Monad APY · legal
Privacy Policy
Last updated: 2026-07-30
What we store
Browsing needs no account and no wallet. We store nothing about you until you use a feature that needs it:
- Your wallet address, once you sign in with Sign-In with Ethereum
- The positions we found for an address you looked up, cached for a few minutes so the next load does not rescan the chain
- Your passport, if you generate one: public on-chain activity for that address, summarised and stored against it, and shown on the leaderboard
- Your IP address and browser user-agent, if you claim the onboarding MON. That row is what stops the same bridge being claimed twice, so unlike the others it is kept rather than expired.
We do not ask for an email address and have nowhere to put one.
Everything else on the site is public data about Monad, stored against pools and protocols rather than against people.
What our servers do, so your browser does not
The yield data, the risk scores and the swap quotes are fetched by our servers, not by your browser. When the price page compares protocols it is our server that calls DefiLlama, the aggregators and the Monad RPCs, so those parties see our address and not yours. Token and protocol icons are stored on this site rather than loaded from an image CDN, for the same reason.
Two things do leave with an address attached, and both are worth naming. Reading a wallet's positions means asking the Monad RPCs about that wallet, which cannot be done without naming it. And building a passport means reading its whole history, which no Monad RPC keeps beyond about eighteen days, so the address being looked up is sent to Etherscan along with our API key.
In both cases it is a public address, and it reaches them from our server rather than your browser, so they see which address was asked about but not who asked. There is no version of reading a wallet that avoids naming the wallet; what we can avoid is attaching you to it, and that is what the server hop does.
Third parties your browser does reach
These see your IP address and whatever their own technology records. They are listed here because it is the honest version, not because we send them anything about you.
- Vercel, on every page: hosting, plus Vercel Analytics and Speed Insights for page views and loading performance. Both are cookieless and aggregate, and neither builds a profile across sites.
- Google Fonts, on every page, for the typefaces.
- X (Twitter), on the news page only, which embeds posts in X's own frames. X sets its own cookies there and applies its own policy, which we do not control. No other page loads it.
- WalletConnect / Reown, only if you open the connect dialog, to reach your wallet.
- LI.FI, only on the bridge page, which runs their widget.
- Your wallet's own RPC, once connected, to read balances.
What we don't do
- We don't custody funds, sign transactions, or have access to private keys
- We don't sell or share user data
- We don't run advertising, ad cookies, or cross-site trackers
- We don't send your address or your searches to the protocols we quote
Cookies
We set one cookie, for the Sign-In with Ethereum session. It is HTTP-only, secure, and not used for tracking. The embedded X posts on the news page set cookies of their own, under X's policy rather than ours.
Deletion
The position cache expires on its own within ten minutes. To remove the rest, disconnect your wallet and email us at the address below. We will remove your address and your passport within 7 days.
The onboarding claim row is the exception. Deleting it would let the same bridge be claimed a second time, which is the one thing it exists to prevent, so it stays. It holds an address, a transaction hash, an IP and a user-agent, and nothing else about you.
Contact
contact@monad-apy.xyz