Sovereign

PRIVACY POLICY

Privacy Policy

Effective July 11, 2026 · Last updated July 11, 2026

This policy explains what information Sovereign collects when you use the service, how we use it, who we share it with, and how long we keep it. It is written to describe what the software actually does — not aspirations.


01

Who we are

Sovereign Protocol (“Sovereign”, “we”, “us”) is a settlement protocol for bilateral over-the-counter (OTC) and shipping-linked trades on the Bitcoin/Liquid Network, operated from Switzerland. Sovereign facilitates settlement of on-chain smart contracts; it is not a bank, broker, or exchange, and does not hold your private spending keys.

If you have questions about this policy or your data, contact us at [email protected].

02

Information we collect

From authentication. When you sign in with a magic link, we collect your email address. When you sign in with Google, Google shares your email address, name, profile picture, and email-verified status, along with a Google account identifier and OAuth tokens that let us confirm your sign-in. Accounts that share an email address (magic link and Google) are linked into a single account.

From you. To use the protocol you provide:

  • Wallet descriptors — a watch-only output descriptor for your Liquid wallet, together with its extended public key (xpub), confidential blinding key, fingerprint, and a label you choose. This lets Sovereign derive your receiving addresses. It does notinclude your private spending keys, so Sovereign cannot unilaterally move your funds outside a deal’s agreed terms.
  • Deal data — for each deal you create or join: the deal identifier, the email addresses of both counterparties, amounts and fees, your Liquid addresses and public keys, contract addresses, on-chain transaction ids, timeouts, and timestamps. Shipping deals also include the vessel IMO number, port (UN/LOCODE), and arrival window you specify.
  • Messages to ATLAS — the text you send to the in-app ATLAS assistant (see section 05).

Automatically. When you sign in, our authentication layer (Better Auth) records the IP address and browser user-agentassociated with your session, plus the session’s creation and expiry time. We keep application logs of protocol activity; email addresses in those logs are masked. We also derive reputation records (deal outcome, amount, settlement transaction id) from completed deals.

03

How we use information

  • To provide the service — authenticate you, derive your addresses, create and settle deals, and track the on-chain and real-world events (block height, vessel arrival) that trigger settlement.
  • To communicate — send transactional emails about your deals (invites, counterparty actions, funding, timeouts, completion, and alerts) and magic-link sign-in emails.
  • For security and integrity — validate sessions, prevent abuse, and verify that addresses match the correct network before a deal is recorded.
  • For oracle verification — the automated agent attests to events (e.g. a vessel reaching a port) so a contract can settle.
  • For ATLAS assistance — process your messages and relevant deal context to answer questions and help you build deals (see section 05).

04

Third parties we share with

We do not sell your data. We share it with the service providers below only as needed to run the protocol. Each is a data processor acting on our behalf.

  • MongoDB Atlas (United States) — our primary database. Stores your account, wallet descriptors, deals, sessions, and reputation records.
  • Amazon Web Services — SES (United States, us-east-1) — delivers our transactional and sign-in emails.
  • Resend (United States) — a fallback email-delivery provider used when SES is unavailable.
  • Anthropic — Claude API (United States) — powers the ATLAS assistant and automated deal narration/alerts. See section 05.
  • Google(United States / global) — provides “Sign in with Google” and shares the profile fields listed in section 02.
  • VesselAPI (vessel-tracking data provider) — supplies vessel position, ETA, and arrival events for shipping deals, keyed to the vessel IMO you provide.
  • Blockstream (public Liquid block explorer) — we query current block height and transaction status. These are public blockchain lookups.
  • CoinGecko — supplies a BTC/USD reference price. No personal data is sent.
  • DigitalOcean (United States, NYC region) — hosts the Sovereign application.

We may also disclose information where required by law, or to protect the rights, safety, and integrity of the protocol and its users.

05

ATLAS and Anthropic

Messages you send to ATLAS are transmitted to Anthropic’s Claude API to generate a reply, and are processed in the United States. Per Anthropic’s published policy at the time of writing, Anthropic does not use data submitted through its API to train its models.

Sovereign does not store your ATLAS conversation history on its servers. Chat history is held in your browser for the duration of the conversation and re-sent with each request so the assistant has context; Anthropic processes it transiently to produce a response. To help you build deals, ATLAS may act on your account (for example, look up your saved wallet or draft a deal) using tools that run against your own logged-in session.

Separately, Sovereign uses the Claude API to generate automated audit narration and alert advisories about deal activity; this may send deal metadata (not your credentials) to Anthropic for that purpose.

06

Data retention

  • Sessions expire after 7 days, after which the IP/user-agent stored with them ages out.
  • Magic-link sign-in tokens are short-lived and expire about 15 minutes after they are issued.
  • Vessel webhook records are automatically deleted after their expiry (they exist only to de-duplicate incoming events).
  • Accounts, wallet descriptors, deals, and reputation records are retained until you ask us to delete them — the protocol does not currently purge them automatically, because a deal must stay recoverable on-chain. On-chain transactions are permanent and outside our control.

07

Your rights

You can request access to the personal data we hold about you, ask us to correct or delete it, or request a copy in a portable format. Depending on where you live, you may have additional rights under laws such as the GDPR. To exercise any of these, email [email protected]. Note that some information (for example, a settled deal’s on-chain transactions) is recorded on a public blockchain and cannot be deleted.

08

Cookies

Sovereign uses a single cookie: the session cookieset by our authentication layer (Better Auth) to keep you signed in. We do not use advertising or third-party analytics cookies. Interface preferences (such as light/dark theme) are stored in your browser’s local storage and are never sent to us.

09

Security and custody

Sovereign does not hold your private spending keys. Funds are locked in on-chain smart contracts on the Liquid Network. Sovereign’s agent participates in settlement per pre-agreed contract terms, but cannot unilaterally move funds outside those terms. Because you connect a watch-only wallet descriptor, Sovereign can generate your receiving addresses without the ability to spend from them on its own.

We restrict access to personal data to the systems that need it and rely on our providers’ infrastructure security (encrypted connections, access controls). No system is perfectly secure, and we cannot guarantee absolute security.

10

Children

Sovereign is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us information, contact us and we will delete it.

11

Changes to this policy

We may update this policy as the protocol evolves. When we do, we will revise the “last updated” date above and, for material changes, take reasonable steps to notify you. Continuing to use Sovereign after a change means you accept the updated policy.

12

Contact

Questions, requests, or complaints about this policy or your data: [email protected].


This policy is current as of the effective date above. We may update it; material changes will be communicated to registered users.