Privacy
Last updated: July 26, 2026
This policy is short because we collect little. Noara is built around public data. The most sensitive personal data it holds is your sign-in email and the wallet address you asked it to watch — but note that on the Guardian tier we also hold the key to a wallet that holds your money, which is explained below and in our Terms.
This English version is authoritative. Noara is operated by Silt LLC (United States), the data controller for the purposes of this policy.
What you give us
- When you sign in on the web: your email address, and — if you sign in with Google or Telegram — the account identifier that provider returns to us. We do not receive your password.
- On Telegram: your chat ID and username (Telegram provides these when you message the bot) and the public wallet address you send it.
- Your settings: alert preferences and, on Guardian, the rules, caps and risk profile you configure.
- If you deposit by card: nothing. Payment and identity verification happen inside our payment partner's own checkout — we never receive your card number, bank details, or identity documents. If you transfer USDC directly on Polygon, we see the sending address — that is public onchain data, and it must be an address you control.
What we read, without you giving it
Public data about the address you registered: positions, trades, settlements on Polygon, and Polymarket market data. This is the same information visible through blockchain explorers. Watching an address does not link it to your legal identity, and we do not try to.
Custody — what we do and don't hold
On the free tier we hold nothing. Monitoring is read-only against a public address you give us; we never have your keys and never take possession of your funds.
On Guardian we do hold funds. We generate a dedicated wallet for you on our servers and store its private key encrypted at rest, so that Noara can act on your rules without asking you each time. That is custody, and we state it plainly: the funds you deposit into that wallet are in our custody until you withdraw them. The wallet is yours alone — never pooled with other users' funds or with company funds — and withdrawals go only to an address you specify, after review by a person.
What we never have
- The keys to your own wallet — there is nowhere in the product to enter a private key or seed phrase, and we never ask for one.
- Your card number or bank details — those stay with our payment partner.
- Exchange logins or API credentials.
- Your identity documents — we don't collect them; our payment partner performs identity verification under its own policy.
How we use it
We use it to run the service: match your address to positions, generate alerts, send them to Telegram, and — on Guardian — enforce your rules and caps. Decision logs are append-only for auditability. We don't sell or rent your data, run ads, or trade against you.
This website
noara.io runs no analytics and no ad trackers. The only cookie we set is the one that keeps you signed in to your account — it is strictly necessary for the service and is not used to track you. Netlify (our host) keeps standard request logs.
Who else sees anything
- Telegram delivers your alerts, under its own privacy policy.
- Netlify hosts this site and keeps standard hosting logs.
- Our payment partner, if you deposit by card: it receives the payment and identity data you give it directly, under its own privacy policy, and tells us only that a deposit succeeded.
- Google, Telegram or our email provider, depending on how you sign in, to verify that the address or account is yours.
- Public RPC and market-data providers see our queries, which include the public addresses being watched — as any onchain lookup does.
- Authorities, if the law genuinely requires it. We have never been asked.
Why we're allowed to hold it
We process your sign-in identifier, settings and wallet address because we need them to provide the service you asked for — that is our contract with you. We keep append-only decision and transaction logs because we have a legitimate interest in being able to audit what an automated system did with someone's money, and because records of financial activity have to be retained. We do not process your data for advertising, we do not sell or rent it, and we do not make any decision about you other than executing the rules you configured.
Retention and deletion
Send /stop to the bot and monitoring ends immediately. To have your
account identifier, address and settings deleted, use the contact form or message the bot —
deletion is manual today and confirmed back to you. Two limits are worth stating
honestly: while you have a funded Guardian wallet we cannot delete the records tied to
it, because we would lose the ability to return your money; and records of deposits,
trades and withdrawals are retained after closure for as long as financial records
must be kept. Onchain activity is public and permanent — nobody, including us, can
delete it. Anonymized operational logs (what the agent decided and why) may be
retained; they exist to audit the agent, not to profile you.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a copy in portable form, object to or restrict how we use it, and withdraw consent where we relied on it. Ask us and we will action it — normally within 30 days — subject to the retention limits above. If you are in the UK or EEA and think we have got it wrong, you may also complain to your local data-protection authority.
Changes and contact
Material changes move the "last updated" date above; if you're on a paying tier, you'll hear about them directly. Questions, data requests or complaints: use our contact form or message @AskNoaraBot on Telegram.