Pre-launch draft · Counsel review required

Privacy & data

Privacy Policy

How Sovra expects to collect, use, protect, retain, and disclose personal information when the U.S. platform becomes operational.

Updated September 1, 2026 10 min read

1. Pre-launch status

Sovra is currently a product concept and does not yet onboard customers, hold funds, or provide digital asset services. This privacy policy is a pre-launch draft describing planned practices for a future U.S. operating entity.

Before launch, the legal entity, state of formation, business address, privacy contact, service providers, retention schedule, applicable state notices, and verified request methods must be inserted and reviewed by qualified U.S. counsel.

This draft is not evidence that Sovra is licensed, registered, operational, or currently processing customer account data.

2. Scope

This policy is intended to cover Sovra websites, mobile applications, customer support, identity verification, trading, hosted wallets, security monitoring, and related communications. It will not govern the independent practices of blockchains, banks, identity providers, or third-party websites.

3. Information we may collect

  • Identifiers and contact information, including name, date of birth, mailing address, email, phone number, Social Security or taxpayer identification number, and government-issued identification.
  • Account and authentication information, including credentials, passkeys, security settings, recovery methods, preferences, and authorized devices.
  • Financial and transaction information, including linked bank details, deposits, withdrawals, orders, balances, wallet addresses, blockchain transaction identifiers, and source-of-funds or source-of-wealth information.
  • Compliance information, including identity-verification results, sanctions and politically exposed person screening, fraud indicators, adverse information, customer risk ratings, and case records.
  • Internet, device, and usage information, including IP address, device identifiers, browser and app data, session activity, approximate location, logs, and security events.
  • Communications, support tickets, complaint evidence, survey responses, and marketing choices.
  • Inferences derived from the above information for fraud, security, compliance, product, and customer-support purposes.

4. Sources of information

Information may come directly from you; your device; linked banks and payment partners; identity, fraud, sanctions, blockchain analytics, custody, and liquidity providers; public records; affiliates; counterparties; and authorities where permitted by law.

5. How information may be used

  • Open, operate, secure, and support accounts; process orders, transfers, statements, and customer requests.
  • Verify identity; conduct KYC and customer due diligence; screen sanctions; monitor transactions; investigate alerts; and meet Bank Secrecy Act, tax, licensing, legal-process, and recordkeeping obligations.
  • Prevent fraud, account takeover, market abuse, money laundering, terrorist financing, sanctions evasion, and other misuse.
  • Reconcile customer assets and cash, manage risk, audit controls, respond to disputes, and protect Sovra, users, and the public.
  • Maintain, debug, secure, measure, and improve the service using proportionate analytics.
  • Send service notices and, with any consent required by law, optional product or marketing communications.

6. Disclosures to other parties

Sovra may disclose the minimum necessary information to identity-verification vendors, banks, payment processors, custody and wallet providers, liquidity venues, blockchain analytics providers, cloud and cybersecurity vendors, customer-support providers, auditors, insurers, and professional advisers.

Information may also be disclosed to FinCEN, OFAC, the IRS, state regulators, courts, law enforcement, and other competent authorities where required or permitted. Sovra does not plan to sell personal information for money. Any advertising-related sharing will be assessed under applicable state opt-out laws before launch.

7. Public blockchain records

Public blockchains are designed to preserve transaction records. Wallet addresses and transaction details may remain publicly visible and may be impossible for Sovra to alter or delete. Do not place personal information in public transaction memos or similar fields.

8. Retention and security

Sovra will retain information only as reasonably necessary for the disclosed purpose and applicable BSA/AML, sanctions, state licensing, tax, accounting, fraud, litigation, cybersecurity, and recordkeeping requirements. Some records must be retained after account closure or a deletion request.

Planned safeguards include encryption, least-privilege access, multi-factor authentication, secure development, vendor due diligence, audit logging, monitoring, incident response, recovery tests, and periodic access reviews. No system can be guaranteed completely secure.

9. U.S. state privacy rights

Depending on your state and whether the relevant law applies to Sovra, you may have rights to know or access, correct, delete, or obtain a portable copy of personal information; opt out of sale, targeted advertising, certain sharing, or qualifying profiling; limit certain uses of sensitive information; and appeal a denied request. Sovra will not discriminate against you for exercising an applicable privacy right.

Before launch, Sovra will publish at least two verified request methods where required and disclose any state-specific appeal and authorized-agent process. Identity verification may be required. Requests may be denied or limited where an exemption applies, including legal retention, security, fraud prevention, or Bank Secrecy Act restrictions.

10. California notice

If Sovra becomes subject to the California Consumer Privacy Act, the final policy will include the required 12-month category disclosures, purposes, sources, recipient categories, retention criteria, sensitive information practices, sale or sharing disclosures, consumer request metrics where required, and links for opt-out or limitation rights.

The current concept site does not sell or share personal information for cross-context behavioral advertising. Applicability and final California disclosures must be confirmed before accepting California residents.

11. Children, transfers, and changes

The future service is intended only for adults aged 18 and older and will not knowingly open trading accounts for children.

Service providers may process information in other U.S. states or countries, subject to applicable contractual, security, sanctions, and transfer controls. Material policy changes will be communicated through the service or another appropriate channel.

12. Privacy contact

The final operating entity, mailing address, toll-free number if required, privacy email, request portal, and appeal contact will be published before customer onboarding. No sensitive information should be submitted through this concept website.