Product privacy notice
Finance Privacy
Effective: 6 September 2026
A public wallet address and its public activity can be personal data when they identify or can be linked to a person. Do not connect another person's address without authority.
1. Controller and contact
vSecure Solutions LLC, 1309 Coffeen Avenue STE 1200, Sheridan, WY 82801, United States, is the controller for Finance product data. Contact privacy@vigthoria.io. Any appointed EEA representative or data protection officer details will be published here. You may complain to the supervisory authority in the EEA country where you live or work, or where the alleged infringement occurred.
2. Data and sources
- Account: Hub identifier, email, username, entitlement and security state, obtained from you and the authoritative Hub.
- Wallet: public address, CAIP-10 identifier, chain, verification and sync timestamps, obtained from your wallet, public blockchains and your selected indexing provider.
- Authentication: short-lived SIWE nonce/session hashes, login/security events and network metadata. Raw private keys, seed phrases and the raw session bearer are not requested or retained.
- Workspace: paper profiles, saved limits, watchlists, generic research requests, model outputs and source/freshness metadata.
- Transaction evidence, only where released: independent user instruction, disclosure approval, unsigned quote, transaction hash and public receipt evidence.
- Security: IP/network metadata, tamper-evident security logs and passkey public credentials. Authenticator seeds are encrypted.
- Minimised analytics: server-allowlisted activation milestones linked to a keyed pseudonym and aggregate count. These exclude wallet addresses, holdings, pairs, amounts, prompts, IP addresses and profit/loss.
3. Purposes and legal bases
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide the requested subscription and workspace | Account, settings, wallet link and requested outputs | Performance of contract; steps requested before contract |
| Authenticate, prevent abuse and protect systems | Security, session and network events | Legitimate interests in service security; legal obligation where applicable |
| Measure first-party product activation | Keyed milestone pseudonym and counts | Legitimate interests in improving the paid software, subject to minimisation and objection rights |
| Comply with law and resolve disputes | Relevant account, security and transaction evidence | Legal obligation; establishment, exercise or defence of legal claims |
| Optional processing expressly offered as consent-based | Only the data described at collection | Consent, withdrawable at any time |
4. Recipients and processor categories
Data is disclosed only where needed to the Vigthoria Hub/Pay services, infrastructure and security providers, professional advisers under confidentiality, authorities where legally required, and user-selected technology providers such as Reown, Alchemy, RPC services and—only where the transaction workflow is released—0x. A public address may be sent for indexing or quote construction. We do not sell private keys or send seed phrases.
5. International transfers
Some recipients may process data outside the EEA. A restricted transfer may proceed only under a documented adequacy decision or appropriate safeguard such as approved standard contractual clauses, with supplementary measures where required. You may request information or a copy of the relevant safeguard from the privacy contact, subject to lawful redactions.
6. Retention
Expired SIWE and approval challenges are removed after their short operational grace periods. Keyed activation milestones are scheduled for deletion after 400 days. Wallet links remain until disconnect or verified Finance-profile erasure. Workspace settings and research history remain while the Finance profile is active, then are deleted on verified erasure unless a proportionate legal, security or dispute hold applies. The hold duration is determined by the applicable limitation or legal-retention period. Payment and tax records are retained by the authoritative billing service for its legally required period. Public blockchain records cannot be erased by Vigthoria.
7. Automated processing and AI
Machine-generated scenarios are disclosed in the interface and have no authority to move funds or make a legally binding decision about you. The central service does not make a solely automated decision with legal or similarly significant effect. Research output is not copied into transaction fields.
8. Your controls and rights
You can disconnect a wallet, download Finance data using the in-product export, or erase the local Finance profile using the protected erasure control. Ecosystem account and billing requests are handled by the Hub. Depending on applicable law, you may request access, correction, erasure, restriction, portability, or object to processing; withdraw consent without affecting earlier lawful processing; and complain to a supervisory authority. We will verify identity and respond within the applicable period.
9. Required data and consequences
Account and authentication data are required to provide a protected paid workspace. A wallet address is optional for research and paper mode but required for wallet portfolio indexing. If required data is not provided, the related feature will remain unavailable.
10. Security and changes
Finance uses TLS, HttpOnly SameSite cookies, exact-origin mutation checks, short-lived challenges, encrypted security credentials, least-privilege access and signed audit controls. No internet service is risk free. Report suspected compromise to security@vigthoria.io. Material notice changes will receive a new effective date and notification where required.