> For the complete documentation index, see [llms.txt](https://boole-ai.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://boole-ai.gitbook.io/docs/legal/privacy-policy.md).

# Privacy Policy

> <mark style="color:purple;">Last updated on 2 December 2025.</mark>

## PORTARA APP BETA - PRIVACY POLICY&#x20;

**COMPLIANCE WITH APPLICABLE LAWS**

WE TAKE YOUR PRIVACY SERIOUSLY AND HANDLE YOUR PERSONAL DATA IN ACCORDANCE WITH APPLICABLE DATA PROTECTION LAWS IN THE JURISDICTIONS IN WHICH WE OPERATE. THIS POLICY IS INTENDED TO MEET THE REQUIREMENTS OF RELEVANT STATUTES AND REGULATIONS IN THESE JURISDICTIONS. BY USING OUR PRODUCTS OR SERVICES, YOU CONSENT TO THE COLLECTION, USE, DISCLOSURE, AND STORAGE OF YOUR INFORMATION AS DESCRIBED IN THIS POLICY.

### 1. Introduction&#x20;

This Privacy Policy (“**Policy**”) explains how Boole Digital Labs Incorporated (“**Boole**,” “**we**,” “**us**,” or “**our**”) collects, uses, maintains, stores, discloses, and safeguards/protects your personal information, Blockchain Identifiers, and other data when you:

* Access or use the Beta located at <https://portara.app/> (including subdomains or related pages, e.g. Portara’s documentation website at <<https://portara.gitbook.io/docs>>);
* Use any related products, services, or features offered by Boole; or
* Communicate with us through electronic or other channels.

We value your privacy and are committed to protecting it in accordance with this Policy. Further details regarding collection, use, disclosure, retention, security, and your rights are set out in Clauses 3–10 of this Policy.

The Beta is a web-based application accessible at <https://portara.app/>, and is owned and operated by Boole. We also operate an informational website at <<https://useportara.com/>> that provides details about the Portara trading terminal and other related information - this is governed by a separate Privacy Policy which you can find on said site. The Beta is the pre-release version of the Portara trading terminal made available to selected participants for testing, feedback, and product development purposes. The Portara Beta trading terminal provides users with an experimental environment to analyse markets, execute trades, interact with AI-driven tools, and connect digital wallets.

Any capitalized terms not specifically defined in this Privacy Statement will have the meaning given to them in our Terms of Use (the “**Terms**”).

Please take a moment to review this Privacy Statement so you understand what personal information we collect, how we use it, and under what circumstances we may share it.

The data controller of your Personal Information is Boole Digital Labs Incorporated, a company which is registered in the British Virgin Islands (“**BVI**”) whose registered office is Nerine Chambers, P.O. Box 905, Road Town, Tortola, VG1110, British Virgin Islands. For privacy inquiries, including requests under applicable data protection laws in the EU, UK, or other jurisdictions, you may contact us at [**support@portara.app**](mailto:support@portara.app)**.**

### 2. Scope

This Policy applies to the Beta, a pre-release version of the Portara trading interface made available to selected participants for testing, feedback, and product development purposes. Participation in the Beta may involve limited or access to trading, analytics, AI-assisted tools, and wallet connectivity.

Users may initially sign up using an email address or Google account to access the Beta. To use wallet-related or account-linked features, users must authenticate via Turnkey, which requires a passkey stored on their device. Boole does not have access to, store, or control any Turnkey passkeys, private keys, or credentials.

During participation in the Beta, users will interact with integrated protocols or third-party services. Boole only collects public and usage-related information necessary to operate the Beta, such as analytics and performance data, and only retains it for as long as reasonably necessary to fulfil these purposes. Boole implements appropriate technical and organisational measures to safeguard the information it collects. Boole does not execute or control any transactions on behalf of users. Turnkey and other integrated services may collect or process information independently in accordance with their own privacy policies. Users are encouraged to review those policies before engaging with such services.

This Policy applies only to information collected by Boole through the Beta, its related website, and electronic communications. It does not apply to (i) offline collection, (ii) third-party websites or services accessible via the Beta or website, or (iii) private keys, passkeys, or credentials managed by Turnkey or other third-party providers. Boole is not responsible for the privacy practices of such third parties.

The Beta and related services are not directed to individuals below the minimum legal age for participation in such services in the relevant jurisdiction. Boole does not knowingly collect personal information from individuals under that age without verifiable parental or guardian consent (see Clause 10: Children’s Data).

This Policy, together with any applicable Beta Terms, governs Boole’s collection and processing of personal information, public account data, and analytics in connection with the Beta. Users may exercise applicable rights under their jurisdiction, such as access, correction, deletion, or withdrawal of consent, where legally permitted. Data collected by Turnkey or integrated protocols remains subject to their respective privacy policies.

### 3. Information We Collect

The table below outlines the types of information collected by Boole during your use of the Beta, how and when it is collected, the purposes for which it is used and the legal basis for its collection. It includes personal, technical, and usage-related data that Boole processes to provide, secure, and improve the Beta. Boole only collects the information necessary for these purposes and does not access or store Turnkey credentials, private keys, or any data managed by third-party protocols. All data processing is carried out on lawful grounds, including consent, performance of a contract, legal obligations, or legitimate interests such as improving functionality and user experience.

| Data Category / Field                                                                                                                                                         | When / How Collected                                                                                                 | Purpose of Collection                                                                                                                                                                                                                                                                                                       | Legal Basis of Collection                                                                                                                    |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| *Account and Authentication Data*                                                                                                                                             |                                                                                                                      |                                                                                                                                                                                                                                                                                                                             |                                                                                                                                              |
| Account identifiers: UUID (profiles.id), email, username                                                                                                                      | When you register or log in via Supabase Auth using Google, email link, or (in future) Telegram/X OAuth providers    | To uniquely identify your account, authenticate you, and maintain your profile                                                                                                                                                                                                                                              | <p>Performance of contract</p><p><br></p><p>Consent</p>                                                                                      |
| Authentication tokens and metadata: session IDs, OAuth tokens (Google, email, Telegram, X), refresh tokens                                                                    | Generated by Supabase Auth during login; stored securely within Supabase’s managed auth tables                       | To maintain login sessions, validate authentication, and enable future login providers                                                                                                                                                                                                                                      | Performance of contract                                                                                                                      |
| Profile details: username, risk\_profile, meta (jsonb preferences, e.g., UI settings or notification preferences)                                                             | When you create or update your profile through the web app                                                           | To personalize your experience, configure your dashboard and risk tools, and store user preferences                                                                                                                                                                                                                         | <p>Performance of contract</p><p><br></p><p>Consent</p>                                                                                      |
| Timestamps: created\_at, updated\_at, deleted\_at (for profiles, wallets, holdings, transactions, messages, insights)                                                         | Automatically added by the database at each insert/update                                                            | To support auditing, debugging, and data lifecycle management (record retention, deletion)                                                                                                                                                                                                                                  | Legitimate interest                                                                                                                          |
| Device identifiers (e.g., device fingerprint, unique device ID)                                                                                                               | Automatically collected when using the app via browser or device                                                     | To enhance security, detect suspicious activity, and prevent fraud                                                                                                                                                                                                                                                          | Legitimate interest                                                                                                                          |
| *Wallet and Transaction Data*                                                                                                                                                 |                                                                                                                      |                                                                                                                                                                                                                                                                                                                             |                                                                                                                                              |
| Wallet connections: wallet type (crypto\_turnkey, crypto\_metamask, fiat), details (address, network), credentials (provider tokens), linked account aliases or display names | When a user connects a wallet (via UI or API)                                                                        | <p>To link blockchain wallets to your profile and enable DeFi features such as balances, transactions, and analytics.<br><br>To display user-friendly labels in dashboards and analytics without revealing sensitive credentials.</p>                                                                                       | Performance of contract                                                                                                                      |
| Holdings: asset\_id, quantity, usd\_value                                                                                                                                     | Automatically updated after a transaction or price refresh                                                           | To calculate and display your real-time portfolio valuation and analytics                                                                                                                                                                                                                                                   | Performance of contract                                                                                                                      |
| Transactions: wallet\_id, asset\_id, group\_id, status, rpc\_response, details, usd\_price                                                                                    | When you initiate transactions (e.g., swaps, deposits, withdrawals). Status updates pulled from blockchain RPC nodes | To execute and record transactions, track progress, and display transaction history                                                                                                                                                                                                                                         | Performance of contract                                                                                                                      |
| Transaction groups: description, created\_at, updated\_at                                                                                                                     | When you batch or categorize transactions manually or automatically                                                  | To organize related transactions for analytics and reporting                                                                                                                                                                                                                                                                | Legitimate interest                                                                                                                          |
| On-chain metadata: wallet address, asset symbols, transaction hashes, event logs, contract interactions                                                                       | Collected from public blockchain APIs (via RPC or indexers) once you connect your wallet                             | To calculate balances, positions, transaction history, and generate AI analytics                                                                                                                                                                                                                                            | Legitimate interest                                                                                                                          |
| Compliance data: IP geolocation, wallet activity patterns, transaction metadata                                                                                               | Automatically inferred from blockchain activity and network logs                                                     | To comply with applicable AML, sanctions, or local regulatory frameworks if triggered by activity type                                                                                                                                                                                                                      | <p>Legal obligation<br></p><p>Legitimate interest</p>                                                                                        |
| *AI Interaction Data*                                                                                                                                                         |                                                                                                                      |                                                                                                                                                                                                                                                                                                                             |                                                                                                                                              |
| AI messages: content (prompt and response), role (user/assistant/system), command (tool invocation JSON)                                                                      | When you interact with AI features (chat, insights, analysis)                                                        | <p>To provide conversational assistance, AI insights, and record prior conversations for continuity</p><p></p><p>To monitor service health, measure token usage for billing, and improve prompt efficiency; includes model version and inference latency for performance monitoring only and not for personal profiling</p> | <p>User consent for optional AI features and analytics</p><p></p><p>Contractual necessity for providing core AI functionality</p><p><br></p> |
| AI insights (futures/positions): prompts, summaries, account\_overview, positions (jsonb), raw\_content                                                                       | When you request AI-generated insights on your connected wallets or positions                                        | To generate personalized portfolio summaries, risk assessments, and predictions using Grok/OpenAI                                                                                                                                                                                                                           | Consent / Performance of contract                                                                                                            |
| AI usage logs and metadata: token counts, model name, latency, truncated prompts (non-sensitive context)                                                                      | When you use any AI feature (via Grok, OpenAI, or future providers)                                                  | To monitor service health, measure token usage for billing, and improve prompt efficiency                                                                                                                                                                                                                                   | Legitimate interest                                                                                                                          |
| *Technical and Analytics Data*                                                                                                                                                |                                                                                                                      |                                                                                                                                                                                                                                                                                                                             |                                                                                                                                              |
| Technical telemetry: IP address, browser type, operating system, device type, time zone, referrer URL, page views, session duration, clickstream events                       | Automatically collected through the frontend (e.g., Supabase logs, browser telemetry, or analytics SDKs)             | To secure accounts, detect fraud, improve system reliability, and optimize product performance                                                                                                                                                                                                                              | Legitimate interest                                                                                                                          |
| Cookies and analytics identifiers: session cookies, local storage tokens                                                                                                      | When you visit the site, stored on your browser                                                                      | To enable login persistence, measure performance, and deliver core app functionality                                                                                                                                                                                                                                        | <p>Consent</p><p></p><p>Legitimate interest</p><p></p><p>Essential cookies rely on contractual necessity for core functionality</p>          |
| Risk and fraud indicators: access patterns, login frequency, location (derived from IP), failed login attempts                                                                | Continuously collected during authentication and transaction initiation                                              | To protect against fraud, suspicious wallet behavior, or abuse                                                                                                                                                                                                                                                              | <p>Legitimate interest</p><p></p><p>Legal obligation</p>                                                                                     |
| Error / crash logs                                                                                                                                                            | Automatically collected when the app or AI services encounter runtime errors                                         | To identify and fix bugs, improve system stability and reliability; may include anonymized device identifiers to assist debugging.                                                                                                                                                                                          | Legitimate interest                                                                                                                          |
| Feature usage events                                                                                                                                                          | Automatically collected during user interactions (e.g., clicks, button taps, feature access)                         | <p>To understand how features are used, inform product improvements, and optimize user experience.</p><p></p><p>To provide optional notifications, alerts, or personalized analytics; collected only with user consent.</p>                                                                                                 | <p>Legitimate interest</p><p></p><p>Consent</p>                                                                                              |
| *Support Data*                                                                                                                                                                |                                                                                                                      |                                                                                                                                                                                                                                                                                                                             |                                                                                                                                              |
| Support messages or inquiries: email, message content, attachments                                                                                                            | When you contact us through a support channel or web form                                                            | To respond to customer inquiries, provide technical assistance, and resolve issues                                                                                                                                                                                                                                          | <p>Performance of contract </p><p><br></p><p>Consent<br></p>                                                                                 |
| Beta feedback: optional surveys, bug reports, or user comments                                                                                                                | When voluntarily submitted by users via in-app forms or feedback channels                                            | To collect user feedback for improving the Beta and future product releases                                                                                                                                                                                                                                                 | <p>Consent</p><p></p><p>Performance of contract</p>                                                                                          |

All data is retained only as ling as necessary to fulfil the purposes set out above and comply with applicable legal obligations. Data collection ensures that the interface is able to properly function, and also helps Boole improve the product, test functionality, and ensure security and reliability. Users may, where legally permitted, access, correct, or request deletion of personal information collected by Boole. It is important that the information we hold about you is accurate and current. Users are encouraged to notify Boole promptly of any changes to their personal information, for example by submitting a support request or updating their registered email.

Where Boole relies on legitimate interest as a legal basis for processing, it does so only after assessing that such interests are not overridden by the rights or freedoms of the User, and that the processing is necessary and proportionate to the purpose pursued.

Boole does not access, store, or control Turnkey credentials, private keys, or any information not explicitly provided to the Beta. Users are encouraged to review the privacy policies of Turnkey and other integrated protocol providers to understand how their data may be processed by those third parties.

Email addresses provided for support or inquiries are treated as personally identifiable information and are used solely for the purpose of responding to user requests. Marketing or promotional communications, if any, will only be sent with the user’s explicit consent and can be withdrawn at any time by emailing <support@portara.app>.

Analytics are conducted using anonymized or pseudonymized data where feasible, and never involve access to Turnkey credentials or private keys. Where required by applicable law (e.g., EU/GDPR, APPI), non-essential analytics, AI telemetry, and tracking are processed only on the basis of user consent. Users may withdraw consent at any time by contacting <support@portara.app>.&#x20;

When you contact <support@portara.app> you will receive a response with a ticket and acknowledgement that you have been placed in our queue. Within 30 days of your email, we will update you as to the status of your enquiry.&#x20;

Boole may also aggregate personal and other data it captures so that the resulting information is no longer capable of identifying an individual. Such aggregated or anonymized data may include usage patterns or performance metrics derived from interactions with the Beta, and may be used to improve or enhance Boole’s Services, generate insights, support marketing or product development, or otherwise operate and optimize its business. Provided that such data does not directly or indirectly identify any User, it is not treated as personal information under this Policy.

### 4. Sharing & Disclosure of Information

We may share personal information, public account identifiers, Blockchain Identifiers, and other data collected through the Beta and related Boole Services with certain third parties to facilitate the provision of our Services, comply with legal obligations, or for operational purposes. Such third parties may include:

* **Affiliates and subsidiaries and their respective officers, employees, contractors, agents, and professional advisers** for internal business purposes.
* **Service providers and contractors** that assist us in operating the Beta, Website, AI features, or related Services. This may include AI infrastructure providers (such as OpenAI or Grok for model inference), analytics and telemetry services (such as Supabase, Amplitude, or similar), hosting providers, authentication services (such as Turnkey and Supabase Auth), or other technical service partners. This includes third-party analytics tools such as Amplitude, mailing automation systems, and other third-party tools that collect and process information provided by users on the Beta in order to enable functionality, analytics, or communications. AI interactions may be transmitted to third-party model providers for inference or processing, but prompts and responses are never shared for advertising or unrelated profiling purposes. We do not, and will never, have access to users’ Turnkey passkeys, private keys, or other credentials, and we do not share such credentials with any third party.
* **Subcontractors and sub-processors** engaged by our service providers, where necessary to perform technical, analytical, or operational tasks on behalf of Boole. These entities are bound by equivalent confidentiality, security, and data protection obligations as our primary service providers and are not permitted to use data for their own purposes.
* **Regulators, government authorities, or law enforcement** as required by law or legal process, or where Boole determines in good faith that such disclosure is reasonably necessary to protect its rights, property, users, or the integrity of the Beta. Disclosure in this context is limited to information collected by Boole and does not include Turnkey passkeys, private keys, or any data enabling access to user accounts.
* **Successors or parties involved in a merger, acquisition, reorganization, sale, or transfer of assets.** Any transferred data will continue to be subject to privacy safeguards.

Boole complies with applicable data protection laws in all jurisdictions where it operates. Where required by local law, we obtain consent, provide notice, and implement safeguards before sharing personal data with third parties, including ensuring lawful basis, contractual safeguards, and user rights where applicable.

Third parties who receive your information are required to protect its confidentiality and may only use it for the specific tasks or services they were engaged to perform on Boole’s behalf.

Users should note that when interacting with third-party protocols or AI features through the Beta, additional information may be shared directly between the user and those protocols, model providers, or authentication services according to their privacy policies. Boole does not control or access this information beyond publicly visible data, telemetry, or limited analytics necessary for app functionality and AI features.

Boole may also compile and share aggregated or statistical information (such as transaction volumes, liquidity metrics, pricing ranges, or feature-usage trends) that cannot reasonably be used to identify any individual user or wallet.

Where AI or analytics integrations involve third-party data processors, Boole ensures that data is either anonymized, pseudonymized, or processed under strict contractual safeguards consistent with applicable data protection laws. Aggregated or anonymized data may also be analyzed internally by Boole to improve functionality, test features, optimize performance, and evaluate AI outputs without identifying individual users. Third parties that assist in delivering notifications, alerts, or portfolio updates may only use the information necessary to deliver those messages and are bound by equivalent confidentiality and data protection obligations. Boole may share minimal necessary data with additional future service providers, AI partners, or analytics tools to provide functionality or improve the Beta.

All sharing by Boole is strictly limited to the purposes described above. Boole does not, and will never, have access to Turnkey passkeys, private keys, or any credentials required to execute transactions on linked protocols. Users’ authentication and transaction control remain solely with them and Turnkey.

Boole may periodically publish or make available a list of key service providers, protocol integrations, or other counterparties that process personal data on its behalf, which may be updated from time to time and is provided in the **Annex: Third-Party Service Providers and Protocol Integrations.**

### 5. Cookies & Tracking Technologies

We use cookies, web beacons, local storage, and other tracking technologies (“Tracking Technologies”) on the Beta and related Boole Services to support functionality, analytics, AI features, and personalization of your experience. These technologies may collect information about your device, browser, usage patterns, and interactions with our Services.&#x20;

Turnkey credentials, private keys, and sensitive authentication information are never collected by cookies or trackers.

**Purpose of Tracking Technologies**

* To maintain core functionality of the Beta, including login sessions, dashboard display, and wallet connections.
* To enable AI features, analytics, and performance optimization.
* To improve user experience, including personalization of settings, notifications, and app behavior.
* To provide optional features such as portfolio alerts, analytics dashboards, and AI-generated insights.
* To detect and prevent fraud, security threats, or anomalous activity.

**Your Choices Regarding Cookies & Tracking Technologies**

All Cookies and Tracking Technologies used on the Beta are considered essential and are required for core functionality. Some examples of the cookies that will be collected are user session cookies and test cookies. Boole will not enable Cookies or Tracking Technologies for marketing purposes. As such, at that stage, the User need not make any decisions in relation to Cookies and Tracking Technology.&#x20;

If you have any enquiries in relation to this  you may email us at <support@portara.app>. You will receive a response with a ticket and acknowledgment that you have been placed in our queue. Within 30 days of your email, we will update you as to the status of our enquiry.

### 6. International Data Transfers

Your personal information, Blockchain Identifiers, and other data collected through the Beta and related Services may be transferred to, stored, and processed in countries other than your country of residence. Such transfers may include, for example, processing analytics, storing usage data, or supporting the operation of the Beta across different jurisdictions.

You should be aware that in some countries, governments, courts, or regulatory authorities may have the legal ability to access or request information processed or stored in those jurisdictions. While Boole implements safeguards, privacy standards in some countries may be lower than those of your home jurisdiction. Boole seeks to ensure that all international transfers comply with applicable local data protection laws and regulations wherever data is stored or processed.

Data stored or processed on our servers located in Tokyo, Japan, is subject to the Act on the Protection of Personal Information (APPI). Boole implements administrative, technical, and contractual safeguards to ensure that such data is protected and handled in a manner consistent with applicable Japanese law.

We ensure that any international transfers are conducted with appropriate safeguards (administrative, technical, and contractual safeguards) to protect your data during international transfers and to maintain compliance with applicable laws, including contractual commitments, standard data protection clauses, or other legally recognized mechanisms designed to provide a level of protection comparable to that of your home jurisdiction.&#x20;

For the avoidance of doubt, no Turnkey credentials, private keys, or other sensitive authentication credentials required for wallet, trading, or AI features are transferred, accessed, or stored during such international processing. Only the public blockchain data, linked transaction metadata, usage data, and voluntary information you provide are subject to these transfers.

### 7. Data Retention

We retain data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal or regulatory obligations, enforce agreements, resolve disputes, or prevent fraud. It is worth repeating that the purpose for which the data was collected includes the proper functioning of the Beta interface (including the Wallet Functions, Trading Functions, and AI Functions) and analyzing usage and improving the Beta interface prior to the launch of the Portara App).&#x20;

Once data is no longer required for the purposes it was collected, we securely delete, anonymize, or otherwise render it permanently inaccessible. Where technically feasible, we will remove personal identifiers from analytics or research datasets while retaining anonymized usage or performance data to help improve the Beta and related Boole Services (such as AI insight models or interface performance benchmarks).

Data retained includes:

* **Personal information** provided by users (e.g., survey responses, beta testing feedback)
* **Blockchain Identifiers** and public blockchain addresses
* **Transaction-related data** (e.g., linked transaction metadata, wallet addresses, transaction summaries)
* **AI-related data** (e.g., interaction logs with non-sensitive content, AI usage metadata such as token counts or model identifiers)
* **Device and usage analytics** (e.g., browser/device analytics, performance telemetry from infrastructure providers such as Amplitude)
* **Temporary technical logs or cached diagnostic data** for service reliability and security monitoring
* **Data processed by infrastructure providers and integrated third-party protocols** supporting wallet connections, DeFi functionality, or AI features (e.g., Turnkey authenticated wallet connections and session metadata, Amplitude usage analytics and performance telemetry)

The data types listed above are retained only as necessary for the operation, improvement, and legal compliance of the Beta and related Services. Certain data, such as wallet addresses, transaction summaries, AI interaction logs (non-sensitive content), and usage metrics, are retained for as long as necessary for the proper functioning of wallet, trading, and AI features, and may also be temporarily retained for debugging, analytics, or performance optimization. AI conversation logs and usage metadata (e.g., token counts or model identifiers) are kept only as needed for service continuity and auditing, then pseudonymized or deleted. Wallet and trading data, including transaction and balance records, are retained as required for legal, auditing, or regulatory purposes. Turnkey passkeys, private keys, and other sensitive authentication credentials are never collected, stored, or accessed by Boole.

Boole and its service providers implement administrative, technical, and physical safeguards to ensure that retained data is protected and securely disposed of when no longer needed. Turnkey credentials and private keys remain fully isolated and inaccessible throughout the data retention lifecycle.

For EU users, you have the right to request deletion of your personal data under the GDPR. Requests can be submitted by contacting <support@portara.app>. Users in other jurisdictions may have similar rights under applicable data protection laws, which Boole will honour where legally required.

### 8. Your Rights

You have certain rights regarding the personal information, Blockchain Identifiers, and other data that we collect through the Portara Beta or related Boole services. Because the Beta’s primary purpose is to support testing, analytics, and improvement prior to launch, some data may be retained in anonymised or aggregated form to maintain or evaluate functionality.&#x20;

These rights may include, where applicable:

<table><thead><tr><th width="262.890625">Your Right</th><th>Description</th></tr></thead><tbody><tr><td>Access</td><td>You can request access to the personal data we hold about you. This includes any email addresses or other voluntarily provided identifiers, usage analytics, or beta testing data. Public blockchain addresses and associated on-chain transaction data are generally already public and may be accessible through blockchain explorers rather than through our systems.</td></tr><tr><td>Correction</td><td>You can request that we correct any inaccuracies or incomplete information. This applies only to the personal or voluntary data you provide to Boole; we cannot alter blockchain or protocol data managed by third parties or on-chain.</td></tr><tr><td>Deletion / Erasure</td><td>You can request that we delete or erase your personal data, where technically feasible and subject to applicable legal or contractual obligations. Please note that some information collected through the Beta is necessary for its functionality (including analytics and testing features), and may be retained in anonymised or aggregated form to support the improvement of the Portara App. This does not extend to blockchain transaction data, public addresses, or data maintained by third-party protocols, which are outside our control.</td></tr><tr><td>Withdraw Consent</td><td>You may withdraw consent for processing activities that require it. However, withdrawal of consent may limit your ability to continue participating in the Beta where such processing is essential to its operation.</td></tr><tr><td>Restrict / Object to Processing </td><td>You may object to or request restriction of certain types of processing where you believe we do not have a legitimate basis, or where such processing is not necessary for the Beta’s functionality. We will review and respond to such requests in accordance with applicable data protection laws.</td></tr><tr><td>Data Portability</td><td>You may request a copy of your data in a portable, machine-readable format where technically feasible. This includes data that Boole maintains about your interactions with the Portara Beta but excludes Turnkey passkeys, private keys, or other credentials, which we never access or store.</td></tr><tr><td>Opt-Out</td><td>You may opt out of certain types of processing, such as optional communications or feature-related feedback collection, including marketing communications.</td></tr></tbody></table>

These rights may be limited where retention of information is required by law, necessary for legitimate business purposes, technically constrained by system design, or where data relates to blockchain or protocol activity that Boole does not control.

To exercise any of these rights, you may contact us at <support@portara.app>. We will honour these rights in jurisdictions where applicable data protection laws grant them. We may need to verify your identity before processing your request to ensure your information is not disclosed or altered by unauthorized persons. We will respond within a reasonable timeframe (normally within one month) and will inform you if additional time is required. You will not be charged any fee for exercising your rights unless your request is manifestly unfounded, repetitive, or excessive.

### 9. Security Measures

We implement commercially reasonable administrative, technical, and physical safeguards designed to protect the personal information, Blockchain Identifiers, and other data you provide or that we collect through the Beta and related Boole services from unauthorized access, use, disclosure, alteration, or destruction. All data stored on Tokyo servers is protected in compliance with APPI, including encryption, access controls, secure storage, and monitoring. This includes administrative, technical and physical safeguards.&#x20;

Despite these measures, no system or network can be completely secure. We cannot guarantee the absolute security of your information, and you acknowledge that any transmission of information through the Beta or the internet is at your own risk. Turnkey credentials, private keys, and data related to interactions you have with integrated protocols or AI/trading features are not stored or controlled by Boole, and users are responsible for securing those credentials or information independently. Users should not share sensitive credentials with others, and are encouraged to follow best practices for password security, including the use of strong passwords and two-factor authentication where available.

Boole will notify affected users and relevant authorities of suspected data breaches as required by applicable law.

### 10. Children’s Data

The Portara Beta and related Services are intended only for individuals who have reached the age of consent in their jurisdiction. We do not allow children to use the Beta or full Services, and we do not knowingly collect personal information from individuals below the minimum legal age.

If we become aware that personal information from an individual below the minimum legal age has been inadvertently collected, we will delete it as soon as practicable. If you believe we may have collected information from a child in violation of this Policy, please contact us immediately at <support@portara.app>.

### 11. Changes to this Policy

We may revise this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or for other operational reasons. If we make material changes, we will notify you by posting the updated Privacy Policy at <<https://portara.gitbook.io/docs/legal/privacy-policy>> or the Beta Interface, and by updating the “Last Updated” date at the top of this Policy. The interface will constantly be changing during Beta, any updates to the interface and its functions that impact the User’s privacy will be reflected here.&#x20;

Updates may include:

* New integrations with protocols
* Changes to Turnkey or other authentication methods
* New types of data collected through the Beta&#x20;
* Updates related to data stored in Tokyo servers or processed under APPI&#x20;

We do not control or have access to Users’ Turnkey passkeys or private keys; therefore, updates related to those systems will only pertain to the data we can access (e.g., public blockchain data, associated email identifiers, transaction analytics). We also do not control the protocols that have been integrated into the Beta; therefore, material changes do not include any changes made to those protocols or their policies. Users should review the privacy policies and terms of use of any integrated protocols independently.

Your continued use of the Beta and related services following any such update constitutes your acceptance of the revised Privacy Policy. We encourage you to review this Policy periodically to stay informed of any changes.

### 12. Contact Us

Questions, comments, or requests regarding this Privacy Policy or your personal data should be addressed by email to [**support@portara.app**](mailto:support@portara.app)**.**&#x20;

We will respond promptly and do our best to address your concerns. For users in jurisdictions with applicable data protection laws (such as the EU under GDPR), you may also contact your local supervisory authority if you are not satisfied with our response.

### Annex: Third-Party Service Providers and Protocol Integrations with whom Personal Information may be shared

| Third Party Name & Jurisdiction       | Purpose / Third Party’s Relationship with the Data (they collect/they share with us/the process/they store) | Data Disclosed                                        |
| ------------------------------------- | ----------------------------------------------------------------------------------------------------------- | ----------------------------------------------------- |
| Supabase Inc. (USA / EU)              | Backend platform; stores auth & app data                                                                    | User profiles, wallets, tx data, AI data              |
| Google LLC (USA)                      | OAuth provider; authenticates users                                                                         | Email, name, profile pic                              |
| Telegram / X Corp. (UAE / USA)        | OAuth provider; authenticates users                                                                         | Username, account ID, display name                    |
| OpenAI LP (USA) / xAI Corp. (USA)     | AI inference; processes user prompts & summaries                                                            | Prompts, wallet summaries, generated outputs          |
| Moralis AG (Switzerland)              | Blockchain API; fetches wallet & token metadata                                                             | Wallet addresses, chain data                          |
| Alchemy Insights Inc. (USA)           | Blockchain infra; RPC requests & node access                                                                | Wallet addresses, tx metadata                         |
| Helius Labs Inc. (USA)                | Solana RPC & analytics                                                                                      | Solana wallet addresses, chain metadata               |
| LIFI GmbH (Germany)                   | Cross-chain bridge routing API                                                                              | Wallet addresses, tx routing info                     |
| Reown / WalletConnect Inc. (USA)      | Wallet connector; links user wallets                                                                        | Wallet address, session metadata                      |
| CoinMarketCap (USA / Binance Group)   | Market data provider; price feeds                                                                           | None (pulls public token data)                        |
| Amplitude Inc. (USA)                  | Analytics; app usage & engagement metrics                                                                   | User\_IDs, session events, usage telemetry            |
| Sentry Inc. (USA)                     | Error & crash reporting                                                                                     | Stack traces, anonymized user/session IDs             |
| Amazon Web Services (USA / Global)    | Cloud hosting & storage infrastructure                                                                      | App data, backups, logs                               |
| Mailgun (Sinch AB, Sweden / USA)      | Transactional email delivery                                                                                | Email address, delivery status, metadata, wallet data |
| Tavily Technologies (USA)             | Search enrichment for AI features                                                                           | Prompt snippets, contextual metadata                  |
| Ethereum / Solana / other blockchains | Public decentralized networks                                                                               | Wallet addresses, on-chain transaction data           |

<br>

<br>
