Legal

Privacy Policy

This Privacy Policy explains what information Aegis processes when you connect a wallet and use our non-custodial, wallet-first platform for crypto trading automation, and how we handle it.

This document is a template provided for general informational purposes only. It is not legal advice and does not create any attorney-client relationship. You should have qualified legal counsel review and adapt this policy to your specific circumstances and jurisdiction before relying on it.

Last updated: 2026

1. Overview

Aegis uses wallet-first authentication. You sign in with a cryptographic wallet signature (Sign-In With Ethereum, EIP-4361) rather than an email address and password, and there is no traditional sign-up process. Because of this, we do not collect an email address, a password, or the kind of personal profile that conventional accounts require in order to use the core platform. Your identity to Aegis is, by default, your verified wallet address.

Optional convenience features may involve additional data. If you choose social login and an embedded wallet through Privy, or use a fiat on-ramp provider, those services process data under their own terms as described below.

2. Information We Process

To operate the platform, we process a limited set of data:

  • Wallet identifiers. Your public wallet address in CAIP-10 form, including any additional wallets you link for multi-wallet access and recovery, and the signatures you produce to authenticate or to authorize sensitive actions (step-up).
  • Connection metadata. Metadata about the venues and services you connect, such as which exchange a trade-only API key belongs to and its configuration. This lets us route orders and manage risk on your behalf.
  • Usage and telemetry. Operational data generated as you use the platform, such as strategy and risk settings, orders and positions, backtests you run, log and audit entries, and basic technical information needed for security, reliability, and debugging.

Just as importantly, there is data we do not have:

  • We do not have your wallet private keys or seed phrase. These never leave your wallet, and Aegis never asks for them.
  • We do not expose your exchange API secret. Exchange API keys are envelope-encrypted with a key-management service, and the secret is never returned by the API to you or any third party.
  • We do not take custody of your funds. Aegis is non-custodial and never holds, signs for, or moves your assets.

3. How We Use It

We use the information we process to:

  • authenticate you by verifying wallet signatures and, for sensitive actions, a fresh step-up signature, and to support multi-wallet account recovery;
  • provide the core service, including connecting to your chosen venues, running the strategies and risk controls you enable, executing backtests, and delivering market data and notifications;
  • maintain security and integrity through our immutable audit trail, tenant isolation, deterministic risk engine, and abuse and fraud prevention;
  • operate, monitor, and improve the reliability and performance of the platform, and to comply with applicable legal obligations.

Automation on Aegis starts disabled and acts only after you explicitly opt in, and any use of your data to act on your behalf is bounded by the settings and permissions you configure.

4. Third Parties

Aegis interoperates with third-party services that you choose to connect or that are required to deliver specific features. These providers are independent, are not controlled by Aegis, and process data under their own privacy policies and terms:

  • Exchanges and market data (for example, Binance), which receive the order and market-data requests needed to trade and to display live prices.
  • Fiat on-ramp (for example, Transak), which you may use to convert fiat to crypto; the provider collects and handles any identity or payment information required for that transaction directly.
  • News classification (for example, APITube), which supplies the news feed we classify deterministically to inform optional, off-by-default risk controls.
  • Wallet and login providers such as MetaMask, WalletConnect (Reown), and Privy, if you choose to use them.

We share only the data necessary for each service to perform its function. We do not sell your personal information.

5. Data Security

We apply defense-in-depth to protect the data we process. Exchange API keys are envelope-encrypted with a key-management service (AWS KMS), and the secret is never returned by the API. Multi-tenant data isolation is enforced at the database layer using PostgreSQL Row-Level Security, so one tenant cannot access another's data. An append-only, double-entry ledger derives balances from immutable sums, and an immutable audit trail together with a transactional outbox provides a verifiable record of activity.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You remain responsible for safeguarding your own wallets, keys, passkeys, and recovery methods.

6. Cookies

We use a minimal set of cookies and similar technologies for functional purposes, such as keeping you signed in and maintaining your session and preferences. We do not rely on cookies to build advertising profiles. Where required by law, we will request your consent before setting non-essential cookies, and you can control cookies through your browser settings.

7. Your Rights

Depending on your jurisdiction, you may have rights over the data we process, including the rights to access, correct, delete, or export it, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. Because authentication is wallet-first, some requests may require you to demonstrate control of the relevant wallet by signing a message. To exercise your rights, contact us using the details below; some data, such as immutable audit and ledger records, may be retained where necessary for security, integrity, or legal compliance.

8. Changes

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above, and material changes may be communicated through the platform. Your continued use of Aegis after changes take effect constitutes your acceptance of the revised policy.

9. Contact

Questions about this Privacy Policy, or requests relating to your data, can be sent to hello@aegis.trade.