Legal
Privacy Policy
Last updated: July 17, 2026
This Privacy Policy explains how TrueHold ("TrueHold", "we", "us") collects, uses, shares and protects personal data when you use our websites, including www.truehold.xyz and app.truehold.xyz, and the products and services offered through them (together, the "Services"). The Services are a self-custodial, read-only crypto portfolio tracker: you connect exchanges with read-only API keys or paste public wallet addresses, and TrueHold assembles a single view of your holdings.
By using the Services you agree to this Policy. Read it together with our Terms of Service and Cookies Policy.
The short version
- We never ask for, collect, or store seed phrases or private keys. Anywhere. Ever.
- Exchange connections are accepted with read-only permissions only — TrueHold cannot move, trade or withdraw your assets.
- We do not sell your personal data.
- You can disconnect a wallet or revoke an API key at any time, and ask us to delete your data.
1. Information we collect
Account information. When you create an account in the app, we collect the identifiers you sign up with — such as an email address and/or a wallet address used for login.
Portfolio connection data. To provide the tracker, we process the public wallet addresses you paste, the read-only exchange API keys you connect, and the data those connections return: balances, positions, transaction history, and derived analytics such as profit and loss. API keys are used solely to read this data on your behalf.
Waitlist and communications. If you join a waitlist or contact us, we collect your email address and the content of your message.
Technical data. Like most online services, our infrastructure processes IP addresses, device and browser information, request logs, and error reports generated when something breaks.
Preferences stored on your device. The landing site stores small preference flags in your browser (for example, your theme choice). These stay on your device and are described in the Cookies Policy.
2. What we never collect
- Seed phrases and private keys — no screen in the Services asks for them.
- Exchange API keys with trade or withdrawal permissions — connections are read-only by design.
- Custody of your assets — funds never pass through TrueHold.
3. How we use information
- To provide the Services: aggregate and display your portfolio, compute analytics, generate alerts, and answer questions through AI features grounded in your own portfolio data.
- To operate, maintain, secure and debug the Services.
- To communicate with you about the Services, including service updates and replies to your requests.
- To improve the Services, using aggregated or de-identified information where practicable.
- To comply with legal obligations and enforce our Terms.
Where AI features process your portfolio data, they do so on our instructions to provide the feature you requested. We do not use your personal data to train third-party foundation models.
4. Legal bases
Where the GDPR or similar laws apply, we process personal data on these bases: performance of a contract (providing the Services you signed up for), legitimate interests (securing and improving the Services), consent (where we ask for it — product analytics and the waitlist), and compliance with legal obligations. Where the basis is consent you can withdraw it at any time, and withdrawing is as easy as giving it.
5. How we share information
We do not sell personal data. We share it only with service providers that help us run the Services and act on our instructions — including cloud hosting (Vercel), database and backend infrastructure (Supabase), error monitoring (Sentry), product analytics (PostHog, EU-hosted, and only where you have accepted analytics — see the Cookies Policy), and transactional email (Resend). Market-data providers we query for prices receive no personal data from us. We may also disclose information where the law requires it, to protect our rights or users' safety, or as part of a corporate transaction — in which case this Policy continues to apply to your data.
6. International transfers
Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards such as standard contractual clauses.
7. Retention
We keep personal data while your account is active or as needed to provide the Services. When you disconnect a wallet or revoke an API key, we stop reading data through it. When you delete your account or ask us to delete your data, we remove it within a reasonable period, except where retention is required by law or for security records, and residual copies may persist briefly in backups before being cycled out.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent at any time. You can exercise these rights by emailing hello@truehold.xyz. If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority. We do not discriminate against you for exercising your rights.
9. Security
We apply reasonable technical and organizational measures to protect personal data, and the architecture itself is our biggest safeguard: connections are read-only, so even in a worst-case scenario your assets cannot be moved through TrueHold. No online service can guarantee absolute security — if you believe you have found a vulnerability, please report it to hello@truehold.xyz (see our Security page).
10. Children
The Services are not directed to anyone under 18, and we do not knowingly collect personal data from children.
11. Changes to this Policy
We may update this Policy from time to time. We will post the new version here and update the date above; for material changes we will provide additional notice where required.
12. Contact
Questions about privacy: hello@truehold.xyz.
