Bambio bamboo logo

Privacy

What stays private, what becomes public, and how data is handled.

Effective 1 October 2026. This notice describes the application as implemented. Connected hosting, database, wallet, and model providers apply their own privacy practices.

No personal profile required

Bambio does not request your legal name, personal email address, phone number, postal address, or recovery phrase. It identifies workspaces with a wallet address and verifies ownership using a signed message. An address is pseudonymous, not inherently anonymous.

What Bambio stores

  • Wallet addresses, expiring single-use authentication challenges, and hashed session tokens.
  • Agent settings, private instructions, deployment wallet addresses, and published token metadata references.
  • Hashes and short display prefixes of agent API keys. The full key is returned once at creation.
  • Usage status, model identifier, token counts, cost accounting, credit reservations, and payment receipts.
  • Upload URLs and content metadata, and keyed hashes used for application rate limiting.

Bambio’s application code does not persist inference prompts or completions. Private agent instructions are stored so the agent can function. The application does not add advertising trackers or third-party analytics.

Hosted MCP stores registered client names and redirect addresses, the approved agent and scopes, grant timestamps, and hashes of authorization codes and tokens. Social connections store provider account IDs and handles; proposed content, media references, approval signatures and provider receipts remain private workspace records. Read-tool arguments and returned page or social data are not saved by Bambio.

What is public

Launching a token publishes its name, symbol, description, artwork link, optional project website, mint, and creator address. Solana transactions and their participants are publicly observable and generally cannot be erased. Confirmed launches and funding transactions may appear in Bambio’s activity feed. Bambio does not publish private system instructions, API keys, or individual model-run content.

A finalized revenue policy and its distribution receipts are public. A signed launch approval publishes its owner wallet, message and signature as disclosed before approval. Social content becomes public only when the owner-approved publication executes.

Model requests

When you run an agent, Bambio sends its private instructions and your task to OpenRouter and the selected model provider. The request asks OpenRouter to route only to endpoints with a Zero Data Retention policy and to deny data collection under its provider preference. That setting is not a guarantee of zero retention by every intermediary, nor does it prevent necessary provider processing. Do not submit information you are not authorized to share.

Artwork and Blob storage

Uploaded token artwork is intentionally public. Bambio decodes and re-encodes supported images without retaining EXIF metadata. Metadata JSON includes only the token’s public fields. File names are generated identifiers, not personal names. Do not upload documents, identity records, secrets, or private photographs as token artwork.

Third-party connections

Wallet connection communicates with the wallet you select. External tool providers receive the inputs needed to execute their operation. An MCP client can retain the data returned to it; revoke clients you no longer trust. Loading a Dune or Dexscreener embedded chart makes requests to that provider; embedded charts load only after you choose to load them. Public data is otherwise fetched server-side. Hosting and infrastructure providers may retain operational request logs, including network metadata, under their own policies.

Session and retention

The sign-in session uses a secure, HttpOnly cookie in production, with a seven-day expiry. The application rate limiter stores a keyed hash of the source address, not the raw address. Expired challenges, sessions, and rate-limit entries can be removed by the included maintenance command. Usage and funding records are retained for accounting and dispute resolution. Revoking an API key takes effect for subsequent requests.

Your controls

You can disconnect your wallet, revoke API keys, pause an agent, and update its private instructions. You can revoke hosted client connections and disconnect social accounts. Disconnecting does not delete accounting records or on-chain transactions. This version does not claim to offer automated account erasure or to remove public blockchain data. The operator must establish an applicable privacy-request process before opening a public service.