Skip to content

Legal

Privacy Policy

Last updated · September 6, 2026

This policy describes what the PRIZM interface and trading API at prizm.trading (the “Interface”) process, what they deliberately never see, and the choices you have. PRIZM has no user accounts: there is no sign-up, no email registration and no profile. Your wallet is created and kept on your own device.

01What we never collect

Private keys, recovery phrases, passwords and passkey secrets never leave your device and are never transmitted to us in any form.

Keys are generated in your browser and sealed there in an encrypted vault (AES-256-GCM). If you enable cloud restore, the only thing stored on our infrastructure is ciphertext that we are cryptographically unable to decrypt: for passkey sync the decryption key lives inside your passkey authenticator; for a username-and-password backup the ciphertext is sealed under a key derived from your password on your device (600,000 rounds of PBKDF2), and the server receives a hash of your username rather than the username itself. Beside the ciphertext we keep a hashed proof of possession that gates reading and overwriting it. We also collect no names, no postal addresses, no payment-card data and no government identifiers, and we run no advertising or cross-site tracking of any kind.

02What is processed

  • Public blockchain data. Wallet addresses, balances, positions and transactions are public information on Solana. The Interface reads them to render your wallet and history, and constructs transactions you may sign.
  • Encrypted vault ciphertext. If you enable passkey sync or a password backup · stored so you can restore on a new device, with the hashed proof described above; opaque to us, deletable on request, and expiring on its own after about thirteen months without use.
  • Session records. When a wallet opens a session, your browser sends a message signed by that wallet and we record the wallet address, the unlock method (passkey or password), the full network address of the request, its user-agent string (cut to 220 characters), first-seen and last-seen timestamps and a login count, plus a daily set of active wallets. These records are kept until we delete them. We attribute platform-fee revenue to the wallet that generated it, and we read the public SOL and token balances of wallets that have opened a session to operate the service (support, abuse review and revenue accounting). Transactions recorded to your PRIZM history (all public on chain, chain-verified before storage) are also kept in a platform-wide operations ledger, encrypted at rest with a server-held key, so we can monitor activity on the service. This is used for security, abuse prevention and operating the service.
  • Region. The hosting platform stamps a two-letter country code on each request from its network address. The Interface reads it to decide whether a leveraged or perpetual open may be built and which controls to show; it is not written to our records, although our hosting provider's aggregate analytics (Section 06) do count views by country. Wallets the operator designates for platform testing and operation, including its own administrative wallet, are judged on their identity rather than the country code when they call the trading API with an API key.
  • Rate limiting. Your network address is used as a short-lived counter key (windows of about a minute) to limit request rates on the Interface and the API.
  • Telegram alerts (optional). If you link a Telegram chat, we store the Telegram chat id keyed to your wallet address (and the reverse), your price-alert list (token mint and symbol, direction, target price · up to fifty), a marker for each alert fired (kept a day so it fires once) and a ten-minute one-time link code. About once a minute we compare your alerts to a third-party price feed and send crossed ones to your chat through Telegram's Bot API; each message contains the token symbol, the direction, your target and the current price. Sending /stop to the bot, or unlinking in the Interface, deletes the chat link and the alert list.
  • API keys (optional). If you generate an API key, we store only its SHA-256 hash · never the key itself · with the wallet it is bound to, the label you gave it, a preview of its last six characters, its scopes, and created and last-used timestamps, plus daily call counters per key and per wallet kept for ninety days. Every API request is authenticated against the hash and rate-limited per key.
  • Perpetuals board. A wallet that builds a perpetual request is added to a bounded list of recent wallets (about two hundred) used to compile a platform-wide leverage outcome board from public on-chain events.
  • Signal reads. Each API read of the signals endpoint, and each read the chart makes while the VIZION lens is open, is logged as an anonymous market row (time, price, lean and similar figures) with no wallet identifier, so the signals can be graded forward.
  • Aggregate protocol metrics. Chain-verified totals (volume, fees) across the platform.
  • Server logs. Standard request logs (IP, user agent, path, status) kept briefly for reliability and security.

03How it is used

To operate, secure and improve the Interface; to deliver the alerts and API access you ask for; to prevent fraud and abuse; to comply with law; and to understand usage in aggregate. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not build advertising profiles.

04Infrastructure and disclosure

The Interface runs on third-party infrastructure that processes data on our behalf: hosting and edge delivery (Vercel, which also stamps the country code above), a managed Redis-compatible key-value store (Upstash) for ciphertext and operational records, and RPC providers that relay blockchain requests (Alchemy, plus Jito's block engine for transaction submission). Quotes, routing, orders and perpetual requests are served by Jupiter's APIs; market data comes from Alchemy, Jupiter's data API (candles and pool data for tokens Alchemy has no series for), Meteora's DLMM data API (pool statistics), the public market-data APIs of Binance and Coinbase, GeckoTerminal (token icons), Sanctum (staking yields), DefiLlama (yields and TVL), Stakewiz (validator names, scores and yield estimates for native staking) and the metadata feeds of Kamino and marginfi; token images are fetched through our proxy from the hosts a token's own metadata names (IPFS gateways, Arweave); alerts are sent through Telegram's Bot API. Blockchain and routing requests from your browser go through the Interface's own same-origin proxies, so those providers see our servers' addresses rather than yours; where the deployment names a fallback RPC provider, your browser may reach it directly, carrying your network address. We may disclose information where required by law, to enforce our Terms, or to protect the service and its users. If PRIZM is ever party to a merger or acquisition, records described here may transfer with it.

05Blockchain data is public and permanent

Transactions you sign are broadcast to a public network. They are visible to anyone, attributable to your address, and cannot be altered or deleted · by you or by us. Consider an address itself potentially identifying: activity linked to it is linkable forever. Tokens you deposit with Jupiter's execution vault for a stop-loss or OCO order are held and moved by that vault under Jupiter's policies, not ours.

06Cookies, local storage and analytics

The Interface uses your browser's storage for function only. Local storage holds the encrypted vault and your interface preferences. While your vault is unlocked, session storage holds a copy of the decrypted signing key, so that reloading the page does not lock you out: that copy is confined to the tab that opened it, lasts for the life of that tab (a browser's “reopen closed tab” or session restore can bring it back, until the idle timer expires it), is cleared when you lock the vault, is never sent anywhere, and expires on its own after three hours without activity. While a stop-loss order session is active, session storage also holds the Jupiter session token your wallet signed for. The Interface sets no advertising cookies and runs no cross-site tracking. It loads one analytics script, Vercel Web Analytics, served from this domain (/_vercel/insights), which reports page views to our hosting provider; we read those figures only in aggregate: page views and visitors by day over thirty days, and the top pages, referrers, countries, device types, browsers and operating systems. No figure identifies a person. Clearing site data removes the local vault · keep your recovery phrase first.

07Retention

Vault ciphertext persists until you delete it, request its deletion, or thirteen months pass without it being read or written. Your PRIZM history and the platform-wide operations ledger expire about thirteen months after the last transaction recorded to them; session records and per-wallet fee attribution are kept until we delete them; daily-active sets and API call counters expire after ninety days; daily aggregate buckets after thirteen months and hourly ones after about two days; alert markers after a day; link codes after ten minutes. Telegram links and alert lists persist until you unlink. Aggregate metrics, which identify no one, may be kept indefinitely. What is on-chain is permanent by nature.

08Security

Everything in transit is encrypted (TLS); vault contents are encrypted on your device before anything is stored; API keys and vault proofs are stored as one-way hashes; the operations ledger is encrypted at rest; access to operational systems is restricted and authenticated. No system is perfectly secure, and the design goal here is that a full compromise of our infrastructure still cannot reach your keys or funds.

09Your rights

Depending on where you live (including under GDPR and the CCPA/CPRA), you may have rights to access, correct or delete personal information we hold, and to know what is processed. Write to legal@prizm.trading from a message proving control of the relevant wallet and we will act on server-side records · noting that on-chain data is beyond anyone's power to erase, and that deleting vault ciphertext is irreversible. You can unlink Telegram and revoke API keys yourself at any time from the Interface. We do not discriminate for exercising rights.

10Children

The Interface is not directed to anyone under 18, and we do not knowingly process their data.

11International transfers

Infrastructure may process data in the United States and other countries whose laws differ from yours; where required, transfers rest on appropriate safeguards.

12Changes and contact

We may update this policy by posting a new version with a new date; material changes will be reflected prominently. Questions and requests · legal@prizm.trading