

When you create a token, its media and metadata are published to IPFS and referenced on the Solana blockchain, together with your wallet address. These networks are public, decentralized, and permanent: we do not control them and cannot erase, modify, or restrict anything published there. On-chain activity is also open to analysis that may allow re-identification of wallet holders.

Rights to erasure and rectification do not extend to on-chain and IPFS data. Do not include personal data in the content of a token.

4. Retention

  • Server logs, IP-based geographic and rate-limiting records: 12 months rolling.
  • Creation attestations and creation records: for as long as the related token is listed on the Platform, and thereafter as long as necessary for legal claims.
  • Submitted creative input (raw data): for as long as the related token is listed on the Platform, and thereafter as long as necessary for legal claims.
  • Generation attempts that do not result in a token: 90 days.
  • Analytics and error data: per our analytics and error-monitoring providers' configurations, capped at what is necessary for the purposes above.
  • Correspondence: as long as necessary to handle the matter.

On-chain and IPFS data are permanent (Section 3) and outside any retention schedule.

5. Processors and recipients

We share personal data only with service providers acting on our instructions:

  • Vercel (hosting, edge network, geographic filtering)
  • Supabase (database)
  • Railway (background processing)
  • Pinata / IPFS (media and metadata storage — published content is public, see Section 3)
  • Analytics providers (currently Mixpanel)
  • Error monitoring providers (currently Sentry)
  • AI generation providers (for editions using server-side generation: your creative input/prompts are sent to the provider to generate the media)
  • Blockchain RPC and market data providers (public on-chain data)

We may add or replace providers within these categories from time to time; this policy will be updated for material changes.

Some providers process data internationally. Where required, transfers rely on recognized safeguards such as standard contractual clauses. We may also disclose data where required by law or to competent authorities upon valid request.

6. Your rights

Depending on your location (including under the GDPR), you may have the right to access, rectify, erase, or receive a copy of your personal data, to restrict or object to processing, and to withdraw consent where processing is based on consent. These rights apply to data under our control; they cannot apply to on-chain or IPFS data (Section 3).

To exercise a right, email us at the address in Section 10 from a verifiable context (e.g., signing a message with the relevant wallet may be requested to verify ownership). You also have the right to lodge a complaint with a data protection supervisory authority.

7. Cookies and similar technologies

The Platform uses strictly necessary technical storage (e.g., wallet session state) and analytics (Mixpanel). Where required by applicable law, analytics run only with your consent, which you can withdraw at any time. You can also limit tracking through your browser settings.

8. Children

The Platform is not directed at anyone under 18. We do not knowingly process data of minors; if you believe a minor has used the Platform, contact us.

9. Changes

We may update this Policy; the "last updated" date will change and material updates will be signposted on the Platform.

10. Contact

contact@wave.baby — single point of contact for privacy requests, including identification of the controller upon legitimate request.