Public documentation · Demo

Privacy notice

What data we process, why, who receives it and what rights you have — written against the actual product code: every claim here corresponds to something verifiable in our repository. We would rather tell you what is not solved yet than promise what the system does not do.

Last updated: 1 August 2026 · Version 2026-08-01

0Where you are: a bounded public demo

Astryum is in a public validation demo phase: anyone can register and try the product with real XRP on mainnet, inside deliberate limits — a per-operation cap and daily limits whose current values the app shows you before you act. It is experimental software in active development, built in the open during the XRPL and Flare builder programs.

This notice explains, with the detail Regulation (EU) 2016/679 (“GDPR”) requires, what we process and what rights you have.

1Who the controller is

ControllerEric G. F. natural person, established in the Principality of Andorra
NRT (Andorran tax id)228765X
Contact (privacy & rights)astryum@astryum.xyz — the controller’s address is provided to authorities and upon legitimate request
EU representative (art. 27 GDPR)Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria — you can address it to exercise your rights (e.g. access or erasure); appointment publicly verifiable at app.prighter.com/portal/astryum

The controller is established in the Principality of Andorra, which is not part of the EU or the EEA: a third country whose data-protection level the European Commission recognises as adequate (Decision 2010/625/EU, confirmed in the Commission’s January 2024 review). In practice: Andorran data-protection law (Llei 29/2021) applies to us under the supervision of the APDA — and, because we offer the service to EU residents, the GDPR also applies to us via its Article 3.2. The rights this notice grants you are full GDPR rights.

No data protection officer is appointed: given the size and nature of this phase, it is not mandatory.

2What data we process and where it comes from

What you give us

  • Email — when joining the waitlist or creating an account (the only field the waitlist asks for).
  • Password — stored only as a hash (scrypt), never in clear text.
  • Username, name and avatar — optional; the avatar is a downsized image in our database, never an external URL.
  • Wallet addresses — when connecting or binding: address, type, network and the nickname you give it.
  • Messages to the AI assistants — what you write travels to our AI provider (section 4).
  • Region — if you pick it in Settings it stays in your browser; it only travels attached to DeFi execution requests and we do not store it.

What using the service generates

  • IP and browser (User-Agent) — your session IP is stored with it; all requests land in the server’s technical logs.
  • Positions and balances — portfolio snapshots read from the public chains.
  • Audit records — what was prepared, when, and the address involved; never the signed transaction.
  • Binding signature — the cryptographic signature proving the address is yours.
  • Agent conversations — the only assistant that keeps history; you can delete it yourself.
  • Record of your acceptance — the terms version, this notice’s version and the date. Not only at sign-up: if you came in with a wallet, or if we change a text materially, we present it again when you enter the dashboard.

Third-party data you enter

If you add someone else’s address to your watchlist, we process that address and your label. That address may belong to another person: by adding it, it is on you to have a legitimate reason to watch it. We process it as part of the service you request, never enrich or cross it with other sources, and delete it when you remove it.

What we do NOT collect: no analytics, no pixels, no geolocation, no identity documents. Details in section 10.

3Purposes and legal bases

Account & authenticationContract performance (6.1.b) — no account, no service.
Terms acceptance and record that this notice was shown to youEvidence obligation (6.1.c) + legitimate interest (6.1.f).
Wallets & portfolioContract performance (6.1.b) — the express request of the service.
Sessions with IP · logs · rate-limit · captchaLegitimate interest (6.1.f) — security and abuse protection; rate-limit counters in memory, not persisted.
Audit of prepared operationsLegitimate interest (6.1.f) — the proof that we only prepare and you sign.
AI assistantsContract performance (6.1.b) — only when you invoke the assistant.
WaitlistConsent (6.1.a) — withdraw by writing to us and we remove you.
Third-party watchlistLegitimate interest (6.1.f) — you supply the legitimacy over that address.

We do not use consent as a catch-all: where the basis is contract or legitimate interest, we say so and justify it. You can object to legitimate-interest processing (art. 21) by writing to us.

4Who receives your data

VercelHosts the web: every web request (IP, browser, pages). Frankfurt (EEA).
RailwayHosts backend and database: the data in section 2 and the technical logs. Amsterdam (EEA).
AnthropicProvider of the AI assistants (USA). Receives your message and context depending on the assistant — in several, your wallet addresses and values; the Legacy assistant anonymises them in your browser before sending. Keys, tokens and credentials never travel. We use their commercial API: content is not used to train their models and inputs/outputs are deleted in ~30 days.
Chain nodes & explorersFlare Networks, Ankr, Ripple, XRPL Cluster, explorers and the Flare Data Connector. The honest nuance: those queries leave from our server — the provider sees the queried address and our IP, not yours. But not everything leaves from the server: what your own browser requests is in the next row.
What your browser requests (sees your IP)CoinGecko, for prices and logos: it sees your IP and which assets you look up, never your address. Public XRPL nodes (xrplcluster.com, xrpl.link, s1.ripple.com) when broadcasting a signed council order and checking its settlement: they see your IP and the transaction, because it does not go through our server. Each EVM network’s default public RPC on some reads. The WalletConnect relay, only if you connect that way. And the logo and icon CDNs (cryptologos, icons.llama.fi, jsdelivr, Wikimedia, icons.duckduckgo.com), which from the image you request can tell which asset or protocol you are looking at. None of this carries analytics or profiling — but it carries your IP, and we would rather you knew. Serving those logos from our own domain would remove most of it: it is on the list and it has started — FXRP is already served from ours, so looking at an FXRP position tells no CDN anything; the rest still goes out.
GoPlus · DefiLlamaGoPlus receives contract addresses we screen for safety (never yours); DefiLlama, pool queries with no personal data.
CloudflareOnly when validating the form captcha: your IP and the challenge token (USA).
Email (Resend or Zoho)Your email and the waitlist message content, depending on the active transport.
Google / AppleOnly if you choose OAuth sign-in: they return your verified email.
Xaman (XRPL Labs)When signing with Xaman: the signing payload, via our server; the app on your phone shows it to you.

We do not sell or share your data with anyone for advertising. There are no recipients beyond those listed.

5Transfers outside the EEA

Your data at rest stays in the EEA (Frankfurt and Amsterdam). The controller accesses it from Andorra to operate the service: that transfer is covered by the Commission’s adequacy decision on Andorra (art. 45). The rest are limited to three flows, each with its safeguard:

  • Anthropic (USA) — assistant messages and context. Safeguard: Standard Contractual Clauses in its data-processing agreement (art. 46), plus the section-4 commitments.
  • Cloudflare (USA) — captcha IP. Safeguard: active participant of the EU-U.S. Data Privacy Framework (art. 45).
  • Resend or Zoho — the waitlist email, under the active provider’s agreement.

Beyond those three, the requests your own browser makes to third parties (section 4) may land on servers outside the EEA, depending on which node or CDN answers. We do not control those as a transfer of ours — they leave your device, not our servers — but they carry your IP, so we tell you anyway.

6How long we keep your data — the honest answer

In this demo phase we have not yet implemented automatic deletion: there is no job purging expired sessions and no delete-account button. In practice, unless you ask us otherwise, your data is kept for the duration of the demo phase. What we do guarantee:

  • If you request erasure, we manually delete your account and everything tied to it, and respond within one month at most (art. 12.3).
  • What you delete is deleted: unbound wallets, Agent conversations and documents, and your waitlist email if you opt out.
  • When the demo phase closes we will set definitive retention periods and publish them here before applying them.

7Data on public chains — what nobody can erase

What you sign is published forever. When you sign a transaction, your address, amount, asset, counterparty and timing are replicated across thousands of nodes, permanently and irreversibly. Neither we, nor you, nor an authority can erase them: erasure and rectification rights do not reach what is already written on a public chain — promising otherwise would be lying to you.

What is in our hands: we hold the link between your address and your identity (account, email, bound wallets) — and that link IS erasable. If you delete your account, your on-chain trail still exists, but it is no longer connected to your identity in our database.

Two public marks we would rather tell you about ourselves: (1) to complete certain operations, operational accounts of ours publish transactions referencing the one you signed — anyone analysing the chain can see your address operated through Astryum; (2) every XRPL transaction we prepare carries a public origin tag (SourceTag) identifying the project — a requirement of the builder program we take part in. Anyone can filter the chain by that tag and find the set of transactions made through Astryum, including yours. The tag goes only on what you sign; our own operational accounts go without it.

Our public transparency feed (/proof) shows what the chain already shows — hashes, amounts, timing — and never your address: an automated test guarantees it.

8Your rights

You have the rights of access, rectification, erasure (with the on-chain limit of section 7), objection, restriction and portability, and to withdraw the waitlist consent at any time. Write to astryum@astryum.xyz from your account email (or with proof of wallet control). We respond within one month at most.

Where to complain — you have two doors, not one:

  • Before the Andorran Data Protection Agency (APDA), the authority supervising us: www.apda.ad
  • And, if you live in the European Union, before your own country’s authority (in Spain, the AEPD). As we have no EU establishment, there is no “one-stop-shop”: your country’s authority is competent to hear you. You can also address our EU representative (section 1).

9Automated decisions

No automated decision produces legal effects on you or significantly affects you (art. 22): every operation on your capital requires your signature; the risk indicators we compute are information shown to you, not decisions applied to you; and the execution module may be region-limited, but you declare the region yourself — we do not infer it from your IP.

10What we do NOT do — and you can verify

  • Zero third-party analytics: no Google Analytics, no pixels, no external telemetry.
  • Zero geolocation: we do not infer your country from your IP.
  • Zero private keys: the server refuses to boot if it detects a user key in its environment.
  • Zero identity documents: we store no IDs, passports or selfies.
  • The waitlist is not readable from outside, and resubmitting an email does not reveal whether it was already on it.
  • The AI context is minimised by design: it never includes keys, tokens or credentials.
  • Your avatar triggers no third-party requests: a local image, never a remote URL.
  • Two cookies, both technical: the access-gate one (httpOnly, signed, no user identifier, 7 days) and the one remembering your EVM wallet connection state, which your browser can read and which holds the connected address, so a reload keeps you connected. No tracking or advertising cookies — that is why you see no banner: both are necessary for what you asked for, and that needs no consent.

11Changes to this notice

If we change this notice we will update the date above; if the change is material (new recipients, new purposes), we will announce it in the app before it takes effect. The published version at any given time is the one that applies.

This notice was written against the product code and is revised with every change affecting a described treatment.

Aviso de privacidad — Astryum