Privacy Policy
Last updated July 22, 2026
This policy explains what information Apsis collects, how it is used, and the third parties involved. Short version: we collect what’s needed to run a regulated savings service, we don’t run advertising or cross-site tracking, and the blockchain parts of your activity are public by nature.
1. Information we collect
- Account details — your email address and authentication data, managed by our auth provider. We never store your password in plain text.
- Identity verification — to move money between banks and the blockchain, our banking partner collects and verifies identity information (KYC). Apsis does not receive or store your ID documents; we receive only a verification status.
- Financial & on-chain data — your linked bank destination, wallet address, and lock activity (amounts, dates, status). On-chain records are public and permanent by design.
- Technical data — basic request and device information (such as IP address and browser) needed to operate and secure the service.
2. How we use it
To provide the service (create and settle locks, return funds to your bank), to meet legal and regulatory obligations (identity, anti-money-laundering), to secure accounts and prevent fraud, and to communicate with you about your locks. We do not sell your personal information.
3. Cookies & local storage
Apsis runs no advertising, analytics, or cross-site tracking cookies. The marketing site sets no third-party cookies at all. Inside the authenticated app, our wallet-security provider sets a small number of strictly-necessary cookies (for bot mitigation and security) and stores functional data in your browser’s local storage so your session and wallet work. These are required for the feature you are using, not for tracking.
If we ever introduce analytics, we will use a privacy-preserving approach and update this policy — and add a consent mechanism where required.
4. Third parties we share data with
To operate, we rely on a small set of processors, each handling only what their function requires:
- Supabase — authentication and application database.
- Privy — wallet security and key management.
- Bridge — bank on/off-ramp and identity verification.
- Circle — issuer of USDC, the stablecoin your savings are held in.
- Base — the public blockchain where your vault lives.
- Infrastructure providers for hosting, bot mitigation, and delivery.
5. On-chain data
Blockchains are public and permanent. Vault addresses, balances, and transactions can be viewed by anyone and cannot be deleted or altered — including by Apsis. Avoid publicly linking your identity to your wallet address if you wish to keep that association private.
6. Data retention & your rights
We keep personal data for as long as needed to provide the service and to meet legal obligations (some financial records must be retained for set periods by law). Depending on where you live, you may have rights to access, correct, delete, or export your data, or to object to certain processing. On-chain data cannot be deleted. To exercise a right, contact us using the details below.
7. Security & children
We use reasonable technical and organizational measures to protect your data, though no system is perfectly secure. Apsis is not intended for anyone under 18, and we do not knowingly collect data from children.
8. Changes & contact
We may update this policy; material changes will be communicated to account holders. For privacy questions or requests, contact privacy@apsis.example (placeholder — to be replaced with a real address).