Quake Name — Privacy Policy
This policy explains what Quake Name collects when you use the websites and the The Quake Registry application, why we collect it, who else sees it, and what you can require us to do about it. It is written to be read rather than to be survived.
The short version
The service is wallet-first: the identifier we hold for you is a public Solana address, which you already publish to the world every time you transact. We do not ask for your name, your address, or a government ID. We do not sell or share personal information for advertising, and we run no advertising or cross-site tracking.
We do count visits, using Google Analytics with its advertising features switched off. It starts on, you can switch it off at any time, and it is never joined to your wallet or anything you own. The cookie notice covers exactly how.
Everything else on this page is detail about that.
What we collect
Information you give us directly:
- your public Solana wallet address, and a signature proving you control it
- the name and any dedication you submit with a bid or claim — both are published on the public registry, permanently, by design
- an optional display handle, shown to other users in place of your address
- an optional contact email address, if you give us one for claim-anniversary notices
- the regions you choose to watch
- the version of the terms you accepted and the time you accepted them
What we collect automatically
Our servers log ordinary request data — IP address, timestamp, path, user agent, and a country code supplied by our content-delivery layer. We use that for security, abuse prevention, and to enforce the sanctions and jurisdiction rules in the terms. Logs are retained for a limited period and are not used to build a profile of you.
We also read the public Solana blockchain. Everything about your transactions — amounts, addresses, timing — is already public there, and is not private information we hold on your behalf.
Google Analytics measures which pages are visited, roughly where from (country or region, derived from an IP address Google does not give us and does not store), and which browser and device type. It sets a random identifier so a returning browser is not counted twice. Google processes this as our service provider under its own terms. Its advertising features are switched off, so this is not joined to an advertising profile, and we never send it your wallet address, your email, or anything you have submitted. It runs only while you have analytics switched on — see the cookie notice for the switch.
Sign-in providers and embedded wallets
You can connect an existing wallet, or sign in with email or a social account (Google, X, or Apple) and have a wallet created for you. Those sign-in methods are operated by Reown (WalletConnect) and the identity provider you pick, not by us.
If you use them, that provider handles your email address, your social profile identifier, and the key material for the embedded wallet, under their own privacy policy. We receive the resulting public wallet address, and the email address only if you also give it to us. We cannot access the keys.
Their sign-in component stores its own state in your browser under keys beginning with "@appkit" — including a list of recently used email addresses, a social username, and cached identity and balance information. That storage is theirs, it stays on your device, and clearing your browser storage clears it.
That component also contacts Reown's servers when the page loads, before you have done anything: it fetches its own configuration from api.web3modal.org and its fonts from fonts.reown.com. Those requests carry your IP address and the address of the page you are on, as any web request does. We have turned off the usage analytics that component sends by default, so no behavioural telemetry is sent, but we cannot make it load without contacting its own servers at all.
What we store in your browser
The application itself sets seven keys, all strictly necessary to make it work, all first-party, and none used for tracking or advertising:
- quake:tenant — the resolved site configuration, so a reload does not refetch it (session storage)
- quake:jwt, quake:jwt:pubkey, quake:jwt:role — your short-lived sign-in session, cleared when you close the tab (session storage)
- quake:ack:<site>:<address> — the version of the disclosures you accepted, so we do not ask again until they change (local storage)
- quake:consent, quake:consent:at — whether you have switched analytics off and when you decided, so we honour it and stop asking (local storage)
Cookies, separately
The keys above are browser storage, not cookies, and are never sent to a server on their own. The only cookies on the service are the two Google Analytics sets — _ga and _ga_<stream> — which exist while analytics is switched on and are deleted when you switch it off. The cookie notice describes them line by line.
Why we use it
We use the information above to operate the registry and the market: to authenticate you, to build the transactions you sign, to publish registry entries, to moderate names, to screen against sanctions lists and jurisdiction rules, to send you the notices you asked for, to diagnose faults, and to keep records the law requires us to keep. We do not use it to build advertising profiles and we do not do automated decision-making with legal effect, other than the moderation and sanctions checks described in the terms.
Legal bases (where the GDPR or UK GDPR applies)
Performance of a contract, for everything needed to place a bid, settle it, and deliver a collectible. Legitimate interests, for security, abuse prevention, and service diagnostics. Legal obligation, for sanctions screening and record-keeping. Consent, for optional email notices, which you can withdraw at any time without affecting anything else.
Names and dedications are public and permanent
This deserves its own section. A name you attach to a registry entry is published, indexed by search engines, written to a public blockchain, and intended to outlive the service. It cannot be deleted on request, because the point of a registry is that its entries are stable. Do not put personal information in a name or a dedication that you would not want permanently public.
Who else sees your information
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose it only to:
- infrastructure providers who host and deliver the service (Amazon Web Services), under contract and only to run it
- Google, as our analytics provider, which receives the page-level measurements described above while you have analytics switched on, and nothing that identifies you to us
- the wallet and sign-in providers you choose to use
- a language-model provider used solely to moderate submitted names and dedications, which receives the submitted text and nothing identifying you
- anyone, for information you publish yourself — names, dedications, handles, and on-chain activity
- law enforcement or a regulator, where we are legally required, and no further than required
- a successor entity, if the service is sold or merged, subject to this policy
Where your information is processed
Our infrastructure runs in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, using the service involves transferring your information to the United States. Where a transfer mechanism is required, we rely on the European Commission's standard contractual clauses with our processors.
How long we keep it
Registry entries, names, and settled transactions are permanent — that is the product. Your account record and preferences are kept while you use the service and for a reasonable period afterwards. Request and security logs are kept for a limited period. Records we must keep for sanctions compliance are kept for as long as the law requires.
Your rights
Depending on where you live, you can require us to do the following. We will not discriminate against you for exercising any of them, and we will not charge you for a first request in any twelve-month period.
- Know and access — what we hold about you, where we got it, why we have it, and who we disclosed it to
- Correct — fix information about you that is wrong
- Delete — erase what we hold, except registry entries and on-chain records, which are permanent and which we cannot delete for anyone including ourselves, and records we must keep by law
- Portability — a copy of what you gave us, in a machine-readable form
- Restrict or object — limit how we process your information, or object to processing based on legitimate interests
- Withdraw consent — for anything you opted into, at any time
- Opt out of sale or sharing — we sell nothing and share nothing for cross-context behavioural advertising, so there is nothing to opt out of under that heading; the analytics you can switch off is covered separately, in the cookie notice, and we honour a Global Privacy Control signal from your browser
- Limit use of sensitive information — we do not collect any
- Appeal — if we refuse a request, ask us to reconsider, and complain to your data protection authority or state attorney general
How to make a request
Write to privacy@quake.name from an address we hold for you, or from any address while signing a message with the wallet the request concerns — a signature is how we verify that a wallet is yours without asking you for identity documents. We respond within 45 days, extendable once by a further 45 days where a request is complex, or within one month where the GDPR applies. An authorized agent may act for you with written permission.
Children
The service is not for anyone under 18, we do not knowingly collect information from anyone under 18, and we delete it if we discover we have. Tell us at privacy@quake.name if you believe a child has used the service.
Security
We use encryption in transit, managed secret storage for the small number of keys the service holds, least-privilege access, and multi-signature governance for anything that can change how funds are routed. None of that makes any system perfectly secure. The single most important security fact remains that we never hold your keys, so a breach of our systems cannot move your assets.
Changes and contact
We publish a new version identifier when this policy changes materially, and ask you to accept it before your next transaction. Questions, requests and complaints: privacy@quake.name.