Skip to content

Privacy Policy

Last updated: 20 September 2026 · Version 2026-09-20-draft

We are a non-custodial interface and we ask for no account. There is no email address, no password and no name unless you choose to add a display name to a profile.

Against your public wallet address, we store:

What Why
Your allocations — which algos, what fraction, copy or counter It is the instruction we act on
Your per-algo ledger and fee high watermarks So you are not charged twice for the same recovery
Your profile, if you create one — handle, display name, bio, avatar The social layer, and it is opt-in
Your acceptance of these documents, with version and timestamp Evidence that you were shown the current terms
Which announcements you have dismissed So a notice you have read does not reappear
Sign-in sessions A cookie proving you control the address

Your wallet address is already public and already on a public blockchain. What we add is the link between that address and the activity above.

  • Your private keys. We never see them. Signing happens in your wallet.
  • Your venue funds. The delegated key can place and cancel orders. It cannot withdraw.
  • Your identity, unless you volunteer it in a profile.

Creating a profile does not publish your portfolio or your P&L. Both are off until you turn them on, and when they are off they are absent from the public response rather than present and empty — a stranger cannot tell the difference between “holds nothing” and “does not share”.

Your identicon is derived from your address. It reveals nothing your address does not already reveal.

One session cookie, set after you sign in with your wallet. It is httpOnly, so no script on the page can read it, and SameSite=Lax. It exists to prove you control your address. We do not use advertising or cross-site tracking cookies.

We do not sell your data. We share it only with:

  • The venues you connect, because that is where your orders go;
  • Infrastructure providers hosting the service;
  • Anyone, where you have explicitly made it public through your profile.

Burning PNL to submit an algorithm is an on-chain transaction. It is public, permanent and outside our control. So is any token transfer you make.

Profile fields can be changed or cleared at any time.

Two things cannot be deleted, and the reasons are structural rather than convenient:

  • Fee ledgers, because deleting one resets a high watermark and silently charges you again for a recovery you already paid for. Exiting an algo sets your multiplier to zero and keeps the row.
  • Published announcements and your acceptance records, because both exist to evidence that you were told something before it happened. A record that can be deleted afterwards evidences nothing.

A formal retention schedule and the erasure rights that apply to you belong here and have not been determined.

See Support.