Privacy Policy
What we collect, what we never receive, and what you can ask us to do with it. Last updated 2 August 2026.
This Privacy Policy explains what information Waypoint (“Waypoint”, “we”, “us”) collects when you use waypoint.world, the Waypoint application, the Waypoint SDK, and related services (the “Services”), how we use it, and what rights you have.
1. The short version
- We never receive your private keys or seed phrase.
- We do not run any AI model, and we do not receive or store the contents of your conversations with one.
- We hold session signing keys, which are scoped credentials — never your master key.
- Blockchain activity is public by design. We did not put it there and we cannot remove it.
- We do not sell your personal information.
2. Information we collect
Information you give us
- Contact details — your email address if you subscribe to our newsletter, request early access, or contact support, along with anything you write to us.
- Publisher information — if you author or publish a waypoint, the information you submit as part of that process, including any details required for review.
Information created when you use the Services
- Wallet address. When you connect a wallet we process your public address. A wallet address is pseudonymous, but it can sometimes be linked to an identifiable person, so we treat it as personal information where the law requires.
- Session metadata. The sessions you create, the protocols and functions you allow, the budgets and expiries you set, and the calls made under each session, including whether they succeeded or failed.
- Session signing keys. We hold the signing key for each session you create. This is a scoped credential limited by the permissions you set. It is not your private key and it cannot be used to move assets outside those limits.
Information collected automatically
- Technical and usage data — IP address, browser type and version, device and operating system, referring page, pages viewed, and time spent, collected through our own logs and analytics providers.
- Approximate location, derived from IP address, which we use for security and to meet legal obligations such as sanctions screening.
- Cookies and similar technologies — see our Cookie Policy.
Information we do not collect
- Private keys, seed phrases, or recovery phrases.
- The contents of your prompts, conversations, or model outputs.
- Model provider API keys.
3. How we use information
We use information to:
- provide, operate, and maintain the Services;
- authenticate session credentials and route calls;
- monitor for security incidents, abuse, fraud, and misuse;
- review waypoints submitted for publication;
- diagnose problems and improve reliability and performance;
- understand which features are used, in aggregate;
- send you the newsletter or product updates you asked for, and respond to your messages;
- comply with legal obligations, including sanctions and anti-money-laundering requirements, and respond to lawful requests.
Legal bases (if you are in the EEA or UK). We rely on: performance of a contract, for providing the Services; legitimate interests, for security, abuse prevention, and product improvement; consent, for marketing emails and non-essential cookies; and legal obligation, for compliance and law-enforcement requests. Where we rely on consent, you may withdraw it at any time.
4. Blockchain data
Transactions you make through the Services are recorded on public blockchains. This data is permanent, public, and outside our control. We cannot amend, delete, or restrict it, including in response to a request to exercise your rights. Anyone can view it, and third parties may attempt to link a wallet address to an identity.
5. When we share information
We do not sell personal information. We share it only:
- With service providers who work on our behalf — hosting, infrastructure, key management, analytics, email delivery, error monitoring, and customer support — under contracts that limit their use of it.
- For legal reasons — where required by law, subpoena, or regulator, or where we believe disclosure is reasonably necessary to protect rights, safety, or property, or to investigate fraud or a security incident.
- In a corporate transaction — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy continuing to apply.
- With your direction — where you ask us to, or where you provide a session credential to a third party, in which case that party acts with the authority you gave it.
6. Retention
We keep information only as long as needed for the purposes described here, or as long as the law requires.
- Contact details: until you unsubscribe or ask us to delete them, plus any period required for record-keeping.
- Session metadata and logs: for the life of the session and a reasonable period afterwards for security, audit, and compliance.
- Session signing keys: until the session expires or is revoked, plus thirty days, after which they are destroyed.
- Technical logs: typically ninety days.
Blockchain data cannot be deleted by us. See section 4.
7. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, hardware-isolated or managed key custody for session signing keys, access controls, and monitoring.
No system is perfectly secure. The design of the Services limits what a breach of our systems could cost you: we do not hold your master key or your funds, and session authority is bounded on-chain by the limits you set. We cannot, however, guarantee the security of any information you transmit to us.
8. International transfers
We use service providers located in a number of countries, so your information may be transferred outside where you live, including to countries whose data protection laws differ from your own. Where required, we use appropriate safeguards such as Standard Contractual Clauses.
9. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate information;
- delete information, subject to legal limits and the permanence of blockchain data;
- restrict or object to certain processing;
- portability — receive your information in a machine-readable format;
- withdraw consent at any time, without affecting processing already carried out;
- opt out of marketing, by using the unsubscribe link or contacting us;
- complain to your data protection authority.
If you are in California, you may also have rights to know what personal information is collected, disclosed, or sold, to delete it, to correct it, and not to be discriminated against for exercising these rights. We do not sell personal information and do not share it for cross-context behavioural advertising.
To exercise any of these, contact contact@waypoint.world. We may need to verify your request. We will respond within the timeframe the law requires.
10. Children
The Services are not directed to anyone under 18, and we do not knowingly collect information from them. If you believe a child has provided us information, contact us and we will delete it.
11. Third-party services
The Services link to and interoperate with third parties — AI providers, wallet providers, blockchain networks, block explorers, and DeFi protocols. Their handling of your information is governed by their own policies, not this one. We encourage you to read them.
12. Changes
We may update this Policy. The current version will always be posted here with its date. If changes are material, we will provide notice through the Services or by email where we have your address.
13. Contact
Questions, or to exercise your rights: contact@waypoint.world