Privacy Policy
Last updated: June 10, 2026
1. Information We Collect
Chaingentic collects and processes the following categories of information in connection with providing the Services:
Information We Collect Automatically: (a) Wallet Addresses — Public blockchain addresses that interact with Chaingentic's Services, including sender addresses, recipient addresses, and contract addresses involved in evaluated transactions. (b) Transaction Data — On-chain transaction parameters submitted for evaluation, including function selectors, call data, token amounts, gas parameters, contract bytecode references, and approval scopes. This data is already publicly available on the blockchain. (c) Evaluation Results — AI evaluation outputs, AI consensus decisions (clean or flagged), and the reasoning generated by Chaingentic's AI models for each transaction evaluation. (d) Usage Analytics — Anonymized and aggregated data about how the Services are used, including evaluation volume, response times, error rates, feature usage, and deployment mode selection. (e) Device and Browser Information — Browser type, operating system, screen resolution, language preference, and similar technical data collected through standard web analytics for service improvement. (f) Network Information — IP addresses, which are processed but not permanently stored in association with wallet addresses or evaluation data.
Information We Do NOT Collect: Chaingentic does not collect, store, or have access to: (a) Private keys or seed phrases — under any circumstances, ever. (b) Real names, home addresses, phone numbers, or government-issued identification. (c) Bank account numbers, credit card numbers, or traditional financial account information. (d) Email addresses — unless you voluntarily provide one by contacting us. (e) Biometric data. (f) Social Security Numbers, Social Insurance Numbers, or equivalent national identifiers.
Chaingentic is designed to operate on pseudonymous blockchain data. We do not attempt to de-anonymize wallet addresses or link them to real-world identities.
2. How We Use Information
Chaingentic uses the collected information for the following purposes:
(a) Transaction Evaluation — To analyze submitted transactions in real time, generate risk assessments, and provide or withhold AI co-signatures based on the evaluation outcome. (b) Model Improvement — To improve the accuracy and performance of Chaingentic's 47 spoke evaluator contracts and AI consensus mechanism. Evaluation data may be used to retrain, fine-tune, or validate AI models. (c) Threat Intelligence — To identify and catalog malicious contracts, known exploit patterns, fraudulent deployer addresses, and emerging attack vectors. See Section 4 (Network Threat Intelligence) for details. (d) Reputation Scoring — To build and maintain pseudonymous reputation profiles for wallet addresses and contract deployers, based on their on-chain behavior and interaction history with Chaingentic. (e) Service Operations — To monitor system performance, diagnose technical issues, prevent abuse, and maintain the security and integrity of the Services. (f) Legal Compliance — To comply with applicable laws, regulations, legal processes, or enforceable governmental requests. (g) Communication — To respond to your inquiries if you contact us directly.
We do not sell, rent, lease, or trade your personal information or wallet data to third parties for marketing, advertising, or any unrelated commercial purpose.
3. AI Model Provider Data Sharing
Chaingentic uses independent AI models from multiple providers to power its consensus mechanism. The specific providers are not disclosed for security purposes.
When a transaction is submitted for evaluation, Chaingentic transmits the minimum data necessary to the AI model providers for analysis. This data typically includes: (a) Transaction parameters (function selector, call data, target contract address, value). (b) Contextual blockchain data (contract verification status, deployer history, token metadata). (c) Spoke evaluator outputs and intermediate risk signals.
Data Minimization: Chaingentic does not transmit your IP address, browser information, or any off-chain personal data to AI model providers. We strip all unnecessary metadata before transmitting evaluation requests.
Provider Policies: Data transmitted to AI model providers is subject to their respective privacy policies and data processing agreements. Chaingentic selects providers that offer enterprise-grade data handling commitments, including commitments not to use customer data for model training without consent. However, Chaingentic cannot guarantee the data practices of third-party providers.
Chaingentic's proprietary evaluation logic, spoke contract architecture, AIERC-193 protocol implementation, and consensus weighting algorithms are never shared with AI model providers. Providers receive only the input data necessary to generate a risk assessment and return the output to Chaingentic.
4. Network Threat Intelligence
Chaingentic operates a collective threat intelligence network. When Chaingentic detects a threat — such as a scam contract, a malicious token deployer, a known rug-pull pattern, a phishing approval, or an active exploit — this threat intelligence is shared across the Chaingentic network to protect all users.
What We Share: Threat signatures, including malicious contract addresses, flagged function selectors, exploit patterns, deployer addresses associated with fraud, and risk classifications.
What We Do Not Share: We do not share the identity (wallet address) of the user who encountered the threat, their transaction details, their evaluation history, or any data that could identify the reporting user.
This threat intelligence sharing is a core feature of Chaingentic. By using the Services, you consent to your transactions contributing to the collective threat intelligence database in anonymized form. If you wish to opt out of contributing to threat intelligence, you may contact contact@chaingentic.io. Note that opting out may reduce the level of protection available to you, as reciprocal threat data may be limited.
5. Data Retention
Chaingentic retains data according to the following schedule:
(a) Transaction Evaluation Data — Retained for ninety (90) days from the date of evaluation. This includes transaction parameters, risk scores, AI model outputs, and evaluation metadata. After 90 days, evaluation data is either deleted or permanently anonymized.
(b) Anonymized Threat Intelligence — Retained indefinitely. Threat signatures, malicious contract databases, and exploit pattern libraries are maintained as long as they remain relevant to the security of the network.
(c) Wallet Reputation Scores — Updated continuously and retained as long as the associated wallet address remains active on any supported network. Reputation data may be retained for up to two (2) years after the last observed on-chain activity from the wallet.
(d) Aggregated Analytics — Anonymized, aggregated usage statistics are retained indefinitely for service improvement and research purposes.
(e) Communication Records — If you contact us by email, your correspondence is retained for as long as necessary to resolve your inquiry, plus a reasonable period for record-keeping, not to exceed three (3) years.
You may request early deletion of your data as described in Section 6 (Your Rights).
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your data. Chaingentic is committed to honoring these rights in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA, Canada), the General Data Protection Regulation (GDPR, European Union), the California Consumer Privacy Act (CCPA, United States), and other applicable data protection laws.
Right of Access: You may request a copy of the data Chaingentic holds in association with your wallet address(es).
Right to Deletion: You may request deletion of your evaluation history and reputation data. Please note that: (i) anonymized threat intelligence derived from your evaluations cannot be attributed back to you and therefore cannot be individually deleted; (ii) deletion of your reputation data may adversely affect your reputation score; and (iii) data required to be retained by law will not be deleted until the retention obligation expires.
Right to Rectification: You may request correction of inaccurate data associated with your wallet address.
Right to Data Portability: You may request your data in a structured, commonly used, machine-readable format.
Right to Object: You may object to certain processing activities, including the use of your evaluation data for model improvement. Objection to core service functions (transaction evaluation) will require discontinuation of the Services.
Right to Opt Out of Threat Intelligence Sharing: You may opt out of contributing to Chaingentic's collective threat intelligence network, as described in Section 4.
CCPA-Specific Rights: California residents have the right to know what personal information is collected, to request deletion, to opt out of the sale of personal information (Chaingentic does not sell personal information), and to non-discrimination for exercising privacy rights.
To exercise any of these rights, contact: contact@chaingentic.io. Please include the wallet address(es) associated with your request. We will respond within thirty (30) days, or within the timeframe required by applicable law.
We may require reasonable verification of your identity (for example, by requesting a signed message from the wallet address in question) before processing your request.
7. Cookies and Tracking
Chaingentic's website (chaingentic.io) may use the following technologies:
(a) Essential Cookies — Small data files necessary for the website to function correctly, including session management and preference storage. These cookies are strictly necessary and cannot be disabled.
(b) Analytics — Chaingentic may use privacy-respecting analytics tools to understand website traffic and usage patterns. We do not use Google Analytics or any Google tracking products.
(c) Local Storage — The Chaingentic Wallet Overlay may use browser local storage to cache evaluation results, user preferences, and session data. This data is stored locally on your device and is not transmitted to Chaingentic's servers except as necessary to provide the Services.
Chaingentic does not use tracking pixels, fingerprinting, cross-site tracking, or third-party advertising cookies. We do not serve ads. We do not build advertising profiles.
You may configure your browser to reject cookies, but doing so may impair the functionality of the Services.
8. Security Measures
Chaingentic implements the following security measures to protect your data:
(a) Encryption in Transit — All data transmitted between your device and Chaingentic's infrastructure is encrypted using TLS 1.2 or higher. (b) Encryption at Rest — All stored data is encrypted at rest using industry-standard AES-256 encryption. (c) Infrastructure — Chaingentic's backend operates on Cloudflare Workers, benefiting from Cloudflare's global edge network, DDoS protection, and infrastructure security certifications. (d) Access Controls — Access to production systems and data is restricted to authorized personnel on a need-to-know basis, protected by multi-factor authentication. (e) Security Audits — Chaingentic conducts periodic security reviews and testing of its infrastructure and smart contracts. (f) Incident Response — Chaingentic maintains an incident response process. In the event of a data breach affecting your data, we will notify affected users and applicable regulatory authorities within the timeframes required by law.
No system is perfectly secure. Despite our efforts, we cannot guarantee absolute security. If you believe you have discovered a security vulnerability in Chaingentic's Services, please report it immediately to contact@chaingentic.io. We take all reports seriously and will investigate promptly.
9. International Data Transfers
Chaingentic is based in Ontario, Canada. Your data may be processed in Canada and in any country where our infrastructure providers (including Cloudflare) or AI model providers maintain facilities.
Canada has been recognized by the European Commission as providing an adequate level of data protection under GDPR. For transfers to countries without an adequacy determination, Chaingentic relies on appropriate safeguards such as standard contractual clauses or other legally recognized transfer mechanisms.
By using the Services, you consent to the transfer of your data to Canada and other jurisdictions as described in this policy. If you are located in a jurisdiction that restricts international data transfers, please review this section carefully before using the Services.
10. Children's Privacy
Chaingentic's Services are not directed to individuals under the age of 18 (or the age of majority in their jurisdiction, whichever is greater). We do not knowingly collect personal information from children.
If we become aware that we have inadvertently collected data from a child under the applicable age threshold, we will take prompt steps to delete such data. If you believe that a child has provided data to Chaingentic, please contact us at contact@chaingentic.io.
11. Changes to This Privacy Policy
Chaingentic reserves the right to update or modify this Privacy Policy at any time. When we make material changes, we will:
(a) Update the "Last updated" date at the top of this page. (b) Where practicable, provide additional notice through the Services or by other means.
Your continued use of the Services after any modification constitutes your acceptance of the updated Privacy Policy. If you do not agree to the updated policy, you must discontinue use of the Services.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
12. Contact Information
For privacy-related inquiries, data requests, or complaints: Privacy: contact@chaingentic.io
For security vulnerability reports: Security: contact@chaingentic.io
For general inquiries: General: contact@chaingentic.io
Chaingentic Patent Pending: CIPO 3,304,029 / PCT/IB2026/052205 Ontario, Canada
If you are not satisfied with our response to a privacy concern, you may have the right to lodge a complaint with your local data protection authority. In Canada, you may contact the Office of the Privacy Commissioner of Canada (www.priv.gc.ca). In the EU, you may contact your national data protection authority.