1. Scope and controller
This policy applies to the ElyxS web application, public documentation, support forms, legal acceptance processes, and related API services.
The ElyxS project team operates the public beta unless a specific deployment identifies a different operator. Privacy questions can be sent to support@elyxs.com.
2. Non-custodial and public blockchain context
ElyxS does not create a password account for normal public use and does not custody wallet assets. You interact with smart contracts through your own wallet.
Public blockchain data is different from normal website data.
Ticket purchases, draw activity, settlement events, prize claims, refund claims, wallet addresses, transaction hashes, and related on-chain records may be public, permanent, and independently copied by third parties.
ElyxS cannot delete or change public Supra blockchain records.
3. Data we collect
Depending on how you use ElyxS, we may process:
- wallet address and public wallet-session data;
- wallet-auth challenge status and public session identifiers;
- profile data that you choose to provide, such as username, display name, avatar, bio, timezone, language, and social links;
- participation history derived from public blockchain data and ElyxS read models;
- support request data, including name, email, request category, optional wallet address, message, and attachments;
- legal acceptance records, including accepted document set, wallet address, timestamp, IP address, user agent, acceptance method, and document-set hash;
- cookie and browser-storage preferences;
- limited analytics and diagnostics if you consent to them;
- operational logs needed for security, abuse prevention, service reliability, and debugging.
Do not send seed phrases, private keys, government identity documents, financial account credentials, or other secrets through support forms or public channels.
4. Why we process data
We process data to:
- provide wallet-based access to the platform;
- display balances, tickets, claims, refunds, and profile information;
- enforce legal acceptance for protected actions;
- operate support and respond to user requests;
- prevent fraud, abuse, spam, sanctions evasion, and security incidents;
- debug product issues and maintain service reliability;
- comply with legal obligations when they apply;
- understand aggregate product usage when analytics consent is granted.
For users in jurisdictions with data-protection laws such as the GDPR, our legal bases may include contract performance, legitimate interests, consent, and legal obligation.
They may also include protection against abuse or security threats, depending on the processing activity.
6. Analytics, diagnostics, and service providers
ElyxS may use the following services, depending on deployment configuration:
- Plausible CE on analytics.elyxs.com for self-hosted product analytics based on consent;
- PostHog for product analytics based on consent if configured;
- the self-hosted ElyxS error pipeline for consent-gated technical diagnostics;
- Resend for support email delivery;
- ElyxS backend APIs and public Supra network services for blockchain reads and application state.
ElyxS does not use advertising networks, marketing pixels, social tracking cookies, or third-party ad retargeting in the public beta.
Where analytics or diagnostics are enabled, ElyxS limits event payloads and redacts wallet addresses, transaction hashes, signatures, public keys, and other sensitive identifiers where practical.
Consent-gated browser error diagnostics are sent to the ElyxS API, sanitized again by the backend, and stored in the local ElyxS Loki service for no more than seven days. This diagnostic path does not send reports to a third-party error-tracking provider.
PostHog automatic capture is disabled. Session replay is disabled unless a separate privacy review explicitly approves it.
7. Retention
We keep data only as long as reasonably needed for the purposes described in this policy, unless a longer period is required for security, dispute handling, compliance, or backup integrity.
Typical retention approach:
- public blockchain records: controlled by the blockchain, not by ElyxS;
- profile data: until you delete it or request deletion, subject to backups and abuse records;
- support requests: for the time needed to resolve the request and maintain support history;
- legal acceptance records: for as long as needed to prove acceptance of the applicable legal documents;
- cookie consent records: until you reset or change your choices, or until the consent version changes;
- security and operational logs: for a limited operational period unless needed for investigation;
- analytics data: according to the configured analytics tool and consent state.
8. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, export, object to, restrict, or withdraw consent for certain personal data.
California residents may have additional privacy rights under California privacy law. EU/EEA and UK users may have additional rights under applicable data-protection law.
You can:
- disconnect your wallet from the frontend;
- change non-essential cookie choices from the cookie preferences link;
- edit or delete profile data where the product allows it;
- contact support@elyxs.com to request access, correction, deletion, or review of personal data we control.
We cannot delete or modify public blockchain records, third-party copies of public chain data, or records that we must preserve for security, legal acceptance, fraud prevention, or legal obligations.
9. Children
ElyxS is not intended for children. You must be at least 18 years old and have reached the legal age required in your jurisdiction to use the platform. Do not use ElyxS if you are under the required age.
If you believe a child has provided personal data through ElyxS, contact support@elyxs.com.
10. International processing
ElyxS services, infrastructure, maintainers, and service providers may process data in different countries.
Where required, we use reasonable safeguards for cross-border processing and rely on service providers that publish appropriate privacy and security commitments.
11. Security
ElyxS uses technical and organizational measures intended to protect data we control. No web service, blockchain integration, wallet action, or network is completely secure.
You are responsible for securing your wallet, device, browser, private keys, seed phrase, and transaction approvals.
12. Changes
We may update this policy when the product, service providers, legal requirements, or data practices change. If required legal documents change, ElyxS may require you to accept the updated documents before protected actions.
13. Contact
Privacy questions and requests can be sent to support@elyxs.com.