Privacy Policy
Last updated: 10 July 2026
This policy describes the data handled by the current Solara software. It does not claim an unimplemented analytics, KYC or marketing stack. The production operator must complete jurisdiction-specific privacy and retention review before opening the platform publicly.
1. Data currently collected
- Account: name, email, password hash, role, status and account timestamps.
- Security: refresh-session token digests, IP address, user agent and authentication audit events.
- Simulation: challenge accounts, orders, positions, fills, balances, rule violations, daily snapshots and trade-journal entries.
- Preferences: appearance, notification, sound, hotkey, copy-trading and affiliate settings.
- Settlement: public Solana addresses, checkout references, quoted native-SOL amounts, transaction signatures and verification results.
- Support: information deliberately included in a support request.
Private keys and seed phrases are never required or stored. The current application does not include a KYC document-upload system.
2. Why data is used
- Authenticate users and protect accounts.
- Operate the simulated trading, risk and challenge systems.
- Verify native-SOL payments and payouts on Solana.
- Detect abuse, investigate incidents and maintain an audit trail.
- Deliver transactional email and requested support.
- Meet legal obligations that apply to the production operator.
3. External services
The software may send limited technical requests to:
- Drift DLOB: current perpetual-market depth used for simulated execution.
- Binance Futures: historical candles and aggregate trades used for chart context.
- Pyth Hermes: SOL/USD quotes used for settlement amounts.
- Solana RPC: public transaction and balance data used for transfer verification.
- Transactional email: Resend or Postmark only when configured by the operator.
- Hosting: the PostgreSQL, Redis, application and logging providers selected for deployment.
Solana transaction data is public by design. Solara does not sell personal data.
4. Cookies and browser storage
Solara uses essential HttpOnly authentication cookies. The short-lived access token is kept in browser memory and is not persisted to local storage. Local storage may cache non-sensitive interface preferences so the app can start quickly. No advertising or analytics cookie is set by the current repository.
5. Retention
Trading, payment, payout and audit records must remain available long enough to explain account and settlement decisions. A production retention schedule, deletion process and backup-expiry policy must be approved before launch; no unsupported fixed retention period is promised by this pre-launch software.
6. Security boundaries
- Passwords use Argon2id hashing.
- Refresh tokens are stored as digests and delivered in HttpOnly cookies.
- Production configuration rejects synthetic market data, public RPC defaults and placeholder secrets.
- Treasury signing remains outside the application.
- Administrative and settlement actions are audit logged.
No system can guarantee absolute security. Users should report suspected account compromise immediately and must never send a private key or seed phrase.
7. User controls
The Data & Privacy section of Settings can generate a machine-readable export containing profile, accounts, orders, fills, journal entries, payments, payouts, rule decisions and user-visible audit events. Requests for correction or deletion can be sent to the address below, subject to records the operator must retain.
8. Children
The service is not intended for anyone under 18. An account or payout may be restricted where age cannot be confirmed when review is required.
9. Contact
Privacy questions and data requests can be sent to privacy@solara-futures.com.