EchoKin Labs

Privacy · Chrome extension · Web DApp

EchoKin Privacy Policy

Effective: August 9, 2026Last updated: August 9, 2026

This policy explains how EchoKin Labs handles information in the EchoKin Chrome extension, echokin.fun, the EchoKin Web DApp, and the supporting account services.

No data sale

We do not sell user data or provide it to data brokers.

No advertising

We do not use user data for personalized, retargeted, or interest-based ads.

Local by default

Optional token history stays on your device and is off by default.

No secret keys

Your wallet private key and seed phrase never enter EchoKin.

Scope and single purpose

EchoKin's single purpose is to provide a manageable onchain companion on supported X and GMGN pages, together with the EchoKin account, backpack, chest, and optional onchain features needed to use EchoKin collectibles.

We collect, use, or transmit only information reasonably necessary to provide, maintain, secure, and measure the reliability of that purpose. We do not use EchoKin data for unrelated advertising, profiling, credit decisions, or generalized market research.

Information by category

“Handled” includes information processed only on your device as well as information transmitted to EchoKin services.

Personally identifiable information

What is handled
A public Solana wallet address, an internal EchoKin account identifier, the EchoKin name you choose or receive, and your language preference. EchoKin does not ask for your legal name, postal address, telephone number, or email address.
Why
To create one EchoKin account for one verified wallet, show your backpack and equipped companion, preserve your preferences, and provide account support.
Local / server processing
The extension keeps the active session and a wardrobe cache in its private IndexedDB storage. The website keeps only your language preference in local browser storage. EchoKin servers store the account, verified wallet binding, pet name, backpack, and equipped loadout.
Retention and deletion
Local session data is removed when you sign out and extension data is removed when you clear it or uninstall the extension. Server account records remain while the account is active and are deleted or de-identified after a verified deletion request, except where limited records are required for security, transaction integrity, or law.
Sharing
Only with infrastructure providers acting for EchoKin when necessary to operate and secure the service. A wallet address and onchain ownership are public by design once used on Solana.
Your control
You may use the signed-out companion without an EchoKin account, sign out at any time, clear extension data in Chrome, or request account access, correction, or deletion through our official X account.

Financial and payment information

What is handled
Public wallet balances and asset ownership, configured payment-token mint and amount, payment and Mint intents, recipient and project receiving addresses, signed transaction bytes needed for submission, transaction signatures, NFT asset addresses, and finalized ownership events. EchoKin does not collect bank-card information, seed phrases, or private keys.
Why
To determine chest eligibility, prepare and verify a user-approved token payment, prevent duplicate payment or Mint, submit an authorized transaction, reconcile finalized ownership, and display transaction activity.
Local / server processing
Your wallet remains responsible for approval and signing. EchoKin validates that signed transactions preserve the reserved recipient and token amount, stores transaction evidence on the server, and reads finalized Solana state through its configured RPC service.
Retention and deletion
Unsubmitted intents expire after a short operational window. Completed payment, Mint, and ownership evidence is retained for account history, fraud prevention, idempotency, support, and chain reconciliation. Public blockchain transactions are independently permanent and cannot be deleted by EchoKin.
Sharing
With the wallet provider you choose, Helius as the configured Solana RPC provider, and the Solana network where the transaction and wallet addresses become public. Tensor receives data only if you separately open or use Tensor; EchoKin does not automatically send your account records to Tensor.
Your control
Every transfer or Mint that spends assets requires approval in your wallet. You may cancel before signing. You can review the token, amount, recipient, network fee, and transaction in your wallet and on a Solana explorer.

Authentication information

What is handled
Wallet sign-in messages, one-time challenges, a hashed nonce, wallet-control verification results, hashed server session tokens, and the active access and refresh tokens stored in the extension. The web DApp uses an HttpOnly session cookie.
Why
To prove control of the wallet, bind the correct wallet to the correct account, keep you signed in, prevent replay, and authorize protected backpack and asset requests.
Local / server processing
The wallet signature is verified for login; EchoKin never receives the wallet private key. Server tokens are stored as cryptographic hashes. Browser-to-server requests use HTTPS, exact origin checks, short-lived challenges, and rotating refresh tokens.
Retention and deletion
A login attempt is usable for about 10 minutes, an access token for about 15 minutes, a refresh session for up to 30 days, and a DApp web session for up to 12 hours. Signing out revokes the active server session and removes local session credentials. Expired security records may remain for routine cleanup and abuse investigation.
Sharing
With the wallet provider you select only as required to display and approve the sign-in request, and with EchoKin's hosting infrastructure to operate authentication. Authentication secrets are not publicly disclosed.
Your control
You choose whether to connect and sign. You may reject a signature request, sign out, disconnect the site in your wallet, or clear the extension's stored data.

Location (including IP address)

What is handled
EchoKin does not request GPS, precise location, or background location. Like most online services, the website and API receive an IP address and standard request metadata when your browser connects.
Why
To deliver the site and API, apply rate limits, troubleshoot availability, and investigate abuse or security incidents.
Local / server processing
The application database does not maintain a location profile. Production web access logs hash client IP fields before storage. When a daily share reward link is created, the server stores only a secret-keyed, day-scoped network fingerprint to enforce one rewarded account per public IP per day; the raw IP is not stored in the reward record.
Retention and deletion
Hashed access logs rotate daily and are retained for no more than 14 days under the current production configuration, unless a specific security incident or legal obligation requires a limited record for longer.
Sharing
With EchoKin's contracted hosting and network infrastructure as necessary to deliver and protect the service. EchoKin does not sell or use IP data for advertising.
Your control
You can use the offline/signed-out companion without an account, but any online website, asset, account, RPC, payment, or Mint feature necessarily sends standard network metadata.

Web history

What is handled
Only if you turn on “Today's tokens,” the extension recognizes supported X and GMGN token contexts and saves normalized token symbols or contract addresses, chain, source type, first/last seen time, dwell time, and view count. It does not save your general Chrome history, raw page URLs, or a copy of posts.
Why
To show the user-facing list of tokens you viewed today inside the EchoKin Side Panel.
Local / server processing
This feature is off by default. Records are processed and stored only in chrome.storage.local on your device and are not transmitted to EchoKin servers.
Retention and deletion
The extension keeps only the current local day, capped at 200 records. The previous day is removed automatically when the local day or time zone changes.
Sharing
None. EchoKin does not transfer the local token-history list to its servers, advertisers, data brokers, or analytics providers.
Your control
You can enable or pause collection in the Side Panel and use “Clear today” to delete the records immediately.

User activity

What is handled
Companion visibility and placement, theme and motion preferences, quick actions, equipped assets, chest requests and results, and account-side payment, Mint, transfer, and ownership activity. EchoKin does not run unrelated cross-site analytics or build an advertising profile.
Why
To make the companion behave as you configured it, synchronize your loadout, prevent duplicate rewards and transactions, show account activity, and maintain service reliability and security.
Local / server processing
Display preferences and companion runtime state are normally stored locally. Account-backed actions such as equipping, opening a chest, paying, Minting, and ownership synchronization are sent to and recorded by EchoKin servers.
Retention and deletion
Local preferences remain until cleared or the extension is uninstalled. Server gameplay and transaction records remain while needed to provide the account, preserve edition allocation and transaction integrity, resolve disputes, and meet security or legal duties.
Sharing
Only with service infrastructure necessary to provide the requested feature, and with the Solana network or RPC provider when the action is onchain. Not for advertising or resale.
Your control
You can hide the companion, change or reset preferences, remain signed out, decline wallet actions, sign out, or request deletion of eligible server-side account data.

Website content

What is handled
On supported X and GMGN pages, the content script can inspect page layout, visibility, current token-route metadata, and visible token markers needed to place and animate the companion. When “Today's tokens” is enabled, it may read visible public post text and trusted token links only to extract a token symbol or contract address. It does not take screenshots, store raw post text, read direct messages, or capture form input.
Why
To render EchoKin without blocking page controls, react to the supported page context, and provide the optional local token-history feature.
Local / server processing
Page inspection happens in the browser. Runtime page context is transient; the optional extracted token record is local as described above. Raw website content is not sent to EchoKin servers.
Retention and deletion
Transient layout and page-context data is discarded as the page changes or closes. Only the optional normalized, current-day token record is retained locally.
Sharing
None by EchoKin. The extension does not upload X or GMGN page content to EchoKin or a third party.
Your control
You can disable “Today's tokens,” clear its records, hide the companion, disable the extension on a site through Chrome, or uninstall it.

Information we do not plan to collect

EchoKin does not plan to collect health information. EchoKin also does not intentionally access or collect personal communications such as direct messages, private chats, email, or the contents of wallet-provider support conversations.

Public X posts visible on a supported page are treated as website content, not personal communications. If “Today's tokens” is enabled, the extension extracts only a token symbol or contract address from visible public content; it does not save or upload the post itself.

Sharing and service providers

We do not sell user data. We do not share it with advertising platforms, data brokers, or information resellers. Data is transferred only when necessary to provide or secure the EchoKin feature you requested, comply with law, investigate abuse, or complete a corporate transaction after any consent required by Chrome Web Store policy and applicable law.

  • Hosting and network providers process requests and encrypted server data on EchoKin's instructions.
  • Helius processes the wallet addresses, asset addresses, signatures, and RPC queries needed to read finalized Solana state and submit authorized transactions.
  • Solana permanently publishes transaction and asset data when you approve an onchain action.
  • Your wallet provider displays and signs requests under the provider's own terms and privacy policy.
  • X, GMGN, Tensor, explorers, and other linked sites receive ordinary browser request information only when you visit or use those independent sites. EchoKin does not provide them with your private EchoKin account record.

Security

EchoKin uses HTTPS for user-data transmission, exact extension-origin checks, scoped browser permissions, short-lived sign-in challenges, rotating sessions, hashed server-side tokens, HttpOnly web-session cookies, transaction-content validation, idempotency controls, and finalized chain reads. Access to operational data is limited to people and systems that need it to operate, secure, support, or legally administer EchoKin.

No system is perfectly secure. Never share a seed phrase or private key with EchoKin or anyone claiming to represent EchoKin. EchoKin support will not ask for them.

Your choices, access, and deletion

  • Use the signed-out companion without creating an EchoKin account.
  • Keep “Today's tokens” off, pause it, or clear the current-day records at any time.
  • Reject wallet signatures and transactions, disconnect the site in your wallet, or sign out of EchoKin.
  • Clear extension data in Chrome or uninstall the extension to remove locally stored EchoKin data.
  • Contact us to request access, correction, or deletion of eligible server-side account data. We may ask you to sign with the bound wallet to verify the request.

EchoKin cannot erase transactions or ownership history already written to a public blockchain. We may also retain narrowly limited records when required for security, fraud prevention, transaction integrity, dispute resolution, or law.

Chrome Web Store Limited Use

EchoKin's use and transfer of information is limited to providing or improving the extension's disclosed single purpose and related maintenance, security, and reliability. Humans do not read user data except with the user's consent for specific support, where necessary for security or law, or where data is aggregated and anonymized for permitted internal operations.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Changes and contact

We will update the date at the top of this page when this policy changes. If a future extension update materially changes user-data practices, EchoKin will provide the disclosure and consent required by Chrome Web Store policy before the new handling begins.

EchoKin currently provides support through the official website and official X account. We do not publish an email address that is not an established support channel.

隐私 · Chrome 扩展 · 网页 DApp

EchoKin 隐私政策

生效日期:2026 年 8 月 9 日更新日期:2026 年 8 月 9 日

本政策说明 EchoKin Labs 如何在 EchoKin Chrome 扩展、echokin.fun、EchoKin 网页 DApp 及其账户服务中处理信息。英文版为主要版本,中文版用于帮助理解并与英文版保持同等数据边界。

不出售数据

不会出售用户数据,也不会提供给数据经纪商。

不用于广告

不会用于个性化、再营销或兴趣广告。

本地优先

可选的今日币种默认关闭,记录只保存在本机。

不接触私钥

钱包私钥和助记词永远不会进入 EchoKin。

适用范围与单一用途

EchoKin 的单一用途,是在受支持的 X 与 GMGN 页面中提供可管理的链上灵伴,并让用户通过 EchoKin 账户、背包、宝箱和可选的链上功能使用自己的藏品。

我们不出售用户数据,不将数据用于个性化广告、再营销、信用评估、数据经纪或与 EchoKin 单一用途无关的市场研究。

分类数据说明

“处理”既包括只在用户设备上进行的本地处理,也包括传输到 EchoKin 服务的信息。

个人身份信息

处理哪些信息
公开的 Solana 钱包地址、EchoKin 内部账户标识、用户选择或系统生成的灵伴名称,以及语言偏好。EchoKin 不要求提供真实姓名、住址、电话号码或电子邮箱。
使用目的
用于为一个已验证钱包创建一个 EchoKin 账户,展示背包和当前装扮,保存偏好并提供账户支持。
本地 / 服务器处理
扩展在私有 IndexedDB 中保存当前会话和背包缓存;网站仅在浏览器本地保存语言选择。服务器保存账户、钱包绑定、灵伴名称、背包和当前装扮。
保存与删除
退出登录时会移除本地会话;清除 Chrome 扩展数据或卸载扩展会删除本机数据。服务器账户记录在账户有效期间保留;收到经钱包验证的删除请求后,会删除或去标识化符合条件的数据,但安全、交易完整性或法律要求必须保留的有限记录除外。
共享范围
仅在运行和保护服务所必需时,由代表 EchoKin 处理数据的基础设施服务商处理。钱包地址及链上所有权一旦写入 Solana,本身即为公开信息。
用户控制
用户可以在未登录状态使用基础灵伴、随时退出、清除 Chrome 中的扩展数据,或通过官方 X 申请访问、更正或删除账户数据。

财务与支付信息

处理哪些信息
公开钱包余额和资产所有权、配置的支付代币 Mint 与金额、支付和 Mint 意图、付款与项目收款地址、提交交易所需的已签名交易数据、交易签名、NFT 资产地址及 finalized 所有权事件。EchoKin 不收集银行卡信息、助记词或私钥。
使用目的
用于判断宝箱资格、准备并验证用户批准的代币付款、防止重复付款或重复 Mint、提交已授权交易、同步最终所有权并展示活动记录。
本地 / 服务器处理
钱包负责批准和签名。EchoKin 校验已签名交易没有改变预留的收款地址和代币金额,在服务器保存交易证据,并通过配置的 RPC 读取 finalized Solana 状态。
保存与删除
未提交的意图会在较短的操作窗口后过期。已完成的付款、Mint 和所有权证据会为账户历史、防重复、反欺诈、支持和链上同步而保留。公开链上交易具有独立的永久性,EchoKin 无法删除。
共享范围
与用户选择的钱包服务商、作为 Solana RPC 服务商的 Helius,以及会公开交易与钱包地址的 Solana 网络处理。只有用户主动打开或使用 Tensor 时,Tensor 才会收到其自身网站请求;EchoKin 不会自动向 Tensor 提供私有账户记录。
用户控制
任何消耗资产的转移或 Mint 都需要在钱包中批准。签名前可以取消,并可在钱包和 Solana Explorer 中检查代币、金额、收款地址、网络费与交易。

身份验证信息

处理哪些信息
钱包登录消息、一次性挑战、哈希后的 nonce、钱包控制权验证结果、服务器端哈希后的会话令牌,以及扩展中保存的当前 access token 和 refresh token。网页 DApp 使用 HttpOnly 会话 Cookie。
使用目的
用于证明用户控制钱包、将正确钱包绑定到正确账户、保持登录、防止重放,并授权读取受保护的背包和素材。
本地 / 服务器处理
登录时验证钱包签名;EchoKin 永远不会收到钱包私钥。服务器令牌以加密哈希保存。浏览器与服务器之间使用 HTTPS、精确 Origin 校验、短时挑战和轮换 refresh token。
保存与删除
登录尝试约 10 分钟有效,access token 约 15 分钟,refresh session 最长 30 天,DApp 网页会话最长 12 小时。退出登录会撤销服务器会话并移除本地凭证;过期安全记录可能为例行清理和滥用调查短期保留。
共享范围
仅在显示和批准登录请求所必需时,由用户选择的钱包服务商处理,并由 EchoKin 的托管基础设施处理身份验证。身份验证密钥不会公开。
用户控制
用户自行决定是否连接和签名,可以拒绝签名、退出登录、在钱包中断开网站连接,或清除扩展数据。

位置(包括 IP 地址)

处理哪些信息
EchoKin 不请求 GPS、精确位置或后台位置。与大多数在线服务一样,浏览器连接网站和 API 时会发送 IP 地址及标准请求信息。
使用目的
用于提供网站和 API、执行频率限制、排查可用性问题,以及调查滥用或安全事件。
本地 / 服务器处理
应用数据库不会建立位置画像。生产网站访问日志会在保存前对客户端 IP 字段进行哈希。创建每日分享奖励链接时,服务端仅保存带密钥、按日隔离的网络指纹,用于限制同一公网 IP 每天最多奖励一个账户;奖励记录不保存原始 IP。
保存与删除
按当前生产配置,哈希后的访问日志每日轮换,最多保留 14 天。只有特定安全事件或法律义务需要时,才会延长保存有限记录。
共享范围
仅由 EchoKin 的托管和网络基础设施在提供、保护服务所必需时处理。EchoKin 不出售 IP 数据,也不将其用于广告。
用户控制
用户可以未登录使用基础灵伴;但任何在线网站、素材、账户、RPC、付款或 Mint 功能都会产生必要的标准网络信息。

网页浏览记录

处理哪些信息
只有用户主动开启“今日币种”后,扩展才会识别受支持的 X 和 GMGN 币种上下文,并保存规范化的币种符号或合约地址、链、来源类型、首次和最后查看时间、停留时间及查看次数。不会保存完整 Chrome 历史、原始页面网址或帖子副本。
使用目的
用于在 EchoKin 侧边栏展示用户当天查看过的币种列表。
本地 / 服务器处理
此功能默认关闭。记录仅在用户设备的 chrome.storage.local 中处理和保存,不会传输到 EchoKin 服务器。
保存与删除
只保留当前本地日期的数据,最多 200 条。本地日期或时区变化后,上一天的数据会自动删除。
共享范围
不共享。EchoKin 不会将本地币种记录传给服务器、广告商、数据经纪商或分析服务。
用户控制
用户可以在侧边栏开启或暂停记录,并通过“清空今天”立即删除。

用户活动

处理哪些信息
灵伴显示和位置、主题与动效偏好、快捷动作、当前装扮、宝箱请求与结果,以及账户侧的付款、Mint、转移和所有权活动。EchoKin 不运行无关的跨网站分析,也不建立广告画像。
使用目的
用于让灵伴按照用户设置运行、同步装扮、防止重复奖励和交易、显示活动记录并维护服务可靠性和安全。
本地 / 服务器处理
显示偏好和灵伴运行状态通常保存在本地。换装、开箱、付款、Mint 和所有权同步等账户操作会发送到 EchoKin 服务器并记录。
保存与删除
本地偏好保留至用户清除数据或卸载扩展。服务器玩法和交易记录在提供账户、保护编号分配和交易完整性、处理争议及履行安全或法律义务所需期间保留。
共享范围
仅与提供所请求功能所必需的服务基础设施共享;涉及链上操作时,由 Solana 网络或 RPC 服务商处理。不会用于广告或转售。
用户控制
用户可以隐藏灵伴、更改或重置偏好、保持未登录、拒绝钱包操作、退出登录,或申请删除符合条件的服务器账户数据。

网站内容

处理哪些信息
在受支持的 X 和 GMGN 页面,内容脚本可以检查放置和运行灵伴所需的页面布局、可见性、当前币种路由元数据和可见币种标记。开启“今日币种”后,可能读取可见公开帖子文字和可信币种链接,仅用于提取币种符号或合约地址。不会截图、保存原始帖子文字、读取私信或捕获表单输入。
使用目的
用于在不遮挡页面控件的情况下展示 EchoKin、响应受支持的页面上下文,并提供可选的本地今日币种功能。
本地 / 服务器处理
页面检查发生在浏览器中。运行时页面上下文是临时的;可选的提取结果只按上述方式保存在本地。原始网站内容不会发送到 EchoKin 服务器。
保存与删除
页面变化或关闭后,临时布局和上下文数据即被丢弃;只有可选的、规范化的当天币种记录会在本地保留。
共享范围
EchoKin 不共享此类内容。扩展不会把 X 或 GMGN 页面内容上传给 EchoKin 或第三方。
用户控制
用户可以关闭“今日币种”、清空记录、隐藏灵伴、通过 Chrome 禁用特定网站上的扩展,或卸载扩展。

不计划收集的信息

EchoKin 不计划收集健康信息,也不会读取或收集私信、聊天等个人通信。

受支持页面上可见的公开 X 帖子按网站内容处理,不属于个人通信。即使用户开启“今日币种”,扩展也只提取币种符号或合约地址,不保存或上传帖子本身。

共享范围与服务商

EchoKin 不出售用户数据,也不向广告平台、数据经纪商或信息转售商共享。只有在提供或保护用户所请求的 EchoKin 功能、遵守法律、调查滥用,或在取得 Chrome Web Store 政策及适用法律要求的同意后完成公司交易时,才会传输必要数据。

  • 托管和网络服务商:按照 EchoKin 指示处理请求和加密的服务器数据。
  • Helius:处理读取 finalized Solana 状态和提交用户授权交易所需的钱包地址、资产地址、签名及 RPC 请求。
  • Solana:在用户批准链上操作后,永久公开交易和资产数据。
  • 用户选择的钱包:按照钱包自身的条款和隐私政策显示及签署请求。
  • X、GMGN、Tensor、Explorer 等外部网站:只有用户主动访问时才会收到普通浏览器请求信息;EchoKin 不会向它们提供私有 EchoKin 账户记录。

安全措施

EchoKin 使用 HTTPS、精确扩展 Origin 校验、最小化浏览器权限、短时登录挑战、轮换会话、服务器端令牌哈希、HttpOnly 网页 Cookie、交易内容校验、幂等控制和 finalized 链上读取。只有为运行、安全、支持或依法管理 EchoKin 而确有需要的人员和系统才能接触操作数据。

任何系统都无法保证绝对安全。请勿向 EchoKin 或任何自称 EchoKin 的人员提供助记词或私钥;EchoKin 支持人员不会索取这些信息。

用户选择、访问与删除

  • 无需创建 EchoKin 账户即可使用未登录状态的基础灵伴。
  • 保持“今日币种”关闭、暂停记录,或随时清空当天记录。
  • 拒绝钱包签名和交易、在钱包中断开连接,或退出 EchoKin。
  • 清除 Chrome 扩展数据或卸载扩展,以删除本地 EchoKin 数据。
  • 通过官方 X 申请访问、更正或删除符合条件的服务器账户数据;为验证请求,EchoKin 可能要求使用绑定钱包签名。

EchoKin 无法删除已经写入公共区块链的交易或所有权历史。因安全、反欺诈、交易完整性、争议处理或法律要求必须保留的有限记录也可能无法删除。

Chrome Web Store Limited Use

EchoKin 对信息的使用和传输仅限于提供或改进已披露的扩展单一用途,以及相关维护、安全和可靠性。除用户为特定支持明确同意、安全或法律所需,或经汇总匿名化后用于允许的内部运营外,人员不会读取用户数据。

从 Google API 获得的信息,其使用将遵守 Chrome Web Store User Data Policy,包括 Limited Use 要求。

政策更新与联系渠道

政策发生变化时,我们会更新页面顶部日期。如果未来扩展更新会实质改变数据处理方式,EchoKin 会在新的处理开始前,按照 Chrome Web Store 政策提供所需披露并取得同意。

当前支持渠道为官方网站和官方 X 账户。我们不会虚构或公布尚未建立的支持邮箱。