Privacy policy
Effective date: 5 October 2026
This policy explains how Trenchbun handles information in its Chrome extension, cloud features and website at trenchbun.fun. Trenchbun is a floating companion for supported Solana trading terminals. Some features process information locally; enabled cloud features send limited information to our service and its providers.
Information we handle
- Preferences and alerts: your chosen bun, visibility, placement, feature settings, price and market-cap targets, priority-wallet settings and notification history.
- Terminal content: the supported page and coin you are viewing, tickers, contract addresses, public links, attached tweets, market information, and visible wallet or account activity needed by enabled features. Readable position and PNL information is used for reactions and holding-position alerts.
- Public account information: tracked-account names, usernames, follower counts, wallet addresses and public transactions. Public blockchain information can still relate to an identifiable person.
- Chat: messages you send to your bun, bounded recent conversation history and the selected coin. Visible position PNL is included in chat requests only when you select the option to include it. Information you voluntarily write in a message is also sent.
- Trenchbun authentication: invitation codes, installation session credentials, expiry information and request-usage counters. These are Trenchbun credentials, not your terminal or wallet login credentials.
- Local interaction signals: activity timing for sleep/wake behavior, dragging and tweet-hover interactions. Sleep detection uses activity events locally; it does not record the text of your keystrokes as a browsing log.
- Connection information: our hosting and API providers receive IP addresses and network metadata when requests reach them. We do not request GPS coordinates or use these requests to build a location profile.
Trenchbun does not request seed phrases, cryptocurrency private keys, wallet connections, transaction signatures or card details. It has no trading, transaction-signing or transfer feature. Browser site permissions are not a browser-enforced read-only security boundary.
How we use information
We use information to display the floating companion, react to readable positions, provide enabled coin and wallet observations, summarize tweets, answer chat messages, save preferences, authenticate cloud access and enforce usage limits. Supported-page information is used for these user-facing features, not to monitor unrelated browsing.
We do not sell user data, use it for advertising profiles, use it for creditworthiness or lending decisions, or transfer it for purposes unrelated to Trenchbun's stated functionality. Our use of user data is limited to the purposes allowed by the Chrome Web Store User Data Policy, including its Limited Use requirements. Necessary service processing, security and legal obligations are described below.
What stays local and what leaves your browser
Preferences, alert state and notification history are stored in extension storage. Chat history is held in Chrome session storage, with up to 20 entries locally; a bounded subset of recent messages is sent for a reply. Cloud session credentials are held separately in extension-origin IndexedDB.
When enabled, cloud features send the identifiers and context needed for the request: for example a tweet ID, an account username, a public wallet address or transaction identifier, or a chat message and its permitted context. Terminal authentication cookies and wallet signing credentials are not part of these requests. Public-data requests may be made directly from the extension or through our backend, depending on the feature.
Service providers and disclosures
- Render hosts the Trenchbun backend and its persistent data.
- OpenAI processes chat messages, supplied conversation context and public tweet text to generate replies and summaries. Requests are processed under OpenAI's API data policies; provider retention can differ from Trenchbun's local retention. See OpenAI API data controls.
- X supplies public posts and account information for requested tweet and account features.
- DEX Screener supplies public token, market and DEX information and token artwork.
- Solana's public mainnet RPC service receives public addresses and transaction identifiers for blockchain lookups.
- OpenAI Sites and its hosting infrastructure serve this website and receive connection metadata for website delivery.
We may disclose information when required by applicable law or when necessary to investigate abuse and protect the service. We do not publicly disclose your Trenchbun authentication credentials, private chat or private position information. Information already on a public blockchain or public post remains available independently of Trenchbun.
Storage and retention
- Local settings and alerts remain until cleared, replaced or removed with the extension. Session chat is temporary; browser session restoration may affect how long Chrome retains it.
- Cloud sessions currently expire after 30 days. Invitations have a configured expiry, normally 72 hours. The server stores hashed credentials and usage records. Expiry blocks access; it is not an immediate deletion guarantee. Expired-session cleanup happens during later service activity.
- Wallet-monitoring state is held in server memory and is eligible for eviction after approximately 30 minutes of inactivity; eviction occurs during later activity or when the process restarts.
- Chat text is processed for the request and is not intentionally written to Trenchbun's backend database. Usage counters are retained separately. This does not mean provider logs or security processing have zero retention.
- Public-post summaries, post status and public-account caches are bounded and refreshed or replaced as the service operates. Cache freshness intervals do not guarantee immediate physical deletion.
Hosting and API providers may retain operational logs, security records or backups under their own policies. We do not promise a single deletion period covering every provider or immediate erasure of backup copies.
Your controls and requests
You can disable features, revoke optional site or service permissions, disconnect cloud access, clear chat using the available control, or uninstall the extension. Disconnecting removes the local cloud credential; it does not by itself revoke or delete the server-side session. Clearing local chat does not erase requests already processed by a provider. Removing Trenchbun cannot erase public blockchain records.
Contact support@trenchbun.fun for privacy questions, access or deletion requests, or cloud-session revocation. Do not send seed phrases, private keys or session tokens. We may request non-secret information to verify a request and identify relevant records. Depending on your jurisdiction, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, or complain to your data-protection authority. Legal and security obligations may limit deletion.
Security and international processing
Cloud requests use HTTPS. Provider API credentials are kept on the backend rather than included in the extension. Access controls, bounded requests and hashed session records help protect service access. No software can guarantee absolute security.
Providers may process information in countries outside your own. The backend is configured in Render's Frankfurt region, but this does not mean all providers process exclusively in the European Union. Applicable provider contractual safeguards and data-protection requirements govern their processing.
Website storage
The website stores your theme and language preferences in your browser's local storage. The current website demo uses simulated coin information and does not connect to your wallet. Our site code does not include advertising or analytics tracking scripts. Hosting infrastructure still receives the connection information needed to deliver the site.
Changes and contact
We will update this page and its effective date when data practices change. Material changes will be disclosed through appropriate website, extension or store notices. Privacy contact: support@trenchbun.fun.