PRIVACY POLICY

Home

Last updated: March 26, 2026

1. Introduction

Bundie ("we", "us", "our") operates the platform at https://app.synthos.fun. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our platform. We are committed to safeguarding your privacy and handling your data transparently.

The data controller responsible for your personal data is Bundie (operated by Lucathree Labs Ltd., registered in the British Virgin Islands). For data protection inquiries, you may contact our Data Protection Officer at privacy@synthos.fun.

2. Information We Collect

2.1 Information You Provide Directly

  • Wallet addresses when you connect an external wallet to the platform.
  • Email address if you choose to sign in via email through Privy.
  • Social account identifiers (Twitter/X handle, Google account information) if you use social login methods.
  • Profile information (username, avatar, bio) if you choose to customize your profile.
  • Social feed content including posts, comments, and interactions you create on the platform.
  • Referral information including referral codes you use or share.

2.2 Information Collected Automatically

  • Device information including browser type, operating system, screen resolution, and device identifiers.
  • Usage data including pages visited, features used, interaction patterns, and session duration.
  • IP address collected for security, analytics, and geo-restriction compliance purposes.
  • Transaction-related metadata such as vault interactions, deposit and withdrawal timestamps, and strategy selections (on-chain data is publicly available).

2.3 Information from Third Parties

  • Privy: Authentication tokens, linked account data, and embedded wallet information.
  • Blockchain networks: Publicly available on-chain transaction data associated with your wallet addresses.
  • Analytics providers: Aggregated usage data from PostHog and Vercel Analytics.

3. How We Use Your Information

We process your information for the following purposes:

  • Service delivery: Connecting your wallet, executing vault deposits and withdrawals, processing transactions, and managing your portfolio.
  • AI-powered personalization: Generating personalized yield strategies, portfolio recommendations, and risk assessments.
  • Social features: Enabling the social feed, user profiles, leaderboard rankings, and community interactions.
  • Points and referrals: Tracking earned points, referral relationships, and leaderboard positions.
  • Platform improvement: Analyzing usage patterns to improve features, performance, and user experience.
  • Security and fraud prevention: Detecting and preventing unauthorized access, abuse, sybil attacks, and fraudulent activity.
  • Communications: Sending service-related notifications if you have provided an email address.
  • Legal compliance: Fulfilling legal obligations and responding to lawful requests.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), our legal bases for processing your personal data include:

  • Contract performance: Processing necessary to provide the Bundie platform and services.
  • Legitimate interests: Platform security, fraud prevention, analytics, and service improvement.
  • Consent: Where you have given explicit consent for specific processing activities (e.g., marketing communications).
  • Legal obligation: Where processing is necessary to comply with applicable laws.

5. Data Storage and Retention

  • User data is stored in Supabase (PostgreSQL) with encryption at rest and in transit.
  • On-chain transaction data is permanently and publicly recorded on the respective blockchain networks and is outside our control.
  • Analytics data is processed and stored by PostHog and Vercel Analytics in accordance with their respective data handling policies.
  • We retain your personal data for as long as your account is active or as necessary to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements.
  • Upon account deletion or request for erasure, we will delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate business purposes.

6. Data Sharing and Disclosure

We do not sell your personal information. We may share your data with the following categories of recipients:

  • Service providers: Privy (authentication), ZeroDev (smart wallet infrastructure), LayerZero (cross-chain messaging), LI.FI (swap routing and bridging), Supabase (database hosting), PostHog (product analytics), and Vercel (hosting and edge analytics). Each provider processes data in accordance with their own privacy policies and data processing agreements.
  • Blockchain networks: When you execute transactions, your wallet address and transaction data are broadcast to public blockchain networks (Ethereum Virtual Machine (EVM) compatible networks) and are permanently, publicly, and immutably recorded.
  • Legal requirements: We may disclose your information if required by law, regulation, court order, subpoena, or other lawful governmental request.
  • Safety and protection: To protect the rights, safety, or property of Bundie, our users, or the public, including to detect and prevent fraud.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction.

7. Cookies and Tracking Technologies

We use the following:

  • Essential cookies: Required for authentication sessions, wallet connections, and core platform functionality.
  • Analytics cookies: PostHog and Vercel Analytics use cookies or local storage to collect anonymized usage data for platform improvement.
  • Local storage: Used for caching user preferences, IndexedDB caching of application data, and session management.

Non-essential cookies (such as analytics cookies) are only placed after you provide consent through our cookie consent mechanism. You may withdraw your consent at any time through the cookie settings on the platform, or by managing cookies through your browser settings. Disabling essential cookies may affect your ability to use the platform.

Do Not Track: Some browsers offer a "Do Not Track" (DNT) signal. There is currently no industry standard for how platforms should respond to DNT signals. At this time, Bundie does not respond to DNT signals. We will update this policy if a standard is established.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete personal data.
  • Right to erasure: Request deletion of your personal data, subject to legal and operational requirements.
  • Right to restrict processing: Request that we limit how we process your data in certain circumstances.
  • Right to data portability: Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to object: Object to processing based on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at privacy@synthos.fun. We will respond to your request within 30 days.

Right to lodge a complaint: If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement. For users in the British Virgin Islands, you may contact the relevant data protection authority.

9. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • The right to know what personal information is collected, used, shared, or sold.
  • The right to delete personal information held by us.
  • The right to opt-out of the sale of personal information.
  • The right to non-discrimination for exercising your privacy rights.

We do not sell personal information. To make a CCPA request, contact us at info@synthos.fun.

10. Automated Decision-Making and AI

Bundie uses artificial intelligence and algorithmic systems to generate personalized yield strategies, portfolio recommendations, and risk assessments. These automated processes analyze your portfolio data, market conditions, and on-chain activity to provide tailored suggestions.

Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. While our AI provides recommendations, all deposit, withdrawal, and investment actions require your explicit confirmation and manual execution. No funds are moved without your direct authorization.

You may request human review of any AI-generated recommendation, express your point of view, or contest an automated decision by contacting us at privacy@synthos.fun.

11. Blockchain Data Disclaimer

Data recorded on blockchain networks is immutable and publicly accessible by design. This includes wallet addresses, transaction amounts, timestamps, and smart contract interactions. We cannot modify, delete, or restrict access to on-chain data. Your use of the platform necessarily involves the public recording of transaction data on blockchain networks.

12. Data Security

We implement reasonable technical and organizational security measures to protect your personal data, including:

  • Encryption of data at rest and in transit (TLS/SSL).
  • Access controls and authentication requirements.
  • Regular security assessments and monitoring.
  • API key authentication for backend services.

However, no method of electronic storage or transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.

13. Children's Privacy

Bundie is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal data from a child under 18, we will take prompt steps to delete such information. If you believe a child has provided us with personal data, please contact us at info@synthos.fun.

14. International Data Transfers

Bundie is accessible globally. Your personal data may be transferred to and processed in countries other than your own, including jurisdictions where our service providers operate. These countries may have data protection laws that differ from your jurisdiction. By using the platform, you consent to the transfer of your data to these jurisdictions. Where required, we implement appropriate safeguards such as standard contractual clauses for international data transfers.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will indicate the date of the last update at the top of this page. Continued use of the platform after any changes constitutes your acceptance of the revised Privacy Policy.

16. Contact

For privacy-related questions, data access requests, or concerns, please contact us at info@synthos.fun.