TrueHold

Legal

Privacy Policy

Last updated: July 17, 2026

This Privacy Policy explains how TrueHold ("TrueHold", "we", "us") collects, uses, shares and protects personal data when you use our websites, including www.truehold.xyz and app.truehold.xyz, and the products and services offered through them (together, the "Services"). The Services are a self-custodial, read-only crypto portfolio tracker: you connect exchanges with read-only API keys or paste public wallet addresses, and TrueHold assembles a single view of your holdings.

By using the Services you agree to this Policy. Read it together with our Terms of Service and Cookies Policy.

The short version

  • We never ask for, collect, or store seed phrases or private keys. Anywhere. Ever.
  • Exchange connections are accepted with read-only permissions only — TrueHold cannot move, trade or withdraw your assets.
  • We do not sell your personal data.
  • You can disconnect a wallet or revoke an API key at any time, and ask us to delete your data.

1. Information we collect

Account information. When you create an account in the app, we collect the identifiers you sign up with — such as an email address and/or a wallet address used for login.

Portfolio connection data. To provide the tracker, we process the public wallet addresses you paste, the read-only exchange API keys you connect, and the data those connections return: balances, positions, transaction history, and derived analytics such as profit and loss. API keys are used solely to read this data on your behalf.

Waitlist and communications. If you join a waitlist or contact us, we collect your email address and the content of your message.

Technical data. Like most online services, our infrastructure processes IP addresses, device and browser information, request logs, and error reports generated when something breaks.

Preferences stored on your device. The landing site stores small preference flags in your browser (for example, your theme choice). These stay on your device and are described in the Cookies Policy.

2. What we never collect

3. How we use information

Where AI features process your portfolio data, they do so on our instructions to provide the feature you requested. We do not use your personal data to train third-party foundation models.

4. Legal bases

Where the GDPR or similar laws apply, we process personal data on these bases: performance of a contract (providing the Services you signed up for), legitimate interests (securing and improving the Services), consent (where we ask for it — product analytics and the waitlist), and compliance with legal obligations. Where the basis is consent you can withdraw it at any time, and withdrawing is as easy as giving it.

5. How we share information

We do not sell personal data. We share it only with service providers that help us run the Services and act on our instructions — including cloud hosting (Vercel), database and backend infrastructure (Supabase), error monitoring (Sentry), product analytics (PostHog, EU-hosted, and only where you have accepted analytics — see the Cookies Policy), and transactional email (Resend). Market-data providers we query for prices receive no personal data from us. We may also disclose information where the law requires it, to protect our rights or users' safety, or as part of a corporate transaction — in which case this Policy continues to apply to your data.

6. International transfers

Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards such as standard contractual clauses.

7. Retention

We keep personal data while your account is active or as needed to provide the Services. When you disconnect a wallet or revoke an API key, we stop reading data through it. When you delete your account or ask us to delete your data, we remove it within a reasonable period, except where retention is required by law or for security records, and residual copies may persist briefly in backups before being cycled out.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent at any time. You can exercise these rights by emailing hello@truehold.xyz. If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority. We do not discriminate against you for exercising your rights.

9. Security

We apply reasonable technical and organizational measures to protect personal data, and the architecture itself is our biggest safeguard: connections are read-only, so even in a worst-case scenario your assets cannot be moved through TrueHold. No online service can guarantee absolute security — if you believe you have found a vulnerability, please report it to hello@truehold.xyz (see our Security page).

10. Children

The Services are not directed to anyone under 18, and we do not knowingly collect personal data from children.

11. Changes to this Policy

We may update this Policy from time to time. We will post the new version here and update the date above; for material changes we will provide additional notice where required.

12. Contact

Questions about privacy: hello@truehold.xyz.