Grailo ← Back to Grailo
Legal

Privacy Policy

Last updated: June 24, 2026

Grailo is built to be privacy-light. It is a mostly client-side interface: you interact with the blockchain through your own wallet, and we collect as little as we can. This policy explains what limited information is involved when you use Grailo, how it is used, and the choices you have.

The short version. We never ask for or store your private keys or seed phrase. We don’t require an account, a name, or an email to browse or transact. Most of what makes Grailo work happens in your browser and on the public blockchain. We don’t sell your data.

1. Information involved when you use Grailo

Wallet address

When you connect a wallet, we receive your public wallet address and read publicly available on-chain information associated with it (such as token balances and the cards you hold) so the interface can display your holdings and build transactions. A public wallet address is pseudonymous but may be linkable to you.

On-chain activity

Transactions you sign — purchases, sales, listings, offers, and similar — are recorded on the public Solana blockchain. This data is public, permanent, and outside our control; it cannot be edited or deleted by us or by you.

Information stored on your device

We use your browser’s local storage to remember preferences and session details — for example your theme choice, your most recently connected wallet, and, if you use LITCOIN fee tiers, the link between your connected wallet and your external staking wallet. This information stays on your device and is not an account on our servers.

LITCOIN linking

If you opt into LITCOIN fee tiers, you may link an external (Base/EVM) wallet and sign a message to prove control of it. We use the resulting address and signature solely to read your staked balance from LITCOIN’s API and apply the correct fee tier.

Technical and log data

Like virtually all websites, our hosting and content-delivery infrastructure may automatically process limited technical data (such as IP address, browser type, and timestamps) to deliver the site, maintain security, and prevent abuse. Where we use analytics, we aim to use privacy-respecting, aggregate measurement only.

2. What we do not collect

We do not collect or store your private keys, seed phrase, or wallet passwords. We do not require you to create an account or provide your name, address, or government identification to use the core interface.

3. How information is used & legal bases

For users in the European Economic Area (EEA) and the United Kingdom, our legal bases under the GDPR / UK GDPR are: performance of a contract and taking steps at your request (operating the interface you choose to use); our legitimate interests in securing the Service, preventing fraud and abuse, and improving it (balanced against your rights and freedoms); your consent where we specifically ask for it (for example, any optional analytics); and compliance with legal obligations. Where processing relies on consent, you may withdraw it at any time without affecting prior processing.

4. Third parties we rely on

To function, Grailo connects to third-party services that may process limited data (such as your wallet address or IP address) under their own privacy policies, including:

We do not control these third parties and encourage you to review their policies.

5. Cookies & local storage

Grailo relies primarily on browser local storage for the preferences described above rather than advertising or cross-site tracking cookies. You can clear local storage at any time through your browser settings; doing so will reset your preferences and disconnect saved sessions.

6. Data sharing

We do not sell your personal information. We may share limited information with service providers acting on our behalf, or where required by law, legal process, or to protect the rights, safety, and integrity of the Service and its users.

7. Public blockchain data

Because the Solana blockchain is public and immutable, any transaction you sign is permanently visible and cannot be removed. Please consider this before transacting.

8. Security & retention

We take reasonable measures to protect the Service, but no method of transmission or storage is completely secure. The security of your wallet, keys, and device is your responsibility. We retain limited technical and log data only for as long as needed for the purposes described in this policy or as required by law; preferences kept in your browser's local storage remain until you clear them. Public blockchain records are permanent and cannot be deleted.

9. Your rights (GDPR, UK GDPR & CCPA)

Depending on where you live, you may have some or all of the following rights over your personal information:

California residents (CCPA/CPRA) additionally have the right to know what personal information is collected and how it is used, to request its deletion, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information.

To exercise any right, contact privacy@grailo.xyz; we will respond within the timeframes required by applicable law and may need to verify your identity first. You also have the right to lodge a complaint with your local data-protection supervisory authority. Important: information written to the public blockchain is permanent and outside our control — we cannot edit or erase on-chain records, and a self-custodial wallet address is controlled by you, not by us.

10. International data transfers

Grailo may be accessed from around the world, and our hosting, RPC, and content-delivery providers may process data in countries other than yours, including outside the EEA or the UK. Where personal data of EEA/UK users is transferred internationally, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses (with the UK Addendum) or transfers to jurisdictions recognized as providing an adequate level of protection. By using the Service you understand that data may be processed in those locations.

11. Children

The Service is not directed to and may not be used by anyone under 18. We do not knowingly collect information from children.

12. Changes to this policy

We may update this policy from time to time. The “Last updated” date reflects the most recent version, and your continued use of the Service indicates acceptance of the updated policy.

13. Data controller & contact

The data controller responsible for your personal information is the entity that operates Grailo, identified in our Terms of Service. Privacy questions, data-subject requests, or complaints can be sent to privacy@grailo.xyz.