This notice explains the limited personal data used to operate controlled CLXAI member access.
CLXAI never requests or stores wallet seed phrases, private keys, payment-card data or custody credentials.
01 / DATA
What is processed
We process your chosen display name, email address, one-way password hash, account status, consent and login timestamps, server-side session identifiers, short-lived token hashes, random referral code, referral qualification status, any Solana public address you voluntarily verify or submit, the time and version of its signed ownership proof, and a minimal administrative audit trail. For abuse review, a random first-party device identifier and a shortened network prefix are converted to keyed HMAC values before storage. Raw device identifiers and raw IP addresses are not stored in the referral-risk tables.
02 / PURPOSE
Why it is processed
The data is used only to review membership, authenticate members, verify email and wallet control, attribute and qualify referrals, show aggregate status counts, prevent duplicate or replayed claims, administer controlled airdrop submissions, deliver requested recovery emails, protect the service and maintain an accountable access history. Device or network matches are risk indicators for human review and are never the sole reason for rejection.
03 / RETENTION
How long it is kept
Unapproved requests are automatically removed after 90 days. Device and network risk HMACs expire after 30 days. Wallet-signature challenges expire after ten minutes and cannot be replayed. Approved account data, verified public addresses and referral attribution remain until the account is deleted or access is withdrawn, subject to records that must be retained for completed reward accountability. Expired sessions and recovery tokens are removed automatically. Security audit records may be retained for incident investigation and accountability.
04 / CONTROL
Your choices
Wallet verification is voluntary for membership, but a signed proof of control is required to participate in the optional Airdrop. Approved members can verify, change or remove a public Solana address before it is locked by an approved referral, final submission or the Airdrop snapshot, reset a forgotten password by email and permanently delete their account. Signing the displayed message does not authorize a transaction or token transfer. Referral dashboards show aggregate counts only, not another member’s identity. For access, correction, objection or deletion questions, contact [email protected].
05 / SECURITY
How it is protected
Access is protected through HTTPS, strong password hashing, single-use time-limited links and challenges, HttpOnly secure cookies, strict same-origin checks, rate limits, optional server-validated Turnstile checks, signed wallet proof, manual approval and server-side authorization. Referral rewards require documented administrator approval and never trigger automatic payment. No online system can promise absolute security.