Privacy Policy
Local-development draft — last updated 17 July 2026
1. Information handled by this build
The account API handles a display name, email address, E.164 phone number, password hash, verification state, and account activity needed to operate the local account service. Passwords and verification codes are never stored in plain text.
2. Security and session data
Sessions are stored server-side. The browser receives only an HttpOnly session cookie. Where recorded, IP address and user-agent values are stored as keyed hashes rather than plain values. Account activity records include events such as sign-in, sign-out, password reset, contact change, and administrative account blocking.
3. Why data is used
- to create and secure an account;
- to verify ownership of an email address or phone number;
- to investigate security-sensitive account activity; and
- to maintain the service and prevent abuse.
4. Sharing and payments
This local build does not connect to payment providers, blockchain RPC services, wallets, or Google OAuth. No real cryptocurrency transaction, private key, seed phrase, or Google Client Secret is collected or stored.
5. Your choices
Before a public launch, this policy must be completed with the legal entity, contact method, retention schedule, jurisdiction-specific disclosures, and a process for access, correction, deletion, and complaint requests.
This draft is provided for local development only and is not a substitute for advice from qualified privacy or legal professionals.