Taking longer than usual. Check your connection, or reload the page.
Privacy Policy
Last updated 7 October 2026
Squidlor is a unified oracle data layer. This policy explains what personal information we collect when you use our website, APIs, smart contracts and related services, how we use it, who we share it with, and the rights you have over it.
Squidlor is non-custodial. We never ask for, and you should never disclose, your private keys or seed phrase, to us or to anyone claiming to represent us.
01Who we are
"Squidlor", "we", "us" and "our" refer to the entity operating the Squidlor unified oracle data layer, including this website, the Squidlor API, the Squidlor smart contracts and our MCP and AI agent interfaces. For privacy questions, or to exercise any of the rights in section 13, contact [email protected].
Where data protection law requires a controller, Squidlor is the controller of the personal information described in this policy, except where we act as a processor on behalf of an enterprise customer under a separate agreement. In that case, that customer's privacy notice governs their end users' data and this policy governs only our direct relationship with the customer.
02Scope of this policy
This policy applies to:
our website and any documentation, dashboards or demos we host;
the Squidlor API, SDKs, MCP endpoint and AI agent interfaces;
embeddable charts and widgets we provide; and
business communications with prospective and existing customers and partners.
It does not apply to public blockchains, oracle networks, wallets or third-party services we do not control. Those are covered in sections 7 and 15.
03Information we collect
Information you give us
Contact and demo requests. When you submit our contact form, we collect your name, email address, company name (optional), the nature of your enquiry and your message.
Account and API access. If you register for API access, we collect the identifiers needed to issue and manage your API keys, and we associate request activity with those keys.
Support and correspondence. Records of messages you send us, including over email or social channels, and any information you choose to include in them.
Enterprise onboarding. For institutional customers, the contract, billing and compliance information needed to enter into and perform an agreement.
Information we collect automatically
Usage and log data. IP address, approximate location derived from it, user agent, referring page, pages and endpoints requested, timestamps, response status and latency. Server logs are generated as a normal part of operating an API.
API telemetry. Which endpoints, pairs, assets and providers a key queries, and at what rate. We use this for rate limiting, billing, abuse prevention and capacity planning.
Device and browser data. Coarse device, browser and screen information used to render the site correctly and diagnose faults.
Blockchain information
If you read from our smart contracts or send a transaction that touches them, the associated wallet address, transaction contents and timing are recorded on a public blockchain by design. We may read and analyse that public data. See section 7 for what this means for your rights.
What we do not collect
Private keys, seed phrases or recovery phrases. We will never ask for them.
Custody of your assets. Squidlor is non-custodial and cannot move your funds.
Special category data (health, biometrics, political or religious beliefs). Please do not send it to us.
04AI assistants, plugins and the MCP endpoint
Squidlor can be used from AI assistants such as ChatGPT, Codex and Claude through a plugin that talks to our Model Context Protocol (MCP) endpoint at api.squidlor.com. This section lists exactly what crosses that boundary, because the assistant, not Squidlor, decides when to call us and shows you the result.
What we receive
The arguments of each tool call the assistant makes: asset pairs, chains, time ranges, token contract addresses, transaction hashes, and, when you ask about a wallet or a transfer, the wallet addresses, amounts and recipient you supplied.
Your Squidlor API key, only if you attached one to the assistant. Anonymous use is supported and is the default.
Standard request metadata (IP address, user agent, timestamps) as described in section 3. We do not receive your conversation, your assistant account, or anything the assistant did not pass as a tool argument.
What we return
Oracle data: prices, per-provider comparisons, history, candles and audit records. This contains no personal information.
Public blockchain data about addresses you name: token balances and their USD value, transaction details and token contract risk reports. We read this from public chains through infrastructure providers (section 9). Anyone can read the same data from the chain; we return it only for addresses the assistant passes to us.
Unsigned transaction payloads for transfers or swaps you asked to prepare. These contain the sender and recipient addresses and amounts you supplied. We never hold keys, cannot sign, and nothing is sent.
If you attached an API key: your webhook subscriptions (URL, symbols, delivery counts, last error), your request counts, and the price alerts or scheduled tasks you created.
We strip internal identifiers and operator diagnostics (database ids, project and account ids, cache and vendor markers) from plugin responses before they leave our servers. If you see a field you cannot account for, tell us at [email protected] and we will remove it or document it here.
What we store
Anonymous calls store nothing beyond the server logs in section 3. They cannot create alerts, tasks or preferences.
Calls with an API key may create durable records you asked for: webhook subscriptions, price alerts, scheduled tasks and saved preferences. They are stored against a one-way hash of your key, never the key itself, and are visible only to callers presenting that key. Delete them at any time through the same tools or by revoking the key.
Usage counters per API key, kept for billing and rate limiting (section 11).
Who else sees it
The assistant provider (for example OpenAI or Anthropic) receives the tool arguments and our responses as part of your conversation under its own privacy policy. To read balances and build quotes we use blockchain data and routing providers, which receive the addresses and amounts involved but not your identity. We do not share plugin traffic with anyone else and we do not use it for advertising.
05How we use information
We use personal information to:
respond to your enquiry, arrange a demo and follow up on it;
provide, operate, secure and improve the API, contracts, charts, widgets and agent interfaces;
authenticate requests, enforce rate limits and meter usage for billing;
detect, investigate and prevent abuse, fraud, scraping and attacks on our infrastructure;
diagnose faults and monitor the availability and accuracy of the data we serve;
send service and security notices, and, where you have asked for them or where permitted, product updates you can unsubscribe from at any time;
understand which capabilities are used so we can prioritise work; and
comply with legal obligations and enforce our terms.
We do not use your information to make automated decisions that produce legal effects for you, and we do not profile you for advertising.
06Legal bases for processing
If you are in the UK, EEA or Switzerland, we rely on the following legal bases under the GDPR:
Contract. To provide services you or your organisation have signed up for, and to handle billing and support.
Legitimate interests. To secure and improve our services, prevent abuse, keep server logs, and contact businesses about products relevant to them, balanced against your rights and interests.
Consent. For optional marketing emails and any non-essential cookies. You can withdraw consent at any time without affecting prior processing.
Legal obligation. Where we must retain or disclose information to comply with law.
07On-chain data and immutability
Public blockchains are permissionless, transparent and, in practice, permanent. This has consequences we cannot engineer away:
Transactions and wallet addresses are visible to anyone, indefinitely, and are replicated across independent nodes worldwide.
A wallet address may constitute personal data where it can be linked to you, including by third parties combining it with data we never see.
We cannot edit, redact or delete anything written to a public blockchain, whether by you, by us or by anyone else.
When your wallet or client broadcasts a transaction or RPC call, the RPC provider, node operator, sequencer or oracle network involved may log your IP address under their own policies.
Because on-chain records are immutable, we cannot fulfil a request to erase or rectify data that already exists on a public blockchain. This is a limitation of the technology, not a refusal to honour your rights. We will still act on such a request for the information we hold in our own systems.
08Cookies and similar technologies
We use cookies and local storage that are strictly necessary to operate the site and keep authenticated sessions working, for example a session cookie once you sign in, and local storage that remembers interface preferences. These do not require consent.
We do not use advertising or cross-site tracking cookies. If we introduce analytics or performance cookies, we will ask for your consent where the law requires it and update this section before doing so. Your browser also lets you block or delete cookies, though blocking essential ones may break parts of the site.
09How we share information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We disclose it only as follows:
Service providers. Hosting, database, monitoring, error tracking, email delivery and customer support vendors that process data on our instructions under contract.
Oracle and data providers. When you query a feed we route the request to the relevant providers. We pass the query, not your identity, but providers and the networks in between may keep their own logs of requests they receive.
Professional advisers. Auditors, accountants, insurers and lawyers, where necessary and subject to confidentiality.
Legal and safety. Where required by law, court order or a valid request from a competent authority, or where necessary to protect our rights, users or infrastructure.
Corporate transactions. In connection with a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply to the transferred information.
10International transfers
We and our service providers operate internationally, so your information may be processed in countries other than your own, including countries that do not provide the same level of data protection. Where we transfer personal information out of the UK or EEA, we rely on an adequacy decision where one exists, or otherwise put appropriate safeguards in place such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum. Contact [email protected] for details of the safeguards used for a specific transfer.
11Data retention
We keep personal information only as long as we need it for the purposes in section 5, then delete or anonymise it. In general:
Contact and demo enquiries: kept while we are in active discussion and for a reasonable period afterwards so we have context if you come back to us.
Account and API records: kept for the life of the account and for as long afterwards as is needed for billing, tax and legal purposes.
Server and security logs: kept for a short operational window, longer where a log is relevant to an ongoing security investigation.
Records we must retain by law: kept for the period the law specifies.
On-chain data is outside this schedule for the reasons given in section 7.
12Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls and least-privilege access to production systems, credential and API key rotation, logging and monitoring, and review of changes to code that touches personal data. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information and the law requires it, we will notify you and the relevant regulator without undue delay.
13Your rights
Depending on where you live, you may have the right to access a copy of your personal information; to have inaccurate information corrected; to have information deleted; to restrict or object to processing, including direct marketing; to receive your information in a portable format; and to withdraw consent you previously gave.
If you are a California resident, you additionally have the right to know the categories and specific pieces of personal information we collect, the right to delete and correct it, the right to opt out of sale or sharing (which we do not do), and the right not to be discriminated against for exercising these rights.
To exercise any right, email [email protected] or use our contact form. We will respond within the time the applicable law allows, and we may need to verify your identity first. You can also authorise an agent to act for you. If you are unhappy with our response you may complain to your local data protection authority (in the UK, the Information Commissioner's Office).
14Children's privacy
Squidlor is a business and developer product and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with their information, contact [email protected] and we will delete it.
15Third-party sites and protocols
Our site and documentation link to third-party services, and using Squidlor may involve wallets, RPC providers, block explorers, oracle networks and blockchains operated by others. We do not control those parties and are not responsible for their privacy practices. Review their policies before you use them.
16Changes to this policy
We may update this policy as our products and the law change. We will revise the "last updated" date above, and where changes are material we will give prominent notice before they take effect, by posting on the site or, if we hold your address, by email.
17Contact us
For any question about this policy or how we handle your information, email [email protected] or reach us through our contact form. We aim to reply to privacy enquiries promptly, and always within the period the applicable law requires.