This Privacy Policy explains how Fungus Inc. dba Liquidium ("Liquidium," "we," "us," or "our") collects, uses, discloses, and protects personal data in connection with the Liquidium Cross-Chain app at https://app.liquidium.fi (the "App").
This policy is intended to cover applicable privacy laws, including the EU/UK General Data Protection Regulation ("GDPR"), to the extent they apply.
1) Who We Are
- Controller: Fungus Inc. dba Liquidium (Delaware corporation)
- Product: Liquidium Cross-Chain web application
- Contact: info@liquidium.fi
If you have privacy questions or want to exercise your rights, contact us at info@liquidium.fi.
2) Scope
This Privacy Policy applies to personal data processed through the App, including account/profile features, wallet authentication, notifications, analytics, and support chat.
It does not apply to:
- Public blockchain data processed independently by blockchain networks
- Third-party wallets, exchanges, and services you choose to use outside the App
- Third-party websites linked from the App
3) Data We Collect
Depending on how you use the App, we process the following categories of data.
A. Wallet and account data
- Wallet addresses you connect (for supported chains such as BTC/ETH/SOL)
- ICP account identifier (`ic_id`) and related profile identifiers
- Cryptographic authentication records (for example, signed messages, nonce records, auth token metadata)
- Linked wallet addresses retrieved from protocol/account profile calls
B. Profile and communication data
- Profile name and avatar URL
- Email address, verification status, and email verification token metadata
- Telegram username/chat link data and verification token metadata
- Notification preferences (critical/general/marketing)
- Referral and invite data (invite/referral codes, invite relationships)
- Invite email logs (sender identifier and recipient email)
- "Heard about us" questionnaire responses
C. Usage, device, and technical data
- IP address and user-agent data processed in server request/tracing context
- Browser/session metadata needed for security, auth, and service operation
- Event and error telemetry captured through analytics tooling
D. Local browser storage and cookies
The App uses browser cookies and storage technologies, including:
- Auth cookie: `liquidium.auth-token` (HTTP-only session/authentication)
- App cookie: `ICPUserId` (used for account/profile state)
- Wallet/provider cookies used by connected wallet infrastructure
- `localStorage` key for theme preference
- `sessionStorage` entries for pending in-app flow state
E. Data from third parties and public sources
- Public blockchain data relevant to positions/transactions
- Data from third-party APIs used by App features (for example social/share verification and blockchain infrastructure APIs)
4) How We Use Personal Data
We use personal data to:
- Authenticate users and secure accounts
- Operate protocol-facing App features (supply, borrow, repay, withdraw, account linking)
- Maintain profiles, notification settings, and referral features
- Send verification and invitation communications
- Provide support chat functionality
- Monitor performance, errors, abuse, and service reliability
- Comply with legal obligations and enforce our Terms
5) Legal Bases Under GDPR
Where GDPR applies, we rely on one or more of the following legal bases:
- Contract necessity: to provide and operate the App features you request
- Legitimate interests: fraud prevention, security, product reliability, and service improvement
- Consent: where required for certain analytics/tracking or communications
- Legal obligation: compliance with applicable laws, regulations, and lawful requests
6) How We Share Data
We do not sell personal data.
We share data with service providers/processors only as needed to operate the App, including categories such as:
- Hosting and infrastructure
- Product analytics and error/event monitoring
- Wallet connection and wallet verification infrastructure
- Email delivery providers
- Support chat providers
- Blockchain RPC/API providers
- Messaging integrations (for example Telegram delivery and webhook processing)
- Social/share verification API providers used by App features
Data may also be disclosed:
- To comply with legal obligations or lawful requests
- To protect users, the App, and our rights
- In a merger, acquisition, financing, or asset transfer context
7) International Data Transfers
Because we use global service providers, personal data may be transferred to and processed in countries outside your jurisdiction, including outside the EEA/UK.
When required, we use appropriate safeguards (for example contractual safeguards) for cross-border transfers.
8) Data Retention
We retain personal data only as long as necessary for the purposes described in this policy, including legal, compliance, security, and dispute-resolution needs.
Examples from current App behavior include:
- Authentication nonce records are short-lived and designed to expire quickly
- Auth token cookies are time-limited
- Profile, notification, referral, and invite records are retained while needed for account features and operational records
- Logs/telemetry are retained according to operational and provider retention settings
When data is no longer needed, we delete or de-identify it where reasonably feasible.
9) Security
We use technical and organizational measures designed to protect personal data, including access controls, token/cookie security controls, and secure transport practices.
No internet service is 100% secure, and we cannot guarantee absolute security.
10) Your GDPR Rights
If GDPR applies to you, you may have rights to:
- Access personal data we hold about you
- Correct inaccurate personal data
- Delete personal data (in certain circumstances)
- Restrict or object to certain processing
- Data portability (where applicable)
- Withdraw consent (where processing relies on consent)
- Lodge a complaint with your local data protection authority
To exercise rights, contact info@liquidium.fi. We may need to verify your identity before fulfilling a request.
11) Cookies and Controls
You can manage cookies and local storage through your browser settings.
Please note that disabling certain cookies/storage may limit core App functionality (including login/session and wallet-related experience).
If we implement additional consent controls, we will reflect that in this policy.
12) Children
The App is not intended for children. We do not knowingly collect personal data from children under the age of 18.
13) Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last updated" date.
14) Contact
For privacy-related requests or questions:
- Email: info@liquidium.fi
This Privacy Policy should be read together with our Terms of Use: https://liquidium.fi/terms.