Privacy Policy
Last updated: August 19, 2026
1. What we collect
What we hold depends entirely on how you signed up. We do not ask for a legal name, a phone number, a date of birth or an address, and there is nowhere in the product to enter them.
- Your account: your public wallet address, and a username you may choose once. Nothing else — no email, no password, no name. Signing in with a wallet is the only way into Akiro, so there is nothing else to hold.
- If you add an email: the address itself, confirmed by a code. It is optional, used only to notify you, and never becomes a way to sign in.
- If you link Discord or X: the account identifier and public username on that platform, plus your roles on our Discord server, which is how role-based access is granted.
- Subscriptions: plan, dates, and the transaction hash of your payment. Transaction hashes are public blockchain data.
- Technical: your IP address is used to rate-limit requests and slow down brute-force attempts, and appears in server logs. Administrative actions on accounts are recorded in an audit log.
2. What we never collect
We never ask for and never store seed phrases, private keys, or wallet passwords. No part of our software requests them, and no member of our team will ever ask you for them under any circumstances. Anyone who does, claiming to be us, is stealing from you.
3. Why we hold it
To operate the account you asked us to create: to sign you in, to know what your subscription entitles you to, and to keep the service from being abused. We do not sell personal data, and we do not run advertising or third-party tracking on this site.
4. Who else sees it
Only services the product genuinely depends on, and only the minimum each one needs:
- Discord and X — if you choose to link those accounts.
- Blockchain data providers — to check on-chain ownership and payments. They see wallet addresses, which are public by nature.
- Cloudflare — as the network in front of the site.
5. How long we keep it
Account data for as long as the account exists. Sign-in sessions expire on their own and are revoked when you log out. Short-lived items — sign-in challenges, rate-limit counters — are deleted automatically within minutes.
6. Your choices
You can unlink Discord or X at any time in Settings. You can ask us to delete your account and its data by contacting us on Discord; we will confirm it is your account before acting on the request. Note that subscription records may be retained where we are required to keep them, and that blockchain transactions cannot be deleted by anyone — they are public and permanent by design.
7. Security
We hold no passwords at all — there are none to leak. Sessions are held in cookies that JavaScript cannot read, which limits what a compromised script could steal. Administrator accounts are required to use two-factor authentication. None of this makes a breach impossible; it makes one less likely and less damaging.
8. Changes
If this policy changes materially, the date at the top changes with it. Continued use of the service after that means you accept the updated policy. See also the Terms of Service and the FAQ.
