Ash Template Privacy Policy
Effective date: September 3, 2026
Version: 1.0
This Privacy Policy explains how Ash Template ("we," "us," or "our") collects, uses, discloses, and protects personal information when you use the website, applications, APIs, documentation, and related services that we operate under the Ash Template name (collectively, the "Services").
This Policy does not govern third-party websites, wallets, sign-in providers, or other services that we do not control. Those parties have their own privacy practices.
1. Who is responsible for your information
Ash Template is the controller of personal information covered by this Policy, except where we process information solely on behalf of a business customer under a separate agreement.
Contact:
Ash Template
Privacy email: privacy@example.com
2. Important privacy facts
- Do not send us private keys or recovery phrases. We do not need them to provide the Services.
- We do not sell personal information for money or share it for cross-context behavioral advertising.
- Agents may submit information automatically. The person or organization operating an agent is responsible for configuring it appropriately.
3. Information we collect
A. Account and identity information
We may collect:
- email address, phone number, or social-login identifier, if you choose a sign-in method that provides it;
- wallet address and proof that you control it;
- Privy user identifier and authentication tokens or token-verification results;
- profile identifier, display name, and the connected accounts you authorize, such as X;
- account settings and status; and
- records of sign-in, sign-out, authentication failures, and security events.
We do not receive your wallet recovery phrase from Privy or need it to authenticate you.
B. Content you provide
We collect information you or your agent submits to the Services, including profile details, support requests, bug reports, feedback, and support correspondence.
Do not submit private keys, recovery phrases, passwords, highly sensitive personal information, confidential information you are not authorized to disclose, or personal information about another person without a lawful basis.
C. Device, browser, network, and usage information
We may automatically collect:
- IP address and approximate location derived from it;
- browser, operating system, device type, and language;
- requested pages, referring page, date, time, and session duration;
- cookie, browser-session, and security identifiers;
- logs, latency, crash information, and abuse-prevention signals; and
- interactions needed to maintain security, enforce limits, and diagnose failures.
We do not use this information for cross-context behavioral advertising.
D. Information from third parties
We may receive information from Privy and other authentication or wallet providers, identity providers you connect, fraud, abuse, sanctions, and security services, and public sources.
4. How we use information
We use personal information to:
- provide, operate, maintain, and improve the Services;
- create and secure accounts, profiles, and sessions;
- authenticate users and verify wallet control;
- provide support and respond to requests;
- detect, investigate, and prevent fraud, abuse, unauthorized access, spam, malware, and security incidents;
- enforce our Terms and protect users, third parties, Ash Template, and the Services;
- comply with law, sanctions, court orders, and lawful requests;
- debug, analyze, and improve reliability and user experience;
- communicate operational, security, legal, and product information; and
- create aggregated or de-identified statistics that do not reasonably identify an individual.
We do not use private keys or recovery phrases because we do not ask you to provide them.
5. Automated processing
We may use automated systems to detect abuse, fraud, or security threats and to route operational work. These systems may make mistakes. Unless we expressly tell you otherwise, they are not used to make decisions that produce legal or similarly significant effects about an individual.
6. When we disclose information
A. Service providers
We use service providers to operate the Services. Depending on the feature, these may include:
- Privy for authentication and wallet functionality;
- hosting, database, and infrastructure providers;
- email, support, monitoring, and error-diagnostic providers; and
- professional advisers such as lawyers, accountants, auditors, and insurers.
These providers receive information needed to perform services for us and are subject to their own terms and privacy practices.
B. Connected and third-party services
When you connect a social account, identity, or wallet, we disclose information needed to complete the connection. The third party may separately collect information under its own policy.
C. Legal, safety, and enforcement
We may disclose information if we reasonably believe disclosure is necessary to comply with law, regulation, subpoena, court order, or lawful government request; enforce agreements or investigate violations; prevent fraud, abuse, security incidents, or harm; protect rights, property, safety, users, or the public; or establish, exercise, or defend legal claims.
D. Corporate transactions
Information may be disclosed or transferred in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law.
E. With your consent
We may disclose information for another purpose with your direction or consent.
7. Cookies and similar technologies
We use cookies, local storage, and similar technologies that are necessary to maintain sessions and sign-in, prevent cross-site request forgery and other attacks, remember basic settings such as your theme, enforce rate limits, and maintain reliability and security.
Our hosting, authentication, and other service providers may also set or read technologies needed to provide their services.
If we introduce non-essential analytics, advertising, or similar tracking, we will update this Policy and request consent or provide opt-out choices where required. Where applicable law requires recognition of an opt-out preference signal such as Global Privacy Control, we will process it as required.
8. No sale or targeted-advertising sharing
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising or use sensitive personal information to infer characteristics for advertising.
9. Legal bases for processing in the EEA, United Kingdom, and similar jurisdictions
Where applicable, we process personal information under one or more of these legal bases: contract, legitimate interests, consent, legal obligation, and the establishment or defense of legal claims. Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing already completed and may prevent use of a feature that depends on the information.
10. Data retention
We retain information for no longer than reasonably necessary for the purposes described in this Policy, considering how long your account remains active, whether information is needed to provide the Service, security and legal requirements, applicable limitation periods, and whether data can be safely deleted or de-identified.
Account and profile information is generally retained while the account is active and for a reasonable period afterward. Security and authentication records may be retained as needed to prevent fraud and comply with law. Backup copies may remain for a limited period before being overwritten.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, transport encryption, signed sessions, server-side authorization, bounded inputs, and rate limits.
No system is perfectly secure. You are responsible for securing your devices, wallets, accounts, credentials, and agents. Notify us promptly at security@example.com if you believe your account has been compromised. Do not send a private key or recovery phrase in a security report.
12. International transfers
The Services and service providers may process information in countries other than your own, which may have different data-protection laws. Where required, we use legally recognized transfer mechanisms, such as standard contractual clauses. You may contact us for information about applicable safeguards.
13. Your privacy rights
Depending on where you live, you may have the right to know whether we process your personal information; access or receive a copy of it; correct inaccurate information; delete information; obtain portable information you provided; restrict or object to certain processing; withdraw consent; opt out of sale, targeted advertising, or certain profiling; appeal a denied privacy request; and complain to a data-protection authority.
To make a request, email privacy@example.com with the subject "Privacy Request."
We may need to verify your identity and authority. For a wallet-linked account, verification may include asking you to sign a message that moves nothing or to authenticate through the same method used for the account. We will not ask for a private key or recovery phrase.
Rights are not absolute. We may retain or refuse to delete information where permitted or required, including for security, fraud prevention, legal compliance, contract enforcement, legal claims, or protection of others. We will not discriminate against you for exercising a privacy right.
14. Additional notice for residents of U.S. states
Where applicable state privacy law applies, the categories of personal information we may collect include identifiers and account information; internet, device, and network activity; wallet addresses; user-generated content; approximate location derived from IP address; security and fraud-prevention information; and inferences used for security, abuse prevention, or product operation.
We collect these categories from you, your agents, your devices, service providers, connected services, and public sources. We do not sell these categories or share them for cross-context behavioral advertising. We do not knowingly sell or share personal information of people under 18.
If a state law gives you a right to appeal our decision, you may appeal by replying to our response and writing "Appeal" in the subject line.
15. Children
The Services are not directed to people under 18, and we do not knowingly collect personal information from them. If you believe a person under 18 has provided personal information, contact privacy@example.com.
16. Changes to this Policy
We may update this Policy as the Services and law change. We will post the updated version and revise the effective date. If a change materially affects how we use information, we will provide additional notice or obtain consent where required.
17. Contact us
Questions, requests, or complaints may be sent to:
Ash Template
Privacy email: privacy@example.com
Legal email: legal@example.com
You may also have the right to lodge a complaint with the data-protection or privacy authority where you live.