STRYX PRIVACY POLICY

Version: 1.0
Effective Date: October 3, 2026
Last Updated: October 3, 2026
Operator: Stryx ("Stryx", "we", "us", or "our")
Contact: [CONTACT EMAIL]

This Privacy Policy explains what personal information Stryx collects, why, who it is shared with, how long it is kept, and the choices you have. It applies to the Stryx website, dashboard, APIs and related services (the "Service") and forms part of our Terms of Use. Terms that are capitalised here have the meaning given in the Terms of Use.

1. The short version

2. Information we collect

2.1 Information you give us

2.2 Information created as you use the Service

2.3 Technical information

2.4 Information from other sources

2.5 What we do not ask for

We do not currently ask for your legal name, a government ID, a postal address, a phone number or bank or card details. If that changes (for example when paid plans arrive), we will update this Policy first.

Accounts made under an earlier sign-up method (email and password) also have an email address and a password. The password is stored only as a one-way hash.

3. How we use information, and why

PurposeExamplesBasis [to be confirmed by counsel]
Provide the ServiceSign you in, hold and use your Stryx wallets' keys to sign what you instruct or schedule, send transactions, show balances, history and proof-of-mintPerforming our agreement with you
Keep it safeRate limiting, spending limits, emergency stops, detecting and investigating abuse and security incidents, keeping the security logOur legitimate interest in security; legal obligations
Operate and supportLetting administrators see accounts and activity to run, support and troubleshoot the Service; aggregate statistics on use and reliabilityLegitimate interests
CommunicateTelling waitlist members when a place opens; service and security messagesConsent (waitlist); legitimate interests
Prove acceptanceKeeping the record that you accepted a version of the Terms and this PolicyLegitimate interests; legal claims
Comply with the lawResponding to lawful requests, sanctions and other legal dutiesLegal obligations

We do not use your information to make decisions about you by automated means that have legal or similarly significant effects, and we do not use it for advertising or to build profiles for others.

4. Private keys

5. Who we share information with

We do not sell your personal information. We share it only as follows.

Stryx administrators can see account and activity information (for example accounts, wallets' addresses, mint history and the security log) as needed to run, support and secure the Service. Their access is itself recorded.

Service providers that help us run the Service. They receive only what they need and may use it only to provide their service to us:

Provider typeWhat they receive
Blockchain networks and RPC (node) providersAddresses and the transactions we send for you; the public network sees them too
OpenSea (data provider)Requests about drops and collections made by our servers. To check whether one of your Stryx wallets is eligible for a mint, or to complete a mint that requires it, we sign in to OpenSea as that wallet, so OpenSea receives the wallet's address and what it asks for
WalletConnect / Reown, if you choose to connect a phone walletThe connection details needed to link your phone wallet; see their privacy policy
Cloud hosting, database and key management providersThe data we store and process, in encrypted or protected form: [list providers once chosen]

When the law requires it, or to protect rights, safety and security, we may disclose information to courts, authorities or other parties.

Business changes. If Stryx is involved in a merger, sale or similar event, information may be transferred, subject to this Policy.

At your direction. For example, when you send assets to an address you provide.

Your browser and OpenSea's image network. The landing page's "live drops" strip and the app's Home page show collection images served from OpenSea's content network. Loading those images makes your browser contact that network directly, so it can see your IP address and browser details. We ask your browser not to send a referrer. We do not control that network.

6. Cookies and similar technologies

7. How long we keep information

InformationHow long [periods to be set by counsel]
Waitlist emailUntil you are invited and sign up, you ask us to remove it, or [12] months pass, whichever is first
Account and profileWhile your account is open, and for [period] after it closes
Stryx wallet records and encrypted keysWhile the wallet exists; the key is deleted when you delete the wallet [and from backups within period]
Transaction and mint records, NFT ledger[period], as they are our record of what we sent for you
Security log[period]
Acceptance recordsFor as long as needed to show what you agreed to, [period] after the account closes
Rate-limit counters (IP addresses)About one hour
SessionsUntil they expire or you sign out
Provider logsAs set by each provider [complete]

We may keep information longer where the law requires it or to deal with a dispute or investigation. Blockchain data cannot be deleted by us.

8. Where information is processed

[Complete once hosting is chosen: where servers, databases and providers are located, and the safeguards used where information moves between countries.]

9. Your choices and rights

You can:

To make a request, contact us at [CONTACT EMAIL]. We may need to check that it is really you (for an account, by asking you to sign a message with your wallet). We will answer within the time the law requires [to be set by counsel]. Some information we must or may keep (section 7), and information already written to a blockchain cannot be erased.

[Region-specific rights and notices (for example the EU and UK GDPR, Nigeria's data protection law, and California privacy law) to be added by counsel to match where Stryx offers the Service.]

10. Security

We use technical and organisational measures designed to protect information, including encryption of private keys, hashing of session tokens, access controls on administrator tools, rate limits and a security log. No system is completely secure, and we cannot guarantee that information will never be accessed without authorisation. If a breach affects your personal information we will tell you and the relevant authorities as the law requires.

11. Children

The Service is for people aged 18 and over. We do not knowingly collect information from anyone under 18. If you believe a child has given us information, contact us and we will delete it.

The Service connects to third-party wallets, blockchains and websites we do not control. Their handling of your information is governed by their own policies.

13. Changes to this Policy

We may update this Policy. Each version has a number and an effective date. For a material change we will tell you, and where the law requires we will ask for your agreement before you continue using the affected features.

14. Contact

Stryx
Address: [REGISTERED ADDRESS]
Email: [CONTACT EMAIL]