Legal

Privacy & Cookie Policy

Last updated: 11 May 2026

1. Who we are

Vestream ("Vestream", "we", "us", "our") is a token vesting tracking and indexing service. Vestream is owned and operated by 3UILD LLC, a limited liability company. References to "the Service" in this policy include the Vestream website (vestream.io), the authenticated dashboard, the Vestream mobile app (iOS / Android), the developer REST API, and the Vestream Model Context Protocol (MCP) server.

For questions about this policy or to exercise any of your rights described below, contact us at [email protected].

2. Information we collect

We collect only what we need to operate the Service. By category:

  • Account identifiers. When you sign up via the mobile app, we store your email address as your account identifier. We authenticate sessions with a one-time code emailed to that address – no password, and we never request or store wallet keys. The desktop dashboard signs you in by scanning a QR code from the mobile app (Pro tier only); your phone authenticates the desktop session.
  • Tracked wallet addresses. EVM (0x…) or Solana (base58) addresses you choose to monitor. These are stored so we can fetch their vesting positions on your behalf and notify you of upcoming unlocks. Wallet addresses are public on-chain data.
  • Notification preferences. Email opt-in status, hours-before-unlock alert preference, and (for the mobile app) an Expo push token issued by your device.
  • Subscription & billing identifiers. If you purchase a paid plan, we store the corresponding RevenueCat customer and subscription ID. Card details are never stored on our infrastructure – they are handled by Apple App Store / Google Play via RevenueCat.
  • Session data. A cryptographically signed, HTTP-only session cookie (web) or bearer token (mobile / API) used to keep you signed in.
  • Developer API keys. If you apply for API access, we store your name, email, company name (optional), and a SHA-256 hash of any issued API keys. Plaintext keys are shown once and never stored.
  • Analytics & technical logs. If you accept analytics cookies, we collect anonymised page-view and event data via Google Analytics 4. Server logs (IP address, user agent, timestamp) are retained briefly for security and rate-limit enforcement.

We do not collect passwords, private keys, seed phrases, or any signing credentials. The Service is read-only – we cannot move your tokens or sign transactions on your behalf.

3. How we use your information

  • To display vesting positions for the addresses you track.
  • To authenticate your sessions across the website, mobile app, and developer API.
  • To send you email or push notifications about upcoming unlock events, when you opt in.
  • To process mobile subscription payments via RevenueCat (Apple App Store / Google Play) and to provision the corresponding service tier.
  • To enforce rate limits and detect abuse of the Service.
  • To analyse aggregate, anonymised usage of the Service to improve it (only when you accept analytics cookies).
  • To respond to your support requests, legal requests, or rights requests.

We do not sell your personal information. We do not share your personal information with third parties for their direct marketing.

4. On-chain data and aggregated index

Vestream maintains an aggregated, anonymised index of public vesting positions across the protocols and chains we support (Sablier, Hedgey, Superfluid, LlamaPay, UNCX, Unvest, Team Finance, PinkSale, HoodLock, Magna, Streamflow, Jupiter Lock – across Ethereum, Base, BNB Chain, Polygon, Arbitrum, Optimism, Avalanche, Robinhood Chain, and Solana). This index is built from publicly available on-chain data and protocol subgraphs.

On-chain data – including wallet balances, vesting schedules, token movements – is inherently public and does not become "your data" by virtue of you tracking a wallet on Vestream. We may use this aggregated, anonymised index to provide statistics, power public-facing pages (e.g. our /protocols and /unlocks calendar), expose it via our developer API and MCP server, and to operate and improve the Service. The presence of a wallet on our index does not imply ownership or control of that wallet by you.

5. Cookies

We use a small number of cookies, grouped by purpose:

  • Essential. An encrypted, HTTP-only session cookie set when you sign in. Required to keep you signed in; cannot be disabled if you wish to use the dashboard.
  • Analytics (optional). Google Analytics 4 cookies, loaded only after you accept analytics in our cookie banner. Used for anonymised page-view and event reporting.

We do not use any advertising or cross-site tracking cookies.

6. Third-party processors

The Service relies on the following sub-processors:

  • Supabase (Postgres database, EU region – AWS eu-west-1) – stores account, wallet, notification, and indexed-stream data.
  • Vercel – application hosting and edge CDN.
  • Upstash – Redis for rate limiting.
  • Resend – transactional email (sign-in OTP, unlock alerts).
  • Alchemy – Ethereum, Base, and Solana RPC.
  • BSC and Polygon RPC providers – chain reads.
  • The Graph – protocol subgraphs (Sablier, Hedgey, UNCX, Unvest, Superfluid).
  • DefiLlama – public TVL aggregates for select protocols.
  • DexScreener and CoinGecko – token price data for USD-equivalents shown in the dashboard.
  • RevenueCat + Apple App Store / Google Play – mobile in-app purchases.
  • Google Analytics 4 – anonymised analytics, only with your consent.
  • Sentry (if enabled) – error reporting; configured to scrub personal data.

Each third party operates under its own privacy policy. We maintain a current list of sub-processors and will publish changes here.

7. International transfers

3UILD LLC is established in the United States. Personal data we hold may be processed in the United States, the European Union (Supabase EU region), or wherever our sub-processors operate. We rely on the Standard Contractual Clauses or equivalent safeguards for international transfers where required.

8. Data retention

  • Account email + tracked wallets: retained until you delete your account or remove the wallets.
  • Notification preferences: retained until you turn off notifications or delete your account.
  • Subscription identifiers: retained for the lifetime of the subscription plus any period required by tax / accounting law.
  • Server logs: 30 days unless required for security investigations.
  • Aggregated, anonymised index data: retained indefinitely as part of the Service's public dataset.
  • API key hashes: until you or we revoke the key.

9. Your rights

Depending on where you live, you may have the right to: access, correct, delete, port, or restrict processing of your personal data; withdraw consent for analytics; object to processing based on legitimate interest; and lodge a complaint with your data protection authority.

To exercise any of these, email [email protected]. We will respond within 30 days.

You can also delete your tracked wallets and notification preferences directly from the dashboard at any time, or unsubscribe from emails using the link in any notification email.

10. Children

The Service is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Security

We use industry-standard measures to protect your data: TLS for all traffic, encrypted session cookies, hashed API keys, role- based access to production systems, and least-privilege database roles. No system is perfectly secure; we cannot guarantee absolute security but we work to reduce risk continuously.

We cannot access your private keys and cannot initiate transactions on your behalf. The Service is read-only.

12. Changes to this policy

We may update this Privacy & Cookie Policy from time to time. When we make material changes, we will update the "Last updated" date at the top, and notify active users via email or in-app notice. Continued use of the Service after a change constitutes acceptance of the updated policy.

13. Contact

3UILD LLC
Email: [email protected]