PHYSi Cookie Policy

Last Updated: Thursday, September 3, 2026 7:30 AM CST

Last updated: September 3, 2026

This Cookie Policy explains how Physi LLC, a Texas limited liability company (the “operator,” “we,” or “us”), uses cookies and similar technologies on the PHYSi Services.

The Services include https://physi.art, https://id.physi.art, associated PHYSi hosts listed at https://physi.art/official, sandbox hosts such as https://sandbox.physi.art, and the native Android application PHYSi (package art.physi.seeker) on the Solana dApp Store and via sideload. Related: Privacy Policy · Terms of Service.

This notice is about device storage (cookies, local storage, session storage, IndexedDB). It does not replace the Privacy Policy.


Managing preferences

PHYSi does not show a cookie banner today. There is no OneTrust (or similar) control, because PHYSi does not set analytics cookies or advertising / targeting cookies.

Storage that the Services write is for operation: wallet session, KiNECKT vault, drafts, and interface preferences. Clearing site data in the browser (or the Android WebView) signs the Participant out of KiNECKT SSO, may lock the vault, and may delete local drafts and UI preferences.

Browser and OS controls still apply. See How to control cookies and site data below.


What cookies and similar technologies are

Cookies are small files a site can store on a computer or phone. First-party cookies are set by the site being visited. Third-party cookies are set by another company (ads, analytics, social widgets).

PHYSi’s product code does not currently set named HTTP cookies the way a shop or ad stack does. PHYSi does use similar technologies that laws and this policy treat the same way:

  • Local storage and session storage — key/value data in the browser, used for session, drafts, and preferences
  • IndexedDB — structured browser storage used by KiNECKT for encrypted vault ciphertext
  • Cookies that infrastructure may set — AWS Amplify / CloudFront / Cognito, or HTTP basic auth on a gated sandbox host, if those systems need a cookie to deliver the page or a guest upload session

Wallet software (Phantom, Solflare, Seed Vault) and the Solana Mobile WebView may store their own data. Those products have their own policies.


Why PHYSi uses this storage

ReasonWhat it does for PHYSi
Keep a sessionRemember a connected Solana address and KiNECKT SSO so every click is not a reconnect
Keep keys on-deviceKiNECKT vault ciphertext and unlock TTL stay on the device; PHYSi servers do not receive the recovery phrase
Finish workTokenize / batch drafts, mint defaults, and similar in-progress forms survive a refresh
Remember UILeaderboard density, ticker visibility, wait-indicator picks, and similar prefs
Host the siteAmplify, CloudFront, and Cognito Identity Pool guest credentials so profiles, images, and AppSync can load

PHYSi does not currently use cookies or pixels to run ads, retarget Participants across other sites, or feed Google Analytics.


Strictly necessary

Required for the Services to function. There is no “reject these and still use KiNECKT / tokenize / market” switch.

Name / keyPurposeWhereHow long
physi-kineckt-sso-pubkeyKiNECKT SSO: last connected public keyphysi.art local / session storageUntil disconnect or site data cleared
physi-kineckt-sso-addressesKiNECKT SSO: address list for the sessionphysi.art local / session storageUntil disconnect or site data cleared
physi-kineckt IndexedDBEncrypted KiNECKT vault ciphertext (not the recovery phrase)physi.art and id.physi.artUntil the Participant deletes the vault or site data
physi-kineckt-sign-session-map-v1Unlock session so signing can continue across tabs for the chosen TTLphysi.art / id.physi.art local storageParticipant TTL (default 24 hours) or lock
physi-kineckt-settings-v1Unlock TTL and lock-on-hidelocal storageUntil changed or cleared
physi-kineckt-unlock-hint-v1UX hint that the vault may need a password on the next signlocal storageTTL
physi-kineckt-last-vault-id / physi-kineckt-last-address:*Last vault and address usedlocal storageUntil changed or cleared
physi-kineckt-export-ackExport / backup acknowledgementlocal storageUntil cleared
physi-remembered-accounts-v1Account roster on this devicelocal storageUntil cleared
physi-seeker-appMarks the Solana Mobile / Android WebView sessionlocal storageUntil cleared
Cognito / Amplify Auth keysGuest Identity Pool credentials for Storage (S3) and related AWS callsAmplify default browser storageSession / token expiry
Amplify / CloudFront / basic-auth cookiesDeliver the host; gated sandbox may keep an HTTP auth sessionHost cookie jarSession or vendor default
Tokenize / batch / collection draft keysIn-progress mint and listing draftslocal storageUntil published, discarded, or cleared

Clearing this class of storage logs the Participant out and can lose unsaved drafts.


Functional

Not required to load a public page. Used to remember how the Participant set the interface.

Name / keyPurposeWhereHow long
physi.market.starredCollectionsStarred market collectionslocal storageUntil changed or cleared
physi.market.leaderboardCardDensityMarket leaderboard densitylocal storageUntil changed or cleared
physi:hideActivityTicker / physi:activityTickerEyeHiddenHide the activity tickerlocal storageUntil changed or cleared
physi:footerBroadcastEyeHiddenHide the footer broadcast striplocal storageUntil changed or cleared
physi:searchBarSwipeHintSeenSearch-bar swipe hint already shownlocal storageUntil cleared
physi:wait-indicator-assignmentsWait-indicator preferencelocal storageUntil changed or cleared
Invite mint layout prefsLayout choice on invite mintlocal storageUntil changed or cleared
physi:emailVerifySentAt:*Email-verify resend cooldownlocal storageAbout 10 minutes
TradingView chart layoutDrawings / interval on the self-hosted chart librarylocal storage (charting library)Until cleared

PHYSi does not currently treat a separate “functional cookie” consent category. These keys are first-party preferences.


Analytics

None as of September 3, 2026. PHYSi does not ship Google Analytics (_ga), Mixpanel, PostHog, Segment, or a similar product-analytics SDK on physi.art or in the current Android production build.

Server logs (IP address, request path, error traces) may still exist on AWS / Amplify for security and debugging. That is not a browser cookie.

If PHYSi later adds analytics cookies, this policy will name them and a consent control will ship with that change if required.


Targeting and advertising

None as of September 3, 2026. PHYSi does not set X / Twitter, Meta, Google Ads, or similar advertising cookies, and does not run a shop checkout cookie stack.

Wallet extensions and Solana Mobile may show their own UI and store their own data. PHYSi does not control those stores.


Local storage and IndexedDB

Cookies are not the only on-device store. PHYSi’s wallet and drafts depend on local storage and IndexedDB.

Local storage and IndexedDB do not expire on a calendar the way many cookies do. They stay until the Services delete them, the Participant deletes them, or the browser / OS clears site data.

KiNECKT: encrypted vault data and unlock session material stay on the device. PHYSi servers do not receive the recovery phrase. A later release may move unlock material into platform secure storage; until then, treat this device like a wallet device.

Cross-host: id.physi.art holds keys. physi.art receives SSO public keys and optional vault ciphertext import. Those writes are first-party on each host, not a third-party ad cookie.


Other tracking technologies

PHYSi does not currently load advertising pixels or web beacons.

The Services call PHYSi APIs and a Solana RPC provider (for example Helius) with the connected public address and the request IP so profiles, listings, and chain state can load. That is request traffic, not a cookie. See the Privacy Policy.

The Android app may enable third-party cookies inside the WebView so physi.art and wallet / Seed Vault flows can share a session. That does not add PHYSi advertising cookies.


Third parties that may store data

PartyRoleTypical store
Amazon Web Services (Amplify, CloudFront, Cognito, S3, AppSync)Host, auth guest credentials, images, APICookies and / or local storage AWS SDKs use
Helius (or the configured Solana RPC)Chain readsNo PHYSi-set browser cookie; IP and public address on RPC requests
Phantom, Solflare, other wallet softwareSign and connectExtension / app storage those vendors control
Solana Mobile / Seed VaultSeeker connectDevice / WebView storage those vendors control
TradingView charting library (self-hosted on physi.art)Terminal chartsLocal chart state; not TradingView cloud login unless a later build adds it

Outside sites linked from PHYSi (explorers, social posts, Solana Mobile legal pages) have their own policies. Example of a third-party cookie policy that is not PHYSi: Solana Labs Cookie Policy.


How to control cookies and site data

Most browsers let the Participant block or delete cookies and clear site data (that includes local storage and IndexedDB).

On Android, clearing storage for PHYSi or the WebView site data has the same effect as clearing physi.art site data.

If cookies or site data are blocked entirely, connect, KiNECKT, drafts, image upload, and some signed actions may fail.

PHYSi does not honor a “Do Not Track” header for cookie purposes. There is no advertising cookie stack to turn off. The Privacy Policy states the same for DNT.


Updates

Physi LLC may update this Cookie Policy. The date at the top is the revision date. Material changes that add analytics or advertising cookies will be reflected here before those cookies ship.


Contact

Questions: hello@physi.art.

© 2026 Physi LLC

Created: Thursday, September 3, 2026 7:30 AM CST