Legal
Privacy Policy
This Privacy Policy describes how KP Labs Inc., a Wyoming corporation ("KP Labs," "we," "us"), collects, uses, and shares information in connection with FROTH Terminal, including the web application at https://terminal.froth.meme/, related interfaces and APIs, and our associated marketing sites, social channels, and support activities (together, the "Services"). By using the Services you acknowledge the practices described here. Capitalized terms not defined here have the meanings in the FROTH Terminal Terms of Service.
1. A note on blockchains
Blockchain networks are public, permanent, and outside our control. When you sign and broadcast a transaction, your wallet address and transaction details are recorded on a public ledger visible to anyone, forever. We cannot edit, delete, or restrict information recorded on a blockchain, and rights described in this Policy (including deletion) do not apply to on-chain data. If you value unlinkability between your identity and your wallet activity, do not share information that links them.
2. Information we collect
2.1. Information you provide.
- Contact information, if you choose to provide it (e.g., email for support, updates, or waitlists).
- Account identifiers, if the Services offer accounts: username, display preferences, and any social login identifiers you link.
- Support communications and any information you include in them.
- Survey, promotion, or event participation information.
2.2. Wallet and blockchain information.
- Public wallet addresses you connect or generate through the Services.
- Public blockchain data associated with those addresses (balances, transaction history, token holdings), which we read from public networks and process through our own indexing and data infrastructure.
- Wallet creation, login, and authentication events processed by our embedded-wallet infrastructure provider, Privy, under its own privacy policy (including any email, phone number, or social login identifier you use to create or access an Embedded Wallet, which Privy processes as part of authentication). We do not collect or store your private keys.
2.3. Information collected automatically.
- Device and usage data: IP address, browser and device characteristics, operating system, language, referring URLs, pages viewed, features used, session timestamps, and interaction events.
- Approximate (country/region-level) location derived from IP address, which we use for the platform-wide and feature-level restrictions described in the Terms of Service.
- Cookies and similar technologies (see Section 8).
2.4. Information from third parties.
- Analytics providers (aggregate usage data) and, where used to supplement our own data infrastructure, third-party blockchain data sources (token metadata, market data).
- Wallet-screening and sanctions/compliance vendors (risk indicators associated with wallet addresses).
2.5. What we do not collect. We do not collect government ID, biometric data, or full payment card information, and we do not perform identity verification by default. If a specific feature or a compliance obligation requires identity information in the future, we will request it at that time and update this Policy.
3. How we use information
We use information to:
- Provide, operate, maintain, and improve the Services, including reading blockchain state for the addresses you use;
- Enforce geographic and eligibility restrictions and screen for sanctions and prohibited activity;
- Detect, investigate, and prevent fraud, manipulation, abuse, and security incidents;
- Respond to support requests and communicate with you about the Services, including administrative notices;
- Send marketing communications where permitted (you can opt out at any time);
- Analyze usage in aggregate to develop features and fix problems;
- Comply with law, respond to lawful requests, and establish, exercise, or defend legal claims; and
- Administer referral, points, or promotional programs, if offered.
Legal bases (EEA/UK-relevant users): performance of a contract (providing the Services you request); legitimate interests (security, abuse prevention, analytics, service improvement - balanced against your rights); legal obligation (sanctions compliance, lawful requests); and consent where required (e.g., non-essential cookies, marketing).
4. How we share information
We share information with:
- Service providers: hosting, analytics, embedded-wallet infrastructure (Privy), supplemental data sources, customer support tooling, and communications vendors, under contracts limiting their use of the information to providing services to us;
- Compliance vendors: wallet screening and sanctions compliance;
- Affiliates: KP Labs affiliates that help operate the Services, consistent with this Policy;
- Professional advisors: lawyers, auditors, accountants, insurers;
- Authorities: where required by law, subpoena, or court order, or where we believe disclosure is necessary to protect rights, safety, or the integrity of the Services, or to investigate fraud or violations of our Terms;
- Business transferees: in connection with a merger, acquisition, financing, reorganization, or sale of assets, including during negotiations; and
- At your direction: when you use features that inherently disclose information (e.g., public leaderboards displaying a username or wallet address).
We may share aggregated or de-identified information that cannot reasonably identify you for any purpose. We do not sell personal information for money, and we do not share personal information with third parties for their own direct marketing without your consent.
5. Your rights
Depending on where you live, you may have rights to: access the personal information we hold about you and receive a copy; correct inaccurate information; delete information; restrict or object to certain processing; withdraw consent where processing is based on consent; and data portability. To exercise rights, contact us at privacy@kplabs.xyz. We may need to verify your identity, and we may retain information where required for legal compliance, security, or dispute resolution. EEA/UK users may also lodge a complaint with their supervisory authority. On-chain data is outside the scope of these rights (Section 1).
6. US state privacy rights
If you are a resident of a US state with a comprehensive privacy law (including California, Virginia, Colorado, Connecticut, Texas, and others), you may have the rights to: know what personal information we collect and how we use and disclose it; access and obtain a copy of your personal information; correct inaccuracies; delete your personal information; opt out of "sale" or "sharing" of personal information and of targeted advertising; limit use of sensitive personal information; and not be discriminated against for exercising these rights. Submit requests to privacy@kplabs.xyz; authorized agents must provide proof of authorization; we will verify, respond within statutory timelines, explain any denial, and provide the appeal process required by your state. We recognize opt-out preference signals, including Global Privacy Control (GPC), as a valid opt-out where required by law.
7. International transfers
We are a US company and process information in the United States and other countries whose laws may differ from yours. Where required for transfers of EEA/UK personal data, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA).
8. Cookies and similar technologies
We use cookies, local storage, and similar technologies for: essential functions (session management, security, geographic enforcement, remembering wallet connections); analytics (understanding usage to improve the Services); and, if used, marketing. Where required by law, non-essential cookies are used only with your consent, managed through the in-product consent banner, and you can withdraw consent there or through browser settings. Disabling essential cookies may break the Services. We do not respond to legacy Do Not Track browser signals, but we do recognize Global Privacy Control (GPC) signals as described in Section 6.
9. Security
We use commercially reasonable technical and organizational measures appropriate to the nature of the information we process. No system is completely secure, and we cannot guarantee absolute security. You are responsible for securing your wallets, keys, devices, and credentials; we will never ask you for your private keys or seed phrase, and anyone who does is attempting to defraud you.
10. Retention
We retain personal information for as long as needed for the purposes described in this Policy, including operating the Services, complying with legal obligations (including sanctions-compliance recordkeeping), resolving disputes, and enforcing agreements, after which it is deleted or de-identified. Retention periods vary by data category; geolocation-enforcement logs and compliance-screening records are retained per our compliance retention schedule.
11. Children
The Services are not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we learn we have done so, we will delete it. Contact privacy@kplabs.xyz if you believe a minor has provided us information.
12. Third-party services
The Services link to and interoperate with third-party websites, protocols, wallets, and applications that we do not control, including the independent privacy practices of blockchain networks, wallet providers, and data providers. This Policy does not cover them; review their policies directly.
13. Changes
We may update this Policy from time to time. We will post the updated version with a revised date, and, for material changes, provide additional notice where required by law (such as in-product notice or email). Continued use after the effective date constitutes acceptance to the extent permitted by law; where consent is required for a new processing purpose, we will obtain it.
14. Contact
Privacy questions and rights requests: privacy@kplabs.xyz
KP Labs Inc., 1309 Coffeen Avenue STE 15908, Sheridan, WY 82801, Wyoming, USA