Xochi
Trade

Privacy Policy

Last Updated: August 2026

1. Introduction

Xochi is designed with privacy as a core principle. We implement data minimisation, encryption-by-design, and zero-knowledge proofs to protect user privacy while meeting regulatory obligations.

2. Information We Collect

Wallet Address: Public blockchain address for service identification. Stored for session duration plus logs.

Transaction Data: Trade intents and execution data necessary for order fulfillment. Retained while needed to complete and reconcile the order, and afterwards only as long as law requires.

Trust Score Data: Credential hashes from identity providers you connect. We store hashes only, not raw credentials. Retained until you revoke.

IP Address: Used for rate limiting and security. Kept for the rate-limit window and any active abuse investigation, then purged.

Error Reports: When a swap fails, we store sanitised diagnostic data: intent ID, status, and a truncated browser user-agent string (basic browser information). Beyond that string we do not collect device identifiers, browser fingerprints, or usage analytics.

3. Information We Do Not Collect

We do not collect: private keys, seed phrases, government ID numbers or images, biometric data, full names or addresses, social security numbers, or any raw personally identifying information (PII).

4. How We Use Information

We use your information to execute trades and process intents, calculate Trust Scores and fee rates, detect and prevent fraud, comply with legal obligations, and improve the Service.

5. Zero-Knowledge Compliance (Xochi's ZK Compliance Oracle)

Xochi's ZK Compliance Oracle is a planned design. It is not live yet. As of July 18, 2026 we do not run sanctions screening, risk scoring, or anti-structuring checks on your trades, and no compliance oracle sits in the trade path.

When it ships, compliance checks will run as zero-knowledge circuits: your device generates a proof, and verifiers confirm it without seeing your trade amounts, exact scores, or screening details. We will update this policy before any screening goes live.

6. Privacy Levels

You control your privacy level for each trade. When you execute a trade, solvers receive information based on your selected tier:

Open/Public: Full trade details visible.
Standard: Trading pair and amount visible.
Stealth: Trading pair and amount range only.
Private: Trading pair only.
Sovereign: Nothing visible until fill.

7. Data Sharing

We share data with cloud infrastructure providers (Cloudflare for hosting and delivery, Datadog for server logs), identity providers for verification, and solvers for trade execution based on your privacy tier. Server logs include the IP address your request came from.

If a swap fails and you send us a report, that report records your wallet address, the IP address it came from, and your browser version, so we can find the failure. It is only created when a swap fails.

We may disclose information when required by valid subpoenas, court orders, or government requests. We do not sell your personal data.

8. Security

We use TLS 1.3 for all connections, AES-256 encryption at rest, zero-knowledge proofs for compliance, and role-based access controls. We conduct regular security audits and maintain a bug bounty programme.

No security measures are perfect. You are responsible for maintaining the security of your wallet and private keys.

9. Your Rights

You may request access to, correction of, or deletion of your personal data (subject to legal retention requirements and blockchain immutability). You may withdraw consent by disconnecting identity providers.

To exercise rights, contact us with your wallet address. We verify identity by requesting a signed message from your wallet.

10. Regional Rights

EEA (GDPR): Data transfers rely on Standard Contractual Clauses. You may lodge complaints with your supervisory authority.

California (CCPA/CPRA): You have rights to know, delete, and opt-out. We do not sell personal information.

Other: We comply with UK-GDPR, Brazil LGPD, and Switzerland FADP.

11. Cookies and Local Storage

Xochi does not set cookies. Not for sign-in, not for security, not for wallet state, not for anything. We add no analytics and load no third-party scripts, so nothing here follows you to other sites. One exception we do not yet control: the wallet library contacts WalletConnect, including a usage-reporting address they run, when any page loads. See Cookies and Local Storage.

The app does save a small amount of data in your browser's own storage so it can remember your theme, your recent swaps on this device, and your sign-in for the current tab. That data stays on your device. It is never sent to us. Clearing your browser data removes it.

See exactly what Xochi saves in your browser, what each item is for, and how to clear it.

12. Data Retention

Attestations are kept until you revoke them. Tier proofs and risk scores expire automatically after 7 days. Trade metadata, IP addresses, and logs are retained while needed for service delivery, security, and legal obligations, then purged. Blockchain data is permanent and immutable.

13. Contact

For privacy-related inquiries or to exercise your rights, contact us at [email protected]

HomeLearnWhitepaperTermsPrivacyCookiesPublic Goods