◆ LEGAL
Privacy Policy
LAST UPDATED - June 23, 2026
Draft for review. This document is a plain-language starting point, not legal advice. It must be reviewed by qualified counsel and have its placeholders completed before it is relied upon.
This Privacy Policy explains how rpc edge by Polaris Lab (polarislab.xyz) ("rpc edge", "we") collects, uses, and protects personal data when you use our websites and Services. We aim to collect as little personal data as possible.
1. Data controller
The controller responsible for your personal data is rpc edge by Polaris Lab (polarislab.xyz). Contact: privacy@rpcedge.com.
2. Data we collect
We collect only what we need to provide and secure the Services:
- Contact & account data: email address and, if you reach out, your Telegram handle and the contents of your messages.
- Service usage data: API keys, request metadata, IP address, and logs needed to operate, secure, rate-limit, and bill the Services.
- Cookieless website analytics: aggregate traffic and performance via Vercel Web Analytics and Speed Insights on every visit (no advertising cookies). Includes automated traffic that hits the site.
- Billing data: plan payments settled on Solana in USDC; we store payment references and amounts, not card numbers.
- Ambassador attribution (when you use a referral link): a first-party cookie (`rpcedge_ambassador`) may remember the referrer for up to 180 days so commissions can be calculated.
We do not knowingly collect special-category data, and we do not take custody of wallet keys or funds. On-chain data (such as public wallet addresses) is public by nature and not collected by us as personal data.
3. How we use data
- To provide, maintain, secure, and improve the Services.
- To authenticate you, enforce rate limits, prevent abuse, and meet legal obligations.
- To communicate with you about your account, support requests, and service changes.
- To bill for paid plans and prevent fraud.
4. Legal bases (GDPR)
Where the GDPR applies, we rely on: performance of a contract (to deliver the Services you request); our legitimate interests (to secure and improve the Services and prevent abuse); compliance with legal obligations; and your consent where required.
5. Sharing and processors
We do not sell your personal data. We share data only with service providers acting on our behalf (and, where required, under processor terms counsel has approved). Current engineering inventory of processors and tools:
- Vercel - website and dashboard hosting, CDN, Web Analytics, and Speed Insights.
- Supabase - authentication, account database, and control-plane state (including API key hashes, not raw secrets after mint).
- ClickHouse - gateway usage metrics used for quotas and the usage UI.
- Solana / USDC - on-chain settlement for plan payments (public transaction data).
- Resend - transactional email when configured (billing and operational mail).
- Google (Gmail) - interim contact mailbox until domain privacy mail is live.
- Telegram - only if you choose to contact us there.
We may disclose data where required by law or to protect rights and safety. Processor agreements and transfer tools remain pending counsel confirmation - see the internal privacy hardening checklist.
6. International transfers
Our providers may process data outside your country (including the United States). Where required, we intend to rely on appropriate safeguards such as Standard Contractual Clauses for transfers from the EEA/UK. The exact transfer package is pending counsel confirmation.
7. Retention
We keep personal data only as long as needed for the purposes above, legal obligations, disputes, and enforcement. Working engineering windows (pending counsel):
- Account and profile data - for the life of the account, then handled under a deletion request.
- API keys - until you revoke them; export shows key prefixes only.
- Invoices and confirmed payments - retained as needed for accounting and fraud prevention (may outlive an account deletion request).
- Usage rollups - about 35 days of dashboard usage history (usage-sync lookback); longer raw gateway logs may exist only in infrastructure systems.
- Hosting and security logs - provider defaults.
Signed-in users can download a machine-readable export of account-held data from Settings → Privacy on the dashboard.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, and to object to processing. Under the GDPR you may also lodge a complaint with a supervisory authority. Under the CCPA/CPRA, California residents have rights to know, delete, correct, and opt out of the sale or sharing of personal information - we do not sell or share personal information as those terms are defined.
To exercise any right: use Settings → Privacy in the dashboard (export / deletion request) or email privacy@rpcedge.com. We will respond within the timeframes required by applicable law.
9. Cookies and measurement
We use minimal cookies and similar technologies. Cookieless Vercel Web Analytics and Speed Insights run on every visit. See our Cookie Policy for details.
10. Security
We use technical and organizational measures appropriate to the risk to protect personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children
The Services are not directed to children under 18, and we do not knowingly collect their data.
12. Changes
We may update this Policy from time to time. We will update the date above and, for material changes, provide additional notice.
13. Contact
Privacy questions or requests: privacy@rpcedge.com.