Your wallet is public.
Your session is private.
Wallet addresses, positions, claims and transaction hashes are public blockchain records. The indexer stores a derived copy for charting and history.
What the application stores
Sign-in challenges expire after five minutes. Session identifiers are stored as keyed hashes and expire after one hour. HttpOnly cookies bind challenges and sessions to your browser. Terms acceptance records store a wallet address, document version and timestamp.
Infrastructure
Your wallet and RPC provider process blockchain requests. Hosting and database providers may process request metadata. The application does not ask for private keys or log raw authentication signatures.
Retention and requests
Expired authentication records are removed by the indexing service. Onchain records cannot be erased. Provider details, operator contact, retention schedules and privacy request procedures must be finalized before public production deployment.