TRUST / DATA BOUNDARY
Privacy
The machine should reveal its state, not collect yours. This notice describes the data boundaries of the public preview.
LAST UPDATED / AUGUST 20, 2026
01
Data the preview handles
When you connect a wallet, the site can read the public wallet address and public on-chain information needed to render the requested experience. A public blockchain is not private; addresses and transactions can be observed and analyzed by others.
The site may also receive ordinary technical request data such as IP address, user agent, route, timestamp, and error information through its hosting provider.
02
What stays on your device
Wallet signing remains in your wallet extension or application. NULLFRAME does not request or store seed phrases, private keys, recovery phrases, passwords, or two-factor authentication codes.
Preview preferences, ordered fragment progress, a randomly generated browser capability, the first inbound Carrier code, your selected Carrier mutation, your assembled Carrier code, scoped local-ritual completion booleans, and a selected cosmetic visual scar may be stored locally in your browser. Local ritual inputs and scenes are computed locally and are not sent to the Signal Chain. Clearing site data removes those local values and permanently loses that browser’s ability to owner-prove an existing Carrier; there is no recovery key.
03
Carrier and continuation records
The optional Transmissible Worlds system records browser-reported fragments, Carrier genomes, bounded mutations, lineages, and coarse-day continuation state so the shared world can respond. Its database stores the active season, a one-way SHA-256 digest of the random browser identifier, a seven-bit fragment mask, all seven room identifiers in observed order without timing, Carrier codes, seven bounded alleles, one mutation locus and allele, root and parent-child relationships, relay-frame indices, and UTC epoch days for creation, return, maturity, and archival.
A public Carrier lookup exposes the requested Carrier code, genome, bounded mutation, coarse creation and maturity state, parent code, whether neutral legacy migration material was used, whether the bounded lineage view is truncated, and at most six child Carrier records. Anyone who has a Carrier URL can inspect that pseudonymous lineage; no owner digest is returned.
The optional code-bound identity stores immutable earned-only ritual receipts: catalog and ritual identifiers, Carrier code, evidence class and source, a policy hash, a bounded printable witness summary, a coarse qualification day, retention-review dates, and a scoped HMAC derived transiently from the browser capability. The raw capability and failed or unearned ritual checks are not stored. Resonance is recomputed from those receipts; it is cosmetic lore, not a unique-person claim, competitive rank, token right, allocation, or future reward.
The Signal Chain database does not store wallet addresses, raw browser capabilities, request IP addresses, user agents, cookies, names, email addresses, free-form text, pointer trails, precise interaction timing, or token balances. Cloudflare may use a request address transiently for coarse rate limiting without writing it to D1. A recorded Echo means the server accepted one deduplicated browser-reported edge; a Mature Echo additionally records time-separated return and propagation. Neither is proof of a unique person or wallet.
Public world responses expose aggregate mature counts, branch diversity, bounded mutation variants, deduplicated hidden-film frame indices, and explicitly archived seasons. They do not expose browser digests or the Carrier codes behind Ghostline. Carrier and continuation records are retained for the life of the public service and are frozen when a season is explicitly archived. The current preview has no per-record deletion path because removing a causal node would corrupt descendant lineage; any future aggregation or erasure process requires a separately tested migration and updated notice. Clearing browser storage does not identify or delete the already pseudonymized server record.
04
Weekly arcade records
The optional arcade archive stores the weekly frame number, game identifier, three-character initials, best score, submission time, verification state, and a one-way SHA-256 digest derived from a random first-party arcade cookie. It does not store the cookie value, wallet address, gameplay inputs, or IP address in the arcade tables. Public score responses expose initials, scores, game identifiers, and rank.
Browser-submitted scores are marked unverified and are not mint entitlements. A future on-chain artifact requires a separate, explicit wallet verification and published mint policy; no score alone authorizes a transaction.
05
Service providers
Cloudflare provides hosting, security, and operational logs. Solana RPC providers return blockchain data. Wallets, explorers, and external venues such as pump.fun process data under their own privacy notices when you use them.
Following an external link leaves the NULLFRAME site. Review the destination and its policies before continuing.
06
Analytics and sensitive data
Product analytics are not enabled unless a production analytics identifier is configured. If enabled, telemetry should be limited to route performance and allowlisted interaction outcomes; wallet addresses, balances, signatures, free-form prediction text, private RPC URLs, and secrets must not be included.
Do not enter personal, confidential, or regulated information into a prediction or any other public blockchain field.