Privacy Policy.
LOSURIA does not collect personal data wherever technically possible. Below: what we do process, why, and your rights under GDPR.
Who is responsible, and what is processed.
1Controller
The data controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (GDPR) is Negentralgorhythms LLC, a Wyoming limited liability company (filing number 2026-001994300), acting through its managing representative and domestic German service-of-process representative as identified in the Impressum. Contact: contact@losuria.com.
2Categories of data processed
2.1 Data we deliberately do NOT collect
- No private keys, no seed phrases, no master secrets. Wallet keys are derived on your device from your passkey's WebAuthn-PRF output and never reach us.
- No fiat payment instruments. The Service does not operate a fiat on-ramp; users acquire crypto through their own channels.
- No KYC documents.
- No email addresses (other than what you may include in correspondence with contact@losuria.com).
- No phone numbers.
- No analytics, behavioural tracking, or cross-site identifiers. No third-party cookies. No advertising trackers.
- No analysis, profiling, or advertising use of your IP address. The only IP processing is security-purpose HTTP access logs at the reverse proxy, used solely for abuse prevention and deleted automatically after at most 7 days (see 2.2).
2.2 Data we do collect or process
2.3 Public on-chain data
The blockchains supported by the Service are public. Wallet addresses, balances, transactions, and contract interactions associated with addresses you derive through LOSURIA are visible to anyone in perpetuity. We do not control and cannot delete on-chain data.
Where data goes and how it is held.
3Recipients / third-party processors
We do not "sell" personal data to any party.
4International transfers
The Service is hosted in Germany (Frankfurt region). Some third parties (notably the push delivery services operated by Mozilla, Apple, and Google) may process data outside the EU/EEA. Where applicable, we rely on the EU Standard Contractual Clauses or equivalent safeguards. You may request a copy of the relevant transfer mechanism from contact@losuria.com.
5Storage and security
- Servers are operated under sole administrative control of the operator from a Frankfurt-region VPS.
- All transport is TLS 1.3 only.
- Authentication is via WebAuthn passkeys (FIDO2). Passwords are not used.
- Application logs are written without PII. The reverse proxy keeps security-purpose HTTP access logs (including IP address) solely for abuse prevention and deletes them automatically after at most 7 days (see 2.2).
- Server-side secrets are restricted to the backend host with file-system permissions.
No system is fully secure. We cannot guarantee against breach. In the event of a personal-data breach affecting your rights or freedoms, we will notify the supervisory authority within 72 hours and you without undue delay, as required by Articles 33 and 34 GDPR.
What you can ask us to do.
6Your rights (Articles 15–22 GDPR)
You have the right to:
- request access to the personal data we hold about you (Art. 15);
- have inaccurate data rectified (Art. 16);
- have your data erased ("right to be forgotten", Art. 17);
- have processing restricted (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- not be subject to a decision based solely on automated processing (Art. 22). The opt-in snipe automation operates on data you actively configure; we do not profile or rank users.
- withdraw a consent you have granted, at any time and without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, email contact@losuria.com with sufficient detail to identify your account (handle and/or wallet address). We respond within one month per Art. 12(3) GDPR.
Right to lodge a complaint
You may lodge a complaint with a data-protection supervisory authority. The lead authority for the operator is the Hessischer Beauftragte für Datenschutz und Informationsfreiheit (HBDI), datenschutz.hessen.de. You may also lodge complaints in the member state of your habitual residence.
Local storage, minors, and automated decisions.
7Cookies and local storage
LOSURIA does not set tracking cookies, analytics, advertising trackers, or any third-party cookies.
A single functional first-party cookie is used:
losuria_version— set only when you actively click "Update now" in the in-app update banner. Contains only a version string (e.g.0.2.0) and is used to route your subsequent requests to the backend container you chose (blue-green deployment). Attributes:Path=/,Secure,SameSite=Strict, 30-day lifetime. No personal data, no IP address, no wallet address, no user identifier is stored. Legal basis: § 25 (2) No. 2 TTDSG / Art. 5 (3) ePrivacy Directive (strictly necessary for the version switch you explicitly requested) — consent is not required (cf. EDPB Guideline 02/2023, para. 18).
Additionally, the PWA uses browser localStorage on your device to persist:
- Your handle and wallet address (EOA + Smart Wallet). No private key, seed phrase, or master secret is stored: the Wallet owner key is derived on demand from your passkey's WebAuthn-PRF output and is never persisted.
- Your preferences (active wallet, MEV-saved counter, last-used chain).
This data never leaves your device. It is removed when you click "Forget all wallets" in the Wallets tab, clear your browser storage, or delete the single cookie via your browser settings.
8Children's data
The Service is not directed at children under 18. We do not knowingly process data from minors. If you believe we have, contact us and we will erase it.
9Automated decision-making
The opt-in snipe-automation feature executes trades autonomously based on parameters you configure (target token, spend cap, slippage, time-to-live). This is not "profiling" in the sense of Art. 22 GDPR — no decisions about you as a person are produced. The only decision made is whether a configured trade matches a configured market event.
10Changes to this policy
We will publish changes on this page. The "Effective" date at the top reflects the most recent revision. Material changes affecting your rights will be flagged at least 14 days before they take effect, where reasonably feasible.
11Contact for data-protection requests
Data-subject requests under Articles 15–22 GDPR: contact@losuria.com. We respond within one month as required by Article 12(3) GDPR. This address is for data-subject requests only and is not a general support channel.