CORRE PROTOCOL: PRIVACY POLICY

    Last Updated: July 18, 2026 | Version: 1.0

    1. OVERVIEW & PRIVACY COMMITMENT

    This Privacy Policy outlines how Corre Protocol ("we", "us", or "our") collects, uses, and safeguards information when you visit or use our web app (corre.bond) and associated interfaces.

    Corre is designed with a privacy-first mindset. As a decentralized finance (DeFi) yield hub and cross-border platform, we minimize off-chain personal data collection while ensuring a seamless, gas-optimized user experience.

    2. INFORMATION WE COLLECT

    A. Account & Authentication Data (Privy)

    When you sign in to Corre, we utilize Privy for embedded wallet generation and authentication. Depending on your chosen login method, Privy processes:

    • Your email address or social login identifier (e.g. Google/Twitter login).
    • Your generated non-custodial Solana public wallet address.

    B. Blockchain Data (On-Chain Records)

    When interacting with Corre vaults, Jupiter stock routing, or transfers, your public wallet address and transaction payloads are written to the Solana blockchain.

    Important Note: Public blockchain data (wallet transactions, vault deposits, token swaps) is permanently visible, immutable, and public by nature. Corre cannot alter or delete data recorded on the blockchain.

    C. Cross-Border Fiat & Bank Payout Data

    When using our cross-border payment features (e.g., sending crypto directly to bank accounts in Africa such as Naira NGN payouts):

    • We collect recipient bank details (bank name, account number, account holder name) strictly necessary to process the payout through regulated fiat payment partners.
    • This data is encrypted and passed securely to licensed payout providers to fulfill bank settlement.

    D. Technical & Network Logs

    Like most web applications, standard server logs are collected by our infrastructure and RPC providers (Netlify, Alchemy, Helius) for security, rate-limiting, and DDoS protection:

    • IP address and user-agent string.
    • Browser type, operating system, and timestamp.

    3. HOW WE USE YOUR INFORMATION

    We process collected data exclusively for operational and compliance purposes:

    1. Service Delivery: Enabling wallet authentication, yield vault interaction, stock trading, and fiat payout settlement.
    2. Gas Sponsorship Security: Validating account eligibility and enforcing anti-abuse rate limits for free gas transactions.
    3. Compliance & Screening: Screening public wallet addresses against global sanctions registries (e.g., OFAC) to comply with international regulations.
    4. User Support: Responding to inquiries submitted through our official support channels.

    4. COOKIES, LOCAL STORAGE & THIRD-PARTY SERVICES

    Corre uses local browser storage (localStorage) solely to maintain active wallet session state so you don't need to re-authenticate on every page refresh.

    We do NOT use invasive cross-site tracking cookies or selling user data to advertising networks.

    Third-Party Service Providers

    • Privy: Embedded wallet authentication and security provider.
    • Solana RPC Nodes (Alchemy, Helius): Blockchain read/write request processors.
    • Fiat Off-Ramp Partners: Licensed fiat gateways for bank payout processing.
    • Netlify: Application web hosting and edge routing.

    5. DATA SECURITY & RETENTION

    All web traffic is transmitted via modern TLS/SSL encryption. Off-chain logs and bank payout details are retained only for the duration required for transaction verification, security auditing, and legal compliance.

    We never store, request, or have access to your private key or seed phrase.

    6. CONTACT & PRIVACY INQUIRIES

    If you have questions or concerns regarding this Privacy Policy, please contact our team: