Architect// privacy
← back to siteopen app

Privacy

We ask for no email, no name and no documents. This page lists everything we keep, and it is not much.

Updated July 2026

01What we store

When you activate the agent, the following is tied to your account:

  • Your public wallet address. It is your identifier. Never the private key, which never reaches us.
  • Your preferences: risk profile, whether you picked the pools or let the agent pick, and the simulated capital you set.
  • The agent's activity in your pools: positions, decisions and results. This is what feeds your dashboard.
  • Your invite code and, if you arrived through one, who invited you.

02What we do not store

No email, no name, no phone, no address, no identity documents. There is no registration and no identity verification. If you lose access to your wallet we have no way to identify you, because we never knew who you were.

03Cookies: two, and none for advertising

  • Session (7 days). Encrypted, readable only by the server. Holds your address after the signature is verified. It is what keeps you inside the app between visits.
  • Invite (30 days). Only exists if you arrived through an invite link, and holds just the code. Deleted as soon as the link is made.

Both are httpOnly: no script on the page can read them, including our own.

04No tracking, no third parties

We use no Google Analytics and no other statistics or tracking tool. There are no pixels, no data sharing with third parties, and we sell nothing to anyone. We have no cookie banner because there is nothing for you to consent to.

Two honest caveats: the hosting that runs the app logs requests (IP address, timestamp) like any server, and the blockchain is public by nature. What your wallet does on-chain is visible to everyone, with or without us.

05Evidence record

We keep a record of moments that could later be disputed, for your protection and ours: when you accepted the terms and which version was in force, and your wallet authentications (the message you signed and the signature). If a dispute ever arises about what was authorised, this is what settles it with facts instead of accounts.

Alongside each of those records we keep your user agent (the browser you used) and a hash of your IP address. We keep the hash and not the IP: it is enough to tell whether two visits came from the same origin, and it cannot be turned back into the address.

These records are immutable by design: not even we can alter or delete them once written. An evidence record you can edit proves nothing.

06Where it lives and for how long

The data sits in a managed database (Supabase), reachable only by the application server. Nothing is read directly by the browser. We keep the history for as long as the account exists, because that is what lets us show you your performance over time.

07Leaving and being forgotten

You can ask to leave, through the contact below and by proving control of your wallet. What we do is called anonymisation, and we would rather describe it in detail than call it "deletion" and let you discover the difference afterwards.

Your wallet address is replaced with an irreversible value — not even we can reconstruct it afterwards. You stop being identifiable and you lose access. Your invite code is disabled. It is final: there is no way back.

Three things survive, and here is why:

  • The evidence record from section 05, for as long as a dispute could still arise. Deleting it would defeat the purpose it exists for, and it protects you as much as us.
  • Invites and rewards.If you invited someone, those records belong to those people and to the money they generated too. We cannot destroy them on a third party's request.
  • Whatever is on the blockchain, which cannot be deleted by us or by anyone.

We answer within 30 days, even if only to refuse and explain why.

08Contact

For any question about personal data, reach us through the channels listed on the site. We answer in Portuguese or English.

SecurityPrivacyTerms