Privacy Policy
Last Updated: April 2026
1. Introduction
Xochi is designed with privacy as a core principle. We implement data minimisation, encryption-by-design, and zero-knowledge proofs to protect user privacy while meeting regulatory obligations.
2. Information We Collect
Wallet Address: Public blockchain address for service identification. Stored for session duration plus logs.
Transaction Data: Trade intents and execution data necessary for order fulfillment. Retained for 90 days.
Trust Score Data: Credential hashes from identity providers you connect. We store hashes only, not raw credentials. Retained until you revoke.
Technical Data: IP address, device info, and browser type for security and rate limiting. Retained for 7 days.
3. Information We Do Not Collect
We do not collect: private keys, seed phrases, government ID numbers or images, biometric data, full names or addresses, social security numbers, or any raw personally identifying information (PII).
4. How We Use Information
We use your information to execute trades and process intents, calculate Trust Scores and fee rates, detect and prevent fraud, comply with legal obligations, and improve the Service.
5. Zero-Knowledge Compliance (Xochi's ZK Compliance Oracle)
Xochi's ZK Compliance Oracle is a planned design. It is not live yet. As of July 18, 2026 we do not run sanctions screening, risk scoring, or anti-structuring checks on your trades, and no compliance oracle sits in the trade path.
When it ships, compliance checks will run as zero-knowledge circuits: your device generates a proof, and verifiers confirm it without seeing your trade amounts, exact scores, or screening details. We will update this policy before any screening goes live.
6. Privacy Levels
You control your privacy level for each trade. When you execute a trade, solvers receive information based on your selected tier:
Open/Public: Full trade details visible.
Standard: Trading pair and amount visible.
Stealth: Trading pair and amount range only.
Private: Trading pair only.
Sovereign: Nothing visible until fill.
7. Data Sharing
We share data with cloud infrastructure providers (Cloudflare) for hosting, identity providers for verification, and solvers for trade execution based on your privacy tier.
We may disclose information when required by valid subpoenas, court orders, or government requests. We do not sell your personal data.
8. Security
We use TLS 1.3 for all connections, AES-256 encryption at rest, zero-knowledge proofs for compliance, and role-based access controls. We conduct regular security audits and maintain a bug bounty programme.
No security measures are perfect. You are responsible for maintaining the security of your wallet and private keys.
9. Your Rights
You may request access to, correction of, or deletion of your personal data (subject to legal retention requirements and blockchain immutability). You may withdraw consent by disconnecting identity providers.
To exercise rights, contact us with your wallet address. We verify identity by requesting a signed message from your wallet.
10. Regional Rights
EEA (GDPR): Data transfers rely on Standard Contractual Clauses. You may lodge complaints with your supervisory authority.
California (CCPA/CPRA): You have rights to know, delete, and opt-out. We do not sell personal information.
Other: We comply with UK-GDPR, Brazil LGPD, and Switzerland FADP.
11. Cookies
We use essential cookies for session management, security, and wallet connection state. These cannot be disabled. We use privacy-respecting analytics (Cloudflare) with anonymised data. We do not use advertising cookies.
12. Data Retention
Attestations are kept until you revoke them. Tier proofs and risk scores expire after 7 days. Trade metadata is purged after 90 days. IP addresses and logs are purged after 7-30 days. Blockchain data is permanent and immutable.
13. Contact
For privacy-related inquiries or to exercise your rights, contact us at [email protected]