Privacy
Privacy at Theme Token
This page describes the data Theme Token handles when you browse the site, connect a wallet, save a draft, use an AI feature, or publish to the BSV blockchain. It was last updated on August 31, 2026.
Browsing and theme sessions
Theme Token uses a short-lived theme session cookie to keep the selected visual theme stable across page loads. The cookie contains a public theme origin and an assignment timestamp. Browser storage may also keep local drafts and interface preferences. Clearing site data removes those local values.
Wallet connections and payments
Wallet access is handled through a BRC-100-compatible wallet such as BSV Desktop or Yours Wallet. The wallet shows permission and transaction requests. Theme Token receives the information approved for that request, such as public identity details, addresses, owned outputs, or a transaction result. Private keys and seed phrases remain in the wallet and should never be entered into Theme Token.
Drafts and AI generation
Connected users can save design drafts in hosted storage. Draft records may include a wallet-derived public identifier, the draft name, design data, generation prompt, provider and model names, file metadata, and expiration timestamps. Binary assets may be stored in Vercel Blob and draft metadata in Vercel KV. The application removes expired drafts during reads and cleanup jobs, and users can delete drafts through the product.
When you request AI generation, the prompt and necessary design context are sent to the configured model provider through the application backend. Avoid including secrets or personal information in a prompt.
Published blockchain data
Publishing writes the selected content and metadata to the public BSV blockchain. That data can be copied, indexed, and served by independent services. It is designed to remain available and cannot be deleted by Theme Token after broadcast. Review names, prompts, author fields, licenses, and files before approving a wallet transaction.
Questions
For a privacy question or a report about data exposed by the web application, use the routes on the contact page. Do not include wallet secrets in a report.