Privacy Policy
Last updated: February 1, 2026
Privacy at a Glance
- Wallet-first — No email, password, or personal identity required. Your wallet address is your account.
- Minimal data collection — We collect only what's necessary: wallet addresses, transaction data, and basic analytics.
- No data sales — We never sell your data to third parties. No advertising trackers or retargeting pixels.
- Non-custodial — We never have access to your private keys, seed phrases, or funds.
- On-chain transparency — All transactions are on public blockchains. Your on-chain activity is already public.
1. Introduction
This Privacy Policy ("Policy") describes how Alkizen ("we", "us", "our") collects, uses, stores, shares, and protects information when you use our multi-chain trading platform at alkizen.exchange and related services (the "Services").
Alkizen is a Web3-native platform that prioritizes user privacy. We operate on a wallet-first authentication model, meaning we collect significantly less personal data than traditional financial platforms. We do not require usernames, email addresses, phone numbers, or passwords.
By using the Services, you consent to the collection and use of information in accordance with this Policy. If you do not agree with the practices described in this Policy, please do not use the Services.
2. Information We Collect
2.1 Wallet & Blockchain Data
- Wallet Addresses: When you connect your wallet to Alkizen, we receive and store your public wallet address(es) for EVM chains (Ethereum, Base, Arbitrum, etc.). This is your primary identifier on the Platform.
- Transaction Data: We record details of transactions you execute through the Platform, including source and destination tokens, chain IDs, amounts, platform fees charged, Relay request IDs, transaction hashes, and transaction status. This data is also publicly available on-chain.
- On-Chain Activity: Information about your swap, bridge, DCA, and limit order activity as processed through Relay. This includes execution timestamps, gas fees, and output amounts.
- Authentication Signatures: When you sign in using Sign-In With Ethereum (SIWE), we process the signed message to verify wallet ownership. We do not store your private keys or seed phrases.
2.2 Automatically Collected Technical Data
- IP Address: Collected for rate limiting (per wallet and per IP) and basic security monitoring. IP addresses are not linked to wallet addresses in our analytics.
- Device Information: Browser type and version, operating system, screen resolution, and device type (desktop/mobile). Collected via standard HTTP headers.
- Usage Analytics: Pages visited, features used, buttons clicked, session duration, and general navigation patterns. Collected via privacy-respecting analytics (no cross-site tracking).
- Cookies: We use essential cookies for session management (SIWE auth tokens) and optional analytics cookies. See Section 7 for details.
- Error Logs: If an error occurs during your use of the Services, we collect diagnostic information including error messages, stack traces, and the state of the application at the time of the error. This data does not include private keys or sensitive wallet data.
2.3 User-Provided Data
- Referral Codes: If you share your referral code or use someone else's referral code, we store the referral relationship linking the referrer and referee wallet addresses.
- Quest & Leaderboard Data: Your quest progress, points earned, badges achieved, and leaderboard ranking are generated from your on-platform activity and stored in our database.
- Support Communications: If you contact us through social media or other channels, we may receive and store the contents of those communications.
3. How We Use Your Information
We use the information we collect for the following purposes:
Core Service Delivery
- Execute swaps, bridges, DCA orders, limit orders, and payments through the Relay protocol
- Display your transaction history, portfolio, and order status
- Calculate and distribute referral revenue share
- Track quest progress and update leaderboard rankings
- Authenticate your identity via wallet signatures
Platform Security & Integrity
- Rate limiting to prevent API abuse (per wallet address and per IP)
- Detect and prevent fraudulent activity, wash trading, and referral system abuse
- Monitor for suspicious transactions and potential platform manipulation
- Enforce our Terms of Service and protect the integrity of the leaderboard and quest systems
Platform Improvement
- Analyze usage patterns to improve user experience and interface design
- Identify and fix bugs, errors, and performance issues
- Understand which features are most valuable to users
- Plan future feature development based on usage data
Legal Compliance
- Comply with applicable laws, regulations, and legal processes
- Respond to lawful requests from government authorities
- Enforce our Terms of Service and protect our legal rights
4. How We Share Your Information
We are committed to minimizing data sharing. We do not sell your personal data to third parties. We may share information in the following limited circumstances:
Service Providers
- Relay Protocol: Transaction data is shared with Relay to execute swaps, bridges, and cross-chain operations. Relay processes this data according to their own privacy policy.
- Infrastructure Providers: We use cloud hosting (Vercel, AWS/Railway), database services (PostgreSQL), caching (Redis/Upstash), and monitoring (Sentry, Datadog) providers who may process data on our behalf under strict data processing agreements.
- Analytics: We use privacy-respecting analytics tools to understand platform usage. Analytics data is aggregated and does not include wallet addresses or transaction details.
Public Blockchain Data
- All on-chain transactions are inherently public. When you execute a swap, bridge, or other on-chain transaction, the transaction details (wallet addresses, token amounts, contract interactions) are recorded on the public blockchain and are visible to anyone.
- Alkizen does not add any additional personal data to on-chain transactions beyond what is required for execution.
Legal Requirements
- We may disclose information if we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation, subpoena, or court order; (b) protect and defend our rights or property; (c) prevent fraud or abuse of the Platform; (d) protect the personal safety of users or the public.
Business Transfers
- In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify users of any such change via the Platform.
5. Data Storage & Security
We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction.
Security Measures
- All data in transit is encrypted using TLS 1.3
- Database encryption at rest for sensitive fields
- API keys, secrets, and Relay credentials are stored in environment variables, never in client-side code
- Rate limiting per wallet and per IP address
- Input validation and sanitization on all API endpoints
- Regular security reviews and dependency audits
- Signed wallet authentication (SIWE) — no password-based authentication that can be compromised
Data Retention
- Transaction Records: Retained indefinitely for audit trail, leaderboard calculation, and referral tracking purposes. On-chain transaction data is permanently public regardless.
- Session Data: Authentication sessions (SIWE tokens) expire after 24 hours of inactivity.
- IP Addresses for Rate Limiting: Retained in Redis cache for up to 15 minutes and then automatically deleted.
- Analytics Data: Aggregated analytics data is retained for up to 24 months. Individual session data is retained for up to 90 days.
- Error Logs: Retained for 30 days, then automatically purged.
- Quest & Points Data: Retained for the lifetime of your account on the Platform.
While we implement industry-standard security practices, no method of electronic storage or transmission over the Internet is 100% secure. We cannot guarantee absolute security of your information.
6. Your Rights & Choices
Depending on your jurisdiction, you may have certain rights regarding your personal data:
Available Rights
- Access: You can view your transaction history, quest progress, referral data, and connected wallet addresses directly through the Platform at any time.
- Data Export: You can export your transaction history from the Platform for your records.
- Deletion: You may request deletion of your account data (quest progress, points, leaderboard rank, referral relationships) by contacting us. Note that on-chain transaction records and publicly recorded data cannot be deleted as they exist on public blockchains.
- Correction: If any data displayed on the Platform is inaccurate, contact us to request correction.
- Opt-Out of Analytics: You can disable optional analytics cookies through your browser settings. Essential cookies required for authentication cannot be disabled while using the Services.
- Wallet Disconnection: You can disconnect your wallet at any time by clicking the disconnect button in the app. This ends your active session but does not delete historical data.
To exercise any of these rights, contact us through our official social media channels (Twitter: @alkizenexchange). We will respond to requests within 30 days.
For users in the European Economic Area (EEA), United Kingdom, or other jurisdictions with specific data protection laws: our legal basis for processing your data includes (a) performance of our contract with you (the Terms of Service), (b) our legitimate interests in operating and improving the Platform, and (c) compliance with legal obligations.
8. Third-Party Services
The Services integrate with or link to the following third-party services, each with their own privacy policies:
Key Third Parties
- Relay (relay.link): Cross-chain execution infrastructure. Processes transaction data to execute swaps and bridges.
- Wallet Providers (MetaMask, Coinbase Wallet, Phantom, etc.): Handle wallet connection and transaction signing. Their data practices are governed by their respective privacy policies.
- WalletConnect: Wallet connection protocol. May process wallet connection metadata.
- Blockchain Networks: All transactions are recorded on public blockchains (Ethereum, Base, Arbitrum, etc.). On-chain data is permanent and public.
- Price Oracles (Pyth, Chainlink): Provide price data for limit order monitoring. We query prices but do not share user data with these services.
We encourage you to review the privacy policies of these third-party services. We are not responsible for their data practices.
9. Children's Privacy
The Services are not intended for individuals under the age of 18 (or the age of legal majority in their jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected information from a child, we will take steps to delete that information promptly.
If you believe a child has provided us with personal information, please contact us through our official channels.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country.
When we transfer data internationally, we implement appropriate safeguards to ensure your data is protected in accordance with this Policy. For users in the EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission for international data transfers where required.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and may provide additional notice through the Platform.
Your continued use of the Services after any changes to this Policy constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Twitter: @alkizenexchange (https://x.com/alkizenexchange)
Website: alkizen.exchange
For data protection inquiries from EEA/UK residents, please clearly state "GDPR Request" in your communication so we can prioritize your inquiry.