Exchange keys
- You create the key yourself on the exchange, granting read permission only. We ask for no trade permission and no withdraw permission.
- Keys are stored encrypted.
- You can revoke a key from the exchange at any moment, without asking us, and it stops working immediately.
- Where an exchange reports whether a key is read-only, a key with trade permission is rejected before it is stored rather than accepted and trusted.
The worst case in a breach is therefore exposure of read-only data and read-only keys. Those cannot move funds. That is a deliberate ceiling on the damage, chosen up front.
Wallets
We read public addresses. There is no field to enter a seed phrase or a private key anywhere in the product, and we would not know what to do with one if you sent it.
A public address reveals history and balances, which is why it is enough for us to rebuild your picture, and it is also why it can never authorise a transaction.
Identity and accounts
No identity verification and no document uploads. You sign in with a wallet or a Google account. A wallet sign-in proves you control an address; it grants us nothing else.
You can delete your account, and doing so removes your data rather than deactivating it.
Check this rather than believe it
Everything above is verifiable without trusting us. Read-only is a property of the key you created, so look at what permissions you granted on the exchange side. If a tracker ever asks for withdraw permission or a seed phrase, that is the moment to stop, whoever it is.