Privacy Policy

Last updated: [2025-10-22]

1) What We Collect

Account and contact: email, password hash, 2FA status, settings.

Usage and device: IP address, browser and device information, timestamps, logs, pages, app events.

Transaction data: deposit and withdrawal addresses, amounts, transaction IDs, order history.

Support: messages, tickets, attachments, phone information if you contact us by phone.

Optional verification if requested: government ID, selfie, proof of address, sanctions or PEP screening results.

Cookies and local storage for login sessions, preferences, analytics, and abuse prevention.

We do not collect or store your private keys.

2) How We Use Data

Create and secure your account including two-factor authentication, fraud, and abuse prevention.

Provide trading, wallet, and support services.

Comply with legal obligations such as AML, CTF, sanctions, tax, or court orders.

Communicate about service changes, security updates, or marketing. You may opt out of marketing messages.

Analyze and improve performance, user experience, and reliability.

3) Legal Bases

Contract performance for providing our services.

Legitimate interests for security, anti-fraud, and service improvement.

Consent for marketing cookies or certain communications.

Legal obligations for AML, CTF, and sanctions checks.

4) Sharing

We may share data with the following parties:

• Service providers for cloud hosting, analytics, email, customer support, security or anti-fraud, blockchain analytics, and optional KYC verification.

• Affiliates under common control following this Policy.

• Authorities where legally required.

• In case of business transfers such as a merger or acquisition.

We do not sell personal data.

5) International Transfers

If data is transferred internationally, we apply appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.

6) Retention

We retain data as necessary to provide services and meet legal obligations such as AML retention periods, then delete or anonymize it.

7) Security

We use administrative, technical, and organizational measures including encryption in transit, least-privilege access, logging, and two-factor authentication support.

No system is completely secure. Keep your account credentials and 2FA information safe.

8) Your Rights

Depending on your region, you may have rights to access, correct, delete, restrict, or object to processing, request data portability, and withdraw consent.

Contact support@cosmonaut.exchange for any request. We may need to verify your identity and certain legal exceptions may apply.

9) Children

Cosmonaut is not intended for minors under 18. We do not knowingly collect data from children.

10) Third-Party Links

Links to third parties such as other exchanges for off-ramp are outside our control. Review their policies before using those services.

11) Changes

We will post updates here with a new effective date. Material changes may also be notified by email or in-app.