1. This website
This policy covers suitstayson.com, including the AI fitting room, Proof of SUIT, Suit Shift game, Hostile Takeover, The Firm, The Company Intranet and community receipts. “SUIT,” “we” and “our” refer to the team providing this website. It does not cover the independent websites you visit through our links.
You can browse, use the fitting room and play practice shifts without a connected wallet. Recording scores on the public leaderboard requires a Solana wallet sign-in. We do not ask you to provide a seed phrase, private key or payment-card details.
2. Your portraits
Selecting an image previews it in your browser. The image is sent for AI processing only after you confirm you have permission to use it and select “Put the suit on.” Your browser resizes the image and sends a JPEG copy to our server, which sends that copy, the fixed headless suit body shown on the page and an editing instruction to xAI’s Grok image service. The suit body is a public site asset; your uploaded image supplies the head and identity for the edit. xAI returns an edited image through our server to your browser.
The current fitting-room application processes the images to complete that request. The fitting room does not automatically save your uploaded or generated images to a SUIT photo database, public gallery or account history. If you separately choose to publish a portrait in Hostile Takeover, the public boardroom rules below apply. Its image responses tell browsers and intermediaries not to cache them. This does not mean the whole process is anonymous or that xAI and infrastructure providers retain nothing.
xAI applies its own processing and retention terms. Its API and business data FAQ currently says inputs and outputs are normally deleted within 30 days, subject to stated exceptions, including legal obligations and suspected policy violations. Read that source for the provider’s current terms; SUIT cannot delete records held independently by xAI.
Only upload images you are entitled to use, with any necessary permission from the people shown. Avoid sensitive documents, private credentials and images you would not want processed by an external AI provider.
The Firm: public blockchain data
The Firm reads public SUIT token-account balances through our server and stores owner addresses, observed balances, first-observed times and changes between snapshots in the site database. It publishes holder counts, holding tiers, the largest eligible wallet and a recent observed activity feed. This does not require a wallet connection. Public blockchain addresses are pseudonymous, not necessarily anonymous. Our server also requests market data from DEX Screener and launch information from StonkFun. The data describes addresses and observed balances, not verified identities or complete purchase histories.
3. What stays on your device
- Portrait previews: selected and generated images are held in the page’s browser memory. Resetting the portrait or leaving the page ends the visible session. Images you download remain on your device until you delete them.
- Suit Shift: your best score is stored in this browser’s local storage under
suit-shift-best-v2(older versions usedsuit-shift-best-v1). It remains until you clear this site’s browser data or your browser removes it. Practice shifts stay on your device. If you connect your wallet before a shift, that shift is submitted to the leaderboard as described below. - Receipts and sharing: receipt images are assembled in your browser. Download and copy controls act on your device. An X sharing control opens a draft; it does not automatically publish it.
Our current website code does not set advertising cookies or include advertising pixels or a third-party analytics script. Browser storage, hosting diagnostics and requests to the services below still involve information processing.
The Company Intranet
The intranet’s meeting excuses, resignation drafts, portfolio reviews and meme exports are created in your browser. The intranet does not send the names, captions, manual portfolio values or app pitches you enter to our server. Those entries stay in the current page session. It does not connect a wallet or read your holdings for a performance review.
Your pinned app IDs are saved in this browser’s local storage under suit-intranet-pins-v1. Use “Reset pins” to restore the default desk, or clear this site’s browser data to remove the preference. Downloads remain on your device, and copy controls write to your clipboard. The app pitch control does not submit or publish your pitch: you choose whether to paste it into the linked X group chat. The other site features opened from the directory follow their respective practices described in this policy.
Wallet sign-in and public scores
Connecting for Suit Shift asks your wallet to sign a message proving you control its public address. It does not authorize a blockchain transaction or let this site move tokens. Your address, best verified score, game rules version and time achieved are stored on our server. Your wallet address and best score are public leaderboard information, even though the table abbreviates addresses.
A necessary, HttpOnly sign-in cookie lasts up to 24 hours. Short-lived sign-in challenges last five minutes; active ranked shifts expire after one hour. We store random identifiers, wallet addresses, challenge messages, expiry times and score-verification records. Your movement inputs are sent when a ranked shift ends so the server can replay it; the leaderboard stores a digest of the submission rather than the full movement log. Expired challenges, sessions and run records are cleared during subsequent sign-in or game requests; this is not a promise of immediate deletion at expiry. Scores remain while the leaderboard operates, unless removed by the team.
For sign-in abuse protection, we store a temporary hash derived from your IP address and the day, alongside a challenge. This is not anonymous data. Disconnecting ends the current server sign-in; it does not delete a posted score. To request removal, use the contact route below. We may ask you to prove ownership of the relevant wallet.
Proof of SUIT and portrait titles
Proof of SUIT uses the same wallet sign-in as the game. Our server sends the signed-in public wallet address and the SUIT token mint to a Solana RPC service to read publicly recorded token accounts. It totals SUIT held directly in that wallet and assigns a community job from the published holding thresholds. The address and balance response may be briefly cached by the running service; this feature does not add a permanent holdings or job-history database.
Your browser keeps the current result, its check time and optional portrait-title preference while the page is open. Holdings checks expire after five minutes. The title is drawn onto the generated image in your browser; your wallet address, balance and job are not added to the image request sent to xAI. Downloaded images are snapshots and do not update when balances change. The wallet sign-in and retention details above also apply.
Hostile Takeover public boardrooms
Hostile Takeover uses the same free wallet sign-in. Creating a company or taking a seat requires a separate confirmation to publish your selected portrait, display name, cosmetic seat title and wallet address. Company names, member profiles, membership dates and the founder’s wallet are public to anyone with the invite link. A wallet address can be linked to public blockchain activity. Do not publish a portrait or name you want to keep private.
Choosing “Use in my boardroom” only copies your generated portrait into the boardroom editor on your device. Saving a seat sends a cropped 512-pixel JPEG to our server and stores it with a managed image identifier. Original uploads and unused AI portraits are not added to the public board. Visitors can download board posters and record the reveal in their own browser. Sharing controls open an X draft; they do not post automatically.
You can remove your public seat, or replace its image, while signed in with the same wallet. Founders can remove members or close their company. Removing the last seat that uses an image immediately disables its public image link and attempts to delete the stored image bytes. Failed deletions and abandoned uploads older than 24 hours are retried in small batches during later boardroom changes, so cleanup may be delayed when the feature is inactive. Short-lived image identifiers, wallet addresses and upload times remain for abuse prevention, and cleaned image records are removed during later requests after 24 hours. Closed-company identifiers, creation time and limited ownership details may remain for request integrity and abuse prevention.
Copies already downloaded, cached or posted by other people cannot be recalled. The invite is public, not a secret credential. It never authorizes editing someone else’s seat. Boardroom titles are for entertainment and are separate from holding-based Proof of SUIT titles.
4. Technical information and security
Loading the site and requesting a portrait sends ordinary network information to our hosting infrastructure, including your IP address and request information. Hosting and security providers may process request times, requested addresses, browser information and diagnostic logs to deliver the site, investigate errors and protect it from abuse.
The portrait handler records limited error diagnostics, such as a provider response status, processing stage or general error category. It is not designed to log image contents, API credentials or raw provider error messages. The current portrait flow does not create a visitor profile or per-visitor generation-history record.
Earlier versions supported abuse-control records containing a keyed hash derived from an IP address, a request identifier, time, outcome and limited usage information. Those records did not contain the photo or raw IP address. Removing that feature does not itself delete any previously retained records; these identifiers are pseudonymous, not a guarantee of anonymity.
Technical records may be kept under the hosting providers’ retention settings and policies; we do not promise a fixed deletion period for those records. We use the information needed to provide the functions you request, maintain the service, address abuse and comply with applicable obligations. We may disclose information when required by law or necessary to address a security incident. No internet service can guarantee absolute security.
5. Other services your browser contacts
- Hosting: the site is delivered through Sites hosting and Cloudflare infrastructure. See Cloudflare’s privacy policy for its handling of end-user traffic.
- Google Fonts: pages request fonts from Google. Those requests expose network information, such as your IP address, to Google. See Google’s privacy policy.
- StonkFun: the receipts section requests public distribution totals and token prices directly from StonkFun, including periodic updates while the page is visible. StonkFun receives the network information needed to answer those requests. The totals are community data, not a request for your wallet holdings.
- Solana RPC: our server uses a Solana RPC service to read public SUIT holdings for Proof of SUIT. The service receives the public wallet address being checked and the requested token mint.
- External links: Jupiter, Dexscreener, X and other linked services have their own terms and privacy practices. Wallet providers also handle your connection and message-signing requests for Suit Shift under their own policies. Trades, sign-ins and posts on linked services happen on those external services. Public blockchain transactions are not made private by this policy.
Providers may process information in countries other than your own. Their applicable terms and safeguards govern their processing. We do not sell your uploads or game scores through this website.
6. Your choices
You can browse without generating a portrait, use the supplied default portrait instead of a personal photo, disconnect your wallet, play without submitting ranked scores, clear this site’s browser data to remove its local game best, and decide whether to download or share an image. Clearing browser data does not delete copies you downloaded, posts you published or provider-held records.
Depending on the law that applies to you, you may have rights to request access, correction or deletion of personal information, or to object to or restrict certain processing. Contact us using the route below. We may need enough information to locate a record and verify the request. Because we do not keep a portrait account history, we may not hold the image or record you ask about.
The website is intended for adults. If you believe a child has submitted personal information through it, contact us so the concern can be assessed.
7. Questions and updates
For a privacy question or request, contact the official SUIT account, @thesuitstayson on X, and ask for an appropriate private contact route. Do not post personal photos, identity documents, private keys or other sensitive information in public replies.
We may update this policy when the website or its data practices change. The date at the top identifies the current version. Our Terms of Use explain the rules for using the site.