Privacy
Last updated:
What we store
- Your Privy DID — the upstream account identifier from Privy. We use it to find your row.
- Wallet addresses you give us (Privy embedded wallet, plus any extras you label).
- Profile fields — display name, country (used for jurisdiction gating), default chain, your auto-confirm cap.
- Watchers — the price triggers you set up.
- Action history — the transactions you confirmed (summary, calldata, tx hash, timestamps, signed-card metadata, requesting IP, user-agent).
- Audit log — security-relevant events (HMAC verify failures, sanctions hits, jurisdiction blocks). Kept for support / abuse cases.
- Email — surfaced from Privy when you've verified one. Used only to send the watcher / tx notifications you opted into.
What we don't store
- Your private keys. Privy holds them in a TEE / sandboxed iframe — we never see them.
- Anything you didn't explicitly hand us.
Who we share with
Operationally we hand specific bits to specific providers:
- Privy — auth, embedded wallets, optional account-deletion webhook.
- DeepSeek — your chat messages + balance summary at request time. We do not send wallet addresses or signed-card metadata.
- DexScreener / CoinGecko / 1inch / OpenOcean / LI.FI / Reservoir — public market-data and routing endpoints. We send the token / chain / amount you're asking about; we do not send your identity.
- Resend — only the recipient email + the email body, when you've opted into a notification.
- Sentry — server error stack traces. We scrub user data; if a payload slips through, request its deletion via the email below.
We do not sell your data. We do not run third-party analytics on the in-app surface.
Cookies
We use a single first-party session cookie (Privy uses its own secure cookies for auth). We do not use advertising or tracking cookies. The on-screen banner asks for your acknowledgement of the session cookie before the app sets it.
Your rights
- Export — Settings → Account → Download all my data ships a signed JSON of everything we have on you.
- Delete — Settings → Account → Delete account cascades through your profile, watchers, and action history in one transaction.
- Correct — most fields are inline-editable in Settings; for anything else, email support@fetchy.fun.
Retention
Your action history and audit log are retained as long as your account exists. Deletion removes them in a single transaction. Backups, where present, age out within 30 days.