> For the complete documentation index, see [llms.txt](https://flipper-3.gitbook.io/flipper-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://flipper-3.gitbook.io/flipper-docs/resources/privacy-policy.md).

# Privacy Policy

**Effective Date:** **July 10, 2026**

This Privacy Policy (“Policy”) describes how **Unified Protocol Inc**., a company incorporated under the laws of the British Virgin Islands, with registration number 2213389 (“we,” “us,” or “our”), manages your personal data when you use the Flipper website and its decentralized apps (collectively, the “Interface”).

By using, browsing, or otherwise engaging with the Interface, you confirm that you have read and understood this Policy. If you do not agree with the provisions of this Policy, you must cease using the Interface immediately.

## <mark style="color:$primary;">I. General Principles</mark>

**I.1.** Flipper is designed to collect as little personal data as possible. Our personal data processing practices vary by Interface feature. The Spot interface (Swap and Trade sections) and Reward program operate via pseudonymous crypto wallet connections, while our advanced trading terminals (Perps terminal, DeForex) offer optional third-party authentication for a seamless user experience. Choosing these optional methods involves processing specific identifying data.

**I.2.** **Spot.** Our Spot interface (the Swap and Trade features, “Spot”) does not collect personal data that can directly identify you. No account creation is needed. Wallet addresses and blockchain transaction data are pseudonymous rather than anonymous. They may constitute personal data where they can reasonably be linked to an individual, including through IP addresses, authentication data, or support records.

**I.3.** **Perps & DeForex.** For margin and synthetic trading, the Interface offers multiple authentication paths. If you connect a standard crypto wallet, we process only your public wallet address and connection status. We also offer an embedded wallet stack via optional social login authentication methods (including Google, Apple, Telegram, email address, X, and Discord). If you explicitly choose to access the Interface through these methods, your profile data (such as your email or username) will be processed by our third-party provider (Privy) on our behalf and made available to us solely for the purpose of managing and securing your account session.

**I.4.** **Blockchain Disclaimer (PLEASE READ CAREFULLY!).** Flipper integrates with various decentralized protocols and blockchain networks (including perpetual-trading protocols on Solana). When you execute a transaction via the Interface, the transaction details, including your wallet address, the recipient’s address, the transaction route, and the amount, are sent to the relevant public network and permanently recorded on its decentralized public ledger (“On-Chain Data”).

This process has the following important implications for your data:

* **Public and Permanent by Design:** All data stored on the blockchain can potentially be accessed by anyone worldwide with internet access.
* **Immutability:** Once transaction data is added to the blockchain, it cannot be altered or removed.
* **Global Data Distribution:** On-Chain Data is replicated and shared across a worldwide network of independent nodes, which may be located in countries with data protection standards that differ from those of your home country.
* **Limitations of Data Protection Rights:** Because blockchain is immutable, permanent, and decentralized, exercising rights such as the “right to erasure” or "right to rectification" is technically impossible for On-Chain Data.

**I.5.** **Roles Under Data Protection Law.**

* You determine the commercial purpose and key parameters of the transactions you initiate. Our role in relation to On-Chain Data depends on the relevant feature and applicable law, and we may act as a controller for processing where we determine its purposes or essential means.
* **Our Role as a Data Controller:** Flipper serves as the data controller for Off-Chain Data (any data we process off the blockchain, whether on our own servers or through third-party providers). This includes, among others, infrastructure and security logs (such as IP address and device/browser information), internal analytics and marketing data, optional authentication data from logging into our Perps terminal via social accounts, data submitted to our AI Assistant, support communications, and data used to administer our Reward and Referral Programs.

**I.6.** **Age Limitation.** Our services are not intended for individuals under 18. We do not knowingly collect personal data from anyone under 18. By using Flipper, you confirm that you are at least 18 years old. If you are a parent or guardian and learn that your child has shared personal data with us, please contact us immediately at <privacy@flpp.io>. If we discover that we have unintentionally collected personal Off-Chain Data from a child under 18, we will promptly delete that information from our records.

## <mark style="color:$primary;">II. Data We Process, Purpose, and Legal Basis</mark>

**II.1.** This section explains the data we process to maintain the security, compliance, and functionality of the Interface, including the purposes for which we use it and the legal basis for processing it under applicable data protection laws.

**II.2.** **Categories of Processed Data.** For transparency, we detail the types of Off-Chain data we process in the table below.

| <mark style="color:$primary;">**Category of Data**</mark>                                                                                                                                                                                                                                                                                                                                                                               | <mark style="color:$primary;">**Specific Data Fields**</mark>                                                                                                                                                                                                  | <mark style="color:$primary;">**Primary Purpose of Processing**</mark>                                                      | <mark style="color:$primary;">**Legal Basis of Processing**</mark>                     |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- |
| **Infrastructure and Security Logs**                                                                                                                                                                                                                                                                                                                                                                                                    | IP address, requested URL, User-Agent, timestamp                                                                                                                                                                                                               | Security auditing, DDoS mitigation, and anti-fraud management                                                               | **Legitimate Interests** (Ensuring network and information security)                   |
| **Authentication Data** (via Privy)                                                                                                                                                                                                                                                                                                                                                                                                     | Email address, social media profile identifiers/names (Google, Apple, X, Discord, Telegram), session tokens                                                                                                                                                    | Creating and securing your account session, provisioning an embedded crypto wallet stack via Privy                          | **Performance of a Contract** (Providing the requested Interface)                      |
| **Internal Analytics and Marketing Data**                                                                                                                                                                                                                                                                                                                                                                                               | Public wallet address, UTM parameters, referrer URL, full User-Agent string, geolocation (region/city level), and transaction parameters (trade parameters)                                                                                                    | Marketing attribution, aggregated user behavior analysis, and engagement tracking to improve Interface design and user flow | **Legitimate Interests** (Improving product and its functionality)                     |
| <p><strong>User-submitted content, including AI interaction data</strong><br><br><em>Note: We do not intentionally collect personal identifiers via the AI chat, and users are strongly advised not to submit any. Your text queries are transmitted to our backend and associated with your public wallet address to process the request; they may then be relayed to a third-party AI provider acting as our Data Processor.</em></p> | Text queries submitted to the AI chat; associated public wallet address                                                                                                                                                                                        | Interpreting user intent to suggest AI-optimized transaction routes                                                         | **Performance of a Contract** (Providing the AI-driven features requested by the user) |
| <p><strong>Support Communications</strong><br><br><em>Note: We strictly advise users against sharing sensitive personal information (e.g., ID documents) or security credentials. Any such unsolicited data is processed only to the extent necessary to delete it or resolve the immediate inquiry and is strictly out of our requested scope.</em></p>                                                                                | Wallet address, email address, and communication history/transcripts, and technical and usage data automatically collected by the messenger (such as IP address, approximate geolocation, operating system, device and browser information, and in-app events) | Resolving user technical inquiries, handling transaction disputes                                                           | **Legitimate Interests** (Providing effective user support)                            |
| **Referral Program Data**                                                                                                                                                                                                                                                                                                                                                                                                               | Public wallet address and cryptographic signature                                                                                                                                                                                                              | Administering the referral network, calculating rewards, and preventing manipulation                                        | **Performance of a Contract** (Administering reward program rules)                     |

**II.3.** **Detailed Legal Basis for Processing.**

* **Performance of a Contract:** We process your authentication details (via Privy), embedded wallet session data, AI chat queries, and referral program data to deliver the Interface features you request. Your use of the Interface constitutes a binding agreement between you and us, as outlined in our Terms of Use. As explained in Section 1.5, when you submit an on-chain transaction, you act as the controller of that transaction; we merely provide non-custodial software that executes your instructions.
* **Legitimate Interests:** We rely on our legitimate interests for essential operations that cannot be optional. After a balancing test, we determined that our processing does not infringe on your fundamental rights and freedoms because:

1. Retaining complete infrastructure logs for 30 days is standard practice and is legally recognized as a legitimate interest under data protection law to safeguard our platform and users from cyber threats.
2. Our marketing and behavioral analytics rely on data linked to public cryptographic (wallet) addresses, which are pseudonymous rather than directly identifying. We apply data minimization and, where possible, aggregation to limit the impact on your privacy.
3. When you voluntarily contact us, you can expect us to process your data to address your request.

**II.4.** **Your Right to Object.** Since we rely on legitimate interests for certain technical and analytical data processing, you have the right to object on the basis of your specific circumstances. Instructions for exercising this right are outlined in Section VIII.

## <mark style="color:$primary;">III. Third-Party Integrations</mark>

**III.1.** The Interface offers advanced features by integrating with, aggregating data from, and interacting with various third-party applications, infrastructure providers, and decentralized smart contracts (collectively “Third-Party Services”).

**III.2.** **Authentication and Embedded Wallets (Privy).** We use a third-party wallet-as-a-service provider, Privy, to power our authentication interface. Privy’s role depends on your chosen login method: If you connect a self-custodial wallet, Privy serves as a technical bridge to read your public wallet address and verify the cryptographic signature, without collecting personal profile data. If you access the Perps or DeForex terminals via optional social login, Privy acts as our Data Processor. In this case, Privy securely collects and processes your login credentials on our behalf to generate and manage an embedded crypto wallet for your session.

**III.3.** **Decentralized Protocols and Liquidity Aggregation.** Flipper functions as an aggregator. When you approve a transaction, your On-Chain Data is submitted directly to the third-party smart contracts. We have no control over these external decentralized protocols and assume no responsibility for their functionality, security, or data practices.

**III.4.** **Operational and Functional Vendors.** We engage trusted Third-Party Services to provide specific features within the Interface. Depending on the service, providers may act as our processors or as independent controllers under their own privacy notices. These vendors process data to provide the following services:

* **Customer Support:** We use Intercom Customer Agent software for live chat support. When you reach out to support, your wallet address and chat transcripts are processed and stored on Intercom’s servers in the United States. As a messaging tool, Intercom also automatically collects certain technical and usage data, such as your IP address, approximate geolocation, operating system, device and browser information, and in-app events, to deliver and secure the chat and help us respond to your inquiry. This processing is also governed by Intercom’s privacy policy.
* **AI Copilot:** Your text queries are first received by our backend, where they are associated with your public wallet address to process your request. They may then be relayed via API to a third-party AI provider OpenAI acting as our Data Processor. Under our agreement, the provider processes your queries only to generate real-time responses during your session; the queries are not used to train its models and are not shared further.
* **Charting Tools:** We use TradingView for market charts. TradingView may set its own functional cookies on your device, which are governed by its privacy policies.
* **Referral & Rewards:** We utilize Claimr to manage our XP and referral quest programs, which verify participation through your wallet address and cryptographic signatures.

**III.5.** **No Endorsement or Control.** Including any Third-Party Service in the interface does not imply that Flipper endorses, approves, or recommends it. We do not oversee or evaluate the privacy practices of these external services.

**III.6.** **Your Responsibility and Assumption of Risk.** Engaging with any Third-Party Service is entirely at your own risk. We recommend that you perform your own due diligence and thoroughly review the terms of service and privacy policies of any authentication providers, analytics vendors, or decentralized protocols before using them through our Interface.

**III.7.** **Limitation of Liability.** Flipper shall not be responsible for any damages, losses, privacy breaches, or other harm that may arise from or be related to your use of or reliance on any Third-Party Service accessed through our Interface, whether directly or indirectly.

## <mark style="color:$primary;">IV. Cookies, Local Storage, and Related Technologies</mark>

**IV.1.** The Flipper Interface uses cookies, local storage, and similar tracking technologies to maintain core functions, authenticate users, and monitor platform performance.

**IV.2.** **Types of Cookies and Technologies Used.** The specific technologies we use vary depending on the section of the Interface you access.

* **Strictly Necessary Cookies & Local Storage:** The Interface uses browser local storage, session storage, and strictly necessary cookies to preserve the application’s state. This includes saving your preferences (such as dark mode), favorite tokens, referral codes, and session tokens. All of this data is stored locally on your device and is essential for the Interface to operate properly.
* **Proprietary Analytics Cookies:** We use first-party analytics cookies, stored for up to 365 days, to track visits and analyze how users navigate the Interface.
* **Third-Party Analytics:** We use Google Analytics to collect aggregated usage data, which is retained in accordance with Google's policies and typically for up to 2 years.
* **Advertising / Remarketing (Spot only):** Spot may load Google Ads tags for campaign measurement and remarketing, which set their own cookies in accordance with Google's policies.
* **Functional Third-party Cookies:** These are set by services such as Privy (authentication), Intercom (customer support), Claimr (rewards), and TradingView (charting), and are necessary for those integrations to function. Please note that Perps does not currently display a separate cookie consent banner; its first-party analytics cookie (365 days) and the functional cookies above are set when you access the terminal.

**IV.3.** **Cookie Management.** You can control your cookie settings through your web browser. Spot also displays a cookie notice that informs you about the cookies we use. Please be aware that disabling strictly necessary cookies or local storage may limit certain Interface features.

## <mark style="color:$primary;">V. Data Sharing and Cross-Border Transfers</mark>

**V.1.** We never sell or rent your personal data to third parties for marketing purposes. We share data only in specific, limited cases to operate, secure, and improve the Interface.

**V.2.** **Authorized Team Access.** To develop, operate, and support our services, only approved team members—such as developers and customer support staff—have access to the technical and analytical data we handle. Our team is global, with key staff in Georgia and Armenia. Access is strictly role-based and protected by internal confidentiality agreements.

**V.3.** **Infrastructure and Hosting.** Our main database and proprietary analytics system are physically located in Frankfurt, Germany, and hosted on Google Cloud.

**V.4.** **Cross-Border Transfers and Safeguards.** Because Flipper operates internationally, your data may be transferred to, stored in, or accessed from countries outside your home jurisdiction, in particular the United States (where certain third-party processors operate) and Armenia and Georgia (where members of our team are located). Some of these countries may not offer the same level of data protection as your home jurisdiction. Where we rely on third-party processors, the relevant transfers are governed by the data-processing terms and international transfer mechanisms that those providers maintain under their own agreements. Where our team members access data, we limit such access to what is strictly necessary and apply role-based access controls, data minimization, and binding confidentiality obligations. In practice, we work primarily with public wallet addresses and pseudonymous identifiers rather than directly identifying information, which further reduces the risks associated with these transfers.

**V.5.** By using the Interface, you acknowledge that your data may be processed in the locations described above.

**V.6.** We may disclose the data we hold if we believe in good faith that such disclosure is strictly necessary to:

1. Comply with applicable laws or respond to a legitimate and legally binding order from a competent court, regulatory body, or law enforcement agency.
2. Enforce our Terms of Use and investigate possible violations.
3. Ensure the security, integrity, and operational stability of our interface.
4. Identify, monitor, or examine potential instances of fraud, security violations, or illegal conduct, including money laundering or sanctions evasion.

## <mark style="color:$primary;">VI. Data Retention</mark>

**VI.1.** **Core Retention Principle.** In line with the data protection principle of storage limitation, we do not store Off-Chain Data longer than necessary for its intended purposes.

**VI.2.** Our retention periods are tailored to each data category and its operational purpose:

* **Infrastructure and Security Logs:** Your system logs, including IP addresses, requested URLs, and User-Agent, are stored in Google Cloud for 30 days to support security auditing and help prevent fraud. After this period, they are automatically deleted.
* **Internal Analytics Data:** Data associated with your public wallet address is currently retained on an ongoing basis for analytical and business purposes; we are in the process of defining automated deletion schedules. Fully aggregated and anonymized versions of this data may be retained indefinitely to enhance the Interface.
* **Support Communications:** Data from your interactions with our support team via Intercom Customer Agent or email is retained as long as needed to resolve your inquiry, typically for an additional 18 months to address follow-up questions or disputes.
* **Error Logs (Spot only):** Server-side error logs, used solely for technical diagnostics, are stored locally on our servers and rotated based on file size. We do not use these logs to identify users.
* **Cookies and Local Storage:**
  * Proprietary analytical cookies are retained for up to 365 days.
  * Third-party analytics services like Google Analytics are kept in accordance with the provider’s policy, usually for up to 2 years.
  * Data in your browser’s local storage remains until you disconnect your wallet or clear your browser data. In contrast, session storage is automatically erased when you close the browser tab.

**VI.3.** **On-Chain Data:** As stated in Section I, data stored on public blockchains is permanent and immutable. Because we do not control this data, it is not subject to our retention or deletion policies.

## <mark style="color:$primary;">VII. Data Security</mark>

**VII.1.** **Security Measures.** We are dedicated to safeguarding the data we process. We apply appropriate technical and organizational safeguards to protect the Off-Chain Data we manage from unauthorized access, changes, disclosures, or destruction. These measures include:

* **Infrastructure Security:** We rely on enterprise-grade cloud providers such as Google Cloud, which offer integrated protections for rate limiting and DDoS mitigation.
* **Encryption:** We use protocols such as HTTPS/TLS to secure data in transit.
* **Access Controls:** We implement strict role-based access controls to ensure that only authorized personnel who need access to perform their duties can access backend systems and databases.

**VII.2.** **Disclaimer.** Despite our efforts to ensure strong security, no online transmission or electronic storage method is completely secure. Consequently, we cannot guarantee the absolute safety of the data we process.

## <mark style="color:$primary;">VIII. Data Protection Rights</mark>

**VIII.1.** **Your Rights:** Depending on your location, you may have certain rights regarding the Off-Chain Data we process.

* **Right of Access:** You can request details about the personal data we keep about you.
* **Right to Erasure (“Right to be Forgotten”):** You may ask us to delete personal data we hold, such as your support communication history or your email address linked to Privy.
* **Right to Rectification:** You are entitled to request the correction of any inaccurate personal data we hold about you.
* **Right to Object / Restriction:** You can object to our processing of your data if we rely on legitimate interests.

**VIII.2.** **Limitations on On-Chain Data.** As noted in Section I, the Interface interacts with immutable, decentralized public ledgers. Once a transaction is recorded on the blockchain, it is technically impossible to erase or modify that data. These constraints are inherent to blockchain technology and are beyond our control.

**VIII.3.** **Exercising Your Rights.** If you wish to exercise any data protection rights, contact us at <privacy@flpp.io>. Spot is pseudonymous; therefore, requests to confirm wallet activity may require you to cryptographically sign a message to verify ownership of the wallet address. For social login or support history requests, please use the same email or social account associated with your request. We aim to respond to requests within 30 days. Where a request is complex, we may extend this period and will inform you accordingly.

**VIII.4.** **Right to Lodge a Complaint.** You have the right to lodge a complaint with the data protection supervisory authority in your country of residence if you believe your rights have been violated.

## <mark style="color:$primary;">IX. Concluding Provisions</mark>

**IX.1.** **Changes to This Policy.** We may update this Policy from time to time. If we implement significant changes, such as adding new types of personal data, engaging new third-party processors, or modifying retention periods, we will notify you in a reasonable manner through the Interface. Your continued use of the Interface after these changes take effect will constitute acceptance of the updated Policy.

**IX.2.** **Personal Data Breach.** If a personal data breach is likely to pose a high risk to your rights and freedoms, we will notify the competent authority and affected individuals without undue delay.

**IX.3.** **Governing Law.** This Privacy Policy and any related disputes will be governed by and interpreted under the laws of the British Virgin Islands, without regard to its conflict-of-law rules unless mandatory provisions of your local jurisdiction take precedence.

**IX.4.** **Contact Information:** If you have any questions, concerns, or requests regarding this Privacy Policy, your data rights, or how your data is processed, please email us at <privacy@flpp.io> or contact our support team at <support@flpp.io>.
