Privacy

Privacy Policy

This page describes what Krexa collects when an agent or its owner uses the product, and which outside services process it. Krexa runs autonomous AI trading agents across several chains, so a meaningful share of the data this product touches (every registration, position, trade, draw and repayment) is written to a public blockchain rather than a private database.

Last updated: September 10, 2026

On-chain data

Agent identity, Krexit Score, credit-line state, draws, repayments, and trade history are written to Solana program accounts and Monad contracts. This data is public, permanent, and readable by anyone, including other on-chain programs via CPI, and it cannot be deleted or made private after the fact. Do not register an agent under a wallet you need to keep anonymous.

Account & wallet data

Sign-in is handled by Privy. An owner who signs up with an external wallet is identified by their public wallet address; an owner who signs up by email has that email address, and the embedded wallet Privy creates for them, stored in Krexa's own database and linked to their agent's on-chain owner key. Referral and waitlist records are also keyed by wallet address, with an email address attached where the signup happened by email rather than external wallet.

Verification (KYA)

Higher credit levels (L3 Growth and L4 Prime) require KYA (Know Your Agent) Tier 2 verification. Basic KYA is an automated check of the owner's signature and the agent's code. Enhanced KYA runs a KYC flow through Sumsub, a third-party identity verification provider, for the agent's human owner; Krexa stores the Sumsub applicant reference and the resulting verification tier and status, not the underlying identity documents, which Sumsub holds.

Email & Telegram notifications

Waitlist confirmation and other transactional email is sent through Resend. Linking a Telegram chat for trade alerts stores that chat's Telegram ID, the linked wallet address, and, for the email-verification linking path, a hashed one-time code and the email address it was sent to. Telegram alerts are on by default once a chat is linked and can be turned off from the chat itself.

Infrastructure

The backend runs on Render; the frontend on Vercel. An optional Redis cache, when configured, holds short-lived data such as rate-limit counters and cached reads. It is not a system of record, and the backend runs without it if it is unavailable.

Data retention, deletion, and your rights

A formal data-retention period, deletion process, and jurisdiction-specific rights (for example under GDPR or CCPA) are not yet published. On-chain records cannot be deleted regardless of policy, since they live on Solana and Monad, not in Krexa's own database. For questions about data held about you or your agent, contact the team directly.

Contact

Questions about this policy or a request about your data go to tejas@krexa.xyz.