What we keep, and why.

We keep what we need to run the challenge and nothing more. No ads, no trackers, no analytics.

The short version

MonFunded never sees your keys and never holds your coins. To run the challenge, our server stores your wallet address, your simulated trades and payouts, and the IP addresses you use, so we can check fair play. There are no trackers, no advertising and no analytics on this site or in the app.

What we store

  • Your wallet address, when you sign in by signing a message with your wallet.
  • A session cookie (monfunded_session) that keeps you signed in for up to 7 days. It is httpOnly, only sent to MonFunded, and removed when you sign out.
  • Your challenge record: the accounts you buy, your simulated orders and positions, your withdrawals and payouts, in an append-only log. Payouts are proven against this log, so it can't be edited.
  • IP addresses of each sign-in, entry and order, linked to your address. We use them only to spot shared accounts and copy trading.
  • Notes our team adds to an account when reviewing fair play.

Your theme, language and sound settings stay in your browser's local storage and never reach us.

What we don't store

No name, email address, phone number or ID document. No private keys, passkeys or recovery phrases: those stay on your device. No card details: MonFunded takes payments in coins only. No tracking pixels or third-party cookies.

Onchain means public

Fees and payouts are Monad transactions. Anyone can see them on a block explorer, and our payouts page lists them with shortened addresses and each account's return. Nobody can remove a transaction from a public blockchain, including us.

Services we call

Some features talk to other services. Each one sees only what it needs:

  • Monad RPC to read the chain and send your transactions.
  • Perpl for challenge prices, and for perps when you trade them with your own AUSD.
  • Kuru for spot swaps and to sell a fee paid in MON.
  • Mera, the passkey library, which runs on your device.
  • Privy, only if you sign in with email or Google. Privy then stores that email under its own privacy policy.
  • Dynamic, only on the fund page, if you connect an outside wallet.
  • Aurora Intents, only if you ask for a deposit address to pay in from another chain.
  • Nansen, which receives the payout address to screen it. No other data.
  • Envio, which indexes the contract's public events.
  • Cloudflare, which carries traffic to our server over HTTPS.
  • Telegram, only if you write to us there.

How long we keep it

The challenge log and the IP records linked to it are kept for as long as MonFunded runs, because payouts and fair-play decisions depend on them. Sessions expire after 7 days.

Your choices

You can stop using MonFunded at any time; your wallet stays yours. To get a copy of the records linked to your address, or to ask a question about your data, write to us on Telegram.

Changes

If this policy changes, the date at the top changes with it. Material changes are also announced on Telegram.