Legal
Privacy Policy
Effective July 16, 2026
Retina is a portfolio information service. We use personal data to provide and secure the service, retrieve information about public wallet addresses, support users, and improve reliability. We do not sell personal data or use it for behavioral advertising.
1. Who we are
Retina ("Retina," "we," "us") operates useretina.xyz and is the controller of personal data described in this policy. Privacy questions and requests can be sent to support@useretina.xyz.
2. Data we process
- Account and identity data: email address; identifiers and basic profile details supplied by Google or X; wallet addresses used for sign-in; and account, entitlement, and session records.
- Portfolio data: public blockchain addresses, user-provided labels and settings, positions, balances, snapshots, schedules, manual entries, and optional provider credentials.
- Technical and security data: IP address, browser and device information, essential cookie and local-storage data, request timing, security events, diagnostics, and service logs.
- Communications: contact details, support messages, and related page and browser information submitted with a support request.
Some portfolio information may be derived from public blockchains and public or commercial data sources rather than supplied directly by you.
3. Why we use data
We use data to authenticate users; create and maintain accounts; provide portfolio tracking, cloud backups, snapshots, schedules, and support; prevent abuse; protect the service; diagnose faults; enforce our terms; and comply with law.
Where applicable, our legal bases are performance of our contract with you, our legitimate interests in operating and securing Retina, compliance with legal obligations, and consent where the law requires it. You may withdraw consent at any time without affecting earlier processing.
4. Sign-in, wallets, and AI
Google and X sign-in provide Retina with an account identifier and available basic profile or email information. We use that information only for authentication and account linking. Although X presents standard read-only permissions during sign-in, Retina does not access or store your social account content or activity. Retina does not retain provider access or refresh tokens for these sign-in methods.
Wallet sign-in asks for a standardized login-message signature. It does not request a transaction, token approval, delegation, or transfer, and a login wallet is not automatically added as a tracked portfolio wallet. Retina does not retain the raw wallet signature after identity verification.
If you add a public wallet address for tracking, Retina and its data providers may query and process its public onchain activity. Blockchain records are public and cannot be deleted by Retina.
If you choose the cloud AI feature, Retina may send your question and limited conversation or portfolio-planning context to Google Gemini to plan a response. AI output is informational and may be inaccurate. Retina does not use AI to make legal or similarly significant decisions about users.
5. Sharing
We share data only as needed with service providers that support hosting and security, authentication, email, AI, support, and blockchain or market-data retrieval. These may include Cloudflare, Supabase, Google, X, Resend, and the data providers used by the features you select. A provider may receive a public wallet address or other request data necessary to return the requested information.
We may also disclose data when required by law, to protect users or the service, or as part of a merger, financing, acquisition, or transfer of the service. We do not sell personal data.
6. Storage, security, and transfers
Retina is local-first, but account and enabled cloud features store data on systems operated for Retina. Sensitive cloud records and portfolio objects are encrypted in storage; they are not end-to-end encrypted unless a feature expressly says so. No method of storage or transmission is completely secure.
Our providers may process data in the European Economic Area, the United States, and other countries. Where required, transfers rely on adequacy decisions or contractual and organizational safeguards available from the relevant provider.
7. Cookies and local storage
Retina uses essential cookies and browser storage for sign-in, security, preferences, local portfolio data, and synchronization state. We do not currently use behavioral-advertising cookies. Google, X, embedded content, and other third parties may use their own technologies under their policies when you interact with them.
8. Retention and deletion
We keep account and portfolio data while the account is active and for as long as reasonably needed to provide the service, resolve disputes, prevent abuse, and meet legal obligations. Short-lived authentication, session, import, and security records expire or are removed under operational retention rules.
You can request account deletion through Retina or by contacting us. Deletion removes account-linked cloud data from active systems after a short safety and processing period. Limited records may remain temporarily in security logs, deletion queues, or backups where necessary. Data held independently on public blockchains or by third parties is governed by those systems.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to complain to your local data-protection authority. You may also disconnect an external provider through that provider. Contact us to exercise a right; we may need to verify your identity.
10. Age, changes, and contact
Retina is not intended for anyone under 18. We may update this policy as the service changes. Material updates will be posted here with a revised effective date and, where appropriate, additional notice.
Contact: support@useretina.xyz.