Privacy Policy
config.json and have qualified counsel review these terms for your actual entity, product and jurisdictions before commercial launch. This template is not legal advice.1. Who controls the data
For a hosted deployment, the data controller or responsible operator is the configured operator. Contact the privacy team at the configured privacy address. Self-hosted users control their own deployment and logs.
2. Data the default project handles
The open-source application does not require user registration. A hosted deployment may process network request data such as IP address, user agent, request time and error information through the hosting or reverse-proxy layer. The application may also store public blockchain addresses, token mint addresses, analysis results, opportunity decisions and paper-trading records.
3. Secrets and wallet data
The standard project is not designed to collect seed phrases or wallet private keys. Do not submit those secrets through forms, prompts, configuration or support requests. Public wallet addresses can still be personal data in some jurisdictions when linked to an identifiable person.
4. Purposes
Data may be processed to operate and secure the Service, provide requested dashboard functions, maintain state, troubleshoot incidents, enforce limits, prevent abuse and improve reliability.
5. Legal bases
Depending on jurisdiction and deployment, processing may rely on performance of a contract, legitimate interests in operating and securing the Service, consent where required, or compliance with law. The operator must tailor this section to its actual activities before launch.
6. Third-party links
Links to X, pump.fun and other third-party services take you outside the Veliox website. Those services may collect information under their own terms and privacy policies. Veliox does not control their data practices.
7. Third parties
If enabled, the Service may send limited token and market context to an AI provider and may query Solana or market-data providers. Operators should list the actual vendors, regions and data-processing terms used in production.
8. Retention
The default application stores state and JSONL event logs until the operator deletes them. A commercial deployment should define retention periods based on operational need, legal obligations and privacy risk.
9. International transfers
Hosting, AI and data providers may process information in other countries. The operator must use appropriate transfer mechanisms where applicable.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to certain processing, request portability, or complain to a supervisory authority. Contact the privacy team to exercise applicable rights.
11. Security
The project uses a no-private-key server design, fail-closed model handling and security headers. No system is perfectly secure. See the Security page for deployment recommendations and vulnerability reporting.
12. Children
The Service is not directed to children. The operator should set and enforce an age threshold that complies with the laws applicable to its deployment.
13. Changes
Material changes will be reflected by updating this Policy and its effective date. Where law requires notice or consent, the operator should provide it.
