Skip to content

Privacy policy

Last updated 18 September 2026.

We collect the minimum we need to run the product: name, email, password hash, wallet ledger, activation metadata, and SMS bodies for a limited time.

What we store

Account data stays until you request deletion, subject to legal holds. Ledger rows are kept for accounting. Full SMS bodies are kept for 30 days, then redacted to the OTP code and hash metadata.

Cookies

We set a first-party session cookie and a CSRF cookie so you can stay signed in and submit forms. They are HttpOnly where possible, and Secure in production. We do not run a third-party ad pixel in v1. Analytics, if enabled later, is Plausible and does not require a cookie banner on its own.

What we do not do

We do not sell your data. We do not run a third-party fingerprint vendor in v1. IP and user agent hashes are used for abuse review and retained for about 90 days.

Processors

Payments go through Stripe or Cryptomus when those flags are on. SMS delivery goes through our provider adapters on the API. The website does not call those providers from the browser.

Requests

Use Contact for access or deletion. Security issues go to [email protected].