Privacy Policy
- ✓ We collect what the app needs to work: your wallet addresses, encrypted keys, orders/trade history, optional recovery email, IP for security, and push tokens if you enable notifications.
- ✓ We do not run analytics or ad trackers, and we do not sell or share your personal information.
- ✓ You have rights — access, correction, deletion, and more — and can complain to a data-protection authority. Email us to use them.
- ✓ We can delete your account and off-chain data on request, but we cannot delete transactions already recorded on a public blockchain — those are permanent and outside our control.
- ✓ Some data is processed by named providers (blockchain RPCs, Jupiter, price/chart APIs, Cloudflare, Google push/AI) — listed below with their role and region.
1) Overview
TokenLight Alert provides crypto price alerts and optional automated trade execution (limit orders). The app includes an AI assistant (TokenLight Sentry) to help you create watches and understand wallet activity.
2) Data We Collect
A. Account and authentication
- ✓ An anonymous account identifier and authentication token for your session.
- ✓ A last-seen timestamp to help manage active/inactive sessions.
B. Wallet and transaction data (custodial)
- ✓ Wallet addresses.
- ✓ Encrypted private keys.
- ✓ Encrypted seed phrases/mnemonics (where applicable).
- ✓ Limit orders, trade records, withdrawals, and transaction hashes.
C. Alerts and monitoring
- ✓ Alerts/watches you create: token address, targets, direction, chain, and status.
D. Recovery and security
- ✓ Recovery email (optional) and verification metadata.
- ✓ OTP challenge metadata for abuse prevention (including IP address and user-agent).
- ✓ Password hash if you set a password (we do not store your plaintext password).
E. Push notifications (optional)
- ✓ Device push tokens and basic device metadata (platform / label).
- ✓ Web push subscriptions (endpoint + keys) when you enable browser notifications.
- ✓ Proactive market insights (optional, on by default, capped at 3/day): our server detects unusual price momentum on tokens you watch and may push an insight notification. These are generated by deterministic server-side math on price data — no AI model and none of your personal data is involved; you can disable them in Wallet → Security, or mute their dedicated Android channel.
F. AI assistant (TokenLight Sentry)
- ✓ If enabled, you provide your own Gemini API key. We store it encrypted.
- ✓ Your prompts are sent from your device to Google Gemini using your key.
- ✓ We do not store your AI chat logs/conversations on our servers.
- ✓ Proactive insight notifications (section 2E) are separate from the chat assistant: they are computed server-side from market prices only and never use your Gemini key or chat content.
F2. Biometric app lock (optional)
- ✓ If you enable the fingerprint/biometric app lock, all biometric matching happens on your device via the operating system (Android Keystore / BiometricPrompt; iOS Keychain / Secure Enclave).
- ✓ We never receive, transmit, or store your biometric data — the app only receives a pass/fail signal from your device.
- ✓ If you choose “use fingerprint next time” for sends, your password is stored in your device’s OS Keystore/Keychain, not on our servers.
F3. Referral program (optional)
- ✓ If you use referrals we store your invite code, the referrer/referred link between accounts, and a ledger of referral earnings (amounts, USD value, payout status and transaction hashes).
- ✓ Referral payouts go to your own in-app wallet addresses — we never ask for external payout details.
- ✓ Referral attach events are logged with IP address for abuse prevention.
F4. P&L share cards (optional)
- ✓ Share cards are rendered entirely on your device; nothing is uploaded to our servers. What you share, and with whom, is your choice via your device’s share sheet.
G. Chrome extension (optional)
- ✓ The extension stores a local popup window ID in Chrome storage to reopen/focus the app.
H. Analytics and advertising
- ✓ We do not run in-app analytics SDKs or advertising trackers.
3) How We Use Data
- ✓ Provide app functionality (alerts, limit orders, wallet operations).
- ✓ Deliver notifications when enabled (browser/device push).
- ✓ Security and abuse prevention (OTP tracking and rate limiting).
3a) Legal bases for processing (GDPR)
Where the EU GDPR applies, we rely on these legal bases:
- ✓ Performance of a contract (Art. 6(1)(b)) — to operate your custodial wallet, execute swaps and orders, and provide the core Service.
- ✓ Legitimate interests (Art. 6(1)(f)) — security, fraud/abuse prevention, sanctions screening, and keeping operational/audit records; balanced against your rights.
- ✓ Consent (Art. 6(1)(a)) — optional features such as push notifications and the AI assistant; you can withdraw consent at any time.
- ✓ Legal obligation (Art. 6(1)(c)) — where we must comply with applicable AML, sanctions, or other law.
4) Third parties and sub-processors
Depending on which features you use, limited data is processed by the providers below (their role and typical region are noted). We share only what each provider needs, and we do not sell or share your personal information for advertising or any other purpose.
- ✓ Google Firebase Cloud Messaging — push-notification delivery; receives your device push token (US / global).
- ✓ Email/SMTP provider — delivers recovery codes; receives your recovery email address (region depends on the provider).
- ✓ Cloudflare — hosting, edge delivery, security, and basic traffic logs; may process your IP address (global edge, US company).
- ✓ Blockchain RPC providers (e.g. Alchemy, QuickNode and other Ethereum RPCs; Helius for Solana) — read chain state and submit your transactions; receive wallet/transaction data that is in any case public on-chain (US / global).
- ✓ DexScreener — token/pair data, pool resolution, and token safety checks (receives token contract addresses only).
- ✓ GeckoTerminal — chart candle (OHLCV) data (receives pool/token addresses only, no personal data).
- ✓ TradingView Lightweight Charts™ — the open-source library that renders in-app charts (runs locally; no data leaves your device through it). Attributed to TradingView per its license.
- ✓ honeypot.is — Ethereum token safety checks (receives token contract addresses only, no personal data).
- ✓ Jupiter — Solana swap execution and token safety/sellability checks (receives token/transaction data).
- ✓ Google Gemini — only if you enable the AI assistant; your prompts are sent from your device using your API key, subject to Google’s terms (US / global).
4a) International data transfers
Some sub-processors above (for example Google/Firebase, Cloudflare) are based in or route data through the United States or other countries outside the EU/EEA. Where we transfer personal data internationally, we rely on an appropriate safeguard — such as the European Commission’s Standard Contractual Clauses or an adequacy decision (e.g. the EU–US Data Privacy Framework where applicable). You can contact us for more detail on the safeguard used for a given transfer. Separately, public blockchains are global by design: any transaction you make is replicated across nodes worldwide.
5) Data Retention
We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it. Indicative periods:
- ✓ Account, wallet, and encrypted key material — for the life of your account; deleted after account closure/deletion (subject to any legal-retention obligation).
- ✓ Orders, trade ledger, and withdrawal history — retained for operational and audit integrity while your account is active and for a reasonable period afterward.
- ✓ Security/OTP and audit logs (incl. IP) — a limited period sufficient for abuse-prevention and security review, then deleted.
- ✓ Recovery email — until you remove it or delete your account.
On-chain transactions are not subject to these periods — they are permanent on the public blockchain and cannot be deleted (see Section 7).
6) Security
We encrypt sensitive wallet data (private keys and seed phrases) at rest, store passwords only as secure hashes, and apply access controls and the account-protection measures described in the Terms. Your optional AI API key is stored encrypted and used only to call the AI provider on your behalf. No method of transmission or storage is 100% secure, and because the wallet is custodial a compromise of our systems could expose key material.
Breach notification: if a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority and affected users without undue delay, as required by law.
7) Your Choices
- ✓ You can choose not to link a recovery email.
- ✓ You can choose not to enable AI and not provide an API key.
- ✓ You can control notifications via device/browser settings.
Your rights
Subject to applicable law (including the GDPR), you have the right to:
- ✓ Access the personal data we hold about you, and get a copy.
- ✓ Rectify inaccurate or incomplete data.
- ✓ Erase your data (“right to be forgotten”) — subject to the on-chain limit below.
- ✓ Restrict or object to certain processing (including processing based on legitimate interests).
- ✓ Data portability — receive certain data in a portable format.
- ✓ Withdraw consent at any time for processing based on consent (e.g. notifications, AI).
To exercise any right, email [email protected]. You also have the right to lodge a complaint with a data-protection supervisory authority — for example, in Ireland this is the Data Protection Commission (dataprotection.ie), or the authority in your EU/EEA country of residence.
On-chain data (important)
We keep personal data off-chain in systems we control, so we can honour access and deletion requests for that data. However, transactions you make are recorded on public blockchains (Ethereum, Solana) by networks the Provider does not control. Those on-chain records are permanent and cannot be edited or deleted by us or anyone — including wallet addresses and transaction history — even after you delete your account. Please keep this in mind before transacting.
Automated processing
Limit orders, OCO/bracket orders, and trailing stops execute automatically based on your instructions, and the token safety checker scores tokens, not people. We do not use your personal data to make automated decisions that produce legal or similarly significant effects about you within the meaning of GDPR Art. 22.
Data deletion requests
You can request deletion of your account and associated data by emailing [email protected].
- ✓ Subject: Data deletion request
- ✓ Include your account ID (shown in Wallet → Recovery in the app) and the email you linked (if any).
- ✓ We may ask for additional information to verify ownership before deletion.
- ✓ We aim to respond within 14 days.
8) Children
TokenLight Alert is not intended for anyone under 18 (or the age required in your jurisdiction).
8a) California privacy rights (CCPA/CPRA)
If you are a California resident, you have additional rights. In the past 12 months we collect the categories described in Section 2 — identifiers (e.g. account ID, wallet addresses, IP), optional contact data (recovery email), financial/transaction records, device data (push tokens), and, if you enable it, your AI API key — for the business purposes in Section 3.
- ✓ We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We run no advertising or analytics trackers.
- ✓ You have the right to know/access, delete, and correct your personal information, to limit use of sensitive personal information, and to not be discriminated against for exercising these rights.
- ✓ To exercise these rights, email [email protected] (subject: “California privacy request”). We may verify your request before acting.
9) Changes
We may update this policy from time to time and will change the “Last updated” date and version above; we review it at least every 12 months. For material changes we will provide notice (for example, in-app) and, where the change affects consent, ask you to review and accept again. Continued use after an update means you accept the revised policy.