Privacy Policy
Grailo is built to be privacy-light. It is a mostly client-side interface: you interact with the blockchain through your own wallet, and we collect as little as we can. This policy explains what limited information is involved when you use Grailo, how it is used, and the choices you have.
1. Information involved when you use Grailo
Wallet address
When you connect a wallet, we receive your public wallet address and read publicly available on-chain information associated with it (such as token balances and the cards you hold) so the interface can display your holdings and build transactions. A public wallet address is pseudonymous but may be linkable to you.
On-chain activity
Transactions you sign — purchases, sales, listings, offers, and similar — are recorded on the public Solana blockchain. This data is public, permanent, and outside our control; it cannot be edited or deleted by us or by you.
Information stored on your device
We use your browser’s local storage to remember preferences and session details — for example your theme choice, your most recently connected wallet, and, if you use LITCOIN fee tiers, the link between your connected wallet and your external staking wallet. This information stays on your device and is not an account on our servers.
LITCOIN linking
If you opt into LITCOIN fee tiers, you may link an external (Base/EVM) wallet and sign a message to prove control of it. We use the resulting address and signature solely to read your staked balance from LITCOIN’s API and apply the correct fee tier.
Technical and log data
Like virtually all websites, our hosting and content-delivery infrastructure may automatically process limited technical data (such as IP address, browser type, and timestamps) to deliver the site, maintain security, and prevent abuse. Where we use analytics, we aim to use privacy-respecting, aggregate measurement only.
2. What we do not collect
We do not collect or store your private keys, seed phrase, or wallet passwords. We do not require you to create an account or provide your name, address, or government identification to use the core interface.
3. How information is used & legal bases
- to operate and display the interface, including your holdings and transaction previews;
- to calculate and collect the applicable service fee, including LITCOIN-based fee discounts;
- to maintain security, prevent fraud and abuse, and debug and improve the Service; and
- to comply with applicable legal obligations.
For users in the European Economic Area (EEA) and the United Kingdom, our legal bases under the GDPR / UK GDPR are: performance of a contract and taking steps at your request (operating the interface you choose to use); our legitimate interests in securing the Service, preventing fraud and abuse, and improving it (balanced against your rights and freedoms); your consent where we specifically ask for it (for example, any optional analytics); and compliance with legal obligations. Where processing relies on consent, you may withdraw it at any time without affecting prior processing.
4. Third parties we rely on
To function, Grailo connects to third-party services that may process limited data (such as your wallet address or IP address) under their own privacy policies, including:
- blockchain RPC and node providers used to read and broadcast transactions;
- CollectorCrypt and LITCOIN, whose public APIs supply marketplace, gacha, and staking data;
- your wallet provider (e.g., the browser extension or app you choose); and
- hosting, content-delivery, and web-font providers.
We do not control these third parties and encourage you to review their policies.
5. Cookies & local storage
Grailo relies primarily on browser local storage for the preferences described above rather than advertising or cross-site tracking cookies. You can clear local storage at any time through your browser settings; doing so will reset your preferences and disconnect saved sessions.
6. Data sharing
We do not sell your personal information. We may share limited information with service providers acting on our behalf, or where required by law, legal process, or to protect the rights, safety, and integrity of the Service and its users.
7. Public blockchain data
Because the Solana blockchain is public and immutable, any transaction you sign is permanently visible and cannot be removed. Please consider this before transacting.
8. Security & retention
We take reasonable measures to protect the Service, but no method of transmission or storage is completely secure. The security of your wallet, keys, and device is your responsibility. We retain limited technical and log data only for as long as needed for the purposes described in this policy or as required by law; preferences kept in your browser's local storage remain until you clear them. Public blockchain records are permanent and cannot be deleted.
9. Your rights (GDPR, UK GDPR & CCPA)
Depending on where you live, you may have some or all of the following rights over your personal information:
- Access — to know what personal information we process and obtain a copy;
- Rectification — to correct inaccurate or incomplete information;
- Erasure (“right to be forgotten”) — to request deletion of certain information;
- Restriction and objection — to limit or object to certain processing, including processing based on our legitimate interests;
- Portability — to receive certain information in a portable, machine-readable format;
- Withdraw consent — where processing is based on consent; and
- Non-discrimination — we will not deny you the Service or charge you differently for exercising your rights.
California residents (CCPA/CPRA) additionally have the right to know what personal information is collected and how it is used, to request its deletion, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information.
To exercise any right, contact privacy@grailo.xyz; we will respond within the timeframes required by applicable law and may need to verify your identity first. You also have the right to lodge a complaint with your local data-protection supervisory authority. Important: information written to the public blockchain is permanent and outside our control — we cannot edit or erase on-chain records, and a self-custodial wallet address is controlled by you, not by us.
10. International data transfers
Grailo may be accessed from around the world, and our hosting, RPC, and content-delivery providers may process data in countries other than yours, including outside the EEA or the UK. Where personal data of EEA/UK users is transferred internationally, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses (with the UK Addendum) or transfers to jurisdictions recognized as providing an adequate level of protection. By using the Service you understand that data may be processed in those locations.
11. Children
The Service is not directed to and may not be used by anyone under 18. We do not knowingly collect information from children.
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date reflects the most recent version, and your continued use of the Service indicates acceptance of the updated policy.
13. Data controller & contact
The data controller responsible for your personal information is the entity that operates Grailo, identified in our Terms of Service. Privacy questions, data-subject requests, or complaints can be sent to privacy@grailo.xyz.