12 gwei

Privacy Policy

Last updated: 2026-08-13

This English-language version is the authoritative and governing version of this document. Any translation is provided for convenience only; in the event of a conflict, the English version controls.

This page explains what data Cherum (“we”) processes when you use cherum.io, app.cherum.io, dashboard.cherum.io, pay.cherum.io, claim.cherum.io, the embeddable widget and the API, and how long we keep it.

1. What we don’t do

We don’t sell your data. We don’t run third-party advertising trackers. We don’t ask for identity documents. Connecting a wallet never gives us control over your funds.

2. Blockchain data is public

Transactions you sign are recorded on public blockchains. Wallet addresses, amounts and transaction hashes are public by the nature of those networks and cannot be deleted by us.

3. Account data

The dashboard signs you in with an email magic link — we store your email address and the wallets you choose to link (via a signed message). Team invitations store the invitee’s email address and role.

4. Operational data

To run swaps, payouts, payments and claims we store the operation’s technical record: addresses, assets, amounts, transaction hashes, timestamps, and the quotes we received. Exchange records are deleted after 365 days on a daily schedule. Records that form part of your dashboard history — payments, payouts, claims — are kept while your account is active, so your books stay complete.

5. Payments (merchants and payers)

For a hosted invoice we store the invoice details the merchant created, the payer’s on-chain payment and, if a refund is requested, the refund address the payer submits. Payment events are delivered to the merchant’s webhook endpoint — the merchant is an independent controller of what they do with them.

6. Security and abuse protection

Our sites sit behind Cloudflare; we read the connecting address and country it forwards to rate-limit abuse and protect payments. Wallet-security events are kept 90 days, service health checks 30 days, internal admin actions 180 days.

7. First-party analytics

We measure visits ourselves: our servers record the page, the referrer, the country, the connecting address and the browser string, kept 90 days. Unique visitors are counted with a salted identifier that resets daily. Campaign attribution uses one first-party cookie holding only the campaign tag and the referring site. No Google Analytics, no ad pixels, no third-party trackers.

8. Templates and contacts sync

If you enable cross-device sync, your templates and contacts are end-to-end encrypted in your browser before they reach us. We store an encrypted blob we cannot read.

9. Who else sees data

To quote and execute a swap we send the necessary technical fields (addresses, assets, amounts) to the liquidity and bridge providers involved in your route. Magic-link emails are delivered through our email relay. Cloudflare proxies our traffic.

10. Retention summary

Exchange operations and quotes: 365 days. Dashboard history (payments, payouts, claims): while your account is active. Admin audit: 180 days. Wallet security events, alerts, our own traffic log: 90 days. Health checks, metrics, payout drafts: 30 days. Routing decisions: 7 days. Deletion runs automatically every day.

11. Your choices

You can use the exchange and the widget without an account. You can unlink wallets and leave a team in the dashboard. On-chain data cannot be deleted (see §2). To ask for a copy or deletion of your account data, write to [email protected].

12. Changes and governing law

We’ll update this page and the date above when practice changes. This policy is governed by the same law and dispute-resolution terms as our Terms of Service.