ZOKI Legal

Privacy Policy

Last Updated: September 25, 2026

⚠️ Draft — not yet reviewed by an attorney. Do not treat as final.

1. Information We Collect

1.1 Wallet Address. When you connect a wallet to sign in, we receive your public wallet address. A public wallet address is, by its nature, visible on the blockchain and not by itself anonymous.

1.2 Session Data. We store a session identifier (via a cookie) after you sign a Sign-In With Ethereum message, so you remain signed in across page loads. We also store account-linked data such as your scan credit balance, Drop capacity balance, and purchase/redemption history, associated with your wallet address.

1.3 Support Form Submissions. If you contact us through our Support page, we collect the name, email address, and message content you provide, and, if applicable, a token address you reference.

1.4 Technical and Usage Data. We automatically collect IP address (used for rate-limiting abuse of forms and endpoints), browser/device information, and basic usage logs (e.g., which pages or endpoints were accessed and when).

1.5 Bot-Verification Data. Form submissions are protected by Cloudflare Turnstile, which may process technical signals about your browser/device to distinguish human users from automated bots. See Cloudflare's own privacy policy for details of that processing.

1.6 On-Chain Data. Because ZOKI operates on public blockchains, transactions you make through the Services (payments, Drop transfers, etc.) are recorded permanently and publicly on the relevant blockchain. This on-chain data is not something we can delete, edit, or control — it exists independently of our systems.

1.7 We do not collect: private keys, seed phrases, government ID, or (unless you provide it voluntarily, e.g., through a support request) your real-world name.

2. How We Use Information

We use the information above to: operate and maintain the Services (e.g., verifying payments, crediting scan/drop capacity); respond to support requests; detect and prevent fraud, abuse, and spam; maintain rate limits and security; and comply with legal obligations.

We do not sell your personal information.

3. Third-Party Service Providers

We use the following categories of third-party providers, who process data on our behalf under their own respective privacy policies:

— Cloudflare — DNS, bot/abuse protection (Turnstile), email routing.

— Resend — transactional email sending (e.g., support-form notifications).

— DigitalOcean — application hosting.

— MongoDB [Atlas or self-hosted] — database storage for account/session/purchase data.

— Blockchain RPC providers (e.g., Alchemy) — used to read and submit blockchain data; these providers may independently log IP addresses associated with RPC requests per their own policies.

— Google Search Console — used to monitor how the Services perform in Google Search (impressions, clicks, indexing status). Does not track individual visitor behavior on the Services.

— Telegram — we post public sale/purchase notifications (e.g., Scan credit and Drop capacity purchases) to a community Telegram channel. These notifications may include the transaction hash, token/currency, and amount involved. Because blockchain transactions are public, a transaction hash can be used by anyone to look up the associated wallet address on a block explorer — so purchase activity posted this way should be treated as visible to the public, not merely to our internal team.

4. Cookies

We use a session cookie to keep you signed in after wallet authentication. We use Google Search Console to monitor how the Services appear in Google Search results (e.g., impressions, clicks, and indexing status). Google Search Console does not set tracking cookies on your browser and does not monitor your individual browsing behavior on our Services — it draws on data from Google's own search index. If we add a visitor-tracking analytics tool (such as Google Analytics) in the future, this section will be updated before that tool goes live.

5. Data Retention

We retain account-linked data (wallet address, credit/capacity balances, purchase history) for as long as your association with the Services continues, and as needed to comply with legal, accounting, or reporting obligations. Support form submissions are retained for up to 2 years from the date of submission. On-chain transaction data is permanent and outside our control, per Section 1.6.

6. Your Rights and Choices

Depending on your jurisdiction, you may have rights to access, correct, or request deletion of personal information we hold about you (excluding on-chain data, which cannot be altered or deleted by us). To make such a request, contact [email protected]. We will respond within a reasonable time.

You can disconnect your wallet at any time, which ends your active session. This does not delete your on-chain transaction history or previously recorded account data.

7. Children's Privacy

The Services are not directed to, and we do not knowingly collect personal information from, anyone under the age of 18. If we learn we have collected such information, we will delete it.

8. International Users

If you access the Services from outside the United States, your information may be transferred to and processed in the United States, where our service providers are located. By using the Services, you consent to this transfer.

9. Security

We use reasonable technical and organizational measures to protect the information we hold, including rate limiting, session-based authentication, and bot-verification on public forms. No system is completely secure, and we cannot guarantee absolute security.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be noted with an updated "Last Updated" date. Continued use of the Services after changes take effect constitutes acceptance of the revised policy.

11. Contact

Questions about this Privacy Policy, or requests regarding your information, can be directed to [email protected].