// Latyx · legal
Privacy Policy
Last updated August 2, 2026
Latyx is a forensic-intelligence tool for public on-chain data, currently offered as a free beta. This policy explains what we collect, why, and the choices you have. Using Latyx as a guest requires no account and no wallet connection.
What we collect
- Inputs you submit - wallet addresses, token or contract addresses, transaction hashes, and links you paste to open a case. These are public on-chain identifiers, but they can become personal data when associated with you or your account.
- Session identity - a hashed guest-session identifier stored in a cookie, or, if you sign in with Google, your account email and name.
- Usage data - per-day request counts used to enforce quotas and prevent abuse, plus limited analytics used to understand product and campaign performance.
- Investigation results - the evidence, risk scores, and reports produced for your cases, associated with your session or account.
- Token utility data - linked wallet addresses; wallet-link challenge and signature verification results; public transaction data; quotes, payment states, and immutable accounting entries for credit grants, reservations, consumption, and restoration. We do not collect your seed phrase or private key.
How we use it
To run the investigations you request, generate reports, enforce usage quotas and budgets, keep the service secure, and improve accuracy and campaign measurement. We do not sell your personal data.
Campaign measurement
We use the X Pixel to understand whether our own ads lead to visits and useful investigations. Page locations are hidden from X, and conversion events contain only an opaque investigation ID for duplicate prevention. We do not send X the wallet, token, contract, transaction, ENS name, social profile, report contents, findings, score, email address, or other subject you investigate. The pixel does not load when your browser enables Global Privacy Control or Do Not Track. X may store or read its own identifier for attribution as described in the X Privacy Policy.
Token utility measurement
Product analytics receive low-cardinality event states, product codes, integer quantities, and a hashed internal cohort key. We do not send PostHog raw wallet addresses, transaction signatures, memos, token balances, emails, or payment-intent identifiers. Public price providers and Solana RPC providers receive the mint, pool, vault, or transaction identifiers needed to validate quotes and payments.
Service providers
To fulfil a case, the identifiers you submit are sent to on-chain and data providers - including Etherscan, GoPlus, Honeypot, DexScreener, and Alchemy - and report text is generated using OpenAI. The service runs on Vercel, with data stored in Neon (Postgres), Upstash (Redis), and Cloudflare R2. Google is used for optional sign-in. PostHog provides product analytics, and X provides the limited campaign measurement described above. These providers process data for the stated service and measurement purposes.
Retention
Guest-session data and its investigations expire automatically after the session lifetime. If you have an account, your data is retained until you ask us to delete it. Public transaction data remains on Solana. Token-payment and immutable accounting records may be retained after account deletion where needed for ledger integrity, fraud prevention, dispute handling, tax, legal, or regulatory obligations. A wallet link’s revocation history may remain even after it is no longer active.
Your choices
You can use Latyx entirely as a guest without creating an account. To request access to, or deletion of, account data, email privacy@latyx.io.
Security
Data is encrypted in transit. Secrets and credentials are stored in managed secret stores and are never exposed to the browser.
Changes
We may update this policy as the product evolves. Material changes will be reflected here with a new effective date.
Contact
Questions about privacy? Email privacy@latyx.io.
