ITER · privacy policy

What we keep, and what we never see

ITER is a self-custodial interface: you hold your own keys, there is no identity check, and there is no account to create. You connect a wallet — that is the whole sign-in. The one exception is support: if you write to us, we keep the email address you give us so we can reply. This page lists everything the app receives.

Last updated 1 August 2026

Draft — not yet reviewed by a lawyer. Every red bracket below is a fact that has to be supplied (legal entity, jurisdiction, contact address). This describes what the software actually does; it is not legal advice and should not be published as-is.

Who this is about

This policy covers the ITER web application and the services behind it, operated by [legal entity name and registered address]. Questions or requests go to [contact email].

What we collect

Nothing at all, until you do one of the following. Browsing the app and connecting a wallet do not send us personal data.

  • Your wallet address, once you connect. Connecting tells us the address, which is what we use to show your positions and attribute referrals. No name and no profile — connecting gives us an address and nothing more.
  • Your wallet address — also if you join the waitlist. Pressing “Join the waitlist” stores your address and the time you joined. Nothing else: no balance, no activity.
  • Your email address and messages, if you contact support. The support panel asks for an email so we can reply, and stores that address along with everything written in the conversation, by you and by us. We never check that the address is yours and never link it to a wallet. Your browser keeps a key to the conversation so it can show it to you again — clearing site data loses the thread, and there is no way to recover it.
  • Usage analytics — only if you allow them. Off unless you accept in the cookie banner, and the scripts are never requested until you do. See the cookie policy.
  • Images you upload. If you create a token, the logo you upload is stored and served publicly. It is resized and re-encoded on upload, which strips any embedded metadata such as EXIF location tags.
  • Standard server logs. Our hosting provider records ordinary request data, including IP addresses, to run and secure the service. Our upload endpoint also uses your IP address to rate-limit abuse — held in memory only and never written to a database.

What we never collect

  • Your private keys or seed phrase. The app cannot see them, and nobody from ITER will ever ask for them.
  • Identity documents. There is no KYC on this interface.
  • A password. There is no account and no sign-in to steal. We hold an email address only if you gave us one in a support message, and never as a login.
  • Advertising or cross-site tracking data. No ad networks, no third-party tracking pixels, no profiles built about you.

We do not sell personal data, and we do not share it for advertising.

Blockchain activity is public, and permanent

Transactions you sign are recorded on a public blockchain by design. That data is not collected by us, is visible to anyone, and cannot be edited or deleted by us or by you — not by ITER, and not by any request under any law. A wallet address can often be linked to a person by combining public sources, so treat every onchain action as public.

Who else is involved

These providers process data on our behalf or as part of connecting you to a chain:

  • Vercel — hosting, plus analytics and performance measurement if you have allowed them.
  • Reown AppKit and WalletConnect — the wallet connection layer. Your own wallet provider has its own privacy policy and we do not control it.
  • RPC and indexing providers — reading chain state necessarily reveals your IP address and the addresses being queried to whoever serves that data.

Any transfer of data outside your country is handled under [transfer mechanism].

How long we keep things

  • Your referral link — while the programme runs. It records which wallet referred which, and nothing else about you.
  • Waitlist addresses — until launch, or until you ask us to remove yours.
  • Support conversations — the email address and the messages are kept after a ticket is closed, so we can pick the thread up if you write again. There is no automatic deletion. Ask us and we will delete a conversation and the address with it.
  • Your cookie choice, and the key to a support conversation — both in your own browser, until you clear it. Neither is sent to our servers on ordinary requests, and clearing them loses the support thread for good.
  • Uploaded images kept indefinitely; there is no automatic deletion. Images are stored by their content, so the same picture uploaded twice is stored once, and replacing a token's logo leaves the old one stored rather than removing it. An upload that is never attached to a token is also kept. Ask us and we will delete a specific image.
  • Server logs[retention period].

Your rights

Depending on where you live, you may have the right to ask what we hold about you, to correct it, to have it deleted, or to object to how it is used. Write to [contact email] and we will respond within [response window]. You can also complain to your local data protection authority.

The honest limit: we can delete a waitlist entry or an uploaded image. We cannot delete anything from a blockchain, because nobody can.

Children

ITER is not directed at children and is not intended for anyone under [minimum age]. We do not knowingly collect their data.

Changes

If we change this policy materially we update the date above and ask for your cookie choice again rather than carrying an old answer forward to terms you never saw.