What this protocol is for
ProveX exists so a fiat payment can be proven without publishing a bank statement. ProveXAgent exists so agents can drive that proof flow without holding your money or your identity file. This Privacy Policy explains what the Interface can see — and what the proving system is designed not to see.
We do not operate a KYC vault. ProveX identity is an attestation and a reputation score, not a passport scan. Zero-knowledge proofs are meant to show that a payment happened, not who your bank is, to the public chain.
Information we process
On your device
- Local demo state (agents, simulated settlements, chat) in browser storage so the Interface can resume. This stays on your machine unless you export it.
- Instructions you type into the console, sanitized of markup, used to plan a settlement. Do not paste secrets, seed phrases, or full card numbers.
On our servers (when enabled)
- Optional model narration: a truncated, sanitized prompt may be sent to an inference API to describe a plan. Proof bytes, keys, and account secrets are not part of that payload.
- Technical logs: IP address, user-agent, and timestamps for abuse, rate limits, and availability. We do not use these to build an advertising profile.
On PulseChain (when you transact)
Signed transactions, escrow parameters, proof public signals (amount binding, chain id, nullifier, custody flag), fee burns, and attestations are public by nature of the ledger. Privacy is in the witness, not in pretending the chain is invisible.
What we do not collect
- Seed phrases, private keys, or wallet passwords.
- Government ID images, selfies, or utility bills as a condition of using the Interface.
- Full off-chain bank account statements. Those belong in the proving client, not in our database.
- Payment-card PAN/CVV. Fiat is P2P between counterparties, not through our merchant account.
How we use information
To operate the Interface, enforce the security kernel (rate limits, sanitization, circuit breaker), narrate plans, debug failures, and comply with law we are actually subject to. We do not sell personal information. We do not use console contents to train a public marketing model as a hidden term of use.
Retention and your controls
Local demo data can be cleared with the Interface reset and by clearing site storage in your browser. Server logs are kept only as long as needed for security and operations. On-chain data cannot be erased by us; that is a property of PulseChain, not a policy choice we can reverse.
International users
PulseChain and this Interface may be reached from many countries. Do not use them where your law forbids. Where GDPR or similar regimes apply to us as a controller of Interface logs, you may request access or deletion of those logs; we cannot delete your published transactions from PulseChain.
Changes
We will update this page when our processing changes. The date in the header is the source of truth. Related: Terms and Risk Disclosure.
