Legal

Privacy Policy

What this interface stores, what it does not collect, and how third-party widgets process data.

Version 2.2 · Last updated 11 September 2026 · Saber Vault

1. Scope

This Privacy Policy explains how the Saber Vault interface (“Service”) handles information when you use the website, Issuer KYB, custody registry, holder allowlist, Howey Converter, Trade Desk, White Paper, and Legal Documents. It is written for the current build: no Operator user accounts, no Operator-hosted database of visitors, and no transmission of KYB or holder packets to a vendor or to Operator servers.

It does not cover Networks (Robinhood Chain, Arc Network, PulseChain), wallet providers, TradingView, Google Fonts, or the preview host, each of which has its own policy.

2. Who is responsible

For information that remains only on your device (browser local storage), you control that copy. Operator does not operate a login that retrieves it from a server in this version.

If Operator later adds accounts, a server, or institutional Status login, this Policy will be updated before that data is collected, and a controller identity and contact will be stated.

3. What this build does not collect

The Service does not ask you to create an Operator account, does not take a password, does not request a seed phrase, and does not upload KYB packets to Operator. It does not intentionally collect Social Security numbers, government ID images, or payment card numbers. Issuer KYB collects entity identifiers (legal name, LEI, EIN/tax ID), addresses, officer names and work emails, beneficial-owner names and ownership percentages, and PEP flags — stored only in your browser.

Absence of server collection is a build fact, not a promise that third-party scripts or your wallet will never see data. See Sections 6 and 7.

4. Information stored locally on your device

The Service writes design and desk records to your browser’s localStorage so the interface can resume work in the same browser. Keys currently used include: saber_network (selected settlement network); saber_issuers (Issuer KYB packets, officer rosters, Program Review results, public website/email/phone); saber_custody (asset-instance custody packets and attestation hashes); saber_holders (holder allowlist packets and wallet addresses); saber_oracle (valuation refresh records); saber_freezes (officer freeze flags); saber_redeems (redeem/burn log); saber_mints (Factory mint specifications); saber_desk and saber_desk_v2 (native balances, RWA balances, orders, liquidity bins, LP positions, tape); saber_protocol (SBRV burns, protocol LP, access bonds, team-ops USDC, protocol events); saber_auth (authorization binding to issuer and officer, timestamp, residual risk); saber_memo (generated memorandum text); saber_mint_spec (last mint specification); saber_consent (Legal Documents version, eSign flag, and TradingView market-data preference).

These records may include asset names, symbols, valuations you type, Howey fact flags, wrapper identifiers, issuer legal names, LEIs, EINs, public contact details displayed on Asset Profiles, officer names and emails, beneficial-owner names and ownership percentages, wallet-attributed owner keys (your address if you connected MetaMask, otherwise “session”), and simulated balances.

Anyone with access to your browser profile can read this data. Clearing cookies/site data deletes it. Operator cannot remotely restore it in this version.

5. Wallet information

If you click Connect MetaMask, the injected provider may share account addresses and chain IDs with the page. The Service uses that address to tag local orders and LP positions and to request wallet_switchEthereumChain / wallet_addEthereumChain for Robinhood Chain (chain 4663), Arc Network (chain 5042002), or PulseChain (chain 369, RPC https://rpc.pulsechain.com).

The Service does not need, and you must not paste, a private key or seed phrase. Wallet software is third-party software. Its privacy practices are governed by MetaMask (or whatever provider you use), not by this Policy.

6. Third parties

TradingView: the Desk loads an Advanced Chart widget from TradingView’s servers. TradingView may process IP address, browser data, and the chart symbol, and may set its own cookies. See TradingView’s privacy policy.

Google Fonts: the interface loads Cormorant Garamond, Source Sans 3, and IBM Plex Mono. Google may process the request (including IP address).

Preview host / Grok: the environment may inject branding and a PWA helper from grok.com. That host may process technical data as described in its own terms.

Networks and RPCs: if you add a Network in MetaMask, later on-chain activity is public on that ledger and is processed by RPC and explorer operators, not by this Policy.

7. Cookies and similar technologies

Operator does not currently set advertising or cross-site tracking cookies for the Service. Functional state uses localStorage as listed above. Third-party embeds (especially TradingView) may use cookies. Details are in the Cookie & Local Storage Notice.

8. Purposes and legal bases (where GDPR/UK GDPR could apply)

If you access the Service from a jurisdiction that requires a legal basis: local storage of Converter and Desk state is for the legitimate interest of providing the interface you requested, and/or for performance of the Terms you accepted by use. Third-party fonts and charts are for displaying the interface.

This build is not intended to process special-category data. Do not enter health, genomic, or other sensitive personal data except as fictitious design examples you are authorized to use.

9. U.S. state privacy notices (including Colorado and California)

Operator does not sell personal information and does not share it for cross-context behavioral advertising in this build. Because records live on your device, “access” and “deletion” are performed by you: inspect or clear site data in the browser. If a server-side profile is added later, a request method will be published here.

Colorado residents (CPA) and California residents (CCPA/CPRA): categories of information that may exist on-device include identifiers you type (name, title, entity), commercial-style design data (valuations, symbols), and internet activity limited to using this site. Sensitive personal information is not requested. We do not use or disclose sensitive personal information for purposes that require a CPRA right to limit in this build.

10. Retention

Local records remain until you delete them or the browser evicts them. Operator does not run a retention schedule against your disk in this version. Generated memoranda may contain personal names you typed; treat them as confidential work papers of your organization.

11. Security

See the Security Policy. No method of electronic storage is 100% secure. localStorage is not encrypted at rest by the Service.

12. Children

The Service is not directed to children under 16 (or under 13 where COPPA applies). Do not use it if you are under 18.

13. International access

The interface may be served from infrastructure outside your country (including the United States). Third-party widgets may transfer technical data internationally. Do not use the Service if that is unlawful for you.

14. Changes

We may update this Policy. The Last updated date will change. Material changes to server-side collection will be described before that collection begins.

Other legal documents