Privacy
How Bags handles data
In the public service, account identity is handled by Privy. Bags stores your public profile, bags, allocations, follows, and public activity in Supabase. A linked wallet remains private unless you explicitly choose to show it on your public profile.
Copied but unpublished drafts remain in your browser’s localStorage for up to one hour and are scoped to the current account. In credential-free development mode, created demo bags and follow preferences are also local to that browser.
Public bag information is intentionally visible to anyone. Private bags are returned only after server verification of the owning account. Bags does not request or store seed phrases or private keys, and local wallet connection does not request signatures or transactions.
Authenticated users can download a JSON copy of their account data or request permanent account deletion from Profile settings. Deletion of an account with a Privy-managed wallet requires assisted review because removing its login may affect wallet recovery. These workflows and this starter notice require qualified legal review before commercial launch.