// LEGAL
Privacy Policy
Last updated: June 2026 · Applies to: Memefolio Chrome Extension & website
Memefolio is a Chrome browser extension that overlays public on-chain Solana portfolio data on X (Twitter) profiles. This policy explains what data we collect, why, and how it is used — written in plain language and structured to meet the requirements of the Chrome Web Store Developer Program Policy and applicable privacy regulations.
We collect the minimum data necessary to operate the service. We do not sell data, run ads, or track your browsing activity.
01
🧩Extension — what it collects
The Memefolio Chrome extension operates entirely client-side. It does not collect, transmit, or store any personal data from your browser.
- The extension reads X (Twitter) page content solely to detect profile avatars and extract public usernames. This data never leaves your device.
- It queries our Supabase database using those usernames as a read-only lookup — only to check if a KOL has registered a wallet. No personal data about you (the extension user) is sent.
- It fetches public on-chain data (token balances, last trade) from the Helius RPC API using the registered wallet address. Wallet addresses are public by nature on Solana.
- Portfolio data is cached locally in
chrome.storage.local for up to 30 minutes to reduce API calls. This cache contains only public blockchain data and is never transmitted to us.
We do not collect: browsing history, URLs visited, keystrokes, cookies, or any data about your X account.
02
📝Registration — what we collect
Registration is optional and only relevant to KOLs who want their wallet to appear in the Memefolio overlay. If you choose to register, we collect and store:
- Your X (Twitter) username and user ID — obtained via OAuth. We request the minimum OAuth scope (read-only identity). We do not access your timeline, DMs, followers, or posting permissions.
- Your public Solana wallet address — verified by a read-only message signature. We never request, store, or process private keys or seed phrases.
- Timestamp of registration — for internal record-keeping.
We do not collect: email addresses, passwords, private keys, seed phrases, phone numbers, or payment information.
03
⚙️How we use your data
Registered data is used for one purpose only: to allow the Memefolio Chrome extension to display on-chain portfolio information to users browsing X.
- Your X username is used as a lookup key when other users' extensions detect your profile on X.
- Your public wallet address is used to query live Solana data via Helius RPC, displayed as a read-only overlay.
- We do not use your data for advertising, profiling, marketing, or any purpose other than the above.
04
🔗Third-party services
We use the following sub-processors. Data shared with them is limited to what is strictly necessary:
- Supabase — our database provider (EU region). Stores registered X usernames and public wallet addresses. Access is protected by row-level security; only a read-only anonymous key is distributed with the extension.
- Helius — Solana RPC provider. Receives public wallet addresses to query on-chain token balances and swap history. All data queried is already publicly available on the Solana blockchain.
- Google (Chrome Web Store) — distributes the extension. Subject to Google's own privacy policy.
We do not share your data with any other third parties, data brokers, analytics platforms, or advertisers.
05
🔒Security
We apply the following security measures:
- Supabase database access is protected by API key authentication and row-level security. Only a scoped read-only key is bundled with the extension.
- Write access to the database (registration) requires server-side authentication via X OAuth — it is never exposed client-side.
- We do not store private keys, seed phrases, or any credentials capable of authorising transactions.
- Extension permissions are limited to
x.com and twitter.com content scripts only. No broad host permissions are requested.
06
✋Your rights & data deletion
If you have registered and wish to remove your data:
- Contact us at privacy@memefolio.xyz and we will delete your entry within 7 days.
- Once deleted, your profile will no longer appear in any Memefolio user's overlay. Cached data on other users' devices will expire within 30 minutes.
- Extension users (non-registered) have no personal data stored on our servers and therefore have nothing to request deletion of.
Depending on your jurisdiction, you may also have rights to access, rectify, or port your data. Contact us at the address below for any such request.
07
🌍Data retention & transfers
Registered data (username + wallet address) is retained until deletion is requested. No retention period is applied otherwise, as the data is necessary for the service to function.
Data is stored on Supabase infrastructure. If you are located in the EU/EEA, please note that data may be processed in data centres outside your region. Supabase participates in standard contractual clauses for international transfers.
08
📋Chrome Web Store compliance
This extension complies with the Chrome Web Store Developer Program Policies, including the Limited Use requirements. Specifically:
- We do not use data obtained from X page content for any purpose other than providing the in-page overlay described in the extension listing.
- We do not transfer this data to third parties except as required to provide the overlay feature (Supabase lookup, Helius RPC).
- We do not use or transfer data for advertising purposes.
- We do not allow humans to read user data unless required for security investigation or legal compliance.
09
✉️Contact
For privacy questions, data deletion requests, or any concerns:
We aim to respond to all requests within 7 business days.