Legal
Privacy Policy
This policy explains what information Mizan collects, why, where it goes, and what you can do about it. It covers the Mizan mobile app and the website joinmizan.app. We have written it to match what the software actually does today; when the software changes in a way that matters to you, this policy changes with it and the date above moves.
1. The short version
- Mizan is self-custodial. Your keys are created on your device and controlled by you. We never have them, so we never have your funds. That is also why there is less of your data for us to keep than a typical finance app would.
- We collect what the app needs to work: a sign-in identity, your public wallet address, your country (to know where the app may operate), the public on-chain activity of your wallet so we can show it to you, and crash reports with identifying details removed.
- We never see identity documents or payment details. If you buy crypto with money from a card or bank, that happens with MoonPay, under MoonPay's own policy. We do not receive, store, use or sell any of it.
- We do not sell your personal information. If that ever changes, we will update this policy first, put an opt-out switch in the app before any sale begins, and tell you. Until then, you can record an opt-out today by email (section 7).
- The blockchain is public. Anything your wallet does on Solana is visible to anyone, forever, and that is true of every Solana wallet — not something Mizan adds or can remove.
2. What we never hold
- Your private keys or recovery material. Your wallet is an embedded wallet provided by Privy. Its key is split into pieces so that the full key exists only on your device, at the moment you use it; the piece Privy stores cannot sign anything on its own. Mizan never receives any piece of it. Mizan's servers cannot sign a transaction for you, cannot move your assets, and cannot recover your wallet.
- Your money. There are no Mizan balances, accounts, pooled wallets or IOUs. The only funds that reach us are the service fee on a swap, which lands in our own wallet on-chain.
- Identity documents, bank or card details. Any fiat purchase is made with MoonPay, which performs its own identity checks. Their partner terms prohibit us from receiving or using that data for anything beyond confirming a purchase, and we have built nothing that could.
3. What we collect, and why
Everything in this table is either necessary to provide the app (the legal basis where one is required is performance of our contract with you or our legitimate interest in running a safe service) or clearly optional and off until you turn it on.
| Information | Where it comes from | Why we have it |
|---|---|---|
| Sign-in identity — an identifier from Apple or Google, and the internal ID our sign-in provider (Privy) issues for it. We do not receive your Apple or Google password. | You, when you sign in. | To know which wallet is yours and to keep anyone else out of it. |
| Wallet address — the public address of your Solana wallet. | Your device, when the wallet is created. | To show your holdings and history, to build swaps and sends you ask for, and to route the service fee correctly. |
| Profile — an optional handle, an optional avatar, and your visibility setting (hidden by default). | You, if you choose. | So people you allow can find and follow you. See section 6. |
| Country — a two-letter country code, derived from your IP address when you use the app. | Derived on our server from your connection, using a geolocation database (MaxMind). | Mizan is only available in some regions. We must know where a request comes from to apply that rule, and we keep the country on your account so the rule is applied consistently. |
| IP address. | Your connection. | To derive the country above, and to limit how many requests one address can make in a short window (abuse protection). Rate-limit counters are deleted within a day. Like every website, our hosting providers keep standard server logs for a limited time. |
| Device attestation — a key identifier that Apple's App Attest issues for your installation. | Your device, via Apple. | To confirm requests come from a genuine, unmodified copy of the app. It identifies an installation, not a person, and it is not used for advertising or tracking. |
| On-chain activity — the holdings, transactions and swaps of your wallet address. | The Solana blockchain, read through an indexing provider (Helius). | To show your balances and history quickly and to keep them accurate. This is public data; see section 4. |
| Send-address check — the address you enter when sending. | You, when you send. | Before a send, our server checks the destination against public sanctions lists (the U.S. OFAC list). The check runs and returns; it is not used to build a profile of you. |
| Push token — the device token used to deliver notifications. | Your device, only after you allow notifications. | To tell you when a transaction confirms. Turn notifications off in your phone's settings and the token stops being used. |
| Crash reports — what went wrong in the app and the state of the app when it did. | The app, via Sentry. | To fix bugs. Personal details are switched off, wallet addresses and identifiers are scrubbed before reports leave the device, and performance tracing is off. See section 8. |
| Early-access email — the address you give on this website or on the app's "not available in your region yet" screen. | You. | To send you one message when Mizan is available. Nothing else. Stored in a table nobody can read from the internet. |
| Support messages — what you write to support@joinmizan.app. | You. | To answer you. |
We do not collect your contacts, your location beyond the country above, your photos, or anything from other apps. We do not use advertising identifiers and we do not have an advertising SDK in the app.
4. Public blockchain data
Solana is a public ledger. Every transaction your wallet makes — what you sent, received or swapped, when, and with which address — is recorded on the blockchain, visible to anyone, and cannot be edited or deleted by us or by anyone else. Mizan reads this data to show it to you; it does not create the exposure and cannot remove it. If you would rather a particular activity not be linked to an address people know is yours, use a different wallet for it.
5. Buying crypto with money (MoonPay)
If you buy crypto with a card, bank account or Apple Pay inside Mizan, the purchase is made with MoonPay, a separate company, in a screen MoonPay controls. MoonPay will ask for the identity information the law requires of it and will process your payment. MoonPay is the controller of that data and its privacy policy governs it.
What Mizan receives is limited to what is needed to show you that a purchase has completed and landed in your wallet — the wallet address (which is yours already) and the status of the order. We do not receive identity documents, card numbers, bank details or the personal information you gave MoonPay, and we do not use, share or sell any of it. This is both a contractual condition of working with MoonPay and a design decision on our side.
6. Profiles and the activity feed
Mizan has an optional social layer. By default your profile is hidden: no handle, no followers, and nothing about your wallet is shown to other users. If you choose a handle, other people can find and follow you, and you choose what they see: nothing, percentages only, or amounts. Tightening a setting applies immediately to what others can see; loosening it does not reveal activity from before you loosened it, because it was never recorded for the feed. You can remove your handle at any time.
7. Selling personal information — and your opt-out
Today, we do not sell or share your personal information in the sense those words carry under U.S. state privacy laws such as the California Consumer Privacy Act, and we do not disclose it to third parties for their own marketing.
We may use and share aggregated, de-identified statistics — for example, "which screened assets are swapped most" or how many people use a feature in a month. These cannot reasonably be linked back to you, we commit not to attempt to re-identify them, and they contain nothing from MoonPay (section 5) under any circumstances.
If we ever decide to sell or share personal information at the individual level, we will, in this order: update this policy to say exactly what and to whom; add an opt-out switch inside the app; and give you notice before the first such sale. Nothing from the fiat purchase flow will ever be included, whatever the setting.
You can record an opt-out now. There is no switch in the app yet because there is nothing to switch off. If you want your preference on file so it is honoured automatically should our practices change, email support@joinmizan.app with the subject "Do not sell or share my personal information" from the address on your account, or include your handle or wallet address. We will confirm within 15 business days and apply it without asking you to justify it.
8. Analytics and crash reports
Crash reporting is the only telemetry in the app today, through Sentry. It is configured so that personal details are not sent, wallet addresses and account identifiers are removed from reports before they leave your device, and performance traces are disabled. It is off entirely in development builds.
Product analytics — which screens are used, how often, by how many people — are not switched on in the app at the time of this policy. When we add them, we will do so in a way that keeps individual-level and aggregate data separate, tie the individual side to the same opt-out described in section 7, and update this policy and the date above before the change ships.
9. Who processes data for us
We use a small number of providers to run Mizan. Each receives only what its job requires and is bound by terms that prohibit using the data for its own purposes.
| Provider | What they do | What they see |
|---|---|---|
| Privy | Sign-in and the embedded self-custodial wallet on your device. | Your Apple/Google sign-in identity, the public wallet address, and one piece of the split key, which cannot sign on its own. The full key is assembled only on your device; Mizan never receives any piece of it. |
| Supabase | Our database and server functions. | The account and activity data in section 3. |
| Helius | Reads the Solana blockchain and tells us when your wallet's activity changes. | Your public wallet address and its public on-chain activity. |
| Jupiter | Finds the best route for a swap across Solana's markets. | The swap you ask for and your public wallet address, so the swap can be built for you to sign. |
| MoonPay | Fiat purchases (section 5). | Everything needed for a purchase; governed by MoonPay's own policy. |
| MaxMind | A geolocation database that runs on our server. | Nothing is sent to MaxMind; the lookup happens on our side. |
| Sentry | Crash reports (section 8). | Crash details with identifiers removed. |
| Apple and Google | Sign-in, app distribution, push notifications, device attestation. | As described in their own policies for those services. |
We may also disclose information where the law requires it, to protect the rights and safety of users or the public, or as part of a merger, acquisition or sale of the business — in which case this policy continues to apply to the information transferred, and you will be told.
10. How long we keep things
- Account, wallet address, profile, country: for as long as you have an account, then deleted within 30 days of a deletion request (section 11).
- Indexed on-chain activity: kept with the account so your history loads quickly; deleted with the account. The underlying blockchain record remains public regardless.
- IP-based rate-limit counters: deleted within one day.
- Device attestation keys: while that installation is signed in; a fresh sign-in creates a new one, and all of them are deleted with your account.
- Push tokens: until you disable notifications, sign out, or delete your account.
- Crash reports: 90 days at Sentry.
- Early-access emails: until Mizan is available in your region and we have sent the one message, or until you ask us to remove it.
- Support correspondence: up to two years, so we can follow up on earlier issues.
- Records we must keep by law (for example, tax records of the fees we received): for the period the law sets.
11. Your controls and rights
- Leave with your funds. From the first screen in Settings, you can send everything in your wallet to any other Solana wallet you control, with no fee from us. This works even when swaps are paused.
- Delete your account. Email support@joinmizan.app from the address on your account, or include your handle or wallet address. We delete the account data in section 3 within 30 days and confirm to you. Deleting your Mizan account does not delete your wallet — the keys are yours, on your device — and it cannot delete anything on the public blockchain. Move your assets out first if you want them somewhere else.
- Profile visibility. Change or remove your handle and visibility in Profile at any time.
- Notifications. Turn them off in your phone's settings.
- Access, correction, portability, objection. Email us and we will provide a copy of the information we have about you, correct it, or explain why we are keeping it. If you are in the EU, UK, California or another place whose law gives you specific rights over your data, you have them and we will honour them; we will not treat you differently for exercising them. You can also complain to your local data-protection authority.
- Opt out of any future sale or sharing. Section 7.
We will ask for enough to confirm the request comes from the account holder — normally an email from the address on the account — and nothing more.
12. Security
Your full key exists only on your device. Every request to our servers is authenticated and checked against the account it claims to be from; the database enforces row-level ownership so one account cannot read another's rows; secrets live only on the server; and every transaction is simulated before you are asked to sign it, so an unexpected drain is refused rather than signed. No system is perfectly secure, and no one at Mizan will ever ask you for your keys, recovery information or password. If you believe something has gone wrong with your account, write to support@joinmizan.app immediately.
13. Children
Mizan is for adults. You must be at least 18 to use it, and we do not knowingly collect information from anyone younger. If you believe a child has created an account, tell us and we will delete it.
14. Where data is stored
Our servers and providers are located in the United States. If you use Mizan from elsewhere, your information is transferred to and processed there. Where the law requires it, we rely on standard contractual clauses or an equivalent safeguard with our providers for that transfer.
15. Changes to this policy
When we change this policy in a way that matters, we will update the date at the top, note what changed, and tell you in the app before the change takes effect. Continued use after that date means the new version applies. Earlier versions are available on request.
16. Contact
Apex AI Labs · support@joinmizan.app · joinmizan.app