Privacy Policy
Last updated: July 14, 2026
1. Scope
This Privacy Policy explains how Asymmetry Horizon, LLC, operating as Noxint (“we,” “us,” or “our”), handles personal information when you use the Noxint web chat and related API and MCP services (the “Service”).
2. Information We Process
2.1 Wallet Identity and Account Data
Noxint uses Privy for wallet-only authentication. We process your Privy user identifier, connected Ethereum wallet addresses, session information, and a wallet-derived display name. If your existing Privy identity includes optional linked profile information, Privy may also make that information available to us. We do not receive or store your private key or seed phrase.
We read public blockchain balances for supported wallets through a configured RPC provider to determine your $NOXINT holding tier. Wallet addresses and on-chain activity are public by design and may be independently visible to anyone using the relevant blockchain.
2.2 Chats, Outputs, and Tool Activity
We store authenticated web chats and AI responses so you can access conversation history and resume interrupted responses.
This includes prompts, relevant conversation context, AI outputs, attachment references, tool names and results, model and usage metadata, and delivery or recovery state. We do not use your chats to train our own AI models.
2.3 Uploaded Files
When uploads are enabled and you attach a supported image, the file is stored in private object storage. Noxint checks your session before issuing a short-lived signed viewing URL, and issues a separate short-lived URL when an AI provider needs the image to answer your request. Do not upload private keys, seed phrases, credentials, regulated records, or other sensitive information.
2.4 Credits and Entitlement Records
We maintain your verified Holder status, credit flow accrual state, credit balance, reservations, usage debits and refunds, token counts, models used, and successful market-data tool counts. These records let us meter use reliably, prevent double charging, restore credits after failures, and investigate disputes or abuse.
2.5 Device, Network, and Security Data
We process IP addresses, request headers, user-agent information, timestamps, security-policy reports, rate-limit state, and diagnostic metadata to authenticate requests, prevent abuse, investigate errors, and protect the Service. We do not use third-party advertising trackers.
2.6 Cookies and Local Device Storage
Privy uses HTTP-only cookies to maintain authentication. Noxint uses first-party cookies or browser storage for required acknowledgments, theme and accessibility preferences, sidebar state, authenticated message drafts, pending-send recovery, and navigation continuity. A pre-authentication prompt stays in memory only and is neither executed nor persisted before wallet verification. These items operate the product and are not used for cross-site advertising.
3. How We Use Information
- Authenticate wallet accounts and owner-scope private data.
- Generate, stream, recover, and deliver requested AI chat responses.
- Retrieve relevant crypto and stock market data and display it in your conversation.
- Verify token holdings, accrue flow credits, meter credits, and reconcile failed or retried requests.
- Enforce rate limits, detect abuse, secure the Service, and comply with legal obligations.
- Monitor aggregate reliability, performance, costs, and feature operation using content-disabled telemetry by default.
- Respond to support, privacy, and legal requests.
4. Processors and Data Flows
We do not sell your personal information. We use:
- Privy for wallet authentication, session tokens, linked-wallet information, and account identity.
- Hosting, model-routing, and object-storage providers to deliver the application, route chat context, and privately store uploads when enabled.
- Underlying AI model providers to process prompts, relevant conversation history, uploaded images, tool results, and a pseudonymous end-user identifier. The selected model and provider can change for availability, safety, or performance. Their processing and retention policies may differ.
- Market-data infrastructure for crypto market data and for stock and SEC-derived data. We send the structured query parameters needed for a tool call, such as symbols, asset identifiers, timeframes, ranges, and requested views. We do not send your full conversation or wallet identity to market-data infrastructure as part of ordinary tool calls.
- MoonPay Commerce when you buy a credit pack. The hosted checkout processes payment and wallet details under its own terms. Noxint receives the order identifier, quoted amount, settlement status, and transaction metadata needed to grant credits and prevent duplicate grants; we do not receive payment-card details.
- PostgreSQL hosting for durable account, chat, entitlement, usage, and delivery records, and Redis hosting for short-lived rate limits, concurrency leases, and resumable-stream state.
- Sentry, when enabled, for error, performance, and reliability monitoring. Noxint configures AI telemetry not to record prompts or outputs by default, scrubs content and direct identifiers before sending telemetry, masks all text and blocks media in error replays, and does not record routine replay sessions.
- Blockchain and RPC infrastructure to read public linked-wallet balances used for token-gated access.
We may also disclose information to professional advisers, service providers operating under appropriate obligations, law enforcement, regulators, or other parties when required by law, necessary to protect rights and safety, or connected with a merger, financing, reorganization, or sale of the business.
5. Legal Bases
Where data-protection law requires a legal basis, we rely on:
- Contract: processing needed to provide the Service you request.
- Legitimate interests: securing, maintaining, debugging, and improving the Service; preventing abuse; and enforcing our Terms, balanced against your rights.
- Legal obligation: processing required by law or valid legal process.
- Consent: where we specifically ask for it and law permits or requires it. You may withdraw consent prospectively.
6. Retention and Deletion
Authenticated web chats remain in our PostgreSQL database until you delete an individual chat or clear your chat history. Those actions remove the chat and its stored messages from the active database. Limited copies may remain temporarily in backups or disaster-recovery systems until they are overwritten.
Credit, entitlement, security, consent, and transaction records may be retained as long as reasonably necessary for fraud prevention, dispute resolution, legal compliance, and reliable accounting. If an account is deleted, the free-trial ledger removes its raw Privy account identifier. We retain keyed, pseudonymous claimant, browser-install, and network-risk fingerprints, plus a keyed erased-identity suppression record. These records remain linkable when we hold the secret and are retained for the life of the service to enforce one-time trial eligibility, investigate abuse, and prevent stale sessions from recreating an erased account. They are not anonymous records. Short-lived Redis data expires automatically according to the feature’s configured time-to-live.
Deleting a chat, deleting chat history, or editing away a message schedules its uploaded objects for deletion. Uploaded objects that are never attached to a message are also scheduled to expire. A durable cleanup process retries temporary storage failures; deletion may not be visible immediately while an upload token or provider cache remains valid. We retain other information only as long as reasonably necessary for the purposes described here, then delete or de-identify it unless law requires longer retention.
7. International Processing
We and our providers may process information in the United States and other countries whose laws differ from those where you live. Where required, we rely on legally recognized transfer mechanisms or other safeguards for international transfers.
8. Security
We use measures designed to protect information, including encrypted transport, wallet-based authentication through Privy, HTTP-only session cookies, origin and request validation, access controls, database constraints, rate limits, bounded inputs, and private-by-default telemetry. No system is completely secure. You are responsible for securing your wallet, device, and recovery methods.
9. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information; object to or restrict certain processing; withdraw consent; or appeal a denied request. You may also have the right to complain to your local data protection authority.
We do not sell personal information or share it for cross-context behavioral advertising. To make a privacy request, contact support@noxint.ai. We may need to verify that you control the relevant wallet before acting on a request.
10. Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us so we can review and delete it as appropriate.
11. Changes to This Policy
We may update this Policy as the Service or law changes. We will post the revised version and update the date above. If a change is material, we will provide additional notice when reasonably practicable.
12. Contact
Questions or requests about privacy may be sent to support@noxint.ai.