Legal

Privacy Policy

Effective 13 September 2026 · Apex AI Labs ("Mizan", "we") · support@joinmizan.app

This policy explains what information Mizan collects, why, where it goes, and what you can do about it. It covers the Mizan mobile app and the website joinmizan.app. We have written it to match what the software actually does today; when the software changes in a way that matters to you, this policy changes with it and the date above moves.

1. The short version

2. What we never hold

3. What we collect, and why

Everything in this table is either necessary to provide the app (the legal basis where one is required is performance of our contract with you or our legitimate interest in running a safe service) or clearly optional and off until you turn it on.

InformationWhere it comes fromWhy we have it
Sign-in identity — an identifier from Apple or Google, and the internal ID our sign-in provider (Privy) issues for it. We do not receive your Apple or Google password.You, when you sign in.To know which wallet is yours and to keep anyone else out of it.
Wallet address — the public address of your Solana wallet.Your device, when the wallet is created.To show your holdings and history, to build swaps and sends you ask for, and to route the service fee correctly.
Profile — an optional handle, an optional avatar, and your visibility setting (hidden by default).You, if you choose.So people you allow can find and follow you. See section 6.
Country — a two-letter country code, derived from your IP address when you use the app.Derived on our server from your connection, using a geolocation database (MaxMind).Mizan is only available in some regions. We must know where a request comes from to apply that rule, and we keep the country on your account so the rule is applied consistently.
IP address.Your connection.To derive the country above, and to limit how many requests one address can make in a short window (abuse protection). Rate-limit counters are deleted within a day. Like every website, our hosting providers keep standard server logs for a limited time.
Device attestation — a key identifier that Apple's App Attest issues for your installation.Your device, via Apple.To confirm requests come from a genuine, unmodified copy of the app. It identifies an installation, not a person, and it is not used for advertising or tracking.
On-chain activity — the holdings, transactions and swaps of your wallet address.The Solana blockchain, read through an indexing provider (Helius).To show your balances and history quickly and to keep them accurate. This is public data; see section 4.
Send-address check — the address you enter when sending.You, when you send.Before a send, our server checks the destination against public sanctions lists (the U.S. OFAC list). The check runs and returns; it is not used to build a profile of you.
Push token — the device token used to deliver notifications.Your device, only after you allow notifications.To tell you when a transaction confirms. Turn notifications off in your phone's settings and the token stops being used.
Crash reports — what went wrong in the app and the state of the app when it did.The app, via Sentry.To fix bugs. Personal details are switched off, wallet addresses and identifiers are scrubbed before reports leave the device, and performance tracing is off. See section 8.
Early-access email — the address you give on this website or on the app's "not available in your region yet" screen.You.To send you one message when Mizan is available. Nothing else. Stored in a table nobody can read from the internet.
Support messages — what you write to support@joinmizan.app.You.To answer you.

We do not collect your contacts, your location beyond the country above, your photos, or anything from other apps. We do not use advertising identifiers and we do not have an advertising SDK in the app.

4. Public blockchain data

Solana is a public ledger. Every transaction your wallet makes — what you sent, received or swapped, when, and with which address — is recorded on the blockchain, visible to anyone, and cannot be edited or deleted by us or by anyone else. Mizan reads this data to show it to you; it does not create the exposure and cannot remove it. If you would rather a particular activity not be linked to an address people know is yours, use a different wallet for it.

5. Buying crypto with money (MoonPay)

If you buy crypto with a card, bank account or Apple Pay inside Mizan, the purchase is made with MoonPay, a separate company, in a screen MoonPay controls. MoonPay will ask for the identity information the law requires of it and will process your payment. MoonPay is the controller of that data and its privacy policy governs it.

What Mizan receives is limited to what is needed to show you that a purchase has completed and landed in your wallet — the wallet address (which is yours already) and the status of the order. We do not receive identity documents, card numbers, bank details or the personal information you gave MoonPay, and we do not use, share or sell any of it. This is both a contractual condition of working with MoonPay and a design decision on our side.

6. Profiles and the activity feed

Mizan has an optional social layer. By default your profile is hidden: no handle, no followers, and nothing about your wallet is shown to other users. If you choose a handle, other people can find and follow you, and you choose what they see: nothing, percentages only, or amounts. Tightening a setting applies immediately to what others can see; loosening it does not reveal activity from before you loosened it, because it was never recorded for the feed. You can remove your handle at any time.

7. Selling personal information — and your opt-out

Today, we do not sell or share your personal information in the sense those words carry under U.S. state privacy laws such as the California Consumer Privacy Act, and we do not disclose it to third parties for their own marketing.

We may use and share aggregated, de-identified statistics — for example, "which screened assets are swapped most" or how many people use a feature in a month. These cannot reasonably be linked back to you, we commit not to attempt to re-identify them, and they contain nothing from MoonPay (section 5) under any circumstances.

If we ever decide to sell or share personal information at the individual level, we will, in this order: update this policy to say exactly what and to whom; add an opt-out switch inside the app; and give you notice before the first such sale. Nothing from the fiat purchase flow will ever be included, whatever the setting.

You can record an opt-out now. There is no switch in the app yet because there is nothing to switch off. If you want your preference on file so it is honoured automatically should our practices change, email support@joinmizan.app with the subject "Do not sell or share my personal information" from the address on your account, or include your handle or wallet address. We will confirm within 15 business days and apply it without asking you to justify it.

8. Analytics and crash reports

Crash reporting is the only telemetry in the app today, through Sentry. It is configured so that personal details are not sent, wallet addresses and account identifiers are removed from reports before they leave your device, and performance traces are disabled. It is off entirely in development builds.

Product analytics — which screens are used, how often, by how many people — are not switched on in the app at the time of this policy. When we add them, we will do so in a way that keeps individual-level and aggregate data separate, tie the individual side to the same opt-out described in section 7, and update this policy and the date above before the change ships.

9. Who processes data for us

We use a small number of providers to run Mizan. Each receives only what its job requires and is bound by terms that prohibit using the data for its own purposes.

ProviderWhat they doWhat they see
PrivySign-in and the embedded self-custodial wallet on your device.Your Apple/Google sign-in identity, the public wallet address, and one piece of the split key, which cannot sign on its own. The full key is assembled only on your device; Mizan never receives any piece of it.
SupabaseOur database and server functions.The account and activity data in section 3.
HeliusReads the Solana blockchain and tells us when your wallet's activity changes.Your public wallet address and its public on-chain activity.
JupiterFinds the best route for a swap across Solana's markets.The swap you ask for and your public wallet address, so the swap can be built for you to sign.
MoonPayFiat purchases (section 5).Everything needed for a purchase; governed by MoonPay's own policy.
MaxMindA geolocation database that runs on our server.Nothing is sent to MaxMind; the lookup happens on our side.
SentryCrash reports (section 8).Crash details with identifiers removed.
Apple and GoogleSign-in, app distribution, push notifications, device attestation.As described in their own policies for those services.

We may also disclose information where the law requires it, to protect the rights and safety of users or the public, or as part of a merger, acquisition or sale of the business — in which case this policy continues to apply to the information transferred, and you will be told.

10. How long we keep things

11. Your controls and rights

We will ask for enough to confirm the request comes from the account holder — normally an email from the address on the account — and nothing more.

12. Security

Your full key exists only on your device. Every request to our servers is authenticated and checked against the account it claims to be from; the database enforces row-level ownership so one account cannot read another's rows; secrets live only on the server; and every transaction is simulated before you are asked to sign it, so an unexpected drain is refused rather than signed. No system is perfectly secure, and no one at Mizan will ever ask you for your keys, recovery information or password. If you believe something has gone wrong with your account, write to support@joinmizan.app immediately.

13. Children

Mizan is for adults. You must be at least 18 to use it, and we do not knowingly collect information from anyone younger. If you believe a child has created an account, tell us and we will delete it.

14. Where data is stored

Our servers and providers are located in the United States. If you use Mizan from elsewhere, your information is transferred to and processed there. Where the law requires it, we rely on standard contractual clauses or an equivalent safeguard with our providers for that transfer.

15. Changes to this policy

When we change this policy in a way that matters, we will update the date at the top, note what changed, and tell you in the app before the change takes effect. Continued use after that date means the new version applies. Earlier versions are available on request.

16. Contact

Apex AI Labs · support@joinmizan.app · joinmizan.app