Skip to main content
Skip to document
Otomate
Back to Explore

OTOMATE / LEGAL

Privacy Policy

How information is handled across Otomate and its connected tools.

Updated September 13, 2026Version 2026-09-13.2
Terms of ServicePrivacy Policy

On this page

  1. 01Overview
  2. 02Data We Collect
  3. 03Connected Assistants and MCP
  4. 04Non-Custodial Model
  5. 05How We Use and Share Data
  6. 06Cookies & Local Storage
  7. 07Push Notifications
  8. 08Data Retention, Revocation & Deletion
  9. 09Public blockchain records
  10. 10Your privacy choices
  11. 11Contact
  12. 12Creative inputs and publication
  13. 13Purposes and legal bases
  14. 14Providers, transfers and policy updates
01

Overview

CD LABS operates Otomate ("we", "us", "our") at otomate.fun, including the Otomate Launcher and a non-custodial trading automation platform on Ink Protocol. This policy explains what data we collect, how we use it, and your rights.

02

Data We Collect

  • Wallet addresses — Your public blockchain address used for authentication and trading.
  • Email address — If you choose to sign in via email or Google (processed by Privy, our authentication provider).
  • Launcher access requests — The operator wallet and email address you submit directly, plus optional X and Telegram handles. We use these details to review your request, prevent abuse, and contact you about the next access step. Submitting a request does not itself grant access.
  • Usage analytics — Optional browser PostHog product analytics and session replay are disabled in this revision. If introduced with the required consent, they may include page views, feature usage and transaction funnel status, with hashed wallet identifiers and masked replay. Hashing is pseudonymisation, not anonymity.
  • Trading preferences — Settings you configure (strategies, risk parameters) stored in our database.
  • Connected assistant data — OAuth client details, approved scopes, grant status, and revocation state when you connect ChatGPT, Codex, Claude, Cursor, or another MCP client.
  • Assistant activity — Security audit and usage metadata including tool name, requested scopes, outcome, latency, redacted arguments, prepared actions, confirmation status, and execution result. We do not intentionally store raw OAuth tokens, private keys, seed phrases, or wallet signatures in these audit records.

Collection tools may process the names, symbols, images, links and other metadata you submit, together with public token, NFT and transaction records. Our hosting, RPC and data providers also receive technical connection information needed to respond to requests, such as an IP address and browser details.

03

Connected Assistants and MCP

When you connect an assistant through the Otomate MCP, you choose the OAuth permissions it receives. Depending on those scopes, the assistant can read market, portfolio, position, performance, policy, monitoring, and action-center data; create an expiring prepared action; or request confirmation of an action.

An action that may move funds or change a position requires the execute:tradesscope, an existing prepared action, and your explicit confirmation in the connected assistant. Otomate then applies policy, risk, cap, simulation, executor, expiry, audit, and revocation checks. You may disconnect Otomate using the connected assistant's controls where supported or contact Otomate support; a revoked grant is rejected by Otomate.

Data returned in response to your request is sent to the connected assistant host, such as OpenAI, under your direction. That provider processes the data under its own terms and privacy policy.

04

Non-Custodial Model

Otomate is non-custodial: we do not take ownership of your assets or receive your private keys or seed phrases. Your assets remain in your wallet or supported trading subaccount. If you enable delegated or embedded-wallet execution, Otomate may submit a scoped instruction through the authorized signer or provider after the required consent and policy checks. Embedded wallet key material is managed through Privy. Access and execution depend on the wallet configuration, provider controls and permissions you authorize.

05

How We Use and Share Data

We use the data above to authenticate you, provide requested reads and actions, enforce permissions and safety controls, prevent abuse, investigate failures, support users, measure reliability, and improve Otomate. We share only what is necessary with processors and execution providers that support those purposes.

  • Privy (privy.io) — Authentication and embedded wallet management.
  • PostHog — Browser analytics and session replay are disabled. Server-side event and error reporting may still be sent to PostHog when configured, including pseudonymous action metadata and hashed wallet identifiers. Disabling browser tracking does not disable this separate server processing.
  • Nado Protocol — On-chain trade execution on Ink.
  • Vercel — Application hosting and CDN.
  • Connected assistant providers — OpenAI or another MCP host receives the tool inputs and outputs needed to fulfill the requests you initiate.

Launcher features also contact configured RPC, indexing, market-data, storage and bridge services, including Codex market data and LayerZero-based bridge infrastructure where available. The providers involved depend on the network and feature you use.

06

Cookies & Local Storage

We use browser local storage to save your UI preferences (theme, trading settings) and session tokens, creative drafts and recovery records. Optional browser PostHog analytics and replay are disabled in this revision. Terms acceptance, wallet connection and notification permission do not provide analytics consent.

The interface stores your terms acknowledgement in this browser with the wallet address, document version and acceptance time. It is not an on-chain signature. A different wallet, revised terms or cleared storage may require another acknowledgement. Accepting the terms is separate from optional analytics or marketing consent.

07

Push Notifications

You may opt in to push notifications for trade alerts. This requires explicit consent via the notification bell icon. Delivery uses stored push subscriptions, including an endpoint and subscription keys associated with your account. You can disable notifications at any time in your browser settings.

08

Data Retention, Revocation & Deletion

Account, trading, assistant grant, prepared-action, and audit data is retained while needed to provide the service, protect users, meet legal obligations, resolve disputes, and enforce our agreements. You may revoke an assistant connection at any time and request deletion of eligible account data by contacting us. Legal, security, fraud-prevention, and immutable on-chain records may be retained where deletion is not permitted or technically possible.

Launcher access-request contact details are retained while a review or approved access relationship is active, then for up to 12 months after the last review activity. We may retain a minimal decision and security record for longer where needed to prevent abuse or meet legal obligations. You may request deletion of eligible contact details using the channels below.

09

Public blockchain records

Wallet addresses and activity can identify or be associated with a person. Transactions on Ink, Robinhood or another public network remain visible through independent nodes and explorers. A browser reset, wallet disconnection or account deletion request cannot remove those public records.

10

Your privacy choices

You can disconnect your wallet, manage browser storage and revoke supported assistant permissions. Depending on the law that applies to you, you may request access, correction, deletion or a copy of eligible personal information, or object to or restrict certain processing. Contact us through the channels below; we may need to verify that the request relates to you.

Requests do not reverse blockchain transactions or remove records that must be retained for legal or security reasons. Where applicable, you may also contact the relevant data-protection authority.

11

Contact

For privacy inquiries and rights requests, email thibault@otomate.trade. You may also reach us on Telegram or Discord.

12

Creative inputs and publication

Collection tools process prompts, reference uploads, generated or imported artwork, metadata, project settings and recovery records to prepare your collection. Campaign and support communications may also be stored. Technical connection data, including IP addresses and browser details, may pass through our application proxies and service providers.

Publishing artwork or metadata to IPFS or a public blockchain can make it accessible to third parties. Removing our stored copy or unpinning content cannot guarantee deletion of independently retained public copies. Do not publish personal or confidential information you do not intend to make public.

13

Purposes and legal bases

Subject to applicable law, we process data necessary to provide the services you request on a contractual basis; use proportionate security, anti-abuse and diagnostic processing for our legitimate interests; rely on consent where required for optional tracking or communications; and retain or disclose records where a legal obligation requires it. These bases apply to the relevant purpose, not to all processing indiscriminately.

You may withdraw consent without affecting the lawfulness of earlier processing. You may request access, correction, erasure, restriction, portability or object where applicable. You can complain to the Andorran Data Protection Agency (APDA) at apda.ad, or another competent authority.

14

Providers, transfers and policy updates

Creative generation, pinning and recovery storage use the providers configured for the requested feature. Processing may occur outside your country. Applicable transfer requirements and safeguards depend on the provider and destination; this policy does not promise European-only hosting or that every provider excludes model training. Contact us for information about the processing relevant to your project.

We publish material changes with a new version and date and provide additional notice or request consent where required. Disconnecting a wallet or revoking an assistant does not automatically erase retained records or revoke every separate on-chain permission.

Otomate© Otomate
PrivacyTermsDocumentationDiscord Official X
Skip to document
Otomate
Back to Explore

OTOMATE / LEGAL

Privacy Policy

How information is handled across Otomate and its connected tools.

Updated September 13, 2026Version 2026-09-13.2
Terms of ServicePrivacy Policy

On this page

  1. 01Overview
  2. 02Data We Collect
  3. 03Connected Assistants and MCP
  4. 04Non-Custodial Model
  5. 05How We Use and Share Data
  6. 06Cookies & Local Storage
  7. 07Push Notifications
  8. 08Data Retention, Revocation & Deletion
  9. 09Public blockchain records
  10. 10Your privacy choices
  11. 11Contact
  12. 12Creative inputs and publication
  13. 13Purposes and legal bases
  14. 14Providers, transfers and policy updates
01

Overview

CD LABS operates Otomate ("we", "us", "our") at otomate.fun, including the Otomate Launcher and a non-custodial trading automation platform on Ink Protocol. This policy explains what data we collect, how we use it, and your rights.

02

Data We Collect

  • Wallet addresses — Your public blockchain address used for authentication and trading.
  • Email address — If you choose to sign in via email or Google (processed by Privy, our authentication provider).
  • Launcher access requests — The operator wallet and email address you submit directly, plus optional X and Telegram handles. We use these details to review your request, prevent abuse, and contact you about the next access step. Submitting a request does not itself grant access.
  • Usage analytics — Optional browser PostHog product analytics and session replay are disabled in this revision. If introduced with the required consent, they may include page views, feature usage and transaction funnel status, with hashed wallet identifiers and masked replay. Hashing is pseudonymisation, not anonymity.
  • Trading preferences — Settings you configure (strategies, risk parameters) stored in our database.
  • Connected assistant data — OAuth client details, approved scopes, grant status, and revocation state when you connect ChatGPT, Codex, Claude, Cursor, or another MCP client.
  • Assistant activity — Security audit and usage metadata including tool name, requested scopes, outcome, latency, redacted arguments, prepared actions, confirmation status, and execution result. We do not intentionally store raw OAuth tokens, private keys, seed phrases, or wallet signatures in these audit records.

Collection tools may process the names, symbols, images, links and other metadata you submit, together with public token, NFT and transaction records. Our hosting, RPC and data providers also receive technical connection information needed to respond to requests, such as an IP address and browser details.

03

Connected Assistants and MCP

When you connect an assistant through the Otomate MCP, you choose the OAuth permissions it receives. Depending on those scopes, the assistant can read market, portfolio, position, performance, policy, monitoring, and action-center data; create an expiring prepared action; or request confirmation of an action.

An action that may move funds or change a position requires the execute:tradesscope, an existing prepared action, and your explicit confirmation in the connected assistant. Otomate then applies policy, risk, cap, simulation, executor, expiry, audit, and revocation checks. You may disconnect Otomate using the connected assistant's controls where supported or contact Otomate support; a revoked grant is rejected by Otomate.

Data returned in response to your request is sent to the connected assistant host, such as OpenAI, under your direction. That provider processes the data under its own terms and privacy policy.

04

Non-Custodial Model

Otomate is non-custodial: we do not take ownership of your assets or receive your private keys or seed phrases. Your assets remain in your wallet or supported trading subaccount. If you enable delegated or embedded-wallet execution, Otomate may submit a scoped instruction through the authorized signer or provider after the required consent and policy checks. Embedded wallet key material is managed through Privy. Access and execution depend on the wallet configuration, provider controls and permissions you authorize.

05

How We Use and Share Data

We use the data above to authenticate you, provide requested reads and actions, enforce permissions and safety controls, prevent abuse, investigate failures, support users, measure reliability, and improve Otomate. We share only what is necessary with processors and execution providers that support those purposes.

  • Privy (privy.io) — Authentication and embedded wallet management.
  • PostHog — Browser analytics and session replay are disabled. Server-side event and error reporting may still be sent to PostHog when configured, including pseudonymous action metadata and hashed wallet identifiers. Disabling browser tracking does not disable this separate server processing.
  • Nado Protocol — On-chain trade execution on Ink.
  • Vercel — Application hosting and CDN.
  • Connected assistant providers — OpenAI or another MCP host receives the tool inputs and outputs needed to fulfill the requests you initiate.

Launcher features also contact configured RPC, indexing, market-data, storage and bridge services, including Codex market data and LayerZero-based bridge infrastructure where available. The providers involved depend on the network and feature you use.

06

Cookies & Local Storage

We use browser local storage to save your UI preferences (theme, trading settings) and session tokens, creative drafts and recovery records. Optional browser PostHog analytics and replay are disabled in this revision. Terms acceptance, wallet connection and notification permission do not provide analytics consent.

The interface stores your terms acknowledgement in this browser with the wallet address, document version and acceptance time. It is not an on-chain signature. A different wallet, revised terms or cleared storage may require another acknowledgement. Accepting the terms is separate from optional analytics or marketing consent.

07

Push Notifications

You may opt in to push notifications for trade alerts. This requires explicit consent via the notification bell icon. Delivery uses stored push subscriptions, including an endpoint and subscription keys associated with your account. You can disable notifications at any time in your browser settings.

08

Data Retention, Revocation & Deletion

Account, trading, assistant grant, prepared-action, and audit data is retained while needed to provide the service, protect users, meet legal obligations, resolve disputes, and enforce our agreements. You may revoke an assistant connection at any time and request deletion of eligible account data by contacting us. Legal, security, fraud-prevention, and immutable on-chain records may be retained where deletion is not permitted or technically possible.

Launcher access-request contact details are retained while a review or approved access relationship is active, then for up to 12 months after the last review activity. We may retain a minimal decision and security record for longer where needed to prevent abuse or meet legal obligations. You may request deletion of eligible contact details using the channels below.

09

Public blockchain records

Wallet addresses and activity can identify or be associated with a person. Transactions on Ink, Robinhood or another public network remain visible through independent nodes and explorers. A browser reset, wallet disconnection or account deletion request cannot remove those public records.

10

Your privacy choices

You can disconnect your wallet, manage browser storage and revoke supported assistant permissions. Depending on the law that applies to you, you may request access, correction, deletion or a copy of eligible personal information, or object to or restrict certain processing. Contact us through the channels below; we may need to verify that the request relates to you.

Requests do not reverse blockchain transactions or remove records that must be retained for legal or security reasons. Where applicable, you may also contact the relevant data-protection authority.

11

Contact

For privacy inquiries and rights requests, email thibault@otomate.trade. You may also reach us on Telegram or Discord.

12

Creative inputs and publication

Collection tools process prompts, reference uploads, generated or imported artwork, metadata, project settings and recovery records to prepare your collection. Campaign and support communications may also be stored. Technical connection data, including IP addresses and browser details, may pass through our application proxies and service providers.

Publishing artwork or metadata to IPFS or a public blockchain can make it accessible to third parties. Removing our stored copy or unpinning content cannot guarantee deletion of independently retained public copies. Do not publish personal or confidential information you do not intend to make public.

13

Purposes and legal bases

Subject to applicable law, we process data necessary to provide the services you request on a contractual basis; use proportionate security, anti-abuse and diagnostic processing for our legitimate interests; rely on consent where required for optional tracking or communications; and retain or disclose records where a legal obligation requires it. These bases apply to the relevant purpose, not to all processing indiscriminately.

You may withdraw consent without affecting the lawfulness of earlier processing. You may request access, correction, erasure, restriction, portability or object where applicable. You can complain to the Andorran Data Protection Agency (APDA) at apda.ad, or another competent authority.

14

Providers, transfers and policy updates

Creative generation, pinning and recovery storage use the providers configured for the requested feature. Processing may occur outside your country. Applicable transfer requirements and safeguards depend on the provider and destination; this policy does not promise European-only hosting or that every provider excludes model training. Contact us for information about the processing relevant to your project.

We publish material changes with a new version and date and provide additional notice or request consent where required. Disconnecting a wallet or revoking an assistant does not automatically erase retained records or revoke every separate on-chain permission.

Otomate© Otomate
PrivacyTermsDocumentationDiscord Official X