Privacy

Privacy Policy

What we collect, how we use it, and the controls you have.

Last updated: June 29, 2026

This Privacy Policy explains what information SOLARISX AI BOT collects, how we use it, the legal bases we rely on, who we share it with, and the rights you have. It applies to the SOLARISX AI BOT website, trading terminal, automation tools, and related services.

1. Who We Are

SOLARISX AI BOT ("we", "us", "our") is the controller of personal data processed through the Service. For data-protection questions, contact us through the in-app support channel.

2. Information We Collect

  • Account data: name, username, email, mobile, country, city, and a salted hash of your password.
  • Identity & compliance data: where required, government-issued ID, selfie/liveness, proof of address, and sanctions/PEP screening results processed by our KYC vendor (Didit).
  • Trading activity: opportunities scanned, routes evaluated, trades executed, PnL, strategy settings, and bot configurations.
  • Wallet & on-chain data: public wallet addresses, deposit/withdrawal transactions, and signed transaction metadata. We never store seed phrases. Encrypted hot-wallet keys (AES-256-GCM) are stored only for users who explicitly provision a managed wallet.
  • Technical data: device, browser, IP address, approximate location, language, time zone, and session diagnostics used for security, fraud prevention, and abuse detection.
  • Communications: support tickets, alerts, and messages sent via Telegram/email when you opt in.

3. Legal Bases (GDPR / UK GDPR)

  • Contract — to provide the Service, authenticate sessions, and execute requested operations.
  • Legal obligation — KYC/AML, sanctions screening, tax reporting, and responding to lawful requests.
  • Legitimate interests — security, fraud and abuse prevention, service improvement, and analytics in aggregate form.
  • Consent — optional communications (e.g. Telegram alerts, marketing). You can withdraw consent at any time.

4. How We Use Data

To operate the trading terminal, authenticate sessions, execute and audit trades, provide customer support, comply with legal obligations (including AML/CFT and sanctions), prevent fraud and market abuse, and improve the Service. We do not use your personal data for automated decision-making with legal effects without your explicit consent.

5. Sharing & Subprocessors

  • Hosting & database — Lovable Cloud (managed Supabase / Cloudflare workerd) for application, database, and edge compute.
  • RPC & block-engine providers — Helius, Jito, public Solana RPCs for transaction routing and on-chain reads.
  • Market data — Birdeye, DexScreener, Pyth, Jupiter for price discovery and routing.
  • KYC — Didit for identity verification and sanctions screening (where required).
  • Communications — Resend for transactional email, Telegram Bot API for opt-in alerts.
  • Analytics & monitoring — limited to operational telemetry and error reporting.

6. International Transfers

Personal data may be processed in countries outside your country of residence, including the EU, the UK, and the US. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or equivalent mechanisms.

7. Security

Passwords are stored as salted hashes. Hot-wallet private keys are encrypted at rest with AES-256-GCM and never logged. Database access is governed by row-level security policies. Network traffic is encrypted in transit via TLS. Access to production systems is restricted to authorised administrators and audited. No system is perfectly secure; you remain responsible for safeguarding your credentials and external wallet seed phrases.

8. Retention

We retain account and trading records while your account is active and for the period required by applicable AML, tax, and accounting rules (typically 5–7 years from account closure). On-chain transactions are immutable and remain on public blockchains indefinitely.

9. Your Rights

  • Access, rectify, export, or delete your personal data (subject to legal retention obligations).
  • Restrict or object to processing based on legitimate interests.
  • Withdraw consent for optional communications at any time.
  • Lodge a complaint with your local data-protection authority (e.g. ICO in the UK, your national DPA in the EU).
  • Residents of California, Virginia, and other US states with applicable privacy laws have analogous rights (access, deletion, opt-out of "sale/sharing" — we do not sell personal data).

10. Cookies & Local Storage

We use strictly necessary cookies and browser local storage for authentication, session continuity, and UI preferences. We do not run third-party advertising or cross-site tracking.

11. Children

The Service is not directed to and may not be used by anyone under 18. We do not knowingly collect data from minors.

12. Automated Decisions

Our trading bot acts on rules and parameters you configure. The bot is software automation, not a decision affecting your legal rights. You remain in control and can disarm or withdraw at any time.

13. Changes

We will post material changes in-app and update the date above. Continued use after the effective date constitutes acceptance.

14. Contact

For any privacy request, reach the team through the in-app support channel. We aim to respond within 30 days, or sooner where required by law.

This document is maintained by the SOLARISX AI BOT team and is provided for transparency. It is not a substitute for independent legal advice. Privacy and crypto-asset regulation evolves quickly — consult qualified counsel for advice specific to your situation.

© 2026 SOLARISX AI BOT · All rights reserved.