Privacy Policy
Last updated: September 1, 2026
This policy separates account data, market evidence, AI-assisted synthesis, payments and the UQX self-custody wallet boundary so each type of information is described according to what the product actually does.
1. Overview
This Privacy Policy explains how Zynost handles information when you use the Zynost website, Zynost application and related services that reference this policy. It also describes relevant boundaries for the UQX wallet experience and Zynost Pay integrations where those products interact with a Zynost account or checkout flow.
Different products have different trust boundaries. Market intelligence, merchant payments and self-custody wallet functionality are not treated as one undifferentiated data system.
2. Account and Authentication Data
Account information. We may process information such as email address, profile information and authentication-related records needed to create and secure an account.
Sign-in providers. If you choose a supported third-party sign-in method, we receive only the account information that provider makes available to the application for authentication.
Security events. We may record account-security events such as session activity, device/session identifiers, 2FA state, password-reset or recovery events, and notification-delivery information needed to protect and operate the account.
3. Research, Portfolio and Journal Data
If you use watchlists, portfolio tracking, alerts, journals or performance features, we process the information you choose to store so the relevant feature can work. This may include assets, quantities, entry prices, trade notes, alert thresholds and analysis history.
Portfolio and journal data is used to provide product functionality such as allocation, unrealized P/L, concentration, performance review and user-requested coaching. We do not describe this data as market data and do not need to send personal identity to public exchange APIs to retrieve market prices.
4. Market and Provider Data
Zynost obtains market, derivatives, on-chain, security, macro and related public or provider-driven data from external services. These requests are generally about assets and markets, not about the identity of the signed-in user.
Provider coverage, retention and request metadata are subject to the relevant provider's own systems and terms. Zynost may cache or normalize market evidence so multiple product features can use a consistent view of the same source data.
5. AI-Assisted Synthesis and Explanations
The Full Scan core is source-driven and deterministic; optional Decision Brief, explanation and certain user-specific coaching flows can use an AI-assisted synthesis layer after the underlying evidence has already been computed.
When such a synthesis feature is requested, the system may send a bounded analysis context needed to generate the requested explanation. The design intent is to send the evidence required for the task rather than unrelated account information. Users should still avoid placing secrets, private keys or recovery phrases into free-text prompts or notes.
6. Subscription and Payment Data
For supported crypto subscription payments, we may process invoice identifiers, selected asset/network, amount, payment status, transaction hash, wallet addresses involved in the checkout flow, subscription activation state and reconciliation records.
Blockchain transaction information is public by nature once broadcast. Zynost does not need card or bank credentials for an on-chain crypto checkout, but payment and account records may still be linked internally so the correct subscription can be activated and reconciled.
Zynost may use Zynost Pay as payment infrastructure through a merchant-facing checkout interface. Payment infrastructure remains a distinct product boundary from market intelligence.
7. UQX Self-Custody Wallet Boundary
UQX includes a self-custody Web3 wallet experience. In the current native Android implementation, wallet generation occurs on-device and local wallet material is protected using device-side storage mechanisms including Android Keystore-backed encryption.
What Zynost can see. Public wallet addresses and public on-chain state can be displayed, linked to application features or used to read token/presale positions where the product requires it.
What is not backend-held. The wallet private key and recovery phrase are device-owned credentials and are not intended to be stored by the Zynost backend as custodial secrets.
Important self-custody reality. A standard recovery phrase can restore control of the wallet elsewhere. If the phrase or private key is exposed, possession of the device is not required for an attacker to attempt wallet control. Users are responsible for protecting recovery credentials.
8. UQX Account and App Data
The UQX application can also contain ordinary account functionality separate from the self-custody wallet, such as authentication, profile settings, 2FA, notification preferences and active-session information.
Legacy backend contracts or historical account data may remain during product migration for compatibility. Their presence does not turn an internal application record into an on-chain wallet transaction, and it should not be confused with self-custody wallet ownership.
9. Technical, Device and Usage Data
We may collect standard technical information needed to operate and secure the Service, such as IP address, browser or app version, device type, error logs, request metadata and feature-usage events.
Push-notification tokens may be processed when notifications are enabled. Device biometric checks are performed by the operating system; the application should receive only the result of the device-authentication flow, not a copy of biometric characteristics.
12. Sale of Personal Data
Zynost does not position the product as an advertising-data business and does not sell user conversation content, wallet recovery phrases or private keys to advertisers. If our data practices materially change, this policy should be updated before the new practice is relied upon.
13. Data Retention
Retention depends on the type of record and why it exists. Active-account data may be retained while the account is in use. Security, payment, fraud-prevention, tax, accounting or legal records may need to be retained longer where required or reasonably necessary.
Deletion of an account does not delete information that exists independently on a public blockchain, and it cannot erase copies retained by third-party systems outside Zynost's control.
14. Your Privacy Choices and Rights
Depending on your location and applicable law, you may have rights to request access, correction, deletion, portability, restriction or objection regarding certain personal information.
You can also manage many product preferences directly in the application. For a privacy request, use the contact page or email privacy@zynost.com.
15. Security
We use technical and organizational measures intended to protect account and application data, but no internet-connected system can guarantee absolute security.
Users should enable available account protections, keep devices updated, use unique passwords, protect recovery codes and never disclose wallet recovery phrases or private keys to anyone claiming to be support.
16. Children's Privacy
The Service is not directed to children under 18. If we learn that personal information was collected from a child contrary to applicable requirements, we will take appropriate steps to address it.
17. Changes to This Policy
We may update this Privacy Policy as products, providers or legal requirements change. Material updates should be reflected by revising the date on this page and, where appropriate, by providing additional notice.
18. Contact
Privacy questions can be sent through the Zynost contact page or to privacy@zynost.com.