Privacy policy
Last updated 2026-05-21
What we collect
- Wallet address. Used to scope your positions, workflows, signals, and API tokens.
- Sign-in nonces + JWT sessions. We verify a wallet signature on a one-time nonce, then issue a short-lived JWT stored in your browser's local storage.
- User preferences. Watchlist, notification toggles, Telegram link state, API token metadata (name, scope, daily cap, last-used timestamp).
- Operational telemetry. Request paths, status codes, and latency are logged for debugging and abuse detection. We do not log request bodies for mutation routes.
- Email (waitlist only). If you joined the waitlist, we store your email solely to send launch updates and beta-access invitations.
What we don't collect
- Private keys, seed phrases, or signing material — Nereid never receives them.
- Off-chain identity (legal name, address, ID) — we do not run KYC.
- Browser fingerprints or third-party advertising trackers.
On-chain data
Every transaction you sign is public on Sui mainnet. We index it for your dashboard, but the data is already on-chain and not confidential. Linking your wallet to off-chain identity is your responsibility.
Cookies + storage
We use local storage and IndexedDB for session JWTs, theme preferences, dismissed banners, and a small offline cache of market data. We do not set third-party cookies for advertising.
Third parties
- Sui RPC providers. We proxy reads for performance. Your wallet address is visible in proxied queries.
- Telegram. If you link a Telegram account, we store your chat_id and forward signals to it according to your notification preferences.
- Anthropic. Copilot and digest features call the Claude API. Prompts include anonymized market context, never your wallet address.
- Cloudflare. The frontend is served from Cloudflare Pages; standard edge access logs apply.
Retention
Account, position, and preference data are retained as long as your account exists. Operational logs are retained for 30 days. Waitlist emails are retained until launch + 90 days, then deleted.
Your rights
You can disconnect your wallet, unlink Telegram, and revoke API tokens from the app's Settings page at any time. To request account deletion or a copy of your data, email privacy@nereid.finance.
Changes
Material changes to this policy will be announced via the in-app banner. Continued use after a change constitutes acceptance.