DAIN Inc.
Privacy Policy
How DAIN handles information across trader accounts, wallets, AI agents, and digital-asset activity.
Effective and last updated: August 31, 2026
trader is an agentic finance application. To respond to prompts, display portfolios, connect accounts and wallets, and perform actions you authorize, DAIN processes account, wallet, transaction, and AI interaction data. Public blockchain activity is visible to others and generally cannot be deleted. Never submit a private key, seed phrase, recovery phrase, password, or authentication code to an AI prompt or support message.
Table of contents
- 1. Scope and who we are
- 2. Information we collect
- 3. Sources of information
- 4. How we use information
- 5. AI and agentic processing
- 6. How we disclose information
- 7. Public blockchains and digital assets
- 8. Cookies and local storage
- 9. Legal bases for processing
- 10. Data retention
- 11. Security
- 12. Your choices and privacy rights
- 13. Regional privacy notices
- 14. International data transfers
- 15. Children
- 16. Changes to this Policy
- 17. Contact us
1.Scope and who we are
This Privacy Policy explains how DAIN Inc. (“DAIN,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information in connection with the trader websites, applications, accounts, APIs, command-line and Model Context Protocol tools, messaging integrations, AI assistants, agents, automations, wallet and transaction features, and related services (collectively, the “Service”).
DAIN Inc. is the controller of personal information covered by this Policy, except where another notice says otherwise. This Policy does not govern independent blockchains, protocols, wallets, venues, or other third parties, which have their own privacy practices.
By using the Service, you acknowledge this Policy and ourTerms of Service.
2.Information we collect
Depending on how you use the Service, we may collect:
- Account and identity information: email address, display name, account and Privy identifiers, authentication events, beta-access or referral status, and information a login provider such as Google makes available with your permission.
- Wallet and blockchain information: public wallet addresses, linked-wallet identifiers, supported network, balances, token holdings, positions, approvals, transaction hashes, orders, signatures, and public onchain activity. We do not ask you to provide a private key or seed or recovery phrase.
- Financial activity and agent configuration:transaction requests and results, quotes, routes, portfolio data, platform and third-party fees, referral attribution and rewards, risk and simulation results, agent and Agent Team objectives, schedules, permissions, budgets, policies, delegated-authority status, and execution history.
- AI and support content: prompts, conversations, instructions, tool inputs and outputs, files or images you submit, generated responses, feedback, support requests, and related context needed to respond or perform an action.
- Device, usage, and diagnostics: IP address as processed by our network and infrastructure providers, browser and device type, operating system, language, referring domain, pages and features used, timestamps, session and performance data, crash and error information, security events, and approximate location inferred from network information. We do not need precise GPS location for the ordinary operation of the Service.
- Commercial and communications information:subscription, billing, referral, and payment status; customer- support communications; and preferences. Payment processors may collect payment details directly; DAIN generally receives a token, status, and limited transaction information rather than full card details.
- Integration information: identifiers, messages, or status from integrations you choose, such as an external wallet, Telegram user and chat identifiers, CLI or MCP installation and session identifiers, connected-device labels and authorization status, an off-ramp provider, or another connected service.
- Administrative and safety records: consent and policy version, support and privacy-request history, account-status changes, security reviews, incident and abuse signals, and audited administrative access or support actions involving your account.
3.Sources of information
We collect information:
- directly from you when you sign in, prompt an agent, or contact us;
- automatically from your browser, device, and use of the Service;
- from public blockchains, indexers, RPC providers, protocols, exchanges, venues, and market-data providers;
- from identity, wallet, payment, communications, analytics, infrastructure, fraud-prevention, and other service providers; and
- from another user or organization when they are authorized to invite you, collaborate with you, or operate an account for you.
We may combine information from these sources and derive information such as account-security signals, feature preferences, portfolio summaries, or suspected fraud risk.
4.How we use information
We use personal information to:
- provide accounts, authentication, wallet linking, portfolio views, AI responses, agents, automations, transaction tools, support, and other requested functionality;
- interpret your instructions, select and call tools, build or submit authorized transactions, monitor execution, and maintain records of agents and actions;
- personalize the Service, remember settings, develop features, and evaluate or improve reliability, relevance, safety, and usability;
- secure accounts and wallets; detect, investigate, and prevent fraud, abuse, attacks, sanctions evasion, and unauthorized activity;
- communicate about transactions, security, support, updates, legal notices, and, where permitted, products or features;
- process subscriptions, referrals, fees, and related accounting;
- comply with law, enforce agreements, respond to legal requests, resolve disputes, and protect users, DAIN, and others; and
- create aggregated or deidentified information that cannot reasonably be used to identify you and use it for lawful purposes.
5.AI and agentic processing
To provide AI and Agentic Systems, DAIN may send prompts, instructions, conversation context, relevant account or portfolio context, and tool inputs and outputs to AI model and infrastructure providers, which may include OpenAI. We limit information to what we reasonably need for the requested feature, security, evaluation, and troubleshooting, subject to provider terms and our agreements.
Prompts and outputs may be reviewed by automated systems and, in limited cases, authorized personnel or service providers for support, safety, abuse prevention, quality evaluation, and debugging. Authorized support or administrative personnel may also access account context when necessary to investigate a request, protect the Service, or perform an audited support action. Do not submit private keys, seed or recovery phrases, passwords, authentication codes, or information you are not authorized to share.
Agentic Systems may use personal information to make operational decisions requested by you—such as selecting a route or determining whether configured execution conditions are met. They are not intended to make decisions about your eligibility for employment, housing, credit, insurance, education, or other similarly significant services. See the regional privacy notices below for rights relating to automated decisions.
6.How we disclose information
We may disclose information to:
- Service providers: companies that support identity and wallet infrastructure, AI, cloud hosting, storage, databases, content delivery, observability, security, payments, communications, customer support, and analytics. Depending on features used, these may include Privy, Google, OpenAI, Amazon Web Services, Stripe, Coinbase, and Telegram.
- Networks and transaction counterparties:blockchains, RPC providers, validators, sequencers, protocols, bridges, relayers, liquidity providers, exchanges, venues, wallets, and other parties necessary to quote, route, submit, settle, or display requested activity.
- Professional advisers and compliance providers:auditors, insurers, lawyers, accountants, investigators, and security, fraud, sanctions, or identity-verification providers.
- Authorities and protected parties: regulators, law enforcement, courts, counterparties, or others when we believe disclosure is required by law or reasonably necessary to protect rights, safety, assets, users, or the Service.
- Business transaction participants: parties to a financing, due diligence review, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections where applicable.
- At your direction: people and services you choose to connect, authorize, invite, or share with.
We do not sell personal information for money or share it for cross-context behavioral advertising. We do not use third-party advertising cookies to follow you across unrelated services. If our practices change, we will update this Policy and provide legally required choices before doing so.
7.Public blockchains and digital assets
Public blockchains are designed to make transaction data permanently visible. When an instruction is submitted, wallet addresses, transaction details, token activity, contract interactions, and other information may become public, replicated globally, and impossible for DAIN to alter or delete. Others may associate a public address with you using information outside the Service.
DAIN does not control public networks or third-party indexers and cannot honor an access, correction, or deletion request by changing a blockchain. We can apply a request only to personal information in systems we control, subject to legal and operational exceptions.
9.Legal bases for processing
Where law requires a legal basis, we process personal information as needed to perform our contract with you, including providing the Service and requested transactions; for legitimate interests such as securing, supporting, improving, and operating the Service; to comply with legal obligations; and with consent where required.
Our legitimate interests include preventing fraud and misuse, protecting accounts and infrastructure, understanding and improving product performance, supporting users, and asserting or defending legal claims. You may withdraw consent at any time, but withdrawal does not affect prior processing and may prevent a feature from working.
10.Data retention
We retain personal information for as long as reasonably necessary to provide the Service, maintain account and transaction integrity, secure our systems, resolve disputes, enforce agreements, and satisfy legal, tax, accounting, anti-fraud, and compliance obligations. The period depends on the type and sensitivity of information, feature used, risk, user choices, and legal requirements.
We may retain financial, transaction, fee, referral, billing, wallet-ownership, consent, security, delegated-authority, and audit records after account closure where needed for legitimate recordkeeping or legal obligations. Account deletion may anonymize or dissociate information rather than erase records that must be preserved. Public blockchain data may remain indefinitely, outside DAIN’s control. Aggregated or deidentified information may be retained for lawful purposes.
11.Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, authentication, encryption where appropriate, monitoring, and incident-response procedures. No system, wallet, network, model, or transmission method is completely secure, and we cannot guarantee absolute security.
You play an essential role: secure your email, devices, account, wallets, and recovery methods; use available multi-factor protections; review wallet prompts and delegated permissions; and report suspected unauthorized activity to support@dain.orgpromptly.
12.Your choices and privacy rights
Depending on where you live, you may have the right to request access to, correction of, deletion of, or a portable copy of personal information; restrict or object to processing; withdraw consent; appeal a denied request; or complain to a data-protection authority. You may also disconnect integrations and CLI or MCP sessions, unlink Telegram, revoke wallet permissions, disable agents, and adjust communication preferences.
To make a request, email support@dain.orgwith the subject “Privacy Request” and describe the request and account email. We may verify your identity and authority before responding. An authorized agent may submit a request where law permits, but we may require signed permission and direct identity verification. We will not discriminate against you for exercising a privacy right.
Rights are subject to exceptions. For example, we may retain information needed to complete transactions, detect security incidents, maintain financial or audit records, comply with law, or establish or defend legal claims. DAIN cannot delete data from a public blockchain or a third party’s independent systems.
13.Regional privacy notices
California. In the preceding 12 months, we may have collected the categories described in Section 2: identifiers; customer-record and commercial information; internet or electronic activity; approximate geolocation; financial and wallet information; user content; and inferences. We collect and disclose these categories for the business purposes in Sections 4 and 6. We do not sell personal information or share it for cross-context behavioral advertising, and we do not knowingly sell or share personal information of people under 18. We use sensitive information, if any, only to provide and secure requested services and for other purposes permitted by law, not to infer characteristics about you.
California residents may request to know, correct, delete, or obtain specific pieces of personal information and may limit certain uses of sensitive information or opt out of sale or sharing where applicable. Because we do not currently sell or share for behavioral advertising, there is no such activity to opt out of. We will honor legally recognized browser preference signals if they become applicable to our processing.
EEA, United Kingdom, and Switzerland. You may have rights to access, correct, erase, restrict, port, or object to processing and to withdraw consent. You may lodge a complaint with your local supervisory authority. Where applicable, you also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to exceptions. Contact us to request human review where that right applies.
Local law may provide additional rights. We will apply the law that governs your request even if a right is not listed here.
14.International data transfers
DAIN and its service providers may process information in the United States and other countries where privacy laws differ from those where you live. Where required, we use recognized transfer mechanisms such as adequacy decisions, standard contractual clauses, or another lawful safeguard. Public blockchain data is replicated according to the network’s design and is not limited to a particular country.
15.Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a person under 18 provided personal information, contact us so we can investigate and take appropriate action.
16.Changes to this Policy
We may update this Policy as the Service, law, or our practices change. We will post the updated version and revise the effective date. If a change is material, we will provide additional notice as required by law. We encourage you to review this Policy periodically.
17.Contact us
For privacy questions or requests, contact DAIN Inc. at support@dain.org. Please use the subject “Privacy Request” for requests about your personal information.
