Privacy Policy

Last updated 1 October 2026

envolvr is built so that the people who run it cannot read what you send to AI models. This policy explains what we can see, what we keep, what is public by design, and who else processes data when you use envolvr: the API, the account app, the SDK and CLI, our smart contracts and this website (the "Service"). "envolvr", "we" and "us" mean the operators of the Service. It should be read with our Terms of Service.

1. Your prompts and responses

Your connection to envolvr is encrypted with TLS that terminates inside envolvr's attested Intel TDX virtual machine; envolvr verify-gateway checks that it does. From there, the gateway forwards each request to the model provider's attested enclave on confidential GPUs, over a channel bound to that enclave's attested key. Requests are decrypted and answered only inside these trusted execution environments. envolvr's operators cannot read your prompts or responses, and we do not use them to train models.

Attestation proves which code runs, and that code is published so you can check it. Each receipt contains cryptographic commitments (hashes) of your request and response, never their text. A commitment lets you prove what was sent and answered; it does not reveal the content.

2. What we keep

To run accounts and billing, the control plane keeps the following, inside the same attested virtual machine:

We do not ask for your name, email address, phone number or any identity document. envolvr's gateway and control plane do not record IP addresses, and their logs, which are public, carry no prompts, keys, wallets or per-caller data. If you email us, we keep the correspondence.

3. What is public by design

Some records live on public blockchains, where anyone can read them and no one, including us, can delete them: USDG deposits, refunds, and the Merkle roots that anchor receipts on Robinhood Chain. Content stays hidden, but metadata does not: a paying wallet, and the timing and volume of its activity, can be linked to envolvr usage. Use a wallet you are comfortable having associated with the Service.

4. How we use data

We do not sell personal data, show advertising or build profiles. Where European data protection law applies, we rely on performance of our contract with you, our legal obligations (such as sanctions compliance), and our legitimate interest in running a secure service.

5. Who else processes data

We may also disclose data if the law requires it, to protect the Service or its users, or as part of a reorganization or transfer of the Service. Little of it identifies you beyond your wallet address, and we cannot disclose prompts or responses that we cannot read.

6. Cookies and browser storage

This website sets no cookies and runs no analytics or tracking. The account app keeps your sign-in session token in your browser's session storage, which is cleared when you close the tab. Your wallet extension or WalletConnect may store data under their own policies.

7. Retention

Account, usage, deposit, refund and screening records are kept for as long as the ledger runs, including after you close your account, because they are needed for accounting, refunds, dispute handling and sanctions compliance. Sign-in sessions expire after 12 hours. Encrypted ledger backups are deleted after 30 days, except the newest copies. On-chain records cannot be deleted.

8. Your rights

The account app shows the records we hold for your wallet: balance, keys, usage and deposits. You can revoke keys and close your account there at any time. Depending on where you live, you may have the right to access, correct, delete or restrict the processing of your personal data, to object to it, to receive it in a portable format, and to complain to your data protection authority. To make a request, write to privacy@envolvr.xyz and prove control of the wallet by signing a message we send you. We delete off-chain records we are not required to keep, but we cannot change public blockchain data.

9. Security

The gateway and control plane run in an attested virtual machine whose code anyone can check. API keys and session tokens are stored only as hashes. Ledger backups are encrypted with keys bound to that virtual machine. No system is perfectly secure, and we cannot guarantee that data will never be accessed without authorization.

10. Children

The Service is not intended for anyone under 18, and we do not knowingly collect data about children.

11. International processing

Our providers operate in several countries, including the United States, so data may be processed outside the country where you live.

12. Changes

We will post any update to this policy on this page and change the date at the top. Material changes are announced on this site before they take effect.

13. Contact

Privacy questions and requests: privacy@envolvr.xyz.