Vasukii is built to store as little as possible. Here's exactly what we do collect, why, and how to get rid of it.
Last updated: August 5, 2026
Vasukii ("Vasukii," "we," "us") is a wallet-based social and privacy platform on Polygon: an encrypted file shredder, disappearing chat, a wallet-verified social feed (Threads), end-to-end encrypted DMs, and the VAK token. There's no email, no password, and no traditional user account — your wallet address is your identity.
This policy explains what limited data our servers touch, what never leaves your device, and what gets published permanently to a public blockchain (which we don't control and can't delete).
Note: crypto staking, presales, airdrops, and similar token activity are restricted or banned in some jurisdictions. If you access Vasukii from such a jurisdiction, you do so at your own risk and are solely responsible for complying with local law — see our Terms of Service for details.
We collect the minimum needed to run each feature. Nothing here includes your name, email, or any government ID — we don't ask for them.
| Feature | What's stored |
|---|---|
| Shredder | By default: nothing but a SHA-256 hash and a destruction timestamp. In "timer" or "one-time" mode: encrypted ciphertext only, auto-deleted on expiry or first retrieval. |
| Threads (public posts) | Post content, likes, reshares, replies, follows, and media you choose to post publicly — all tied to your wallet address. |
| Stories | Client-encrypted media envelopes and view counts, auto-expiring. |
| DMs | End-to-end encrypted message ciphertext and your public identity key. We cannot read message contents. |
| Chat rooms | Messages and room presence, tied to wallet address. |
| Games, streaks, badges | Wallet address, scores, play timestamps, and badges earned. |
| Airdrop, jackpot, duels, polls | Wallet address, amounts, transaction hashes, and outcomes needed to pay out VAK correctly. |
| NFT / profile picture minting | Wallet address and mint/transaction records. |
| Wallet verification | A cryptographic signature proving control of a wallet — not a password, never reusable off-site. |
| Notifications | Delivered via the decentralized Push Protocol (push.org) to wallets that separately opt in on-chain; we don't hold a device push-token database. |
| Basic request logs | IP address, path, method, user agent, and timestamp — kept briefly for abuse prevention (see "Security logging"). |
Signing in means signing a message with your wallet (e.g. MetaMask, WalletConnect) — that signature proves control of the address without ever handing us a private key or a password. Your wallet address itself is pseudonymous, not anonymous: it's a public identifier, and anything you post under it (Threads posts, badges, on-chain transactions) is publicly associable with that address, on Vasukii and on the blockchain itself.
The shredder, DMs, and stories all use client-side AES-256-GCM encryption (via the browser's Web Crypto API). In practice this means:
Because we never hold the keys, we're also unable to recover this content for you if you lose access to your own key or wallet.
Some actions — VAK token transfers, tips, airdrop claims, NFT/PFP mints, jackpot and duel payouts — are Polygon blockchain transactions. Once submitted, these are recorded permanently and publicly on-chain, outside of Vasukii's control. We cannot edit, hide, or delete blockchain records; any request to erase that data needs to go through the network itself, which by design doesn't support that.
We share the minimum data each of these needs to function:
We don't share data with advertisers, data brokers, or any party outside what's needed to operate the features above.
Like most web services, we log basic request metadata (IP address, path, method, user agent, timestamp) to detect abuse, rate-limit bad actors, and keep the shredder honest. A subset of this — hash and destruction-mode only, never file content — is published on our public transparency log. Suspicious traffic (scanners, credential-stuffing attempts) may be logged in more detail and rate-limited or blocked; this is aggregate/security data, not used for profiling or marketing.
Vasukii doesn't use tracking cookies or third-party ad trackers. We use Vercel's cookieless Web Analytics and Speed Insights to understand aggregate traffic and performance — no cross-site tracking, no individual profiles built from it.
Depending on where you live, you may have rights to access, correct, or delete personal data we hold, or to object to certain processing. In practice, for most of Vasukii that means:
Vasukii is not directed at, and is not intended for use by, anyone under 18. We don't knowingly collect data from children. If you believe a minor has used Vasukii, contact us and we'll take appropriate steps to remove any associated off-chain data.
We'll update the "last updated" date above when this policy changes, and post material changes here. Continued use of Vasukii after an update means you accept the revised policy.
Questions about this policy or a data request: privacy@vasukii.xyz, or reach us at @Vasukiiofficial.