Privacy Policy and Notice at Collection
Effective August 30, 2026 | Version 2026-08-30
1. Who we are and scope
This policy explains how personal information is handled when you use Felix Trade. References to “Felix,” “we,” “us,” or “our” mean the provider responsible for making the Felix service available to you. This policy covers felix.trade, the Felix API, MCP server, SDKs, agent runtime, support and feedback features, and related services. It does not govern independent third parties, public blockchains, or trading venues.
This policy is a notice about processing, not a request to consent to every use. We rely on the legal bases described below. By affirmatively accepting the Felix Terms, you acknowledge that you received this policy.
2. Notice at collection
We collect the following categories for the listed purposes:
- Identifiers: email, internal account and key IDs, wallet addresses, and support identifiers, to create and secure accounts and respond to requests.
- Commercial and financial activity: plans, fees, balances, orders, fills, positions, transfers, and transaction identifiers, to execute instructions, reconcile money, bill, and maintain audit records.
- Internet and device activity: bounded request metadata, IP or one-way IP-derived signals, user agent, timestamps, errors, latency, and security events, to authenticate, rate limit, debug, prevent abuse, and operate the Service.
- User content: prompts, strategy code, agent settings, support tickets, feedback, and attachments you choose to send, to provide the requested feature and support.
- Marketing and attribution data: waitlist email, consent version, referral code, campaign fields, referrer host, landing path, and experiment variant, to deliver requested communications and measure acquisition.
- Inferences and risk signals: fraud, sanctions, credential, anomaly, and platform-integrity signals, to protect users, Felix, and third parties and to comply with law.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics about you. Providing account and transaction information is necessary to use authenticated or trading features; providing optional marketing or profile information is voluntary.
3. Information you provide
You may provide an email address, account label, profile or billing details, prompts, strategy code, risk settings, support and feedback content, and wallet addresses. Never send us a private key, seed phrase, full API key, password, or authentication cookie through prompts, tickets, or email. If you include another person’s information, you must have authority to do so.
4. Wallet, key, and blockchain data
Felix processes public owner, Safe, deposit, venue, and destination addresses and related on-chain activity. Blockchains are public, immutable systems. Other people may view and correlate addresses, balances, approvals, and transactions independently of Felix, and we cannot erase public-chain records.
Felix does not receive the plaintext owner private key or seed phrase generated on an owner-controlled client. Separate, narrowly scoped execution material may be processed inside attested signing infrastructure to perform owner-authorized, allowlisted actions. We store the minimum operational records needed to prove and enforce that authority, investigate incidents, and reconcile transactions.
5. Information collected automatically
We collect bounded service and security logs, including endpoint, method, status, timing, request correlation data, rate-limit state, device and browser characteristics, and connection information. Where feasible, Felix stores sensitive application fields encrypted and uses keyed or one-way indexes for matching. We may collect cookies or local-storage values needed for security, session continuity, preferences, and privacy-respecting analytics.
6. Sources of information
We receive information from you and your software; from your use of Felix; from public blockchains; from trading venues, wallet and bridge providers, RPC and market-data providers; from fraud and sanctions screening sources; and from service providers that help us operate, secure, communicate, and bill.
7. How we use information
- create, authenticate, recover, and administer accounts and credentials;
- provision wallets and execute, route, reconcile, settle, and report authorized activity;
- run research, backtests, agents, alerts, subscriptions, feedback, and support;
- enforce limits, prevent abuse, investigate incidents, and protect users and the Service;
- maintain accounting, audit, legal, tax, and compliance records;
- debug, measure, and improve performance, reliability, safety, and usability;
- send transactional notices and communications you requested; and
- create aggregated or de-identified analytics that do not reasonably identify a person.
8. Legal bases for EEA and UK processing
Where GDPR or UK GDPR applies, we process personal data to perform our contract with you, including account, execution, support, and billing functions; for legitimate interests such as security, fraud prevention, debugging, reliability, recordkeeping, and product improvement; to comply with legal obligations; and with consent where we specifically ask for it, such as certain marketing communications or optional cookies. You may withdraw consent without affecting earlier lawful processing. We balance legitimate interests against your rights and do not use that basis where your rights override our interests.
9. How we disclose information
We may disclose the minimum information reasonably necessary to:
- processors and service providers for cloud hosting, database, security, analytics, email, AI processing, support, and payment operations;
- venues, networks, wallets, bridges, relayers, RPC and data providers to execute or reconcile an action you requested;
- professional advisers, auditors, insurers, and financing parties under confidentiality obligations;
- authorities or affected parties when required by law or reasonably necessary to protect rights, safety, funds, or the Service;
- a successor in a merger, financing, reorganization, or sale, subject to applicable notice requirements; or
- another party at your direction or with your consent.
Current core provider categories include AWS infrastructure, Cloudflare network security, Supabase database services, Vercel website delivery, transactional email providers, AI model providers, blockchain RPC providers, and supported venues and routing providers. Providers and venues may change as the Service evolves.
10. Retention
We retain information for the shortest period reasonably necessary for its purpose, taking into account security, sensitivity, legal obligations, dispute and fraud risk, and whether the record is needed to reconcile money. Registration challenges generally expire after 10 minutes. Withdrawn waitlist records are deleted or suppressed within 30 days. Routine operational and security logs are generally retained for up to 24 months. Support and feedback records are generally retained for up to 3 years after closure. Account, legal-acceptance, transaction, fee, tax, audit, fraud, and incident records may be retained for the account lifetime and up to 7 years afterward where needed for legal, accounting, security, or claims purposes.
We may retain a record longer for an active dispute, security incident, legal hold, or binding legal obligation. Encrypted backups age out on their normal rotation. De-identified data may be retained longer. Public blockchain and third-party venue records are outside our control and may be permanent.
11. Security
We use safeguards designed for the sensitivity of the information, including TLS in transit, encryption at rest, application-layer encryption for sensitive database fields, access controls, KMS-managed infrastructure secrets, attested signing controls, monitoring, anomaly detection, rate limits, audit records, and tested recovery procedures. No system is perfectly secure. We cannot guarantee that unauthorized access, misuse, alteration, loss, or destruction will never occur. If an incident affects personal information, we will notify affected people and authorities as required by applicable law.
12. Your rights and requests
Depending on applicable law, you may request access, correction, deletion, portability, or a description of processing; object to or restrict certain processing; withdraw consent; opt out of a sale, sharing, or targeted advertising; or appeal a denied privacy request. We will not discriminate against you for exercising a right. Some requests are limited by security, legal, financial-record, public-chain, and other lawful exceptions.
Send requests to privacy@felix.trade. We may verify control through an authenticated session, a signature from the recorded owner address, or another proportionate method. Never send a private key, seed phrase, password, or full API key. Authorized agents may submit requests where applicable, subject to proof of authority. If we deny a request and your law provides an appeal right, reply with “privacy appeal.”
13. California and other US state notices
In the preceding 12 months, we collected the categories described in Sections 2 through 6, used them for the purposes in Section 7, and disclosed them to the recipient categories in Section 9. We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined by California law. We have not knowingly sold or shared personal information of people under 18. California residents may request to know, access, correct, or delete information and may use an authorized agent, subject to verification and legal exceptions.
Felix does not currently offer a financial incentive in exchange for personal information. If that changes, we will provide a separate notice. Where an applicable state law requires an appeal or attorney-general contact after an appeal, we will provide it with our decision.
14. Cookies, Global Privacy Control, and Do Not Track
Felix uses necessary storage for sessions, security, preferences, and account continuity and may use limited analytics to understand service performance. We do not use third-party advertising cookies to sell or share personal information for cross-context behavioral advertising. Because Felix does not currently perform that sale or sharing, a Global Privacy Control signal does not change advertising activity; if that practice changes, we will honor legally valid GPC signals. Browser “Do Not Track” signals are not standardized, and Felix does not independently respond to them. Third-party venues and links may use their own technologies under their own policies.
15. Automated processing
Felix uses automated systems for authentication, rate limiting, fraud and anomaly detection, risk controls, routing, and agent execution. A user configures and authorizes trading agents, which may produce economically significant outcomes. Security systems may automatically block or pause activity, but you may contact us to request review where applicable. Felix does not use personal information to make solely automated employment, housing, education, insurance, or consumer-credit eligibility decisions.
16. International transfers
We operate from the United States and providers may process information in other countries. Where required, we use an applicable lawful transfer mechanism, such as an adequacy decision, contractual safeguards, or another mechanism recognized by law. You may contact us for information about safeguards relevant to your data.
17. EEA and UK complaints
If EEA or UK law applies, you may lodge a complaint with the data-protection supervisory authority where you live, work, or believe a violation occurred. We would appreciate the opportunity to address your concern first through privacy@felix.trade, but contacting us first is not required.
18. Children
Felix is not directed to anyone under 18, and we do not knowingly collect personal information from children. Contact us if you believe a child provided information so we can investigate and delete it where required.
19. Changes and contact
We may update this policy and will identify the new effective date and version. We will provide additional notice for material changes as required by law. A material privacy change does not retroactively change the purpose for which data was collected without an appropriate legal basis.
Privacy contact for Felix Trade. Questions, rights requests, and appeals: privacy@felix.trade. Legal contact: legal@felix.trade.