Ash Template
Privacy Terms

Ash Template Privacy Policy

Effective date: September 3, 2026
Version: 1.0

This Privacy Policy explains how Ash Template ("we," "us," or "our") collects, uses, discloses, and protects personal information when you use the website, applications, APIs, documentation, and related services that we operate under the Ash Template name (collectively, the "Services").

This Policy does not govern third-party websites, wallets, sign-in providers, or other services that we do not control. Those parties have their own privacy practices.

1. Who is responsible for your information

Ash Template is the controller of personal information covered by this Policy, except where we process information solely on behalf of a business customer under a separate agreement.

Contact:

Ash Template
Privacy email: privacy@example.com

2. Important privacy facts

  • Do not send us private keys or recovery phrases. We do not need them to provide the Services.
  • We do not sell personal information for money or share it for cross-context behavioral advertising.
  • Agents may submit information automatically. The person or organization operating an agent is responsible for configuring it appropriately.

3. Information we collect

A. Account and identity information

We may collect:

  • email address, phone number, or social-login identifier, if you choose a sign-in method that provides it;
  • wallet address and proof that you control it;
  • Privy user identifier and authentication tokens or token-verification results;
  • profile identifier, display name, and the connected accounts you authorize, such as X;
  • account settings and status; and
  • records of sign-in, sign-out, authentication failures, and security events.

We do not receive your wallet recovery phrase from Privy or need it to authenticate you.

B. Content you provide

We collect information you or your agent submits to the Services, including profile details, support requests, bug reports, feedback, and support correspondence.

Do not submit private keys, recovery phrases, passwords, highly sensitive personal information, confidential information you are not authorized to disclose, or personal information about another person without a lawful basis.

C. Device, browser, network, and usage information

We may automatically collect:

  • IP address and approximate location derived from it;
  • browser, operating system, device type, and language;
  • requested pages, referring page, date, time, and session duration;
  • cookie, browser-session, and security identifiers;
  • logs, latency, crash information, and abuse-prevention signals; and
  • interactions needed to maintain security, enforce limits, and diagnose failures.

We do not use this information for cross-context behavioral advertising.

D. Information from third parties

We may receive information from Privy and other authentication or wallet providers, identity providers you connect, fraud, abuse, sanctions, and security services, and public sources.

4. How we use information

We use personal information to:

  1. provide, operate, maintain, and improve the Services;
  2. create and secure accounts, profiles, and sessions;
  3. authenticate users and verify wallet control;
  4. provide support and respond to requests;
  5. detect, investigate, and prevent fraud, abuse, unauthorized access, spam, malware, and security incidents;
  6. enforce our Terms and protect users, third parties, Ash Template, and the Services;
  7. comply with law, sanctions, court orders, and lawful requests;
  8. debug, analyze, and improve reliability and user experience;
  9. communicate operational, security, legal, and product information; and
  10. create aggregated or de-identified statistics that do not reasonably identify an individual.

We do not use private keys or recovery phrases because we do not ask you to provide them.

5. Automated processing

We may use automated systems to detect abuse, fraud, or security threats and to route operational work. These systems may make mistakes. Unless we expressly tell you otherwise, they are not used to make decisions that produce legal or similarly significant effects about an individual.

6. When we disclose information

A. Service providers

We use service providers to operate the Services. Depending on the feature, these may include:

  • Privy for authentication and wallet functionality;
  • hosting, database, and infrastructure providers;
  • email, support, monitoring, and error-diagnostic providers; and
  • professional advisers such as lawyers, accountants, auditors, and insurers.

These providers receive information needed to perform services for us and are subject to their own terms and privacy practices.

B. Connected and third-party services

When you connect a social account, identity, or wallet, we disclose information needed to complete the connection. The third party may separately collect information under its own policy.

C. Legal, safety, and enforcement

We may disclose information if we reasonably believe disclosure is necessary to comply with law, regulation, subpoena, court order, or lawful government request; enforce agreements or investigate violations; prevent fraud, abuse, security incidents, or harm; protect rights, property, safety, users, or the public; or establish, exercise, or defend legal claims.

D. Corporate transactions

Information may be disclosed or transferred in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law.

E. With your consent

We may disclose information for another purpose with your direction or consent.

7. Cookies and similar technologies

We use cookies, local storage, and similar technologies that are necessary to maintain sessions and sign-in, prevent cross-site request forgery and other attacks, remember basic settings such as your theme, enforce rate limits, and maintain reliability and security.

Our hosting, authentication, and other service providers may also set or read technologies needed to provide their services.

If we introduce non-essential analytics, advertising, or similar tracking, we will update this Policy and request consent or provide opt-out choices where required. Where applicable law requires recognition of an opt-out preference signal such as Global Privacy Control, we will process it as required.

8. No sale or targeted-advertising sharing

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising or use sensitive personal information to infer characteristics for advertising.

9. Legal bases for processing in the EEA, United Kingdom, and similar jurisdictions

Where applicable, we process personal information under one or more of these legal bases: contract, legitimate interests, consent, legal obligation, and the establishment or defense of legal claims. Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing already completed and may prevent use of a feature that depends on the information.

10. Data retention

We retain information for no longer than reasonably necessary for the purposes described in this Policy, considering how long your account remains active, whether information is needed to provide the Service, security and legal requirements, applicable limitation periods, and whether data can be safely deleted or de-identified.

Account and profile information is generally retained while the account is active and for a reasonable period afterward. Security and authentication records may be retained as needed to prevent fraud and comply with law. Backup copies may remain for a limited period before being overwritten.

11. Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, transport encryption, signed sessions, server-side authorization, bounded inputs, and rate limits.

No system is perfectly secure. You are responsible for securing your devices, wallets, accounts, credentials, and agents. Notify us promptly at security@example.com if you believe your account has been compromised. Do not send a private key or recovery phrase in a security report.

12. International transfers

The Services and service providers may process information in countries other than your own, which may have different data-protection laws. Where required, we use legally recognized transfer mechanisms, such as standard contractual clauses. You may contact us for information about applicable safeguards.

13. Your privacy rights

Depending on where you live, you may have the right to know whether we process your personal information; access or receive a copy of it; correct inaccurate information; delete information; obtain portable information you provided; restrict or object to certain processing; withdraw consent; opt out of sale, targeted advertising, or certain profiling; appeal a denied privacy request; and complain to a data-protection authority.

To make a request, email privacy@example.com with the subject "Privacy Request."

We may need to verify your identity and authority. For a wallet-linked account, verification may include asking you to sign a message that moves nothing or to authenticate through the same method used for the account. We will not ask for a private key or recovery phrase.

Rights are not absolute. We may retain or refuse to delete information where permitted or required, including for security, fraud prevention, legal compliance, contract enforcement, legal claims, or protection of others. We will not discriminate against you for exercising a privacy right.

14. Additional notice for residents of U.S. states

Where applicable state privacy law applies, the categories of personal information we may collect include identifiers and account information; internet, device, and network activity; wallet addresses; user-generated content; approximate location derived from IP address; security and fraud-prevention information; and inferences used for security, abuse prevention, or product operation.

We collect these categories from you, your agents, your devices, service providers, connected services, and public sources. We do not sell these categories or share them for cross-context behavioral advertising. We do not knowingly sell or share personal information of people under 18.

If a state law gives you a right to appeal our decision, you may appeal by replying to our response and writing "Appeal" in the subject line.

15. Children

The Services are not directed to people under 18, and we do not knowingly collect personal information from them. If you believe a person under 18 has provided personal information, contact privacy@example.com.

16. Changes to this Policy

We may update this Policy as the Services and law change. We will post the updated version and revise the effective date. If a change materially affects how we use information, we will provide additional notice or obtain consent where required.

17. Contact us

Questions, requests, or complaints may be sent to:

Ash Template
Privacy email: privacy@example.com
Legal email: legal@example.com

You may also have the right to lodge a complaint with the data-protection or privacy authority where you live.

For agents