01
who this covers
this policy covers the ondisplay.app website and the on display. collector app provided to invited testers. the app is in development, with no public download yet. features and sign-in methods may be available only to selected testers.
on display. operates this service and handles privacy requests at support@ondisplay.app.
02
visiting the website
you can visit the website without an account or wallet. the website currently uses no analytics scripts, advertising pixels, embedded social feeds or non-essential cookies. its display preview runs in your browser.
cloudflare delivers and protects the website. it processes connection and request information such as your ip address, browser information, requested pages and request times. links to x and other external sites open those services, whose own privacy notices apply.
if you email us, we receive your email address, message and any attachments you choose to send. proton mail provides our support inbox. do not send recovery phrases, private wallet keys or sign-in codes.
03
accounts and sign-in
an account is not required for public collection browsing. if you create an account or link a sign-in method, supabase provides authentication and stores your account identifier, connected provider identities and the email address or phone number supplied through that method. verification and security records may include sign-in times, ip addresses and delivery or error information.
email codes are delivered through resend. phone verification, where enabled for testing, uses twilio verify and mobile carriers. these services receive the destination and information needed to deliver and protect the verification process.
apple sign-in can provide your apple account identifier and your chosen real or relay email address. google sign-in, when available to you, can provide a google account identifier, email address and basic profile information such as a name or profile image. this is used to authenticate you, link sign-in methods and maintain your account. we do not request gmail, drive or contacts access.
x sign-in and linking are being configured. when enabled, they use your x identifier, username, basic profile information and email where you authorize access. the authentication provider can also request read-post and offline-access permissions as part of its default scope. on display. does not use those permissions to read or analyze your timeline. it does not request posting or direct-message permissions.
provider identity data is stored with the account in supabase. account sessions and any provider tokens returned as part of those sessions are handled by the authentication service and may be retained in the app’s protected device session storage. we do not use google or x account data for advertising, sale, timeline analysis or ai model training. access is limited to account operation, service providers supporting that operation, necessary support and security, and legal obligations.
you can revoke a social provider’s access in that provider’s account settings. revoking provider access does not itself delete an on display. account or its saved content. account removal is a separate request.
04
wallets, collectibles and public data
when you look up a public wallet or collectible, the app sends the relevant public address, asset identifier and network request to blockchain nodes, indexers, metadata hosts or marketplaces. these include supported solana rpc services, publicnode, blockscout and magic eden. artwork may load directly from its creator’s host or an ipfs or arweave gateway. these services can receive your ip address and request information even if you have not created an account.
wallet connection and proof features use public addresses, connection sessions and signed messages to check control of a wallet. the app does not ask for or collect recovery phrases or private wallet keys. wallet connection session secrets are different from the keys that control your assets and are stored on the device for the connection.
selected solana listing and cancellation tests use a transaction-preparation service operated through bullenciaga and magic eden. the relevant public wallet, asset and proposed order details are processed to prepare and check the request. your external wallet must approve the transaction. submitted transactions and signatures are visible on the relevant public blockchain and may also be indexed by other services.
public blockchain data can be linked to a person when combined with an account or other identifying information. disconnecting a wallet or deleting an account cannot erase blockchain history or copies maintained independently by other services.
06
what stays on your device
local displays, preferences, favorites, drafts and local transaction receipts are currently stored on your device. ordinary png and mp4 exports are rendered locally, without uploading the display to a rendering service. sharing an export sends it to the destination you choose.
account sessions use protected device storage on the iphone. connected wallet sessions also use protected device storage and have an app-level expiry check. saved display data and selected media use app storage. cross-device display synchronization is unfinished; local data should not be treated as an online backup.
the app uses system media pickers for content you select and requests photo-library access when needed to save an export. permissions can be managed in your device settings. local files, exports and device backups can have different lifetimes from an online account.
07
why we use this information
we use account and profile information to provide the features you request, authenticate access, save published content and respond to support requests. where european data-protection law applies, our basis is performance of our agreement with you, or steps you request before that agreement.
we use necessary connection, verification and operational records to prevent abuse, investigate errors and protect accounts and the service. our basis is our legitimate interest in a secure, reliable service, balanced against your rights. legal obligations can require specific records to be retained or disclosed. where a feature requires consent under applicable law, you can withdraw that consent without affecting earlier lawful processing.
providing account or publication information is optional, but we cannot provide the corresponding account or sharing feature without the information it needs. public browsing remains available without an account. we do not make solely automated decisions with legal or similarly significant effects about you.
08
service providers and international processing
we use cloudflare for website delivery and protection, supabase for authentication, database and public media storage, resend for account email, proton mail for correspondence, and twilio verify for enabled phone verification. apple, google, x and external wallet providers operate the sign-in or wallet service you choose. blockchain nodes, indexers, marketplaces and media hosts process the collection requests described above.
information is shared with service providers to operate these functions, with other people when you publish content, and where required by applicable law. we do not sell account information or use google or x user data for targeted advertising.
our providers may process information outside your country. processing locations and applicable safeguards depend on the service involved. contact support@ondisplay.app for information about the providers, processing locations and transfer arrangements relevant to your information.
09
retention and removal
account and published-profile information is kept while your account remains open and needed to provide the service. after a verified closure request, we remove personal account and profile data and owned uploaded media that are no longer needed, except identified records required by law or needed for an active dispute or security investigation.
we keep ordinary support correspondence for up to 12 months after the request is resolved, then delete it unless a specific legal obligation or active dispute requires longer retention.
operational, authentication, delivery and security records are used to operate the service, investigate faults and protect accounts. provider log and backup retention periods vary by service and plan. removing live account data does not necessarily remove it immediately from these records or backups; those copies remain until the applicable rotation or deletion process completes. contact support@ondisplay.app for information relevant to your request. no automated inactive-account purge or complete self-service account deletion/export is currently implemented.
public blockchain records cannot be deleted by us. local files and exports remain on your device or chosen destination until removed there. public-media caching and independent copies are described above.
10
your choices and privacy requests
you can edit supported profile fields, change profile visibility, disconnect a wallet and revoke social-provider access. to request access, correction, a copy of your information or deletion, contact support@ondisplay.app. account export and deletion currently require support assistance rather than a complete self-service flow.
we may ask for proportionate information to confirm that a request is yours. we will never ask for a recovery phrase, private wallet key or sign-in code. where applicable, you can also request restricted processing, object to processing based on legitimate interests, withdraw consent or request data portability.
where european data-protection law applies, we respond without undue delay and normally within one month; if a lawful extension is necessary, we explain it within that first month. you can complain to the data-protection authority where you live, work or believe an infringement occurred. these rights can have legal exceptions, which we will explain when relevant.
11
children and policy changes
if you have a concern about a child’s personal information in the service, contact support@ondisplay.app so it can be reviewed and appropriate action taken.
we will date revisions to this policy and explain material changes before applying them where required. new features or new uses of provider data may require additional notice or permission. this policy does not announce a public app release.