Plasma Trade Privacy Policy
Plasma Trade is a browser extension that provides token intelligence, paper trading, wallet tools, and user-authorized Solana transaction execution on explicitly supported trading-terminal websites.
Data processed
Plasma Trade may process token addresses, symbols, prices, liquidity, volume, market-cap information, and other public token context visible on a supported page. Public token identifiers may be sent to Jupiter, GeckoTerminal, DEX Screener, Pump.fun, InsightX, Bubblemaps, and public Solana RPC services to provide market data, token context, quotes, account information, and user-requested transactions.
When a user authorizes an on-chain trade, the selected public wallet address, token mints, amount, slippage settings, and signed prepared transaction are sent to the transaction and Solana infrastructure providers required to submit that trade. Decrypted private keys and wallet recovery secrets never leave Plasma's background wallet vault.
If a user enables Telegram tracking, messages from only the groups or channels the user allowlists are retrieved from the Telegram Bot API and reduced locally to validated Solana token-address calls. API credentials are kept only in active extension memory and are not saved.
If a user separately enrolls in always-on automation, Plasma sends the public owner wallet, the newly created public Automation Wallet address, public wallets or Telegram chats selected for monitoring, strategy limits, detected token addresses, and execution status to Plasma's automation service. The hardened executor controls only the separately funded Automation Wallet under server-enforced spending and fee policies. The extension never uploads an existing wallet secret for automation.
Referral features may process public wallet addresses, wallet-signed attribution or claim messages, public transaction signatures, confirmed slots, public fee-token mints and amounts, referral allocations, and payout status. Plasma's referral service independently checks qualifying public on-chain fee receipts before crediting rewards.
Local storage and wallet security
Optional Plasma accounts use a wallet-signed login challenge to verify a public wallet address. Plasma stores that public address, an account identifier, signup time, sharing preference, and hashed session credentials. Account login does not import private keys or authorize trading. Users can continue as guests without signing up.
Basic usage sharing is optional and off by default. When enabled, Plasma reports that its visible panel is open and counts completed paper buys and sells. Reports contain an account identifier or random guest-installation identifier, event type, deduplication identifier, and time. They do not contain browsing URLs, token selections, trade amounts, private keys, or keystrokes. The private operator dashboard shows aggregate account, guest, paper-trading, and verified-trading metrics; installations and wallet-linked accounts are not claimed to be unique people.
The extension stores preferences, presets, watchlists, paper-trading records, positions, wallet profiles, and overlay layout in Chrome extension storage. Device-wallet secrets are encrypted with AES-GCM before storage. The encryption material and encrypted wallet records stay within the Chrome extension profile. The supported webpage cannot access wallet secrets.
Clipboard text is read only after the user invokes the Paste feature. Plasma does not monitor the clipboard in the background. The extension does not collect browsing history, cookies, terminal authentication tokens, advertising identifiers, or keystroke data.
Data sharing
Plasma Trade does not sell personal data and contains no advertising analytics. Data is shared only with the infrastructure providers required to deliver a user-requested feature, such as public market-data providers, Solana RPC providers, Jupiter, Telegram when enabled, and Plasma's referral service when referral features are used.
User control and retention
Optional activity is retained for up to 30 days and removed when sharing is turned off successfully. Turning sharing off stops new reports immediately; if offline, use Remove previously shared activity after reconnecting to remove server data. Login challenges expire after 5 minutes; server sessions expire after 30 days, while the extension signs out on browser restart. Short-lived keyed, hashed IP rate-limit identifiers are used for abuse prevention and removed after expiry. Delete account removes the account and its activity, not wallets or independently required referral and payout accounting. Guest identifiers expire after 30 days of inactivity.
Users can disable the overlay, remove wallets, reset extension data, and uninstall Plasma Trade. Uninstalling causes Chrome to remove extension-local storage subject to Chrome's own profile backup behavior. Verified referral and payout records may be retained to provide accounting, fraud prevention, replay protection, reconciliation, and claim history.
Always-on automation tasks and replay-protection records remain on the service until the user removes the tasks or requests account deletion. Pausing stops new automated execution. The withdraw-all control pauses the Automation Wallet and asks the policy executor to return its supported assets to the user-selected owner wallet.
Children and changes
Plasma Trade is not directed to children. Material changes to this policy will be reflected by updating this page and its effective date.
Contact
Questions about this policy can be sent to johnjohn77216@gmail.com.