Aevra← Back to Aevra

Aevra — Privacy Policy

Effective September 16, 2026 · Version 1.0


The short version

Aevra is built to collect as little as possible, and most of what it holds is either public already or something you typed on purpose.

The full detail is below. This summary is not the policy; if they disagree, the sections below win.


1. Who this policy is from

Aevra is made and run by Alan Geleff, one person in Colorado, United States. There is no company behind it, and no team with access to your data beyond the providers named in Section 5. When this policy says "we," that means one person.

This policy explains how your personal data is handled when you use aevra.art, any Aevra subdomain, and the Aevra mobile app (together, the "Service").

Contact: legal@aevra.art

For the purposes of the UK and EU GDPR, Alan Geleff is the data controller for the data described here.

2. What we collect

2.1 Things you give us on purpose

What Where it comes from Why we have it
Wallet addresses and the chain each belongs to (Solana, Tezos, EVM, XRP, Bitcoin Ordinals) You connect or link a wallet It is your account. It identifies you, scopes your data, and tells us which NFTs to display.
A signature proving you control that wallet Your wallet, at sign-in Authentication. It is a read-only message signature; it cannot move funds.
Your handle, display name, bio, avatar, cover image, hero style and social links You type them Your public profile.
Posts — the piece or exhibit you posted, its chain, a cached snapshot of its image, title, collection and creator, your caption, and any creator credit You post them To show your post in the feed and on your profile.
Comments on posts, and comments on individual pieces You write them To show the conversation.
Curator notes on pieces, and the platform credit attached to them You write them To show your note alongside the piece.
Follows, likes and favorites You tap them To build your feed, your notifications and public counts.
Trays, folios and exhibits — your curated arrangements and published shows You build them To save them and show them.
Frame, matte, corner and layout preferences; hidden or "junk" overrides You choose them So your gallery looks the same on every device.
Support messages — the email address you give us, plus your subject, category, priority and description You submit the form at /support To answer you.
Reports you file about content or profiles, and the reason you give You file them Moderation, and to stop the same person reporting the same thing twice.
Issue reports (the in-app bug/problem tool) — a description plus the target item, a deep link, and technical context (chain, mint, media type, URL, browser user-agent, platform) You submit them To reproduce and fix the problem.

2.2 Things collected automatically

What Detail Why
Sign-in records Account, chain, and timestamp — one row each time you sign in Security, and so we can show "last seen."
Last-seen time A timestamp on your account Presence and inactivity.
A visitor identifier A random ID kept in your browser, used for signed-out people So share and view counts on a post are counted once per person rather than once per page load. It is not linked to a name and does not follow you to other sites.
Share and "wall" events on posts Post, viewer ID (your account or the visitor ID above), and which of the two kinds of event it was The public share count and wall count on a post.
Reputation and activity An XP number, a level, a reputation score and tier, computed from your activity on Aevra In-app reputation. Computed by us, from data we already hold.
Passkey records, if you create one A credential ID, the credential's public key, a usage counter, a label you choose, and created/last-used timestamps To let you sign in with a passkey. The private key never leaves your device.
Push notification subscriptions, if you turn them on The push endpoint URL your browser gives us, the two encryption keys that browser generates, your browser user-agent string (first 200 characters) and your account So we can send the notifications you asked for. Push is strictly opt-in: it requires you to tap, and we never send silent or background push.
Cross-device sign-in codes A short pairing code, an account reference and a temporary token, when you use "scan to sign in" To hand a session from one device to another. Single-use, and expires after 8 minutes.
Cast session codes, if you cast a gallery to a screen A code, a wallet address, a label and display settings To drive the second screen.
Purchase and donation records Your wallet address, the amount, and the public transaction signature To grant what you bought, and to show a supporters tally. All of this is already public on-chain.
Invite codes, while the invite gate is on The code, when it was used, and by whom Access control.
Server logs Our hosting provider records ordinary request logs, which include IP addresses Security, abuse prevention and debugging. Kept for 1 day, then discarded. These logs stay with our hosting provider and are not forwarded anywhere else.

2.3 What we deliberately do not collect

About the one place an IP is used. So that people who are not signed in can still report bad content, we need a way to tell one anonymous reporter from another. We do that by taking your IP address and browser user-agent, combining them with a secret only our server knows, and storing the resulting one-way hash — never the IP itself. The hash cannot be reversed to an IP and cannot be recomputed by anyone outside Aevra. If you are signed in, we store your account ID instead and no hashing happens.

2.4 NFT metadata we cache

To make galleries load quickly, we keep a light cache of public NFT metadata: asset ID, title, image URL, collection, creator, chain, media type and traits. This is public on-chain data, and it is about the asset, not about you. We do not store NFT image files — artwork is fetched from wherever the creator put it and passed through an image-resizing proxy each time. Images that you upload, such as an avatar or a cover image, are a different thing and are stored by us, as described in Section 5.1.

3. Why we use your data, and our legal basis

What we do Why Legal basis (UK/EU GDPR)
Show your gallery, profile, posts and exhibits It is the product Performance of a contract
Keep you signed in and sync your settings across devices It is the product Performance of a contract
Send push notifications you enabled You asked for them Consent — withdraw any time by turning them off
Answer your support message You asked us to Performance of a contract / legitimate interests
Moderate content, handle reports, prevent abuse and spam Keeping the service safe and lawful Legitimate interests; legal obligation
Rate-limit and protect against attack Security Legitimate interests
Grant what you purchased and show a supporters tally You bought or donated Performance of a contract
Fix bugs from an issue report You reported it Legitimate interests
Compute reputation, XP and tiers In-app features Legitimate interests

We do not use your data to train AI models, and we do not sell or rent it. We have never sold personal data and we do not "share" it for cross-context behavioural advertising as those terms are used in US state privacy laws.

4. What is public

Aevra is a public gallery. The following are visible to anyone on the internet, signed in or not, and can be indexed by search engines:

That last one deserves emphasis. Linking a wallet to a public handle connects your on-chain history to that identity, permanently and publicly. Blockchains are public and permanent. Anyone can look up an address on a block explorer and see every transaction it has ever made. If you do not want a wallet associated with your Aevra profile, do not link it.

Private to you: your favorites, your junk/hide overrides, your frame and layout preferences, your notification settings and read state, your support messages, and the reports you file (the person reported never sees who reported them).

5. Who we share data with

We do not sell your data. We share it in these situations only.

5.1 Service providers who run Aevra for us

Provider What it does What it can see
Vercel Hosting, serverless functions, CDN All requests, including IP addresses in runtime logs, which are kept for 1 day and are not forwarded anywhere else
Supabase The database Everything in Section 2 that we store
Cloudflare R2 Object storage for avatars, uploaded images and share cards The images you upload and the URLs that serve them
wsrv.nl Image resizing proxy for NFT artwork The image URLs being fetched, and the requesting IP
Fastmail Sends support emails Your support message and the email address you gave
Web push services (Google, Apple, Mozilla, depending on your browser) Deliver push notifications The notification payload and your push endpoint

5.2 Blockchain data providers

These are queried so we can read public chain data. They see the wallet addresses being looked up and the requesting IP.

Provider For
Helius, and api.mainnet-beta.solana.com as a fallback Solana
Alchemy EVM chains
TzKT and objkt Tezos
Ordiscan and ordinals.com Bitcoin Ordinals
XRPL public nodes (xrplcluster.com, xrpl.ws, s1.ripple.com) XRP Ledger
Xaman (XUMM) Linking an XRP wallet
Bonfida / SNS Resolving .sol names
CoinGecko Price display

5.3 Media and content hosts

NFT artwork lives wherever its creator put it. Loading a piece means your browser or our servers fetch it from:

IPFS gateways — ipfs.io, gateway.pinata.cloud, ipfs.4everland.io, dweb.link · Arweave — arweave.net, permagate.io · or the creator's own server.

These hosts see the request and the IP it came from. We do not control them.

5.4 Other third parties your browser contacts

Loading Aevra causes your browser to request assets from Google Fonts (fonts.googleapis.com, fonts.gstatic.com), cdnjs (Cloudflare), unpkg and jsDelivr. Those services receive your IP address and browser user-agent as part of an ordinary web request.

5.5 App store distribution

Aevra is distributed through the Solana Mobile dApp Store, and listing assets are stored on Arweave via ArDrive. Solana Mobile receives the information in our store listing and may receive information about installs and, under the Developer Agreement, may request transaction-related dApp data. Solana Mobile's own privacy practices are theirs, not ours.

5.6 Legal and safety

We may disclose data if we reasonably believe it is necessary to comply with the law or a valid legal process; to enforce our Terms; to investigate fraud, abuse or a security incident; or to protect the rights, property or safety of our users, of the public, or of us. We report child sexual abuse material to the National Center for Missing & Exploited Children and to law enforcement, together with associated account data, without notice to the account holder.

5.7 A change of ownership

If Aevra is later moved into a company, sold, or taken over by someone else, data may transfer as part of that. We would tell you before your data became subject to a different privacy policy.

5.8 Our internal tools

There is a private Telegram group where Aevra gets built and tested, and a bot in it that logs those messages and uses Anthropic's API to summarise them on command. That is a private chat between Alan and a handful of testers. It does not receive Aevra user content, and no Aevra user data is sent to any AI model.

5.9 Binding our providers

We require our service providers to handle data only on our instructions, to keep it secure, and to comply with the Solana Mobile Publisher Policy where they have access to user data. The public blockchain endpoints and IPFS gateways listed above are queried anonymously and receive no personal data from us beyond a public wallet address and the requesting IP.

6. How long we keep things

Data Kept for
Account, profile, wallets, preferences Until you delete your account
Posts, comments, curator notes, exhibits, trays Until you delete them, or until you delete your account
Sign-in records Until you delete your account
Passkeys Until you remove the passkey or delete your account
Push subscriptions Until you turn push off, the browser invalidates the subscription, or you delete your account
Content reports Until the reported content is deleted, which cascades the report away
Issue reports and support emails 24 months
Purchase and donation records Kept indefinitely, with your account link removed when you delete your account — see Section 10
Server logs (including IP) 1 day. Our hosting provider keeps runtime logs for 24 hours and then discards them
Database backups 7 days. A backup is taken daily and kept for seven days, so deleted data can persist in a backup for up to a week before it rolls off

7. Your choices and your rights

7.1 Things you can do yourself, right now

7.2 Rights you have under the law

Depending on where you live, you may have the right to:

To exercise any of these, email legal@aevra.art. We will respond within the time the law requires — generally 45 days under the California CCPA/CPRA and the Colorado Privacy Act (each extendable by a further 45 days where the law allows, with notice to you), and one month under the UK and EU GDPR (extendable by two further months for complex requests).

How we verify you. Aevra has no email or password, so the only reliable proof that an account is yours is a signature from a wallet on it. We may ask you to sign a message to verify a request. If you cannot sign, we may be unable to act on the request — not because we are being difficult, but because we would have no way to tell you from someone impersonating you.

Colorado residents. The Colorado Privacy Act gives you the rights above, including the right to opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. Aevra does none of those three, so there is nothing to opt out of. You may appeal a refused request by writing to legal@aevra.art with "Appeal" in the subject; if we refuse the appeal you may contact the Colorado Attorney General.

California residents. We do not sell or share personal information as the CCPA/CPRA defines those terms, and we have not in the preceding 12 months. You may still exercise the access, deletion, correction and non-discrimination rights above.

UK and EU residents. Your legal bases are in Section 3. You may lodge a complaint with your local supervisory authority — the ICO in the UK. Aevra is operated from the United States, so using it involves an international transfer; where required, those transfers are covered by the European Commission’s Standard Contractual Clauses and, for the United Kingdom, the UK International Data Transfer Addendum, as incorporated into the data processing agreements of the providers that host Aevra — Supabase, Vercel and Cloudflare.

8. Security

We collect the minimum we need, and we do not make any of the sensitive data categories listed in the Terms of Service §8.5 available to a third party.

No service is perfectly secure. Your wallet is the weakest link and it is the part we cannot protect. Guard your seed phrase, read every transaction before you sign it, and treat any message asking for your recovery phrase as an attack.

If we suffer a breach affecting your personal data, we will notify you and the relevant regulators as the law requires.

9. Children

The Service is not directed to children, and we do not knowingly collect personal data from anyone under 18. If we learn that we have, we delete it. If you are a parent or guardian and believe your child has given us data, email legal@aevra.art.

We also never use deceptive or coercive design to get consent, and if you decline something we respect it.

10. Deleting your account — exactly what happens

Go to Settings → Danger zone, type DELETE, and sign with a wallet on the account. The signature is required so nobody else can delete your account for you.

Deleted outright, immediately, by database cascade:

your account record and profile · every linked wallet · every sign-in record · every passkey · your push notification subscriptions · your posts and their captions, snapshots and credits · your comments on posts · your comments on pieces · your curator notes · your follows, in both directions · your mentions · your trays, folios and exhibits · your favorites · your junk/hide overrides · your frame and layout preferences · your notification read state · your unlocks · your legacy profile rows.

Notifications are not stored at all — they are computed live from the data above, so they disappear the moment it does.

Anonymised rather than deleted:

Survives deletion:

What no one can delete. Your wallet address and the transaction signature for anything you bought or donated are recorded on a public blockchain. That record is permanent and public, it was never ours, and neither we nor you nor anyone else can remove it. Deleting your Aevra account removes our copy and our link to you; it cannot remove the chain's.

Nothing on-chain is affected. Your wallet, your NFTs, your Access Chip and your Adornments stay exactly where they are. Aevra never had the ability to change that.

Deletion is permanent and cannot be undone.

11. Cookies and local storage

Aevra does not use cookies for tracking or advertising, and there are no third-party advertising or analytics cookies.

Aevra sets two cookies, both strictly necessary for the service to work:

Because both are strictly necessary to deliver a service you asked for, they do not require a consent banner under UK or EU rules. We set nothing else.

Aevra also uses your browser’s local storage — data that stays on your device and is never sent anywhere except back to Aevra when the app needs it. It holds:

Clearing your browser’s site data for aevra.art removes all of it, clears the cookies above, and signs you out.

12. Changes to this policy

We may update this policy. When we make a material change we will update the Effective Date and Version at the top and tell you in the app before it takes effect. We keep prior versions, and will send you any earlier version on request.

13. Contact us

Alan Geleff 1136 N Calhan Ave Castle Rock, CO 80104 United States


© 2026 AevraTermsPrivacyCopyrightDMCAAboutSupport@aevradotart