Otomate

Privacy Policy

Last updated: August 21, 2026

1. Overview

Otomate ("we", "us", "our") operates app.otomate.trade, a non-custodial perpetual trading automation platform on Ink Protocol. This policy explains what data we collect, how we use it, and your rights.

2. Data We Collect

  • Wallet addresses — Your public blockchain address used for authentication and trading.
  • Email address — If you choose to sign in via email or Google (processed by Privy, our authentication provider).
  • Usage analytics — Pseudonymous interaction data collected via PostHog to improve the product (page views, feature usage, transaction funnel status). Wallet addresses are hashed before being sent to analytics.
  • Trading preferences — Settings you configure (strategies, risk parameters) stored in our database.
  • Connected assistant data — OAuth client details, approved scopes, grant status, and revocation state when you connect ChatGPT, Codex, Claude, Cursor, or another MCP client.
  • Assistant activity — Security audit and usage metadata including tool name, requested scopes, outcome, latency, redacted arguments, prepared actions, confirmation status, and execution result. We do not intentionally store raw OAuth tokens, private keys, seed phrases, or wallet signatures in these audit records.

3. Connected Assistants and MCP

When you connect an assistant through the Otomate MCP, you choose the OAuth permissions it receives. Depending on those scopes, the assistant can read market, portfolio, position, performance, policy, monitoring, and action-center data; create an expiring prepared action; or request confirmation of an action.

An action that may move funds or change a position requires the execute:tradesscope, an existing prepared action, and your explicit confirmation in the connected assistant. Otomate then applies policy, risk, cap, simulation, executor, expiry, audit, and revocation checks. You may disconnect Otomate using the connected assistant's controls where supported or contact Otomate support; a revoked grant is rejected by Otomate.

Data returned in response to your request is sent to the connected assistant host, such as OpenAI, under your direction. That provider processes the data under its own terms and privacy policy.

4. Non-Custodial Model

Otomate is non-custodial: we do not take ownership of your assets or receive your private keys or seed phrases. Your assets remain in your wallet or supported trading subaccount. If you enable delegated or embedded-wallet execution, Otomate may submit a scoped instruction through the authorized signer or provider after the required consent and policy checks. Embedded wallet key material is managed by Privy using secure infrastructure and is not exposed to Otomate personnel.

5. How We Use and Share Data

We use the data above to authenticate you, provide requested reads and actions, enforce permissions and safety controls, prevent abuse, investigate failures, support users, measure reliability, and improve Otomate. We share only what is necessary with processors and execution providers that support those purposes.

  • Privy (privy.io) — Authentication and embedded wallet management.
  • PostHog — Product analytics (pseudonymous usage data, with hashed wallet identifiers).
  • Nado Protocol — On-chain trade execution on Ink.
  • Vercel — Application hosting and CDN.
  • Connected assistant providers — OpenAI or another MCP host receives the tool inputs and outputs needed to fulfill the requests you initiate.

6. Cookies & Local Storage

We use browser local storage to save your UI preferences (theme, trading settings) and session tokens. PostHog may set analytics cookies. No advertising cookies are used.

7. Push Notifications

You may opt in to push notifications for trade alerts. This requires explicit consent via the notification bell icon. You can disable notifications at any time in your browser settings.

8. Data Retention, Revocation & Deletion

Account, trading, assistant grant, prepared-action, and audit data is retained while needed to provide the service, protect users, meet legal obligations, resolve disputes, and enforce our agreements. You may revoke an assistant connection at any time and request deletion of eligible account data by contacting us. Legal, security, fraud-prevention, and immutable on-chain records may be retained where deletion is not permitted or technically possible.

9. Contact

For privacy inquiries, reach us on Telegram or Discord.