Legal

SimplFi Privacy Policy

Last updated: August 31, 2026

Operator: Dork Labs Inc., a Wyoming corporation (“Dork Labs,” “we,” “us,” or “our”)
Product: SimplFi (simplfi.xyz)
Related: Terms of Service · Product Disclosures
Contact: support@simplfi.app

This Privacy Policy describes how we collect, use, share, and retain information when you use the SimplFi website, application, and related APIs (the “Interface”).

The Interface is a non-custodial software front end for the DorkFi protocol on Algorand and for third-party services (including Privy, Exodus XO Swap, Coinbase, and MoonPay). It is not a bank or custodial account.

By using the Interface you agree to this Policy, our Terms of Service, and our Product Disclosures. If you do not agree, do not use the Interface.

1. Who is responsible

Dork Labs Inc., a Wyoming corporation, is the controller of personal information we process for SimplFi, except where a third party is an independent controller (for example Privy for your login, or Coinbase or MoonPay for cash-out KYC).

Contact: support@simplfi.app

2. What this Policy covers — and what it does not

This Policy covers information processed through SimplFi by Dork Labs.

It does not cover:

  • The DorkFi protocol or other front ends.
  • Public blockchains (Algorand, Base, and others). Wallet addresses and transactions you sign are typically public and permanent. We cannot delete them.
  • Independent third-party products you use from SimplFi (Privy, Stripe, MoonPay, Coinbase, Exodus, Circle, RPC/indexer providers). Those companies have their own privacy policies.

3. Information we process

We aim to collect only what is needed to run the Interface. We do not currently operate a first-party product-analytics tool (for example Google Analytics, Mixpanel, or PostHog). Hosting, partners, and the blockchain still generate data, as described below.

3.1 Information you provide

  • Get Started login. Email, Google, Apple, or passkey is collected by Privy in your browser. We do not host a separate password database. We may see a display name (for example an email prefix) in the session Privy returns to the Interface.
  • Account profile. Preferred name and avatar are stored in your browser’s localStorage, keyed to your wallet address. They are not synced to Dork Labs servers and do not roam across devices. Clearing site data or using another browser removes them.
  • Support. If you email support@simplfi.app, we receive the content of that message and your email address.
  • Connect Wallet. If you connect Pera, Defly, or another wallet, we receive the public address you connect, not your seed phrase or private keys.

3.2 Information created by use of the Interface

  • Wallet and network identifiers. Algorand address, Base (EVM) address, and related public on-chain balances and positions the Interface reads in order to show Savings, Borrow, Portfolio, and Account.
  • Transaction metadata you approve. Asset, amount, contract, and similar details needed to build the transaction you sign. Signed transactions go to the network, not into a Dork Labs custody ledger.
  • Device local data. In addition to profile, the Interface may store in localStorage things like savings/borrow activity you viewed and chart snapshots, plus locale/number-format settings. This stays on your device unless you send it to us (we do not currently upload it).
  • Technical and server logs. When you load the Interface or call our APIs, our host and application may record IP address, user agent, date and time, request path, referrer, and error diagnostics. We use IP address in particular when required by cash-out partners (see §3.3).

3.3 Information processed to move USDC or cash out

Our production APIs (/api/offramp, /api/xo-swap) are a thin relay. They may receive and pass on:

FlowTypical dataWho else sees it
Card / Apple Pay on-rampPayment details are entered with Privy and its processors (which may include Stripe, MoonPay, or Coinbase). We do not intend to receive full card numbers.Privy and those processors; their KYC/AML if required
USDC Base ↔ AlgorandAmounts, pair, quotes, order identifiers, and wallet addresses needed to create an Exodus XO Swap order. Our server may forward client IP because the Exodus API is geo-gated.Exodus; blockchains after you sign
Cash-out (Coinbase)Base USDC address, client IP (required by Coinbase CDP), optional amount, redirect URL, and a partnerUserRef. Coinbase then runs its own sell / identity flow.Coinbase
Cash-out (MoonPay)We sign a MoonPay widget URL with a server secret. MoonPay collects identity and payout details in its widget.MoonPay

We do not run the identity check for fiat on-ramp or off-ramp. That KYC sits with MoonPay, Coinbase, Stripe, and similar partners. They may collect government ID, bank account, and other information we never see.

3.4 Information we do not collect (on purpose)

  • Seed phrases or Privy backup material (those stay with you or Privy).
  • Full payment card PAN/CVV on Dork Labs servers.
  • Biometric templates (passkeys are handled by your device and Privy).
  • Precise GPS location. IP may imply a coarse region (and is used for partner geo rules).

4. How we use information

We use the information in §3 to:

  • Provide, operate, secure, and debug the Interface.
  • Let you sign in via Privy, display balances, and submit transactions you approve.
  • Proxy swap quotes/orders and cash-out session URLs to partners.
  • Comply with law, enforce our Terms, and respond to lawful requests.
  • Communicate with you if you contact support.
  • Improve reliability (for example fixing errors). We do not currently use this data for advertising.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

5. Legal bases (EEA/UK and similar laws)

Where those laws apply, we process personal information because:

  • Contract: to provide the Interface you asked to use (Terms of Service).
  • Legitimate interests: to secure the service, prevent abuse, and keep logs that are reasonably necessary — balanced against your rights.
  • Consent: where a partner or browser feature requires it (for example certain cookies or a Privy login method you choose).
  • Legal obligation: if we must retain or disclose information under applicable law.

6. How we share information

We share information only as needed:

  • Service providers / processors that host the Interface, terminate TLS, or run our Node APIs.
  • Independent partners you choose to use: Privy, Exodus, Coinbase, MoonPay, Stripe (if used in the on-ramp), Circle (USDC), and Algorand / Base node and indexer operators. They process data under their own policies.
  • Public blockchains. Anyone can read transactions you broadcast.
  • Professional advisers and authorities when required by law or to protect rights, safety, or the Interface.
  • Business transfer. If Dork Labs merges, raises capital, or sells assets, information may transfer under this Policy.

We do not share information with data brokers for their independent marketing.

7. Cookies and local storage

The Interface uses:

  • Essential cookies / storage required for the session (including Privy’s cookies or local storage for login and embedded wallet).
  • localStorage for profile, in-app history/charts, and locale settings, as in §3.2.

We do not currently use non-essential advertising or analytics cookies. If we add them, we will update this Policy (and obtain consent where required).

You can clear cookies and site data in your browser. That may sign you out of Get Started and delete local profile/history. It will not delete on-chain positions or your Privy account (see §9).

8. Retention

  • Server/API logs (IP, paths, errors, relayed swap/offramp metadata): kept only as long as reasonably needed for security, debugging, and legal compliance, then deleted or aggregated. Exact periods depend on our host.
  • Support emails: kept as long as needed to handle your request and our records.
  • Browser localStorage: until you clear it or the Interface overwrites it.
  • Privy, Coinbase, MoonPay, Exodus: retained under their policies. We cannot delete data we do not hold.
  • Blockchain data: retained by the networks indefinitely.

9. Your choices and rights

Depending on where you live (including the EEA, UK, and California), you may have rights to access, correct, delete, export, or restrict personal information, or to object to certain processing, and to withdraw consent.

How to exercise rights with us: email support@simplfi.app. We may need to verify the request. We will not discriminate against you for exercising privacy rights.

Practical limits:

  • We cannot erase public blockchain records or transactions you signed.
  • Get Started account and embedded-wallet data is held by Privy. Use Privy’s account tools or ask us and we will point you to Privy. Deleting SimplFi localStorage does not delete Privy.
  • Cash-out / on-ramp KYC is held by Coinbase, MoonPay, or Stripe — contact them.
  • If we only see a wallet address and have no email on file, we may be unable to locate a “user file” beyond logs.

You may stop using the Interface at any time. Protocol positions remain on-chain.

If you are in the EEA/UK, you may lodge a complaint with your local supervisory authority. We encourage you to contact us first.

10. Children

The Interface is for users 18 or older. We do not knowingly collect personal information from children. If you believe a child has used SimplFi, contact support@simplfi.app and we will take reasonable steps to delete information we hold.

11. International transfers

Dork Labs is in the United States (Wyoming). Partners (Privy, Coinbase, MoonPay, Exodus, hosting, and RPC providers) may process data in the U.S. and other countries. Those countries may not provide the same legal protections as yours. Where required, we and our providers use appropriate transfer mechanisms (for example contractual clauses). By using the Interface, you understand your information may be processed in the United States.

12. Security

We use reasonable administrative and technical measures appropriate to a non-custodial interface (HTTPS, server secrets kept off the client, origin allowlists). No method is 100% secure.

You are responsible for your email, social login, passkey, devices, and wallet. We cannot recover a lost Privy session or a signed on-chain transfer. Do not send seed phrases to support@simplfi.app.

13. California (CCPA/CPRA) notice

If the California Consumer Privacy Act applies:

  • Categories collected (in the last 12 months, as applicable): identifiers (email if you contact us or use Privy; IP; wallet address); commercial / transaction information (on-chain activity the Interface displays; swap and cash-out metadata); internet / electronic activity (logs); inferences we do not currently build for profiling.
  • Sources: you; your device; Privy; blockchains; partners you use; our servers.
  • Business purposes: §4.
  • Sold or shared for advertising: no.
  • Sensitive personal information: we do not collect SSN or government ID on our servers. Partners may collect that for KYC.
  • Retention: §8.
  • Rights: know, delete, correct, opt out of sale/share (we do not sell/share), and non-discrimination — exercise via support@simplfi.app. We do not use or disclose sensitive personal information for purposes that require a CPRA right to limit.

Authorized agents may submit requests with proof of authority.

14. Changes

We may update this Policy by posting a new version and changing the “Last updated” date. Material changes may also be noted in the Interface. Continued use after the effective date is acceptance. If you do not agree, stop using the Interface.

15. Contact

Dork Labs Inc.
A Wyoming corporation
support@simplfi.app

For this Policy, our Terms of Service, or our Product Disclosures, use the same address.