Legal
Privacy Policy
Last updated · August 15, 2026
This policy describes what the PRIZM interface at prizm.trading (the “Interface”) processes, what it deliberately never sees, and the choices you have. PRIZM has no user accounts: there is no sign-up, no email registration and no profile. Your wallet is created and kept on your own device.
01What we never collect
Private keys, recovery phrases, passwords and passkey secrets never leave your device and are never transmitted to us in any form.
Keys are generated in your browser and sealed there in an encrypted vault (AES-256-GCM). If you enable passkey vault sync, the only thing stored on our infrastructure is ciphertext that we are cryptographically unable to decrypt · the decryption key lives inside your passkey authenticator. We also collect no names, no postal addresses, no payment-card data and no government identifiers, and we run no advertising or cross-site tracking of any kind.
02What is processed
- Public blockchain data. Wallet addresses, balances and transactions are public information on Solana. The Interface reads them to render your wallet and history, and constructs transactions you may sign.
- Encrypted vault ciphertext. If you enable sync · stored so you can restore on a new device; opaque to us, deletable on request.
- Operational telemetry. When a wallet opens a session, we record the wallet address, the unlock method (passkey or password), IP address, user-agent string and timestamps, and we attribute platform-fee revenue to the wallet that generated it. Transactions recorded to your PRIZM history (all public on chain, chain-verified before storage) are also kept in a platform-wide operations ledger, encrypted at rest, so we can monitor activity on the service. This is used for security, abuse prevention and operating the service.
- Aggregate protocol metrics. Chain-verified totals (volume, fees) across the platform.
- Server logs. Standard request logs (IP, user agent, path, status) kept briefly for reliability and security.
03How it is used
To operate, secure and improve the Interface; to prevent fraud and abuse; to comply with law; and to understand usage in aggregate. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not build advertising profiles.
04Infrastructure and disclosure
The Interface runs on third-party infrastructure that processes data on our behalf: hosting and edge delivery (Vercel), a managed data store for ciphertext and operational records, and RPC providers that relay blockchain requests. Quotes and routing requests are served by Jupiter's public APIs; market data comes from sources such as Pyth and DefiLlama. Requests to these services necessarily carry network metadata such as your IP address. We may disclose information where required by law, to enforce our Terms, or to protect the service and its users. If PRIZM is ever party to a merger or acquisition, records described here may transfer with it.
05Blockchain data is public and permanent
Transactions you sign are broadcast to a public network. They are visible to anyone, attributable to your address, and cannot be altered or deleted · by you or by us. Consider an address itself potentially identifying: activity linked to it is linkable forever.
06Cookies and local storage
The Interface uses your browser's local storage for function only: the encrypted vault, session state and interface preferences. No advertising cookies, no third-party analytics beacons, no fingerprinting. Clearing site data removes the local vault · keep your recovery phrase first.
07Retention
Vault ciphertext persists until you delete it or request its deletion. Operational telemetry and logs are kept only as long as they serve security and operations. Aggregate metrics, which identify no one, may be kept indefinitely. What is on-chain is permanent by nature.
08Security
Everything in transit is encrypted (TLS); vault contents are encrypted on your device before anything is stored; access to operational systems is restricted and authenticated. No system is perfectly secure, and the design goal here is that a full compromise of our infrastructure still cannot reach your keys or funds.
09Your rights
Depending on where you live (including under GDPR and the CCPA/CPRA), you may have rights to access, correct or delete personal information we hold, and to know what is processed. Write to legal@prizm.trading from a message proving control of the relevant wallet and we will act on server-side records · noting that on-chain data is beyond anyone's power to erase, and that deleting vault ciphertext is irreversible. We do not discriminate for exercising rights.
10Children
The Interface is not directed to anyone under 18, and we do not knowingly process their data.
11International transfers
Infrastructure may process data in the United States and other countries whose laws differ from yours; where required, transfers rest on appropriate safeguards.
12Changes and contact
We may update this policy by posting a new version with a new date; material changes will be reflected prominently. Questions and requests · legal@prizm.trading
