ALLIN1 (also referred to as the All-in-One Terminal) is an accountable crypto intelligence workspace. We combine public-source, social, market, and blockchain data with information you choose to provide so you can investigate, compare Signals, follow Tracking, participate in Spaces, and configure bounded Agents. This policy applies to our public website, application, APIs, and communications that link to it.
01Information we collect
Depending on how you use ALLIN1, we may collect the following categories:
- Account and authentication data. Email address, account identifier, display name, avatar, plan and beta-access status, and security events. If you sign in or link an X account, Supabase and X may provide a provider identifier, handle, profile information, and—only when the provider and your settings permit it—an email address. We do not receive your X password.
- Information you provide. Account settings, Spaces, Channels, messages, Calls, saved Tracking rules, Investigation queries, support requests, Agent configuration, and other content you submit.
- Wallet and execution information. Public wallet addresses, chain and transaction metadata, simulation results, Agent mandates, and audit records. ALLIN1 does not need your private key to provide wallet intelligence, and does not take custody of user funds.
- Public and third-party intelligence. Public X profiles and posts, public blockchain data, market data, news, protocol data, and other information obtained from public sources or licensed providers. Public does not mean that every use is unrestricted; we process this information subject to applicable law and provider terms.
- Device and usage information. IP address (stored as a one-way hash for analytics and abuse prevention), browser family, approximate country when supplied by our hosting layer, device and network information, pages visited, referring site, timestamps, feature interactions, and error or performance information.
- Communications. Information in emails, feedback, support conversations, surveys, or other messages you send to us.
02How we use information
- Provide, secure, maintain, and improve the Terminal, Spaces, Signals, Calls, Investigations, Wallets, Tracking, and Agents.
- Authenticate accounts, link or unlink identities at your request, keep sessions secure, prevent abuse, and enforce access controls.
- Process and display the data needed for the feature you use, including public social and on-chain intelligence, market context, and user-created Space content.
- Measure accountable outcomes and preserve audit trails. Historical Calls, execution records, and other accountability records may remain after an item is deleted when needed to keep the record accurate or meet legal obligations.
- Understand product usage, diagnose failures, improve relevance and reliability, and communicate about service changes, security, or support.
- Comply with law, respond to lawful requests, protect the rights and safety of users and the service, and establish or defend legal claims.
We do not sell personal information. We do not use the data obtained from an X login to post, like, follow, send direct messages, or take other actions on X unless a separate feature clearly asks for that permission and you expressly authorize it.
03Cookies and local storage
ALLIN1 uses a small set of cookies and browser storage technologies. They support the service rather than an advertising profile.
| Category | Purpose | Typical lifetime |
|---|---|---|
| Essential session cookies | Keep you signed in across the marketing site and app, refresh a session, and enforce beta access. | Up to 30 days |
| OAuth security cookies | Bind an X or Google authorization response to the account and action that started it, including identity linking. | Short-lived; normally minutes |
| Preference storage | Remember interface choices such as display or relevance-protection preferences. | Until cleared by you |
| Anonymous measurement storage | Generate a random session identifier and visitor identifier for aggregated product analytics. | Session or longer-lived browser storage |
Our analytics tracker removes access tokens, refresh tokens, authorization codes, and similar secrets from recorded URLs. You can clear cookies and local storage in your browser, but disabling essential cookies may prevent sign-in, identity linking, or protected features from working.
04When we share information
We share information only as needed to operate the service, deliver a feature you request, or meet a legal and safety obligation. Recipients may include:
- Infrastructure and authentication providers. Supabase provides authentication and database infrastructure. Hosting, storage, email, monitoring, and security providers may process information on our instructions.
- Data and research providers. Social, market, news, blockchain, and protocol-data providers supply information displayed or analyzed in ALLIN1. Their own terms and privacy notices may also apply.
- AI and research processors. When you use Argus or an AI-powered Investigation, the relevant prompt and limited context may be sent to a model or research provider to produce the requested result. Do not submit passwords, private keys, recovery phrases, or other secrets.
- Other users and Space participants. Content you intentionally publish to a public or shared Space, including your display name and Calls, is visible according to that Space’s settings. Private wallet authority, session tokens, and private keys are not shared with Space creators.
- Professional advisers, authorities, or transaction parties. Where reasonably necessary for legal compliance, safety, fraud prevention, a merger or asset transfer, or to enforce our agreements.
05Retention and security
We keep information for as long as needed to provide the service, maintain security and accountable history, resolve disputes, comply with legal obligations, and enforce our agreements. Retention varies by category: active account and security records may be kept while an account is active and for a reasonable period afterward; aggregated analytics and public-source history may be retained longer; temporary OAuth state is designed to expire quickly.
We use access controls, encrypted transport, scoped service credentials, token-hiding practices, and other reasonable administrative and technical safeguards. No internet service is completely secure. You are responsible for protecting your email account, browser, wallet keys, recovery phrases, and any access you grant to an Agent.
06Your choices and rights
You can review or update account information in Account settings, unlink a connected identity where the feature permits it, clear browser storage, and stop using the service. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent where processing relies on consent.
To make a privacy request, contact the service operator through the support channel made available in the app and include enough information for us to verify the request. We may retain information that we must keep for security, fraud prevention, legal compliance, or the integrity of historical accountability records.
07Children and international use
ALLIN1 is not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided information, contact us so we can investigate and delete it where required.
ALLIN1 and its providers may process information in countries other than where you live. By using the service, you understand that information may be transferred to locations with different data-protection rules, subject to the safeguards required by applicable law.
08Changes and contact
We may update this policy as the service, providers, or legal requirements change. We will post the new effective date here and, where appropriate, provide additional notice. Continued use after an update means the revised policy applies to future use.
For privacy questions, use the support contact presented in the ALLIN1 application. Please do not send private keys, seed phrases, passwords, or OAuth secrets in a support request.
Important: This policy is a plain-language product policy and should be reviewed and adapted by the service operator and qualified privacy counsel before a broad commercial launch.