1. Overview
This Privacy Policy (“Policy”) describes how Minara (“Minara,” “we,” “us,” or “our”) collects, uses, stores, and shares personal information when you access or use our crypto AI platform, including the web application, mobile applications, Autopilot trading features, perpetual contract services, the Minara desktop and AI agent applications, optional third-party account connectors (including Google Workspace connectors), and all associated tools and interfaces (collectively, the “Services”). By using the Services, you acknowledge that you have read and understood this Policy and consent to the collection and use of your information as described herein.
This Policy should be read alongside our Terms of Use, which governs your use of the Services and is incorporated by reference.
If you connect a Google Account to Minara, please see Section 3 (Google User Data), which describes specifically how we handle information obtained through Google APIs. Section 3 governs Google user data and takes precedence over any conflicting provision elsewhere in this Policy.
2. Information We Collect
We collect information in three primary ways: information you provide directly, information generated automatically through your use of the Services, and information obtained from third-party systems.
2.1 Information You Provide
- Account information – email address, hashed password, social media accounts you linked, and subscription tier.
- Identity verification data – where required by applicable law or our compliance procedures, government-issued identification documents and related verification materials.
- Support interactions – messages, attachments, and communications you send to our support team.
2.2 Financial and Trading Data
- Deposit and withdrawal records – transaction amounts, timestamps, originating and destination wallet addresses, and network confirmation data.
- Account balances – current and historical balances held in your Account Abstraction (“AA”) wallet (signer infrastructure provided by Particle Network).
- Perpetual Wallet data – balances, positions, order history, funding rate payments, liquidation events, and margin information associated with each perpetual contract Perpetual Wallet linked to your account. You may operate multiple Perpetual Wallets simultaneously under a single Minara account; data from all such wallets is collected.
- Transaction history – a complete record of all on-chain and off-chain transactions executed through the Services, including those initiated by the Autopilot feature on your behalf.
- Wallet export events – timestamps, wallet identifiers, and metadata of any wallet private-key export actions you initiate through the in-app export flow. The exported key material itself is delivered directly to you.
2.3 Autopilot and Strategy Data
- Autopilot authorizations – records of your consent to activate, modify, pause, or revoke Autopilot trading on a specific Perpetual Wallet, including the strategy selected (official Minara strategy or, when available, user-generated strategies), authorization timestamps, and any parameter configurations you set.
- Strategy execution logs – a full audit trail of every trade, order, modification, or cancellation executed by the Autopilot system on your behalf, including the strategy version in effect at the time of execution.
- Strategy performance data – realized and unrealized profit and loss, win rates, drawdown metrics, and other performance statistics generated from Autopilot activity.
2.4 Usage and Technical Data
- Device and environment data – device type, operating system, browser type and version, IP address, and time zone.
- In-app behavioral data – pages visited, features accessed, click events, session duration, and error logs.
- AI interaction logs – prompts you submit to the Minara AI agent, conversation transcripts, and AI-generated outputs. These logs may include trading instructions you communicate to the AI.
2.5 Cookies and Tracking Technologies
We use cookies and similar technologies for session management, fraud prevention, security monitoring, and analytics. You may control non-essential cookies through your browser settings; however, certain cookies are required for the Services to function and cannot be disabled.
2.6 Google Account Data (Optional Connectors)
If you choose to connect a Google Account, we access content from your Gmail, Google Calendar, Google Drive, and Google Forms only to the extent permitted by the authorization scopes you grant, and only to carry out the specific actions you request. Connecting a Google Account is entirely optional and is not required to use the Services. See Section 3 for full details, including the scopes we request, our use of AI inference providers, retention and deletion practices, and our Limited Use commitments.
2.7 Minors
The Services are intended solely for users who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. We do not currently perform identity verification or age verification at the point of registration. If we become aware that personal information has been collected from a user under 18, we will take reasonable steps to delete that information and terminate the associated account as promptly as practicable. If you believe a minor has registered for the Services, please notify us at team@minara.ai.
3. Google User Data (Google Workspace APIs)
Minara offers optional connectors that allow you to link a Google Account so that the Minara AI agent can act on your Gmail, Google Calendar, Google Drive, and Google Forms content at your explicit request. This section describes how Minara collects, uses, transfers, retains, and deletes information obtained through Google APIs (“Google user data”).
This section governs all Google user data and takes precedence over any conflicting provision elsewhere in this Policy. Where another section of this Policy describes a broader use of data — for example, model improvement using anonymized data, or the sharing of aggregated statistics — that description does not apply to Google user data.
3.1 Authorization Scopes We Request
Minara requests the narrowest scopes that support the features you enable. Scopes are requested per connector: if you enable only the Calendar connector, only the Calendar scope is requested.
| Scope | What it permits and why we need it |
|---|---|
| .../auth/drive.file | Read and edit only the specific Drive files you select through the Google file picker, and files Minara creates at your request. Minara cannot list, search, or access the rest of your Drive. |
| .../auth/gmail.readonly | Search and read the messages you ask about, so that Minara can summarize, locate, or answer questions about your mail. This scope does not permit any modification of your mailbox. |
| .../auth/gmail.compose | Create and update drafts in your Gmail account. Drafts remain visible and editable in Gmail before you send them. Minara does not label, archive, move, mark as read, or delete your messages. |
| .../auth/gmail.send | Send a message only when you explicitly ask Minara to send it and have approved the recipient and content. |
| .../auth/calendar.events | View, create, update, and cancel calendar events at your request. Changes are written directly to your Google Calendar. |
| .../auth/forms.body.readonly | Read the title, questions, sections, and structure of a Google Form you ask about. Minara does not create or modify forms. |
3.2 How We Use Google User Data
Google user data is accessed only after you explicitly connect a Google Account, and is used solely to provide and improve the specific user-facing features you request — for example, summarizing a message you asked about, drafting a reply you requested, creating a calendar event, or reading a document or form you selected. Minara never performs a write operation on your Google Account without an explicit request from you for that specific action.
We do not use Google user data for advertising, marketing, profiling, credit assessment, or resale.
3.3 Transfer to AI Inference Providers
To generate responses, Minara transmits the minimum Google user data necessary to complete your requested operation to third-party AI models, authorized and connected by Minara or the user. For any workflow involving Google user data, routing is restricted by an administrator-controlled allowlist. No Google user data is routed to any model or provider outside this allowlist.
Our configuration for these workloads enforces the following controls:
- Input and output logging disabled;
- The model provider’s own use of inputs and outputs disabled;
- Zero Data Retention enforced;
- Provider data collection denied;
- Routing restricted to endpoints that do not retain prompts or responses;
- Routing restricted to endpoints that do not use prompts or responses for model training;
- Fallback to non-compliant providers disabled — if no compliant endpoint is available, the request fails rather than being routed elsewhere.
3.4 No Use for AI or Machine Learning Model Training
Neither Minara nor any of our AI inference providers uses Google user data to develop, train, fine-tune, evaluate, or improve any generalized or foundational artificial intelligence or machine learning model. This prohibition applies equally to raw Google user data and to any aggregated, anonymized, or derived form of it. Google user data is not subjected to human review for model development purposes.
3.5 Sharing of Google User Data
We do not sell Google user data, and we do not share it with any third party other than the AI inference providers described in Section 3.3, except where disclosure is required by law or is necessary to investigate a security incident affecting your account. In particular, Google user data is never shared with Autopilot strategy providers and is never included in the aggregated or anonymized statistics described in Section 5.
3.6 Retention, Deletion, and Your Controls
Google user data is processed only for as long as needed to fulfil your request and is not retained for unrelated purposes. OAuth access and refresh tokens are stored encrypted and are used only to make API calls on your behalf.
You may withdraw access at any time:
- Disconnect the connector in Minara (Settings → Connectors). This revokes the token and deletes the stored credential together with any cached Google content associated with it.
- Revoke Minara’s access directly in your Google Account at myaccount.google.com/permissions.
- Request deletion of any remaining Google-derived data by writing to team@minara.ai.
3.7 Limited Use Commitment
Minara’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Legal Basis / Justification |
|---|---|
| Operate and deliver the Services, including executing trades and displaying portfolio information | Performance of contract |
| Provision and management of AA wallets and perpetual contract Perpetual Wallets | Performance of contract |
| Executing Autopilot trades on your behalf pursuant to your authorization | Performance of contract; explicit consent |
| Monitoring Autopilot strategy performance and generating audit logs | Performance of contract; legitimate interest |
| Improving AI models, trading algorithms, and platform performance (using anonymized data only). Google user data is never used for this purpose in any form, raw or anonymized — see Section 3.4. | Legitimate interest |
| Sending transactional communications (e.g., deposit confirmations, liquidation alerts, Autopilot activity notifications) | Performance of contract |
| Enforcing our Terms of Use and investigating abuse, fraud, or market manipulation | Legitimate interest; legal obligation |
| Complying with applicable laws, regulations, and lawful authority requests | Legal obligation |
| Sending optional marketing communications (with opt-out available) | Consent |
We do not use your personal financial data or trading history to train AI models without first anonymizing or aggregating such data so that it cannot be attributed to you individually.
This paragraph does not apply to Google user data. Google user data is excluded from all model development entirely, including in anonymized or aggregated form, as described in Section 3.4.
5. Sharing of Information
We do not sell your personal information. We may share your information in the following circumstances:
Infrastructure and service providers. We share data with hosting, payment processing, analytics, security, and wallet infrastructure vendors under strict data processing agreements (“DPAs”) that prohibit commercial exploitation of your data.
Perpetual DEX and blockchain infrastructure. To operate the perpetual contract features, we transmit necessary transaction data (including wallet addresses, order parameters, and margin instructions) through our infrastructure—including dedicated nodes we operate for execution performance—to the applicable Perpetual DEX protocol and its underlying blockchain network. Such nodes act solely as relay infrastructure and do not alter the terms or outcome of your transactions. Once broadcast to the network, this data is processed on a public, permissionless blockchain and is inherently visible on-chain. Minara does not control any Perpetual DEX protocol’s consensus rules, smart contracts, or validator set.
Autopilot strategy providers. When you activate an Autopilot strategy, anonymized performance data may be shared with the strategy’s creator for the purpose of performance attribution and improvement. Your personal identity and account details are not shared with strategy authors.
Legal and regulatory authorities. We may disclose your information in response to lawful requests from government authorities, courts, or regulators, or where we reasonably believe disclosure is necessary to protect the safety of any person, prevent fraud, or comply with applicable law. We will notify you of such requests unless legally prohibited from doing so.
Corporate transactions. In connection with a merger, acquisition, asset sale, or similar transaction, your information may be transferred to the acquiring entity, subject to equivalent privacy protections.
At your direction. We may share information with third parties when you explicitly instruct us to do so.
Aggregated or anonymized statistics. We may share aggregated, non-personally identifiable data with partners, researchers, or the public for analytical or promotional purposes. This never includes data obtained through Google APIs, in raw, aggregated, anonymized, or derived form.
6. Blockchain Data and Public Ledger Notice
You acknowledge that transactions executed through the Services, including those initiated by the Autopilot feature, are recorded on public blockchains. Blockchain records are immutable and publicly accessible. While Minara takes steps to protect your identity, the on-chain wallet addresses associated with your account and all transactions made from those addresses are permanently visible on the public ledger. Minara cannot delete or modify on-chain transaction records.
7. Security
We implement industry-standard security measures to protect your personal information, including Transport Layer Security (TLS) encryption for data in transit, hashed credential storage, role-based access controls, and regular security audits.
While we take reasonable precautions, no system is perfectly secure. You are responsible for maintaining the confidentiality of your account credentials and for promptly notifying us at team@minara.ai if you suspect unauthorized access to your account.
8. Data Retention
We retain personal data only for as long as necessary to:
- Deliver and improve the Services;
- Comply with applicable legal and regulatory requirements (including anti-money laundering record-keeping obligations, which may require retention for five years or longer); and
- Resolve disputes and enforce our rights.
When data is no longer required for these purposes, it is securely deleted or irreversibly anonymized. Note that on-chain transaction records cannot be deleted due to the immutable nature of public blockchains.
Retention of Google user data is governed separately by Section 3.6, which describes shorter, purpose-limited retention and the controls available to you for revoking access and deleting stored Google credentials and content.
9. Your Choices and Rights
Depending on your jurisdiction, you may have the right to:
- Access a copy of the personal information we hold about you;
- Correct inaccurate or incomplete account information;
- Delete your personal data and close your account (subject to legal retention obligations);
- Restrict or object to certain processing activities;
- Portability – receive your data in a structured, machine-readable format;
- Withdraw consent for optional processing activities (e.g., marketing communications, Autopilot activation) at any time without affecting the lawfulness of prior processing.
The following categories of data are available for access or export upon request:
- AI interaction logs
- Autopilot authorization records and strategy execution logs
- Wallet activity logs
- Account information
To exercise any of these rights, submit a request to team@minara.ai. We may ask you to verify your identity before processing your request. We will respond within the timeframe required by applicable law.
10. Updates to This Policy
We may revise this Policy from time to time to reflect changes in our Services, legal requirements, or data practices. Material changes will be communicated in-app or via email with reasonable advance notice before taking effect. The “Last updated” date at the top of this Policy will always reflect the most recent revision. Continued use of the Services after the effective date of any update constitutes your acceptance of the revised Policy.
11. Contact
If you have questions, concerns, or requests relating to this Privacy Policy, please contact us at:
Email: team@minara.ai