Privacy
Wallet addresses and verified email addresses are stored as account identities under an internal UUID. Session cookies authenticate your requests. Magic-link tokens and session tokens are stored as hashes, not raw tokens.
We store watchlists, alert preferences, state notifications and subscription-provider metadata. Private keys, wallet signature bodies, SIWE nonces, magic-link tokens and payment card details are not analytics payloads.
First-party usage analytics use a random anonymous session identifier before login and an internal user ID after login. Payloads are restricted to symbol, timeframe, universe and entrypoint. Device cookies are used for referral anti-abuse checks; the server stores keyed hashes rather than browser fingerprints.
Configured email delivery providers receive the destination email address and transactional email content. Payment providers, if enabled later, process payment details independently. This build does not enable payment collection.
Data retention: No automatic account/analytics purge schedule has been enabled in this build. A production retention period must be confirmed before commercial release.
Account deletion requests: a verified support contact must be published before commercial release; this draft does not invent a contact address.