Vasukii

Privacy Policy

Vasukii is built to store as little as possible. Here's exactly what we do collect, why, and how to get rid of it.

Last updated: August 5, 2026

01Overview

Vasukii ("Vasukii," "we," "us") is a wallet-based social and privacy platform on Polygon: an encrypted file shredder, disappearing chat, a wallet-verified social feed (Threads), end-to-end encrypted DMs, and the VAK token. There's no email, no password, and no traditional user account — your wallet address is your identity.

This policy explains what limited data our servers touch, what never leaves your device, and what gets published permanently to a public blockchain (which we don't control and can't delete).

Note: crypto staking, presales, airdrops, and similar token activity are restricted or banned in some jurisdictions. If you access Vasukii from such a jurisdiction, you do so at your own risk and are solely responsible for complying with local law — see our Terms of Service for details.

02Data we collect

We collect the minimum needed to run each feature. Nothing here includes your name, email, or any government ID — we don't ask for them.

FeatureWhat's stored
ShredderBy default: nothing but a SHA-256 hash and a destruction timestamp. In "timer" or "one-time" mode: encrypted ciphertext only, auto-deleted on expiry or first retrieval.
Threads (public posts)Post content, likes, reshares, replies, follows, and media you choose to post publicly — all tied to your wallet address.
StoriesClient-encrypted media envelopes and view counts, auto-expiring.
DMsEnd-to-end encrypted message ciphertext and your public identity key. We cannot read message contents.
Chat roomsMessages and room presence, tied to wallet address.
Games, streaks, badgesWallet address, scores, play timestamps, and badges earned.
Airdrop, jackpot, duels, pollsWallet address, amounts, transaction hashes, and outcomes needed to pay out VAK correctly.
NFT / profile picture mintingWallet address and mint/transaction records.
Wallet verificationA cryptographic signature proving control of a wallet — not a password, never reusable off-site.
NotificationsDelivered via the decentralized Push Protocol (push.org) to wallets that separately opt in on-chain; we don't hold a device push-token database.
Basic request logsIP address, path, method, user agent, and timestamp — kept briefly for abuse prevention (see "Security logging").

03Data we never collect

  • No email address, phone number, or real name
  • No password — authentication is a wallet signature, never stored
  • No plaintext file contents in shredder mode — encryption happens entirely in your browser before anything is sent
  • No decryption keys — for shredded files, DMs, and stories, keys live only in your browser (often only in a URL fragment, which browsers never transmit to a server) and are never sent to us
  • No advertising identifiers, and we don't sell or rent data to advertisers or data brokers

04Wallets, not accounts

Signing in means signing a message with your wallet (e.g. MetaMask, WalletConnect) — that signature proves control of the address without ever handing us a private key or a password. Your wallet address itself is pseudonymous, not anonymous: it's a public identifier, and anything you post under it (Threads posts, badges, on-chain transactions) is publicly associable with that address, on Vasukii and on the blockchain itself.

05Encryption & the shredder

The shredder, DMs, and stories all use client-side AES-256-GCM encryption (via the browser's Web Crypto API). In practice this means:

  • Shred mode: the server never receives the file at all — only a hash proving it existed.
  • Timer / one-time mode: the server stores ciphertext it cannot decrypt, deleted automatically on expiry or after the configured number of accesses.
  • DMs & stories: encrypted on your device before it ever reaches us; we store and relay ciphertext, and only the intended recipient's browser holds the key to read it.

Because we never hold the keys, we're also unable to recover this content for you if you lose access to your own key or wallet.

06On-chain activity

Some actions — VAK token transfers, tips, airdrop claims, NFT/PFP mints, jackpot and duel payouts — are Polygon blockchain transactions. Once submitted, these are recorded permanently and publicly on-chain, outside of Vasukii's control. We cannot edit, hide, or delete blockchain records; any request to erase that data needs to go through the network itself, which by design doesn't support that.

07Third parties & processors

We share the minimum data each of these needs to function:

  • Vercel — hosting, serverless functions, and (cookieless) Web Analytics / Speed Insights.
  • Postgres provider (e.g. Neon, Supabase, or Vercel Postgres, depending on deployment) — stores the data described above.
  • Polygon network — the public blockchain that settles VAK transfers, mints, and payouts.
  • Push Protocol (push.org) — decentralized notification delivery to wallets that opt in.

We don't share data with advertisers, data brokers, or any party outside what's needed to operate the features above.

08Retention & deletion

  • Shredded files: never stored to begin with.
  • Timer / one-time uploads: deleted automatically on expiry or first retrieval; a periodic sweep also purges anything left over.
  • Public content (Threads posts, badges, etc.): kept until you or we remove it, since it's part of a public social feed.
  • Raw request logs (IP, path, user agent): kept only as long as needed for abuse prevention, then purged on a rolling basis.
  • On-chain records: permanent, by the nature of a blockchain — see "On-chain activity" above.

09Security logging

Like most web services, we log basic request metadata (IP address, path, method, user agent, timestamp) to detect abuse, rate-limit bad actors, and keep the shredder honest. A subset of this — hash and destruction-mode only, never file content — is published on our public transparency log. Suspicious traffic (scanners, credential-stuffing attempts) may be logged in more detail and rate-limited or blocked; this is aggregate/security data, not used for profiling or marketing.

10Analytics & cookies

Vasukii doesn't use tracking cookies or third-party ad trackers. We use Vercel's cookieless Web Analytics and Speed Insights to understand aggregate traffic and performance — no cross-site tracking, no individual profiles built from it.

11Your rights & choices

Depending on where you live, you may have rights to access, correct, or delete personal data we hold, or to object to certain processing. In practice, for most of Vasukii that means:

  • Stop using a wallet address — there's no account to "close" beyond that.
  • Contact us (below) to request deletion of off-chain data tied to your wallet address, where technically possible.
  • Understand that on-chain data (transactions, mints, transfers) cannot be deleted by us or by you.
  • Opt out of notifications at any time through the Push Protocol channel itself.

12Children's privacy

Vasukii is not directed at, and is not intended for use by, anyone under 18. We don't knowingly collect data from children. If you believe a minor has used Vasukii, contact us and we'll take appropriate steps to remove any associated off-chain data.

13Changes to this policy

We'll update the "last updated" date above when this policy changes, and post material changes here. Continued use of Vasukii after an update means you accept the revised policy.

14Contact

Questions about this policy or a data request: privacy@vasukii.xyz, or reach us at @Vasukiiofficial.