MASTRtrade Privacy

What MASTRtrade knows about you: almost nothing.

MASTRtrade is a Solana trading terminal by MASTR Labs. It runs at mastrtrade.com, as an installed web app and as an Android package in the Solana dApp Store. This page explains what data is processed and where. The controller is the operator named in the imprint. Last updated 25 September 2026.

No keys, ever

MASTRtrade never asks for, receives or stores a seed phrase, a private key or a recovery phrase. When you connect a wallet, MASTRtrade only reads the public address you approve, to display balances and positions and to prepare trades for it. Every trade is signed in your wallet, never inside MASTRtrade.

Optional account: your wallet, nothing else

You can use everything without an account. If you choose sign in with your wallet, your wallet signs a short text (the site name, your address and a one time code). It is not a transaction and costs nothing. The server checks the signature and opens a session for 30 days through a cookie that only this site can read. There is no email, no password and no registration form.

While signed in, your watchlist, watched wallets, portfolio addresses, alert rules, armed levels, filter presets, chart drawings, settings, push subscriptions, a linked Telegram chat and the "since your last visit" markers are also stored on the mastrtrade.com server under your public key, so they follow you to other devices. The server stores exactly these lists, your public key, a hashed session token and the time of your first and last sign in. It does not store IP addresses or balances with the account, and nothing you did not put in a list, apart from the trade log described below. Under Settings → Account you can see every stored list, sync, sign out or use Delete account, which removes the account and every list from the server immediately.

Data that stays on your device

Without an account, your watchlist, watched wallets, portfolio addresses, alert rules, filter presets, chart drawings and settings live only in your browser or app storage on your own device and are never uploaded. With an account they are additionally synced as described above. You can export, import or delete the local copy at any time under Settings. The version of the terms you accepted before your first trade is also kept on your device. When you connect Phantom or Solflare on a phone, a key pair that only opens the wallet app's answers (it cannot sign or move anything) and the wallet's session code are kept on your device too; disconnect deletes them. The server never receives them.

Trades

When you send a trade through MASTRtrade, the server keeps a log entry: the time, the tokens and amounts, the transaction signature, its status, the terms version you accepted and a referral code if your link carried one. If you are signed in, your public key is added. Solana transactions are public on chain anyway. The log serves security (proof of what was shown and signed), abuse protection and fee accounting. Delete account removes the entries tied to your public key.

Data that reaches the server

The mastrtrade.com server answers the app's data requests. To do that it receives the request itself (for example a token mint, a wallet address you look up, or a market feed name) together with the technical data every web server sees: your IP address, the user agent and the time. The server keeps short lived caches of market data, a cache of token images it fetched for you (so gateways do not see your IP address), token snapshots and a register of token identities (website, X handle, image) that is shared by all visitors and contains nothing personal, plus standard access logs for operation, abuse protection and error analysis. Logs are not used for profiling and are not sold or shared.

Third party data providers

The server fetches public market and chain data from Jupiter, DexScreener, GeckoTerminal, DefiLlama, Solana RPC providers (Helius when configured) and the PumpPortal public stream. Trades are built through Jupiter and, with MEV protect on, sent through the Jito block engine. These requests are made by the server or, for the live launch stream, by your browser. The addresses and mints you look up may therefore be part of requests to these providers. Their own policies apply to them.

No tracking, no ads

MASTRtrade has no analytics scripts, no advertising, no tracking across days or sites and no third party cookies. The only fee is the platform fee shown in the trade preview.

To know how many people use it, the server counts visitors as plain numbers. While the terminal is open and visible it knocks once a minute (the same request that runs the background work), and the server marks that knock under a code made from the IP address and the browser name with a random key of that day. The key is deleted when the day is over and only the number of visitors per day remains, so no visit can be traced back to an address or linked to another day. No IP address and no cookie is stored for this, and the numbers are seen only by the operator.

Notifications

Alerts run inside your browser or app and, when you are signed in, also on the server, so they can reach you while the app is closed. Push messages only appear if you grant the permission; they are delivered through the push service of your browser vendor (for example Google, Apple or Mozilla) and can be revoked in your browser or system settings. Telegram messages only go to a chat you linked yourself.

The MASTRscan bot on Telegram reads the messages Telegram hands it (in a group: commands such as /scan, and every message when the group made it an admin; in a private chat: every message) only to find a Solana token address or a command. It answers with the public scan of that token. The text of the messages, the names and the chat are not stored; the server keeps only short technical markers (the message number against double delivery, a hash of the chat and the token for 10 minutes so the same token is not answered twice, and a daily count of answered scans).

Android app

The Solana dApp Store build is a native package that opens mastrtrade.com inside the app. It needs the internet permission and nothing else. Wallet requests are handed to your installed wallet app through Mobile Wallet Adapter: connecting, signing in and, where execution is enabled, signing a trade all happen in the wallet app. MASTRtrade never sees the wallet's keys.

Your rights and contact

You can delete all local data under Settings and, when signed in, your account, every server side list and your trade log entries with Delete account. Depending on where you live, data protection law (for example the Swiss Federal Act on Data Protection, the EU General Data Protection Regulation or the privacy laws of your US state) lets you ask for access to, correction or deletion of your data and complain to your data protection authority (for example the FDPIC in Switzerland). For requests and questions use the contact in the imprint, or reach MASTR Labs through mastrlabs.com or @MASTRxyz.