Privacy Policy

Last Updated: September 19, 2026 — effective upon publication

This Privacy Policy explains how agleam processes information when you use agleam.xyz and agleam Earn. It describes the current product implementation; third-party services have their own practices. Please also read our Terms of Use.

1. Scope and overview

agleam Earn is a non-custodial interface without investor registration. Its wallet flow does not ask for a name, email address, phone number, account password, private key, or seed phrase. There is no administrator dashboard or sign-in system, and the Interface does not load administrator authentication services or process administrator identity or session information. agleam processes wallet addresses, public blockchain information, browser storage, and technical or security information needed to operate and protect the Interface.

2. Wallet and public blockchain information

When you connect or enter the Interface, the application may obtain your public wallet address, chain and provider information from your wallet. The address may be sent to agleam backend services and used to retrieve balances, transfers, transaction activity, vault positions, earnings, withdrawable amounts, and transaction-preflight information from blockchain, RPC, indexed, and protocol sources.

Transaction intent may include information such as an amount, destination, and transaction data used for preflight checks. If you approve and submit a transaction, its address, amount, token movements, approvals, transaction hash, receipt, and other details can become permanently public on the blockchain. A public address is pseudonymous, not necessarily anonymous: agleam or others may be able to associate it with a person using onchain and offchain information. agleam does not receive or store your private keys, seed phrase, or wallet password.

A durable backend reporting ledger retains submitted transaction observations, public wallet addresses, verified vault deposit and withdrawal events, assets and amounts, reviewed vaults, block and transaction identifiers, timestamps, transaction status, reliably derived tracked positions or values, cumulative totals, historical snapshots, and synchronization or reconciliation status. These records support internal database queries, not a public reporting dashboard or administrative API. An observation from the Interface alone is not proof: confirmed agleam attribution requires backend verification of the actual onchain transaction and receipt. Unproven historical activity remains unattributed, and tracked agleam-attributed positions are distinct from the shared Morpho vault’s total assets. Reporting is separate from financial execution, cannot sign or move funds, and reporting failures must not block wallet transactions.

3. Technical, security, and log information

When the Interface or its APIs are used, agleam and its infrastructure may process request and response details, timestamps, network or device information, errors, and similar operational metadata. Hosting or logging services may process IP addresses or other connection information. Application logs are configured to exclude query strings and redact certain authentication, cookie, and response-cookie fields, but logs and infrastructure records may still contain technical information.

Protected API routes use an IP-derived, pseudonymous value and a browser token to prevent abuse and enforce rate limits. Security records are stored in the backend database. Pseudonymization reduces direct exposure but does not make information necessarily anonymous.

4. Cookies and browser storage

  • API security cookie: protected API routes may set a first-party HttpOnly cookie used for rate limiting. Its browser maximum age is six hours. It is not described as an advertising cookie.
  • Session storage: the Interface uses browser session storage to retain locally observed transaction activity under a wallet-address-derived key. Its lifetime is controlled by the browser.
  • Wallet connection storage: Reown/AppKit and WalletConnect functionality may use local storage and wallet-session persistence for connection state and related metadata, such as selected network or wallet and cached wallet-related display information. Exact retention and vendor handling are controlled in part by those services and your wallet.

You can use browser and wallet controls to clear cookies or storage and disconnect a wallet. Doing so may end a connection, remove local activity, or reduce functionality; it does not erase blockchain records or information independently held by third parties.

5. Analytics

agleam maintains a backend reporting ledger for internal queries about recorded onchain activity, observations, balances, and historical growth. It is not an advertising tracker, and wallet-linked reporting data is not necessarily anonymous. agleam does not deploy marketing trackers, and Reown/AppKit analytics is disabled in agleam’s configuration. Wallets, Reown/WalletConnect, RPC providers, hosting providers, and other independent services may have their own technical collection or analytics practices, which agleam does not control.

6. How information is used

Information described above is used to:

  • connect your wallet and present the network, balances, position, earnings, and activity associated with its public address;
  • prepare, validate, submit, and show the status of transactions you choose to authorize;
  • retrieve and calculate protocol, vault, liquidity, rate, and accounting information;
  • maintain wallet-session and local activity functionality;
  • secure, troubleshoot, monitor, and improve the reliability of the Interface and APIs; and
  • prevent abuse, enforce rate limits, and comply with applicable legal obligations.

7. Third-party infrastructure

Operation of the Interface involves external services, including your wallet provider, Reown/AppKit and WalletConnect connectivity, Robinhood Chain and RPC infrastructure, Morpho APIs and protocol infrastructure, Steakhouse-curated vault infrastructure, hosting, database, and logging providers. Depending on the service and your interaction, these recipients may process wallet addresses, public blockchain activity, IP addresses, device or request information, and connection metadata under their own terms and privacy policies.

Public pages also load fonts from Google Fonts. Wallet-connectivity software on Earn pages can contact Reown services and load Reown-hosted fonts before a wallet is connected. These requests expose connection information such as an IP address and request metadata to the receiving service; visiting a page does not itself authorize a wallet transaction. Retired administrator URLs are unavailable and do not load authentication software.

agleam does not control independent providers’ collection, legal bases, security, location, retention, deletion, or use of information. Blockchain participants worldwide may receive and reproduce public transaction data. Because provider locations and data flows are not fully established by the application code, your information may be processed in countries other than where you live, subject to the relevant provider’s practices and applicable law.

8. Retention

Reporting records, checkpoints, and snapshots are stored persistently in the application database rather than only in browser or process memory, supporting internal historical queries after deployments and restarts. The application does not currently promise an automatic deletion period for those records. There is no active administrator authentication processing. Removing sign-in functionality does not itself erase information previously retained by independent providers or backups. Operational retention, backup deletion, and legal requirements require separate confirmation and must not be inferred from a session or cache expiry.

Untrusted transaction hints have a separate bounded intake lifecycle: pending hints expire after seven days, and rejected or expired hints are recycled while aggregate counters are retained. That intake limit and expiry do not apply to verified audit records, canonical blockchain event records, checkpoints, or historical snapshots, and do not erase public blockchain data.

agleam backend services temporarily cache public wallet activity, position accounting, vault totals, APY, liquidity, and related protocol data in server memory to operate efficiently. Cache expiry is not a promise of immediate physical deletion: expired entries may remain until later cleanup, replacement, or process restart.

The API security cookie has a browser maximum age of six hours. Backend rate-limit security records have operational expiry states, but deletion may occur later through subsequent cleanup or database maintenance. Session storage, Reown/AppKit local storage, and wallet connections persist according to browser, wallet, and provider behavior. Diagnostic logs, infrastructure records, database backups, and vendor-held information may follow operational or vendor retention periods that agleam cannot state from the current implementation. Confirmed blockchain records are public and effectively permanent. An expiry date does not guarantee deletion from backups, third-party systems, or the blockchain.

9. Data security

agleam uses technical measures intended to reduce risk, including non-custodial wallet authorization, restricted browser-cookie access for the API security cookie, pseudonymous rate-limiting records, and log redaction for selected sensitive request fields. No system, wallet, network, database, or transmission method is completely secure. agleam cannot guarantee that information will never be accessed, altered, lost, or disclosed. Protect your device and wallet, use trusted software, and never share private keys or seed phrases.

10. Public blockchain permanence

agleam cannot edit or delete information recorded on Robinhood Chain or another public blockchain. Disconnecting a wallet, clearing browser storage, or making a privacy request does not remove onchain transactions. Blockchain explorers, nodes, indexers, protocols, and other parties may continue to make this data available independently of agleam.

11. Your choices and rights

You may choose not to connect a wallet or submit a transaction, disconnect through your wallet, and clear relevant browser cookies or storage. Browser settings may block storage, though this can prevent parts of the Interface from working. Your wallet or third-party provider may offer additional privacy controls.

Depending on where you live, applicable law may give you rights concerning personal information, such as access, correction, deletion, restriction, objection, or portability, and a right to complain to a regulator. These rights may be limited where data is public, immutable, not controlled by agleam, needed for security or legal compliance, or cannot reasonably be linked to a verified requester. A wallet address can sometimes be linked to an identity, so agleam will evaluate a request rather than assume that all wallet data is anonymous. The general contact below should not be used to send sensitive information.

12. Children’s privacy

The Interface is not directed to children. Do not use it if you are below the age at which you can lawfully agree to the Terms of Use in your jurisdiction. The reviewed application does not knowingly request traditional account details from children. If you believe a child has provided personal information through the Interface, use the general contact below without posting sensitive information publicly.

13. Changes to this Policy

We may update this Policy to reflect product, provider, legal, or operational changes. The updated version will be posted here with a revised date and will take effect upon publication unless a later date is stated or applicable law requires additional notice.

14. Contact

For general questions about this Policy, contact agleam through the official agleam account on X. Do not post private keys, seed phrases, identity documents, wallet credentials, or other sensitive personal information on X. X is a public third-party platform and is not currently a dedicated privacy-rights or legal-notice channel.