Otomate

Privacy Policy

Last updated: September 1, 2026

1. Overview

Otomate ("we", "us", "our") operates otomate.fun and app.otomate.trade, including the Otomate Launcher and a non-custodial trading automation platform on Ink Protocol. This policy explains what data we collect, how we use it, and your rights.

2. Data We Collect

  • Wallet addresses — Your public blockchain address used for authentication and trading.
  • Email address — If you choose to sign in via email or Google (processed by Privy, our authentication provider).
  • Launcher access requests — The operator wallet and email address you submit directly, plus optional X and Telegram handles. We use these details to review your request, prevent abuse, and contact you about the next access step. Submitting a request does not itself grant access.
  • Usage analytics — Pseudonymous interaction data collected via PostHog to improve the product (page views, feature usage, transaction funnel status). Wallet addresses are hashed before being sent to analytics.
  • Trading preferences — Settings you configure (strategies, risk parameters) stored in our database.
  • Connected assistant data — OAuth client details, approved scopes, grant status, and revocation state when you connect ChatGPT, Codex, Claude, Cursor, or another MCP client.
  • Assistant activity — Security audit and usage metadata including tool name, requested scopes, outcome, latency, redacted arguments, prepared actions, confirmation status, and execution result. We do not intentionally store raw OAuth tokens, private keys, seed phrases, or wallet signatures in these audit records.

3. Connected Assistants and MCP

When you connect an assistant through the Otomate MCP, you choose the OAuth permissions it receives. Depending on those scopes, the assistant can read market, portfolio, position, performance, policy, monitoring, and action-center data; create an expiring prepared action; or request confirmation of an action.

An action that may move funds or change a position requires the execute:tradesscope, an existing prepared action, and your explicit confirmation in the connected assistant. Otomate then applies policy, risk, cap, simulation, executor, expiry, audit, and revocation checks. You may disconnect Otomate using the connected assistant's controls where supported or contact Otomate support; a revoked grant is rejected by Otomate.

Data returned in response to your request is sent to the connected assistant host, such as OpenAI, under your direction. That provider processes the data under its own terms and privacy policy.

4. Non-Custodial Model

Otomate is non-custodial: we do not take ownership of your assets or receive your private keys or seed phrases. Your assets remain in your wallet or supported trading subaccount. If you enable delegated or embedded-wallet execution, Otomate may submit a scoped instruction through the authorized signer or provider after the required consent and policy checks. Embedded wallet key material is managed by Privy using secure infrastructure and is not exposed to Otomate personnel.

5. How We Use and Share Data

We use the data above to authenticate you, provide requested reads and actions, enforce permissions and safety controls, prevent abuse, investigate failures, support users, measure reliability, and improve Otomate. We share only what is necessary with processors and execution providers that support those purposes.

  • Privy (privy.io) — Authentication and embedded wallet management.
  • PostHog — Product analytics (pseudonymous usage data, with hashed wallet identifiers).
  • Nado Protocol — On-chain trade execution on Ink.
  • Vercel — Application hosting and CDN.
  • Connected assistant providers — OpenAI or another MCP host receives the tool inputs and outputs needed to fulfill the requests you initiate.

6. Cookies & Local Storage

We use browser local storage to save your UI preferences (theme, trading settings) and session tokens. PostHog may set analytics cookies. No advertising cookies are used.

7. Push Notifications

You may opt in to push notifications for trade alerts. This requires explicit consent via the notification bell icon. You can disable notifications at any time in your browser settings.

8. Data Retention, Revocation & Deletion

Account, trading, assistant grant, prepared-action, and audit data is retained while needed to provide the service, protect users, meet legal obligations, resolve disputes, and enforce our agreements. You may revoke an assistant connection at any time and request deletion of eligible account data by contacting us. Legal, security, fraud-prevention, and immutable on-chain records may be retained where deletion is not permitted or technically possible.

Launcher access-request contact details are retained while a review or approved access relationship is active, then for up to 12 months after the last review activity. We may retain a minimal decision and security record for longer where needed to prevent abuse or meet legal obligations. You may request deletion of eligible contact details using the channels below.

9. Contact

For privacy inquiries, reach us on Telegram or Discord.