Privacy Policy

Last updated: July 14, 2026 · Deletion policy v2026-07-14

1. Data We Collect

  • Account data: email address (if you sign up with email or Google), Solana wallet address (if you sign in with Phantom).
  • Credentials: Your Polygon private key, encrypted with AES-256 (Fernet) before storage. We never store it in plain text.
  • Payment data: NowPayments order IDs and subscription status. We do not store card numbers or crypto wallet seeds.
  • Usage data: IP address (logged at Terms acceptance), bot activity logs, trade execution records.
  • Cookies: A single authentication cookie (polyedge_token, 24-hour JWT, strictly necessary).

2. How We Use Your Data

  • To authenticate you and maintain your session.
  • To operate your copy-trading bot on your behalf using your encrypted private key.
  • To process payments and manage your subscription.
  • To detect fraud, abuse, and enforce our Terms of Service.

3. Third Parties

  • Google — OAuth 2.0 sign-in (Google Privacy Policy applies).
  • NowPayments — crypto payment processing.
  • polygon-rpc.com — Polygon Foundation public RPC for trade execution.
  • Polymarket CLOB — trade execution on prediction markets.
  • Vercel — frontend hosting and edge network.
  • Vultr — backend server hosting (Seoul, South Korea).
  • Clerk — sign-in and account identity.
  • Privy — trading-key custody. Keys live inside Privy's secure hardware enclave and never touch our servers. Privy is the processor of record for that key material: when you delete your account we revoke every authorization and stop all signing, and the enclave-held material expires with its 90-day authorization window. Privy does not offer an API to destroy the raw material earlier.
  • Convex — application database hosting.
  • Resend — transactional email delivery.
  • Anthropic — powers the support chat; messages you type there are processed by Anthropic and are not stored by us.

We do not sell your personal data.

4. Data Retention & Account Deletion

We keep your account data while your account exists. You can end that at any time, yourself, from your Account page. Here is exactly what happens when you delete your account:

  • Right away: your MiniMe stops trading. Its trading keys are destroyed and every trading authorization is revoked.
  • For 30 days: your account is scheduled for erasure. You can cancel from the Account page during this window.
  • After 30 days: your account, profile, trading history, simulator sessions, analytics events, wallet links, and sign-in identity are permanently erased — from our database, our servers, and our sign-in provider.
  • Then: we send one final email confirming the erasure.

Two categories are kept, with your identity removed:

  • Payment records (amounts, dates, transaction references) — tax and anti-money-laundering law requires us to keep them. Your name, email, and account link are stripped.
  • Consent records (see section 4a) — kept as proof of what was authorized, identified only by an anonymous code, never by you.

If you also want your public wallet address removed from our leaderboards, tick that option in the deletion flow — the exclusion is permanent. Trades already recorded on the Polygon blockchain are public and permanent by design; no one, including us, can erase them.

You can download everything we store about you as a single file from the Account page before (or instead of) deleting.

4a. Trade Consent Records

When you authorize live automated trading via the per-session consent modal, MiniMe.bot records your authorization — source wallet, bet size, defense filter selections, and timestamp. These records exist as an audit trail for your protection: they are your record of what you agreed to, on what terms, on which day. You may export them at any time from the Account page. If you delete your account, the records are kept as proof of authorization but your identity is replaced with an anonymous code — nothing in the retained record names you.

5. Your Rights (GDPR / CCPA)

  • Right to access, rectify, or erase your data.
  • Right to data portability.
  • Right to opt out of any non-essential data processing.
  • We do not sell personal information (California residents: no opt-out needed).

Access, portability, and erasure are self-serve on your Account page (“Download my data” and “Delete account”). For anything else, email privacy@minime.bot.

6. Cookies

We use one strictly necessary cookie (polyedge_token) for authentication. No analytics or marketing cookies are set without consent. You can delete cookies at any time via your browser settings; doing so will log you out.

7. Security

Private keys are encrypted at rest using Fernet symmetric encryption. Transmission occurs exclusively over HTTPS. We conduct regular security reviews and do not log sensitive credentials.

8. Children

minime.bot is not directed to anyone under 21. We do not knowingly collect data from minors.

9. Contact

For privacy inquiries: privacy@minime.bot