Privacy · Version 2026-07-21-v2

Privacy Notice

This Notice explains the information involved when you visit LEV7, connect a wallet, request a route, interact with a public blockchain, or contact us.

Effective and last updated: July 21, 2026

Unapproved draft and live-site warning. On July 21, 2026, the public domain was observed serving an earlier build and shorter notice. This repository draft is not the operative public notice unless and until it is verified and deployed. The repository does not identify the privacy controller's exact legal name, physical address, or EU/UK representative, and it does not define Cloudflare log retention or a production rights-request workflow. Those facts must be completed and verified against actual vendor settings before launch. This Notice describes the data flows visible in the current code; it is not permission to collect additional data without updating the product and Notice.

1. Scope and controller

This Privacy Notice applies to personal information processed through lev7.finance, the LEV7 interface, related APIs, and communications with the Operator (collectively, the “Interface”). “LEV7,” “we,” “us,” and “our” refer to the person or legal entity operating the Interface (the “Operator”). Before launch, the Operator's legal name and address must be published in this section.

This Notice does not govern independent wallets, blockchains, RPC providers, bridges, solvers, exchanges, explorers, token issuers, or other third parties. They may be separate controllers with their own notices. Public blockchains are not controlled by us, and information written onchain is public and generally cannot be changed or deleted.

2. Notice at collection

The table below summarizes the categories the current Interface may collect, why they are used, and how long they are kept. We do not use these categories for materially unrelated purposes without additional notice or consent where required.

Category and examplesPurposesRetention criteria
Device and network data: IP address, browser and device details, request headers, referring URL, pages and API routes requested, timestamps, errors, and approximate location inferred from IP.Deliver and secure the Interface; prevent abuse; diagnose errors; maintain availability; comply with law.Infrastructure and security logs are retained under production Cloudflare settings and then deleted or aggregated unless a longer period is needed for security, disputes, or law. The Operator must publish the configured period before launch.
Wallet and blockchain data: public wallet address, ENS name if available, selected connector and network, token balances and holdings, approvals, transaction hashes, recipient address, and public transaction history.Connect the wallet at your request; display balances; build routes; monitor requested delivery; prevent fraud and unlawful use; support and disputes.The app has no first-party wallet database. Data remains in your browser and wallet, is queried through RPC and route providers, may appear in infrastructure logs, and may become permanent if submitted to a public blockchain. Vendor periods must be inventoried before launch.
Quote and transaction data: origin and destination chains, assets, amounts, decimals, slippage, requested route, estimated and actual fees, app/referral data, transaction steps, and delivery status.Request quotes and executable routes; present transaction details; deliver WETH; troubleshoot; account for fees; comply with law.The Worker processes route data transiently and does not write it to an application database. Quote URL parameters may appear in Cloudflare logs; Relay and other providers apply their own periods; signed transaction facts may remain public onchain.
Consent and eligibility data: legal-document version, acceptance timestamp, required affirmations, signed cookie and local-storage record, transient transaction-risk checkbox state and request header, and server request metadata.Enforce current terms; maintain a browser record; establish and defend legal rights; request renewal when documents change.The local record lasts until cleared or superseded, and the signed HTTP-only cookie lasts up to one year. There is no durable consent database or plan-bound transaction-acceptance record. A checkbox is ephemeral; only infrastructure logs may incidentally record its request.
Communications: email address, name or handle, wallet address you choose to provide, message contents, and attachments.Respond to requests; provide support; investigate incidents; manage disputes and legal obligations.For as long as needed to respond and for reasonable security, recordkeeping, dispute, and legal periods; longer only if a legal hold or law requires it.

The current code has no advertising SDK, newsletter, profile database, or first-party analytics SDK and does not configure targeted advertising. Coinbase Wallet and WalletConnect functional telemetry are disabled in the current connector configuration. The Operator must still complete a vendor-contract and data-flow review before making a final legal conclusion about “sale” or “sharing.” We do not intentionally collect government identifiers, payment-card numbers, biometric data, health data, precise geolocation, private keys, or recovery phrases. Never provide private keys or a recovery phrase to us or anyone claiming to represent LEV7.

3. Information we process

Information collected automatically

When your browser requests a page or API, hosting and security systems such as Cloudflare can receive IP address, request headers, device and browser characteristics, URL, referring page, date and time, response status, performance, and security signals. Cloudflare observability is enabled in the current deployment configuration. A quote request uses URL parameters containing chain, token, amount, decimals, and slippage, so those details may appear in request logs.

Wallet and public blockchain information

When you connect a wallet, the Interface and wallet libraries can process your public address, selected account, chain, connector, available ENS name, and connection state. The Interface requests native and token balances from RPC providers and may repeat balance reads while connected. To execute a route, our server receives your public address as the proposed user and recipient. Public addresses are pseudonymous, not anonymous; they can be linked with transactions, holdings, ENS records, other public data, or information held by third parties.

Wallet libraries can initialize before you connect. Wagmi may persist connector and chain state in local storage. If configured, WalletConnect or Reown may create a client identifier, contact its relay infrastructure, and use IndexedDB or local storage for client and session state. Coinbase Wallet may use browser storage when selected. The current configuration disables Coinbase Wallet and WalletConnect functional telemetry, but it does not eliminate data needed to provide a requested wallet connection.

Route and transaction information

We process the origin asset, chain, amount, decimal precision, slippage, wallet address, expected output, estimated fees, route steps, and delivery status needed to request and display a Relay route. Your browser and wallet send signed transactions to RPC or wallet providers, not private keys to us. The Interface polls a public WETH balance after a route to determine whether delivery appears complete.

Market and media requests

The browser can connect directly to Lighter market-data services and load token or chain images from URLs supplied by Relay. Those hosts receive ordinary network-request data such as IP address and user agent. Links to Blockscout, Uniswap, Robinhood, Lighter, and other sites also disclose data to those sites when you follow them.

Information you provide

We receive information you voluntarily include in an email, legal notice, privacy request, support message, or dispute. Do not send secrets or information unnecessary to resolve the issue.

4. Sources

We obtain information from:

  • you, your browser, device, and wallet;
  • public blockchains, explorers, ENS, and smart contracts;
  • service providers and integrations, including Cloudflare, ConnectKit, Wagmi, Reown or WalletConnect, Relay, RPC providers, and Lighter;
  • publicly available sources;
  • another person who contacts us about a transaction, dispute, or possible violation; and
  • corporate transaction counterparties, professional advisers, and authorities where legally permitted.

5. How we use information

We use information as reasonably necessary to:

  • provide, operate, maintain, and improve the Interface;
  • connect wallets, obtain quotes, construct requested routes, and show transaction and delivery information;
  • authenticate the current signed legal-acceptance cookie and apply basic request-integrity, security, fraud, and abuse controls;
  • debug errors, protect systems and users, investigate incidents, and prevent malicious or unlawful activity;
  • respond to messages, privacy requests, and legal notices;
  • comply with law, enforce terms, establish or defend legal claims, and cooperate with lawful process; and
  • evaluate or complete a financing, reorganization, merger, acquisition, sale, or similar corporate event.

The current code does not implement geolocation blocking, sanctions or wallet screening, KYC, age verification, or automated eligibility decisions. Those purposes must not be claimed as operational unless corresponding controls and disclosures are deployed.

We may aggregate or deidentify information and use it for lawful purposes. We will not attempt to reidentify information treated as deidentified where law prohibits it.

7. How we disclose information

We may disclose the information described in this Notice to:

  • Hosting and security providers, including Cloudflare and related infrastructure vendors;
  • Wallet and connection providers, including your wallet, ConnectKit, Wagmi, Reown or WalletConnect, and RPC providers;
  • Route and protocol providers, including Relay, solvers, bridges, supported networks, token contracts, Lighter, Uniswap, and explorers, as necessary for the interaction you request;
  • Professional advisers and vendors, such as lawyers, auditors, insurers, security firms, email providers, and compliance providers, subject to appropriate duties;
  • Authorities and affected parties where we reasonably believe disclosure is required or permitted to comply with law, protect rights or safety, investigate misconduct, or respond to an emergency; and
  • Transaction counterparties and successors in a financing, diligence process, reorganization, merger, acquisition, bankruptcy, or sale, subject to lawful safeguards.

A blockchain transaction discloses information publicly to validators, nodes, indexers, analytics companies, explorers, and anyone else. We cannot control their collection, replication, analysis, or retention.

8. Third-party services

Some Third-Party Services act independently and some may process data for or jointly with the Operator; that role depends on facts and contracts that must be inventoried before launch. Review their notices. Wallet providers may process device and account data; RPC providers receive addresses and queries; Relay receives wallet and route details; Lighter receives market-data connections; and public networks publish transactions. A third party may combine that information with data it already has. Nothing here disclaims the Operator's own selection, configuration, disclosure, contracting, or non-waivable duties.

9. Cookies and browser storage

The current Interface uses storage necessary to requested features:

  • Wagmi stores connector and chain state in local storage. Wallets and WalletConnect or Reown can also use local storage and IndexedDB for client identifiers, pairing, and session state;
  • LEV7 stores the accepted legal-document version and timestamp in local storage and a signed, secure, same-site, HTTP-only server cookie with up to a one-year life to enforce the current gate; and
  • security and infrastructure providers may use strictly necessary cookies or equivalent storage to protect and deliver the service.

The current code disables Coinbase Wallet and WalletConnect functional telemetry and does not deploy advertising or first-party analytics cookies. WalletConnect may still initialize its client when a project ID is configured, even before wallet assent. Before serving a market requiring prior consent for that initialization or storage, the Operator must delay it or obtain valid consent. You can clear browser storage or wallet sessions in browser and wallet settings; doing so may disconnect the wallet or require renewed acceptance.

10. Sale, targeted advertising, DNT, and GPC

The current code does not configure advertising, cross-context behavioral advertising, or targeted-advertising uses, and the Operator does not receive payment for personal information through the Interface. The Operator must review vendor contracts and actual production transfers before launch to confirm whether any disclosure is a regulated “sale,” “sharing,” or targeted-advertising activity. If it is, the Operator must add the required opt-out methods and signals before the activity begins.

Browsers may send Do Not Track signals, for which no uniform legal or technical standard applies. Because we do not currently engage in cross-site behavioral tracking, the Interface does not change its behavior in response to DNT. The Interface currently has no configured sale, sharing, or targeted-advertising activity for Global Privacy Control to change. If such activity is introduced, legally recognized preference signals must be detected and honored before launch. Third-Party Services may collect activity under their own practices, subject to the role and contract review described above.

11. Retention

The application code does not write wallet, quote, route, or transaction-risk-checkbox data to a first-party database. It processes those values in the browser or Worker, while Cloudflare logs may record requests and providers receive the data described above. The Operator has not configured or documented the exact Cloudflare, email, or vendor periods. That is a launch blocker: the final Notice must state each actual period, or a specific criterion where a fixed period cannot be given, and deletion must be configured and tested.

Wagmi, wallet, and WalletConnect browser records remain until their software expires or removes them or you clear them. The local legal record remains until cleared or superseded; the signed acceptance cookie lasts up to one year. Provider periods are set by those providers and must be inventoried. Public blockchain records and copies held by nodes or third parties may persist indefinitely and cannot be deleted by the Operator.

12. Security

The current code uses HTTPS deployment assumptions, same-origin JSON checks, a signed secure HTTP-only acceptance cookie, and disabled connector telemetry. Those technical measures are limited and do not establish a complete security program. Before launch, the Operator must adopt and test access control, vendor diligence, incident response, deletion, breach assessment and notice, training, and review programs. No system, wallet, network, transmission, or storage method is completely secure. Protect your device and wallet, verify domains and contract addresses, and never disclose a private key or recovery phrase.

13. International processing

The Interface and providers may process information in the United States and other countries whose laws differ from those where you live. Public blockchains operate globally and do not have a single processing location. The Operator has not yet verified adequacy coverage, contractual clauses, supplementary measures, processor agreements, or how a person may obtain a copy of applicable safeguards. The Interface must not be offered in a market requiring those measures until they are selected, executed, documented, and accurately described here.

14. Your privacy rights

Depending on where you live and subject to exceptions, you may have the right to request access to or a copy of personal information; learn its categories, sources, purposes, and recipients; correct it; delete it; obtain a portable copy; restrict or object to processing; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain sensitive-information use; and appeal a denied request. You also may have the right not to receive discriminatory treatment for exercising a right.

The intended request address is privacy@lev7.finance, but it must be provisioned and tested before launch. The Operator has not yet built the required intake, safe email or signed-message verification, authorized-agent, access, correction, deletion, export, appeal, deadline, or audit-log workflows. The Interface must not launch where those duties apply until the workflows and all required request methods are operational. We will never request a private key or transaction to verify a privacy request.

Rights apply only to information we control. We cannot edit or delete a blockchain, reverse a transaction, or require independent third parties to delete their copies. We may retain information where an exception applies, including for security, legal compliance, or claims.

California disclosures

The Operator has not supplied the production logs and vendor records needed to make a verified preceding-12-month disclosure. Before this Notice is approved, those records must be reconciled against the categories below. Based solely on the current code, the Interface is capable of collecting: identifiers (IP address, public wallet address, ENS name, and wallet or WalletConnect client identifiers); Internet or other electronic network activity (requests, pages, browser/device details, referrer, errors, and wallet/RPC connections); commercial information (requested assets, amounts, routes, and public transaction activity); approximate geolocation inferred from IP by infrastructure providers; and communications you send. The code does not intentionally collect the sensitive categories listed in section 2 or create eligibility inferences.

The current code can disclose identifiers and network activity to Cloudflare, wallet/connection systems, RPCs, Lighter, and remote media hosts; and identifiers, commercial information, and network activity to Relay, solvers, supported networks, and explorers when you request a route or transaction. A signed transaction makes identifiers and commercial activity public. The code does not configure a sale or cross-context behavioral sharing of these categories, but the Operator must complete both the historical-record review and contract-based classification described in section 10. Sources and purposes are in sections 4 and 5. Where the CCPA applies, the rights above and the legally required lookback period apply.

EEA and UK rights

Where GDPR or UK GDPR applies, you may also object to processing based on legitimate interests, request restriction, and lodge a complaint with your local data-protection supervisory authority. We encourage you to contact us first. The Operator must determine whether an EU or UK representative or data-protection officer is legally required and add their contact information before launch in those markets.

15. Children

The Interface is intended only for adults who are at least 18 and the legal age of majority where they live. Public pages are not currently age-verified, so infrastructure and direct market-data services can receive ordinary network data before the adult affirmation. The Interface is not directed to children. An age statement does not replace obligations that apply if the Operator gains actual knowledge or if age-design laws apply. If you believe a child has provided offchain personal information, contact privacy@lev7.finance so we can investigate and delete it where appropriate. Public blockchain data may not be removable.

16. Changes to this Notice

We may update this Notice to reflect changed practices, technology, vendors, or law. We will post the revised Notice with its new date and version. If a change is material, we will provide additional notice and obtain consent where required. A new Notice does not authorize materially different processing before it becomes effective.

17. Contact

The intended request address is privacy@lev7.finance, but it must be provisioned, monitored, and tested before publication. The Operator's legal name, physical address, formation jurisdiction, additional legally required request methods, and any required representative or DPO details must also be added before launch. Do not send private keys, recovery phrases, or unnecessary sensitive information. This Notice version is 2026-07-21-v2.