Last updated: August 28, 2026
Granite has no accounts, analytics, telemetry, advertising, or user database. The hosted product never asks for private keys. Network providers still receive the minimum public and network data needed to serve requests.
Granite's hosted interface is watch-only observation software for Arweave and AO. It builds a local portfolio and visual feed from public addresses and process IDs. The source code is currently maintained privately during security validation and is intended to be published under the MIT License.
The Granite application does not operate a personal-data collection pipeline. Specifically:
Modern browsers can send Content Security Policy violation reports when a script is blocked by our policy. We accept these reports at /.well-known/csp-reports on the same origin you're already loading the app from - never a third-party endpoint. Our server returns HTTP 204 and does not persist the report body. The fact that a violation happened may appear in standard hosting access logs (URL + timestamp + IP); we use this only to detect attempted exploits, not to identify users. No tracking IDs, no cookies, no cross-request correlation.
Granite stores your public addresses, private labels, and preferences only on the device running the app:
The hosted product does not accept or store private keys. Granite has no server-side portfolio copy, recovery database, or account reset capability.
Granite can create a link or QR code that copies a public portfolio to another device. The payload contains public addresses, display labels, and the selected address only. It never contains private keys, passwords, contacts, transaction notes, activity history, or signing authority.
The portfolio payload is placed in the URL fragment (the part after #), which browsers do not send to Granite's web server during a normal page request. However, anyone who receives the link or QR code can read the included public addresses and view their public on-chain balances and activity. Treat a portfolio link as public information and share it only with intended recipients.
Granite communicates with the following external services to observe public activity. These are not ours - they are public Arweave and market-data infrastructure:
These services may see your IP address and, for portfolio blockchain queries, public addresses or transaction data. Granite does not receive or store a server-side copy of your portfolio requests. The separate public Network Briefing does aggregate a bounded network-wide sample as described below; it is not based on a visitor's portfolio or watchlist. These requests never contain your private keys, password, seed phrase, or recovery material.
Granite already uses HyperBEAM for canonical AO token balance reads and transfer verification. As Granite is developed further with the Arweave community and ecosystem, we intend to move additional suitable query, coordination, hosting, and application-service workloads toward permaweb infrastructure using Arweave and AO Computer. Community-operated infrastructure may take a greater role over time. This broader transition remains a roadmap direction.
Arweave and AO data may be public and permanent. A future permaweb migration will not be used to publish private keys, passwords, recovery material, or plaintext private user data. We will update this policy before any migration materially changes what data leaves a device, where it is processed, or how long it is retained.
The Network Briefing at /news is one shared report generated from a bounded sample of recent public Arweave and AO metadata. It is not personalized, does not accept a portfolio address or prompt, and does not collect an email address. All visitors receive the same cached report.
If server-side AI editorial is enabled, Granite sends only the bounded public network evidence packet to a dedicated AI API project. The daily publication may also create up to two conceptual story illustrations from the selected story's verified headline, explanation, and technical detail. It does not send a visitor's IP address, portfolio, watchlist, labels, browser data, private notes, or credentials. The AI service may retain API request content under its own platform data controls. Granite requests non-persistent text responses, validates all output locally, and falls back to deterministic copy or text-only cards if AI is unavailable. Page visits and the refresh button cannot trigger an AI request.
Granite does not accept or store visitor-provided AI API keys. A future bring-your-own-key capability would require a separate privacy and security review before release.
Granite cannot recover, control, or move funds associated with an address you add. Adding or naming a public address proves no ownership and grants no authority over it.
Granite does not knowingly collect data from anyone, including children under 13. Since we collect nothing from anyone, we are compliant with COPPA in the most literal way possible.
Granite's landing page and hosted watch-only product currently run on Railway. Railway and upstream network providers may process IP addresses, request paths, timestamps, and ordinary transport metadata to deliver and secure the service. Granite does not add tracking identifiers or operate an account, analytics, crash-telemetry, or user-profile database.
Our longer-term intention is to transition suitable parts of Granite toward a permaweb architecture running through Arweave and AO Computer, including HyperBEAM-backed services where appropriate, with the community and ecosystem taking an increasing role in operating and evolving that infrastructure. That transition has not yet occurred. Railway remains the current host until a reviewed migration is deployed and independently verifiable.
If we ever change this policy, we will update this page and the "Last updated" date above. Given that our policy is essentially "we collect nothing," changes would likely mean we started collecting something - and we'd be upfront about why.
Granite's source code is intended to be published under the MIT License after the current security-validation period. Until then, this policy describes the behavior of the hosted preview and will be updated if that behavior changes.
Questions, concerns, or compliments about this policy can be directed to our GitHub Issues. We read everything.