Privacy notice
Updated July 16, 2026Operator
Oqto Inc., a company incorporated in the British Virgin Islands, operates the Oqto interface. Privacy questions and requests may be sent to hi@oqto.fun.
What is processed
Oqto processes public wallet addresses and blockchain activity; profile nickname and bio; follows and watchlists; short-lived wallet signing challenges; X account ID, username, and OAuth session state when you connect X; support communications; and transaction or application diagnostics. Public-chain information remains public independently of Oqto.
Network rate limiting
The hosted API temporarily uses the network address supplied by the hosting layer to enforce short request limits and protect endpoints from automated abuse. The in-memory bucket expires with its short request window and is not used to create a wallet balance, determine token ownership, or maintain a location history.
Why
Data is used to provide market, portfolio, social, creator-claim, routing, support, security, and reliability functions. Oqto does not maintain an offchain custodial asset balance. Portfolio and balance views are derived from public chain state and the connected wallet.
Storage and retention
Market and transaction indexes are stored in PostgreSQL. Social profiles, follows, watchlists, and authorization records are stored in D1. Used or expired signing challenges are deleted; rate-limit buckets expire after their short window. OAuth access tokens are used to verify the connected X identity and are not stored by the application. Operational logs and backups follow the service retention schedule.
Service providers
Hosting, database, RPC, wallet, X, metadata, chart, and routing providers process the minimum data needed to provide their service. Connecting a wallet or X account may expose data under that provider’s own privacy terms.
Your choices
You can disconnect your wallet, avoid connecting X, remove follows or watchlists, and stop using the interface. Blockchain records and immutable token metadata cannot necessarily be changed or deleted. Where rules applicable to you grant data access, correction, deletion, objection, or portability rights, contact Oqto at hi@oqto.fun.
Security
Oqto uses signed wallet challenges, one-time nonces, bounded request bodies, rate limits, least-privilege service identities, encrypted backups, and protected production signing infrastructure. No system is risk-free. Oqto will never ask you to send a seed phrase or private key.
