Show values in NEAR or US dollarsThe NEAR price is unavailable right now, so amounts stay in NEAR.
Create

Privacy policy

What this site does with information. Written from what the code does.

Last updated 21 September 2026

Experimental software. Shards is non-custodial software provided as it is, with no warranties, by its contributors. By using it you accept the risk of using it.

This policy describes what Shards does with information when you use this website. Shards is published by its contributors; there is no company behind it. It is written from what the code actually does, and the short version is that we keep almost nothing.

1. What we do not collect

We do not ask for or collect your name, your email address, your phone number, your date of birth, your postal address, or any identity document. There is no account to register and no password.

We set no cookies. Not for sessions, not for preferences, not for anything.

We run no analytics and no third-party trackers. There is no Google Analytics, no Plausible, no PostHog, no Mixpanel, no Segment, no advertising pixel and no third-party error-reporting service in this application. When a page breaks, our own server writes down what broke; "When a page breaks" below says exactly what that is and what it is never allowed to contain.

We do not sell, rent or share personal information with anyone for marketing, and we never have. Nothing is used for profiling or for any automated decision about you.

2. Public blockchain data

Everything you do on chain, whether creating a launch, buying, selling, claiming fees or dividends, or applying for a takeover, is a public NEAR transaction recorded permanently on a public ledger. It includes your account ID, the amounts, and the time.

We did not put it there and we cannot remove it. Anyone in the world can read it, with or without this website. If your account ID is linked to your real identity anywhere else, that link follows you here.

3. Your wallet account ID

When you connect a wallet we see your NEAR account ID, which is a public identifier, not a secret.

Looking is free. Your portfolio, your holdings and your claims are public blockchain records, so we look them up by account ID alone. Connecting a wallet is enough to see them and nothing is signed.

Two things do ask you to sign a message first: uploading a token image, and applying for a community takeover. Signing proves the account is yours. We never see your private key, and signing a message never authorises a transfer.

That sign-in produces a short-lived token that stays in the browser tab you are using and is thrown away when you close it. It leaves your browser only as proof on those two requests, we do not store it on our side, and it expires on its own.

4. What stays on your own device

We store a few preferences in your browser’s local storage. These never reach our servers:

  • which colour theme you chose;
  • your slippage tolerance;
  • which wallet you last connected with;
  • a record of an unfinished token creation, so you can resume it;
  • that you have seen the risk notice, so we do not show it to you again.

Clearing your browser’s site data removes all of them.

5. IP addresses and server logs

Our servers see the IP address of requests, as every web server does. We use it for one thing: rate limiting, so that one source cannot flood the API, the blockchain proxy, the image uploader or the error reporter. Ordinary request logs, which include IP addresses, are written by the servers and by the Cloudflare service in front of them.

We do not use IP addresses to build a profile, to track you across sites, or for advertising. Those logs are not shipped anywhere, not archived and not backed up. Each service keeps roughly 30 MB of recent log and overwrites the oldest as it fills, which on a busy service is a matter of days. Rate-limit counters last as long as the rate-limit window and no longer. Cloudflare keeps its own logs under its own policy, which we do not control.

6. When a page breaks

If a screen throws an error, your browser sends a short report to our own server so that we find out a page is broken without waiting for somebody to tell us. It goes nowhere else: there is no Sentry, no Datadog and no third-party error service in this application, and the report is not used to count visitors or to measure anything.

A report contains only:

  • the error message and the developer stack trace;
  • the path of the page you were on, such as the create page or a token page. Never the part of the address after a question mark;
  • your browser’s user-agent string, which is what every web request already sends;
  • the time, and the build the site was serving.

Your wallet keys, your seed phrase and your sign-in token can never be in one. The report is stripped of anything shaped like a credential before it is written, and your IP address is not written down at all. A wallet account ID may appear, because it is already public on chain.

Reports live in the same short-lived server log as every other request and are overwritten as it fills. Nothing is shipped, archived or backed up.

7. Images you upload

When you create a token you may upload an image. It is pinned to IPFS, a public, distributed, content-addressed network, through our pinning provider, Pinata. A hash of the image and its IPFS address are written into the launch’s configuration on chain.

This is public and effectively permanent. Anyone can fetch it. We can stop paying to pin it, but we cannot delete it from IPFS, and we cannot remove the reference already written on chain. Do not upload anything private, anything containing personal information, or anything you do not have the right to publish.

8. Community takeover applications

If you apply for a community takeover, we store your NEAR account ID and the contact details you type into the application form, together with your application’s status. Operators reviewing the application can read them.

Only put contact details there that you are willing to share.

9. Blockchain requests

The interface reads chain data through our own server rather than sending your browser straight to a node operator. A side effect is that the node operator sees our server, not you.

10. Where this runs, and who else handles data

The website and the API run on rented servers behind Cloudflare. We do not own the hardware and we do not name the host here, because that is an attack surface rather than a privacy fact. Besides that host, these parties see something:

  • Cloudflare sits in front of the site, terminates the connection first and sees every request, including IP addresses, under its own privacy policy.
  • Pinata pins uploaded images to IPFS and receives the image file. Its privacy policy governs what it does with it.
  • Your wallet provider is a separate application we do not control, with its own privacy policy.
  • NEAR RPC providers receive the blockchain queries our server makes, and see our server rather than you.

There are no other processors, and no analytics vendor of any kind.

11. Why we are allowed to do this

Where the UK or EU General Data Protection Regulation applies, the controller of the little personal data described here is the contributors who publish Shards, and the Contact section below is how you reach us. We rely on legitimate interests, being the running of a secure, working service and the prevention of abuse, for IP-based rate limiting and server logs, and on performance of a contract for the account-linked features you ask us to provide. We do not rely on consent, because there is no optional collection here to consent to. We are not the controller of the NEAR blockchain and cannot act on anything recorded there.

12. Your rights

Depending on where you live, you may have the right to ask what we hold about you, to correct it, to have it deleted, to object to its processing, to restrict it, or to receive a copy. You may also have the right to complain to your local data-protection authority.

Because we hold so little, those rights reach very little. We cannot delete, alter or hide anything recorded on the NEAR blockchain, and we cannot remove a file from IPFS. Those are outside anyone’s control, including ours.

13. Children

This service is not for anyone under 18. We do not knowingly collect information from children.

14. Security

We keep very little, which is the strongest protection we can offer. What we do keep sits on the rented infrastructure described above, behind ordinary access controls and TLS. No system is perfectly secure, this software is experimental, and we cannot guarantee anything.

15. Changes

We may update this policy. The "last updated" date above changes when we do, and continuing to use the site after a change means you accept it.

16. Contact

Questions about this policy, and requests about your rights, go to @shardsmarket (https://x.com/shardsmarket).

Be aware of the hard limits above before you ask: nothing on the blockchain and nothing on IPFS can be deleted, by us or by anyone.

Nobody from this project will ever ask you for your seed phrase, your private key or a signature "to verify your wallet". Anyone who does is trying to rob you.