Legal
Privacy Policy
XAUConnect Labs ("we", "us") respects your privacy. This policy explains what information we collect when you use XAUConnect, how we use it, and your choices.
Last updated: June 22, 2026
1. Scope
This Privacy Policy applies to the XAUConnect website at xauconnect.com, our web application, admin tools, and public API. It does not govern third-party wallets, RPC providers, block explorers, or DeFi protocols you interact with through the Interface — those services have their own privacy policies.
2. Non-custodial design
XAUConnect is non-custodial. We do not collect or store your seed phrase, private keys, or wallet passwords. Signing happens in your wallet extension or mobile app. We cannot access funds in your wallet without a transaction you authorize on-chain.
3. Information we collect
3.1 Wallet & on-chain data
- Public wallet addresses you connect or submit in API requests (for quotes, builds, swap recording, and admin analytics)
- On-chain transaction hashes you voluntarily submit via
POST /swap/recordor similar endpoints - Connected wallet metadata such as chain ID, connector type, and connection timestamps when you opt in to wallet tracking for product analytics
Blockchain data is public by design. Anyone can view transactions associated with your address on chain explorers.
3.2 Usage & API data
- IP address, user agent, referrer, and request timestamps (server and CDN logs)
- API route, parameters (token addresses, chain keys, amounts — not private keys), response status
- Optional client identification headers:
X-Client-Id,X-Client-Name,X-Client-Source - Quote and build request metadata stored for routing quality and abuse prevention
3.3 Account data (admin only)
The admin dashboard at /xaxmd5 uses email/password authentication for authorized operators. Credentials are hashed; session tokens are stored server-side. This applies only to admin users, not general swap users.
3.4 Cookies & local storage
- Essential storage: theme preferences, slippage settings, recently selected tokens, session tokens for admin login
- Analytics: we may use privacy-conscious analytics to measure page performance and feature usage. No advertising cookies are required to swap.
4. How we use information
We use collected information to:
- Provide swap quotes, transaction builds, and cross-chain routing
- Record completed swaps for analytics, fee reconciliation, and DeFiLlama-style transparency
- Detect abuse, rate-limit API traffic, and protect infrastructure
- Improve routing, UX, and documentation
- Operate admin dashboards (connected wallets, swap volume, API agent attribution)
- Comply with legal obligations and enforce our Terms
We do not sell your personal information to data brokers.
5. Legal bases (EEA/UK users)
Where GDPR applies, we process data based on:
- Contract / legitimate interest: operating the Interface you request
- Legitimate interest: security, fraud prevention, and product improvement
- Consent: where required for non-essential cookies or marketing (if ever offered)
- Legal obligation: responding to lawful requests from authorities
6. Sharing & processors
We may share limited data with:
- Infrastructure providers: cloud hosting (e.g. Azure), CDN (Cloudflare), database (PostgreSQL)
- Blockchain RPC providers: Alchemy, Helius, and public RPC endpoints to fetch chain state
- Aggregator partners: 1inch, 0x, Jupiter, bridge APIs — only parameters needed to obtain quotes (wallet address may be included as
takeroruser) - Law enforcement: when required by valid legal process and permitted by law
Processors are bound by contractual confidentiality and data-processing terms where applicable.
7. Retention
- API logs: typically retained up to 90 days for operations and security, unless longer retention is required for disputes or law
- Swap records: retained in our database for analytics and protocol reporting until deleted as part of routine data lifecycle policies
- Admin sessions: expire automatically; refresh tokens rotated on logout
- Server logs: rotated per hosting provider defaults (generally 30–90 days)
8. Security
We use TLS encryption in transit, access controls on production servers, and hashed credentials for admin accounts. No system is perfectly secure; you should use hardware wallets for large holdings and verify contract addresses before signing.
9. International transfers
Our servers may be located outside your country (including Southeast Asia and cloud regions used by Azure and Cloudflare). By using the Interface, you acknowledge that data may be processed in jurisdictions with different privacy laws than your own. Where required, we implement appropriate safeguards for cross-border transfers.
10. Your rights
Depending on your location, you may have the right to:
- Access personal data we hold about you
- Request correction or deletion of certain data
- Object to or restrict processing
- Data portability (where technically feasible)
- Withdraw consent for optional processing
- Lodge a complaint with a supervisory authority
Because most data we hold is tied to public wallet addresses, deletion may be limited where records are needed for fraud prevention, accounting, or legal compliance. Contact us to exercise rights.
11. Children
The Interface is not directed to persons under 18. We do not knowingly collect data from children. If you believe a minor has provided information, contact us for deletion.
12. Changes
We may update this Privacy Policy. The "Last updated" date at the top reflects the latest revision. Material changes may be announced on the website or in release notes.
13. Contact
Privacy inquiries and data subject requests: [email protected]. Data controller: XAUConnect Labs. See About for company details.