Privacy Policy
Last updated 7 October 2026. This page explains what Onagi collects about you, why, who else sees it and what you can ask us to do about it. It is part of the Terms of Service.
Two honest starting points. First, we do not run identity verification today, so we hold less about you than a regulated exchange would; that may change, and this page will change with it. Second, blockchain activity is public and permanent by design. We cannot delete it, and neither can you.
1. Who we are
The controller of the personal data described here is Onagi. You can reach us at [email protected].
2. What we collect
We collect only what the Service needs to work, to stay safe and to meet our legal duties.
| What | Where it comes from |
|---|---|
| Wallet address and the signatures you make | Your wallet, when you sign in or authorise something |
| Email address, or a Google or X identifier, and the embedded wallet created for it | Privy, our authentication provider, when you sign in that way |
| Telegram user id, username, first name, language setting and chat id | Telegram, only if you link the bot |
| Profile name, picture, cover and bio, the accounts you follow, and comments and likes you post on token pages | You, if you set or post them |
| Trading and ledger records: orders, fills, positions, fees, pocket moves, rewards and agent settings | Your use of the Service |
| IP address, request logs, approximate location derived from the IP, user agent, device and browser data, timestamps | Automatically, at the edge (Cloudflare) and on our servers |
| Message text you send to the assistant or the Telegram bot, and what it replies | You, when you use those features |
| Notification subscription, if you turn notifications on | Your browser provides a delivery address and encryption keys for sending notifications to this device |
| Browser storage: preferences and cached view state (see section 12) | Your own browser |
| Support correspondence | You, when you write to us |
We do not ask for and never want your recovery phrase or private key. We do not collect government identity documents today. We do not knowingly collect special category data, and you should not send it to us or type it into the assistant.
3. Why we use it
- To run the Service: to authenticate you, hold your account, route orders, keep the history, move money between your pockets at your request, calculate and send rewards, run the agent you enabled, and answer you in chat or on Telegram.
- To keep it safe: to detect and stop wash trading, self-crossing, reward abuse, multiple accounts, bots, scraping, denial of service attempts, account takeover and fraud.
- To meet legal duties: to comply with sanctions law and our geographic restrictions, to respond to lawful requests from authorities, to keep financial records, and to establish or defend legal claims.
- To improve the Service: to measure reliability and performance, to find and fix bugs, and to understand which parts of the platform are used, using aggregated data wherever we can.
- To tell you things you need to know: service messages, security notices and changes to these documents.
We do not sell personal data. We do not run advertising trackers and we do not share your data with advertising networks or data brokers.
4. Legal bases
Where data protection law such as the GDPR applies to you, our legal bases are:
- Performance of a contract: everything needed to give you the account and the Service you asked for.
- Legitimate interests: security, abuse and fraud prevention, network and service integrity, product improvement, and defending legal claims. We balance these against your rights, and you can object as described in section 8.
- Legal obligation: complying with sanctions law, including freezing an account we learn is linked to a sanctioned person or address, record keeping and lawful requests.
- Consent: where we ask for it, for example if we ever add optional analytics or marketing messages. You can withdraw consent at any time, without affecting what was done before.
5. Who receives it
We share the minimum needed with the following categories of recipient, each under a contract or under their own published terms.
| Who | What they get, and why |
|---|---|
| Privy | Authentication, embedded wallets and wallet signing: your email or social identifier, your wallet address and the transactions signed from it. |
| Cloudflare | Delivery, caching and protection, including the human check at sign-in (Turnstile): IP address, request metadata, browser and security signals. |
| Google Fonts | The site's typefaces load from Google's font servers, so your browser sends your IP address and browser details to Google when a page opens. |
| WalletConnect | The sign-in library loads a wallet directory from WalletConnect when the app opens: your IP address and browser details. |
| Browser push services | Only if you turn on notifications: your browser maker's push service (for example Google, Apple or Mozilla) receives a subscription address for your device and the notifications we send to it. |
| Logo and image sources | Some market logos and pictures load from where they are published (such as Lighter, CoinGecko, Polymarket, GitHub and IPFS gateways), which see your IP address and browser details. |
| Chain node and RPC providers | Reading and broadcasting Robinhood Chain and Polygon transactions: addresses and transaction data, plus the connection metadata any network request carries. When you open Bring, your browser also asks public node providers on other networks for your address's balances there. |
| Relay (cross-chain bridge) | Only when you use Bring, to bring money from another network or convert ETH in your wallet: your wallet address, the networks, the token and the amount, needed to quote and complete the transfer. |
| Trading venues: Pons, Uniswap pools (v2, v3 and v4), Lighter, Polymarket | Order and position data needed to execute and settle what you asked for. |
| Telegram | If you link the bot: your Telegram id and the messages you exchange with it. Our team's internal alert channel can also carry a shortened wallet address and an amount. If the assistant passes your question to our team, the question, your name or username and a shortened wallet address go to the team's internal Telegram group. |
| DeepSeek | Assistant and agent language features: the messages you send and earlier turns of the conversation, your wallet address, your Telegram name and username, and the account data the assistant looks up to answer, such as balances, positions and trade history. Telegram conversations may also be reviewed by it in daily batches to sort and label support problems. Our team's internal operations alerts, including shortened wallet addresses and amounts, are also processed for triage. Do not put secrets, keys or sensitive personal details into those messages. |
| Z.ai | Backup language model, used only when DeepSeek does not answer: the same messages and context. |
| Anthropic | AI tools our team uses to operate and maintain the platform. They can process operational data such as wallet addresses, trading records and logs, including the messages involved in a problem we are looking into. The assistant you chat with does not run on Anthropic's models. |
| Anyone who opens your profile | Your wallet address, profile name, picture, cover and bio, the month you joined, who you follow and who follows you, and comments you post on token pages. While you are listed on the leaderboard (the default; switch off Show me on the leaderboard in Edit profile to hide), also your open and closed positions with their results, your account total and its curve. |
| Hosting and infrastructure providers | Servers, storage, logging and monitoring for the platform. |
| Professional advisers, authorities and successors | Lawyers, auditors and accountants under duties of confidence; courts, regulators and law enforcement where we are legally required or permitted; an acquirer or successor entity if the business is reorganised or transferred, subject to this policy. |
Third parties named here act as separate controllers or as our processors depending on the service; their own privacy notices apply to what they do with your data.
6. On-chain data is public and permanent
Deposits, withdrawals, swaps and settlements are transactions on a public blockchain. Anyone can read them, copy them and keep them forever, and anyone who links your wallet address to your identity can see your history. Nobody, including us, can edit or delete a confirmed transaction.
The rewards ledger is published as part of how we prove the platform is honest: each cycle records which wallet received how much. Those records are wallet based, not name based, but they are still permanent and public. Treat every address you use on Onagi as public.
7. How long we keep it
- Account, ledger and financial records: kept for as long as you have an account and afterwards for as long as we are required to keep financial records or need them to establish, exercise or defend legal claims. Where a retention period is prescribed by law, that period applies.
- Security and request logs: kept for a short period, ordinarily up to 12 months, unless a log is part of an open investigation.
- Assistant and bot messages: kept without a fixed end date, so the assistant can refer back to earlier conversations and so we can look into problems and abuse. You can ask us to delete them at any time.
- Support correspondence: kept while the matter is open and for a reasonable period afterwards.
- Backups: copies of our data, kept on our own servers and with our storage provider, are retained for up to 90 days and removed by scheduled pruning.
- On-chain records: permanent, and outside anyone's control.
8. Your rights
Depending on where you live, you may have the right to:
- ask what we hold about you and get a copy;
- have inaccurate data corrected;
- have data deleted, where the law allows and where we are not required to keep it;
- restrict or object to processing based on our legitimate interests;
- receive data you gave us in a portable format;
- withdraw consent where processing is based on consent;
- complain to your data protection supervisory authority.
Write to [email protected]. We may need to verify that the request comes from the holder of the account, ordinarily by asking you to sign a message with the wallet in question. We answer within one month where the GDPR applies, and without undue delay otherwise.
The honest limits. We cannot delete anything recorded on a blockchain, because no one can. We cannot delete ledger and financial records we are required to keep, or records we need to defend a claim or to prevent fraud. Deleting the account data we can delete may make the account unusable, and it does not reverse settled trades or payouts.
9. International transfers
Onagi is operated across borders and our providers are in several countries, including the United States, the European Union and China, where our language model providers DeepSeek and Z.ai are based. Your data will therefore be transferred outside the country where you live, to places whose data protection law may differ from your own.
Where the law requires a basis for a transfer, we rely on what the law provides for that transfer, such as an adequacy decision, contractual clauses or, where neither is in place, the transfer being necessary to give you the service you asked for, such as an answer from the assistant, together with technical measures like encryption in transit. Our language model providers process messages under their own published terms. You can ask us which basis applies to a particular transfer.
10. Children
The Service is for adults only. It is not directed at anyone under 18, and we do not knowingly collect data from anyone under 18. If we learn that we hold data of a child, we will delete what we can and close the account. If you believe a child is using Onagi, tell us at [email protected].
11. Security
We use encryption in transit, access control on our systems, rate limiting, monitoring and alerting. Your embedded wallet is yours; its key is secured by Privy, not by Onagi. To trade for you, our servers hold a signing permission for your wallet, limited by a signing rule at Privy (see section 4 of the Terms), and a trading key for your Lighter account, which is deleted once you have removed the permission and your positions there are closed. The platform's day-to-day wallets, the treasury that sends payouts, the buyback wallet and the wallet that supplies gas, are run by our servers, each with its own key, and hold running money only. The treasury's long-term wallet is kept offline and its key is on none of our servers. Trading fees taken from your wallet first land in a fee vault contract from which our servers can draw only a daily limit. Every movement these wallets make is public on Robinhood Chain.
No system is perfectly secure. We cannot guarantee that our systems, our providers' systems, the chain or your own device will not be compromised. Protect your login and your wallet, use a strong unique password and two factor authentication where your login provider offers it, and never share your recovery phrase with anyone, including anyone claiming to be us.
12. Cookies and browser storage
We do not use advertising cookies or tracking pixels, and nothing here follows you to other sites.
- Local storage in your browser holds your own preferences and view state so the app opens the way you left it: the sidebar state, sound setting, palette, navigation and recent searches, the last wallet you used, chart settings, and small caches of prices and lists. This data stays in your browser, is readable only by this site, and you can clear it from your browser settings at any time. Clearing it signs you out of some conveniences but never affects your balance.
- Authentication cookies and storage set by Privy keep you signed in. Without them you would have to sign in on every page.
- Cloudflare may set a security cookie to distinguish real visitors from automated traffic and to protect the site from attack.
- Session storage keeps your Onagi sign-in session while the tab is open; your browser clears it when you close the tab.
- Two preference cookies set by this site, each kept for up to 30 days:
onagi_telremembers whether the app opens in the phone or the computer layout, andonagi_ayrikremembers if you asked to keep the introduction pages and the app on one address. They hold only that choice.
These are all strictly necessary or preference storage. If we ever add analytics that use cookies or follow you across sites, we will ask for consent first.
13. Changes to this policy
We may update this policy. The date at the top changes with it, and a material change is announced on the site or in the app before it takes effect. Continuing to use the Service after that date means you accept the updated policy.
14. Contact
Questions, requests and complaints go to [email protected]. If you are in the European Economic Area or the United Kingdom and you are not satisfied with our answer, you may complain to your national supervisory authority.
Also read the Terms of Service and the Risk Disclosure.