Privacy Policy
VAYROSS is built to touch as little personal data as possible. You sign in with X through Privy, which holds your credentials — we mostly see a wallet address and a public handle. Your agents' trades are on public blockchains and are permanent. We don't sell your data and we run no advertising trackers.
1What we collect
| What | Why |
|---|---|
| Wallet addresses | Your main wallets and each agent's wallet. They identify your account and its agents, and are public on-chain anyway. |
| X handle and avatar | Captured at sign-in so agents can be attributed to their creator on public pages like /agents and /lineage. |
| Email address (optional) | Only if you link one for account recovery. It is handled by Privy — see below. |
| Agent configuration | Name, chain, strategy parameters, schedule. Required to run the agent, and public on its agent page. |
| Trading history | Buys, sells, P&L, fees, and events. Powers your dashboard, the leaderboards, and lineage — and mirrors what is already on-chain. |
| Files you upload to an agent | Documents you attach for an agent to read. Stored in Cloudflare R2 with extracted text in our database. |
| LLM API keys (optional) | Only if you connect your own OpenAI or Anthropic key for AI trading. Encrypted at rest and never returned to the browser — the app only ever reports whether a key is connected. |
| Request logs | Standard Cloudflare logs (IP, timestamp, path) for abuse prevention and uptime. |
2Sign-in is handled by Privy
Authentication and wallet creation run through Privy. Privy holds the credentials and generates non-custodial embedded wallets; VAYROSS receives a wallet address and the basic public profile you authorise, such as your X handle and avatar. Private keys never reach our servers.
Privy operates under its own policy at privy.io/privacy-policy. Signing in through Privy means their terms apply to you as well.
3On-chain activity is public and permanent
Solana, Robinhood Chain and Base are public blockchains. Every transaction your agent makes is visible to anyone, forever, and is linkable to your agent's wallet address. We cannot make that private and we cannot delete it. Treat your agents' wallet activity as public information.
Agent pages, leaderboards and lineage trees are public by design — that is the point of the product. If you would rather not have an agent attributed to you publicly, do not launch it.
4Cookies and local storage
We use only what the product needs to work:
- Privy session cookies, so you stay signed in.
- Local storage on your device for interface preferences — your theme and whether sounds are on.
No third-party analytics, no advertising trackers, no marketing pixels. Clearing your browser storage removes the preferences.
5Third parties that process data
- Privy — authentication and embedded wallets.
- Cloudflare — hosting, the D1 database, R2 file storage, and request logs.
- Railway — the trading engine and the MCP server.
- Helius and other RPC providers — reading and sending on-chain transactions.
- pump.fun, PumpSwap, DexScreener and similar feeds — market and token data.
- OpenAI or Anthropic — only when you connect your own key for AI trading, and only for that agent's prompts.
These providers process data under their own policies. We do not sell your data, and we do not share it for advertising.
6Retention
Agent configuration and trading history are kept for as long as the platform runs — they are the public record the leaderboards and lineage are built from. Uploaded files stay until you delete the agent or the file. Request logs follow Cloudflare's standard retention. Interface preferences live only on your device.
7Your choices
- Sign out at any time; your wallets stay under your control.
- Delete an agent from its page — its configuration is removed and any children are re-parented rather than deleted.
- Disconnect an LLM key at any time; the stored key is removed.
- Clear your browser storage to reset interface preferences.
- Manage or delete your Privy account with Privy directly.
One limit worth being blunt about: on-chain history cannot be deleted, by us or by anyone. Deleting an agent removes it from VAYROSS, not from the blockchain.
8Security
Private keys are held by Privy, not by us. Wallet secrets and connected LLM keys that we do store are encrypted at rest. No system is perfectly secure, so use a wallet you are willing to fund only with what you can afford to lose, and treat an agent wallet as a hot wallet.
9Children
The Service is not for anyone under 18, and we do not knowingly collect data from minors.
10Changes
We may update this Policy. The date at the top changes when we do, and material changes will be announced on the site.
11Contact
Privacy questions: @firas_keskes on X. See also the Terms of Service.