Legal
Privacy policy
What Krypsis collects, why, who receives it, and how long any of it lasts.
Last updated 17 September 2026
The short version
Krypsis has no accounts. It does not know your name, your email or your face, and it never asks. It uses the least it needs to run swaps and sends, keep the service safe, run Rewards and help you when something fails. A swap record is kept for 7 days, then deleted. If you sign up for Rewards, your wallet address and your points are kept longer: see If you sign up for Rewards.
We sell nothing and share nothing for advertising. What leaves Krypsis goes to the route provider that runs your swap, our infrastructure providers, the wallet connection service you pick, and the public Robinhood Chain RPC your browser reads balances from: see Who receives it.
What we collect
Krypsis processes these kinds of information:
- Network information: your network address, and the country a request comes from, when known.
- Browser details: your browser's user agent string, and your time zone, which the page sends with every request.
- Session identifiers: a random value in a cookie named krypsis_session, and a token that proves a request came from the page. The cookie is http only and same site. Our side keeps a hash of its value with its start and end times, never the value itself.
- Wallet addresses: an address you connect and prove with a signature, and the address you sign up for Rewards with.
- Swap and send records: the two assets, the amounts, the route, the receiving address you typed, the deposit address the route provider issued, the provider's order identifier, the status, and the transaction hash once there is one.
- Rewards records: if you sign up, your points and the swaps that earned them. If you sign up for Rewards has the detail.
- Error records: when something fails, the error ID, its code, the HTTP status, the request method and the API route. Nothing about you.
- Messages: what you write to us by email.
Why we use it
- To run swaps and sends: to price them, create them, follow them and tell you where they are. The session is what keeps a swap yours while you use Krypsis.
- To keep Krypsis secure and fair: we apply strict rate limits and abuse prevention. Their counters hold one way hashes made with our own secret, never your addresses themselves, and expire within a day.
- To run Rewards: to count points, work out each epoch's allocations and prepare claims.
- To help you: an error ID or a swap ID lets us find what happened without asking you to describe it.
- To meet legal obligations, such as answering a valid legal order.
We use none of it for advertising and build no profile from it.
What your browser stores
Besides the session cookie, Krypsis writes a few entries into your browser's local storage. They stay on your device and we cannot read them.
krypsis.session: the token that proves a request came from this page, which mode the app is in, and when the session endskrypsis.prefs: which routes you want quoted, whether you asked for a fixed rate, and any exchange you turned offkrypsis.order: the swap you are following, so you can close the page and come back to itkrypsis.pending: the key that stops one swap being created twice if your connection dropskrypsis.sound: whether sound is on
Clearing the Krypsis data in your browser removes all of them. Clearing them while a swap is running loses your view of it, unless you made a recovery link first.
A WalletConnect connection is kept in the page's memory, not in your browser's storage, so closing the page ends it.
Who receives it
The route provider runs your swap. It receives only what it needs to price, run and deliver it: the assets, the amount, the route, the receiving address, and the network details every web request carries (network address, browser, time zone, country). It handles them under its own policy.
Our infrastructure providers serve Krypsis and see the requests that reach it, as with any online service. Our logs keep only the error records above.
If you connect a wallet, WalletConnect and the public Robinhood Chain RPC receive what If you connect a wallet describes.
If a valid legal order reaches us, we will answer it with what we actually hold, kept only as long as How long we keep it says. If Krypsis is ever acquired, swap records or Rewards data could pass to whoever takes it on, under this policy.
If you connect a wallet
Connecting a wallet is optional and no route needs it. A browser wallet such as MetaMask, OKX Wallet or Rabby talks to the page directly.
If you choose WalletConnect, your browser opens a connection to WalletConnect's relay and may load a verification frame from WalletConnect. That reaches them, not us: they see your network address and whatever their own software sends. They handle it under their own terms.
Whichever way you connect, the only thing Krypsis receives is the address you proved. We keep it for 24 hours, or until you disconnect, and use it for abuse prevention and for Rewards if you sign up.
While a wallet is connected, your browser reads its balances from the public Robinhood Chain RPC. Those balance reads send the wallet address to that RPC.
If you sign up for Rewards
If you sign up for Krypsis Rewards, we keep your wallet address, when you signed up, and your volume and points per epoch.
For each swap or send that counts, we keep its ID, whether it was a swap or a send, the route, the two assets, its dollar value, its points, its status, and when it was made and settled. We never keep a sending, receiving or deposit address with it.
Signing up links your wallet to the swaps this browser session made earlier in the same epoch, so they count too.
Allocations use your wallet's public KRYPSIS balance on Robinhood Chain at the epoch's snapshot. When claims open, only a fingerprint of each epoch's list goes on chain, and a claim shows your wallet and its amount, like any transfer.
This data is kept until 90 days after the last epoch's distribution, then deleted, unless the law requires us to keep it longer. You can ask us to delete it sooner: see Asking what we hold, asking for deletion.
What we do not collect
No name, no phone number, no document, no photograph. No email address unless you write to us.
No private key and no seed phrase. Ever. Not in the app, not by email, not on X. Anyone asking you for one in our name is not us.
No analytics, no advertising, no tracking pixel and no cross site cookie. Krypsis loads no third party script of its own, and its fonts and images come from our own domain. The one exception is WalletConnect, and only if you pick it: see If you connect a wallet.
How long we keep it
- Swap and send records, and recovery links: 7 days after the swap is created.
- Sessions: 24 hours, or 7 days after you create a swap.
- A wallet address you proved: 24 hours, or until you disconnect.
- Quotes: a quote expires after about 20 seconds. Its record is deleted within the hour, or with the swap that used it.
- Rate limit counters: less than a day.
- Error records: as long as our infrastructure providers keep logs. They hold nothing about you.
- Rewards data: until 90 days after the last epoch's distribution, unless the law requires longer.
- Email: as long as it takes to answer you and to keep a record of the answer.
Database backups are kept for a limited time, so a deleted record can survive in a backup for up to 30 days.
What is already on chain
A swap ends in transfers on a public blockchain. Those transfers are permanent and anybody can see them. Nothing in this policy changes that.
The Private route breaks the link on chain between your deposit and the delivery. It does not erase either one.
Asking what we hold, asking for deletion
Write to organization@krypsis.network. If you have the swap ID or an error ID, include it. For Rewards data, include your wallet address, and we may ask you to prove the wallet is yours. Without one we may not be able to find the record, because there is no account to look you up by.
We will tell you what we hold and, if you ask, delete it before its time is up.
Three honest limits. Deletion cannot undo anything already on chain. It cannot reach the route provider's own records, which it keeps under its own policy, so ask the provider about those separately. And a deleted record can survive in a backup for up to 30 days.
Changes to this policy
This policy can change. The version on this page is the one that applies, and the date at the top says when it was last changed.
How to reach us
organization@krypsis.network. Include the error ID from the screen if there was one, and one line about what you were doing.