What join.fun collects, why, how long it's kept, and how to have it deleted. join.fun is run by join.fun. Questions: hello@join.fun.
Last updated October 7, 2026
What we collect
- Wallet addresses: the wallet that launches a coin, the payout wallets you enter or connect, and the wallet a claim code is tied to. Wallet addresses and transactions are public on Solana.
- Coins: the name, ticker, image, description and links you enter (uploaded to pump.fun's public metadata storage), the platform and handle a coin's fees are for, and that account's permanent ID on the platform when we look it up.
- Accounts on X, Twitch, Kick, YouTube, TikTok, Instagram, Facebook, Snapchat, Reddit, Discord, GitHub, Farcaster and Telegram: handles and permanent account IDs. We read them from the platform's official API when a coin is launched, or from your login when you claim. For X we also read the public profile name and picture to fill in a launch, and the text of claim posts.
- Logins: Privy (privy.io) runs join.fun's logins and creates your join.fun wallet. We receive your Privy user ID and the accounts you linked (ID and username). Your join.fun wallet's keys are never available to join.fun. Privy's privacy policy covers what Privy stores.
- Claims: the coin, platform, account ID and handle, payout wallet, amount, transaction and time of each claim. Paid claims (handle, claim post text, amount) are shown publicly on join.fun.
- Claim codes and reviews: the code, platform, handle, coins, payout wallet, any link you send, a one-way hash of your IP address, and times; our team's decision and a log of each step, including which team member acted.
- Resource verification: exact game, music or organization IDs; the controlling account or team identity, linked payout wallet, ownership code, evidence link, reviewer decision and immutable launch recipient record. Ownership evidence and reviewer identities are restricted to authorized reviewers; the verified destination is shown on the coin.
- Security: one-way hashes of IP addresses for rate limits; two short-lived cookies (a sealed login state for 10 minutes and a signed connected-account cookie for 15 minutes); small flags in your browser's storage (for example, that you logged in before, or a claim waiting to finish).
- AI features: what you type in the Ask box is sent to xAI (Grok) to draft a launch. Image descriptions are sent to Higgsfield (Grok Imagine) to draw coin images, and kept with a one-way hash of your IP address to limit use.
- Our host (Vercel) keeps standard request logs, such as IP address and browser, for security and debugging.
We don't use advertising trackers, and we don't sell personal data.
Login tokens
When you log in with Kick, YouTube (Google), Facebook and Reddit, our server uses the platform's access token once to read your account ID and username, then revokes it where the platform allows. Tokens are never stored, logged or sent to your browser.
Logins with X, Twitch, TikTok, Instagram, Discord, GitHub and Farcaster go through Privy; join.fun doesn't receive those tokens.
We only ask for identity access: never permission to post, read messages, or act for you later.
Music catalog access uses app credentials rather than listener account access. Short-lived catalog tokens are stored encrypted in a shared cache. Catalog listings identify resources and artists; they do not prove that a person controls an artist or organization.
How we use it
To launch coins, hold and pay creator fees to the right account, check that a claimant controls the account, prevent double payouts and abuse, review claim codes, and show coins and claims on join.fun.
How long we keep it
- YouTube channel IDs and handles from YouTube API Services: refreshed or deleted within 30 days.
- Twitch and Kick account IDs found when a coin is launched: re-checked within 24 hours, otherwise deleted.
- Reddit account IDs: deleted when the Reddit account is deleted (checked daily).
- Login cookies: 10 to 15 minutes. Rate-limit records: about a day.
- Coin, claim and review records: kept while needed to hold and pay fees, and as a record of payouts.
- On-chain data (Solana transactions, coin metadata) is public and permanent; nobody can delete it.
YouTube
join.fun uses YouTube API Services. By connecting YouTube you also agree to the YouTube Terms of Service (https://www.youtube.com/t/terms), and Google's Privacy Policy (https://policies.google.com/privacy) covers Google's handling of your data. You can remove join.fun's access at any time at https://myaccount.google.com/permissions.
Deleting your data
Email hello@join.fun with your platform, handle and any wallet involved, to see what we hold or to have it deleted. We'll confirm the request comes from the account holder, then delete or anonymize the data we hold within 30 days. Records we need to account for payouts are anonymized rather than deleted, and on-chain data can't be changed.
You can also remove join.fun's access in your account settings on Google, Meta, Twitch, Kick, Reddit or any other platform you logged in with.
Children
join.fun isn't for anyone under 18.
Changes and contact
We'll change the date at the top when this policy changes. join.fun, hello@join.fun.
