free sign in →

Privacy Policy

Last updated: 2026-05-14 · Effective date: 2026-05-25

Summary

We collect the minimum data needed to deliver subscriptions: an email address, payment metadata (handled by our payment processors — we never see your card number), and optionally your Telegram handle (if you link Telegram for real-time alerts). We don't sell or share your data with advertisers. We don't track you across the web.

1. What we collect

  • Account data: email address, password hash (never plaintext), account creation timestamp, last login timestamp.
  • Subscription data: tier, billing period, payment method, subscription status, current period end date.
  • Payment metadata: for Stripe — Stripe customer ID, subscription ID, charge IDs (we never see your card number; Stripe handles all PCI scope). For crypto — your sending wallet address, chain, token, and transaction hash for confirmation.
  • Telegram (optional): if you link Telegram, your chat ID and username, so our bot can deliver alerts.
  • Server logs: IP address, user agent, request timestamps, and request paths — for security monitoring, rate-limiting, and abuse detection. Logs are retained 30 days then rotated out unless flagged for an incident investigation.

2. What we do NOT collect

  • Card numbers, CVVs, or any direct payment instrument data.
  • Your wallet's private keys (we never ask for them; Sifaka does not custody your funds).
  • Cross-site browsing behavior. We do not deploy ad-network tracking pixels, third-party analytics that profile you across sites, or fingerprinting beyond what's needed for security.
  • Personal data beyond what you give us. We don't enrich your email with data brokers.

3. How we use the data

  • Deliver the subscription you paid for (tier resolution, signal dispatch via web / Telegram).
  • Process payments and renewals via Stripe and on-chain watchers.
  • Send transactional email — receipts, renewal reminders, security alerts. We do NOT send marketing email.
  • Detect abuse (account sharing, scraping, payment fraud) and enforce rate limits.
  • Internal product analytics — aggregate-only metrics on subscription growth, tier mix, churn. No individual-user behavior tracking.

4. Third parties [LEGAL]

We share specific data with the following processors:

  • Stripe (payments) — full payment data including card. Their privacy policy: stripe.com/privacy.
  • Telegram (alerts, optional) — only if you opt in by linking your account. Your TG metadata is sent to Telegram per their normal API.
  • Pinata + IPFS (commitment plaintext, 30-day delayed) — published publicly as part of our public trust stack. The plaintext does NOT contain your personal data; it's the signal record itself.
  • Polygon blockchain (commitment hashes) — we publish SHA-256 hashes of our signals to Polygon. These hashes do not contain your data.
  • Fly.io (hosting) — our application infrastructure. Their privacy policy: fly.io/legal/privacy-policy.

We don't sell your data, ever. We don't share with advertisers.

5. Data retention

  • Account data: retained while you have an active account; deleted within 30 days of account deletion request (subject to legal hold for tax / compliance records).
  • Payment records: retained for 7 years for tax and accounting purposes per applicable law.
  • Server logs: 30 days, then aggregated / deleted.
  • Signal commitments on Polygon & IPFS: permanent and immutable by design — they're the basis of our public track record. They contain no personal data.

6. Your rights [LEGAL — GDPR / CCPA / etc.]

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and personal data, subject to retention obligations above.
  • Object to or restrict certain processing.
  • Data portability — receive a copy of your data in a machine-readable format.
  • Withdraw consent where processing is consent-based.

To exercise any of these rights, email privacy@chronax.ai from the address on your account. We respond within 30 days.

7. Cookies & tracking

We use a small number of strictly necessary cookies — session cookies for keeping you signed in, CSRF tokens, payment-flow continuity. We do NOT use analytics cookies that track you across the web. We don't deploy advertising trackers.

Your browser's Do-Not-Track header is honored where applicable.

8. Security

We use industry-standard practices: HTTPS everywhere, password hashing (Argon2 / bcrypt), secrets stored in encrypted secret managers (Fly.io secrets, 1Password), least-privilege access, and audit logging of admin actions. We are committed to disclosing material breaches within 72 hours of discovery as required by applicable law.

9. Children

Sifaka is not directed at children under 18. We do not knowingly collect data from minors. If you believe a minor has signed up, contact us and we will delete the account.

10. Changes

Material changes to this policy will be announced via the email on file at least 14 days before they take effect.

11. Contact

Email: privacy@chronax.ai
Operating entity: [ENTITY NAME TBD]