Privacy

Last updated 20 September 2026

The short version

VaultOS collects nothing about you. No accounts, no cookies, no analytics, no tracking pixels, no third-party scripts. There is no sign-up, so there is nothing to sign up with.

What is stored, and where

Three things are recorded, and all of them concern the agent rather than you:

  • Your policy — the limits you set. Numbers and settings, nothing identifying.
  • The audit trail — what was checked, what was decided, and which rule decided it.
  • Executed actions — amounts and timestamps, used by the daily limits.

By default these live in the server’s memory and disappear when it restarts. If a Supabase database is configured, they are written there instead, using a key that never leaves the server.

Cookies

None. Not for analytics, not for preferences, not for sessions. That is why there is no cookie banner — showing one where no cookies exist would be theatre rather than consent.

The blockchain

Transactions are submitted to Base Sepolia, a public test network. Anything sent to a public blockchain is public, permanent and outside anyone’s control — including ours. The wallet address and every transaction it makes can be read by anyone, forever.

Base Sepolia is a test network. The tokens have no monetary value.

Third parties

The server talks to three services, and only the server does:

  • Coinbase Developer Platform — holds the agent’s wallet keys and broadcasts transactions.
  • OpenServ (SERV) — receives the text of an opportunity when you ask for an assessment, and returns an opinion.
  • Supabase — stores the records above, if configured.

Your browser never contacts any of them, and no credential for any of them is ever sent to your browser.

Contact

This is a hackathon project. Questions belong with whoever is running the instance you are looking at.