DOCS / PRIVACY POLICY
Privacy Policy
Pantessa is non-custodial and collects as little as it can to run the Service. This policy explains what we collect, why, who we share it with, and what stays public on-chain.
Last updated: September 3, 2026
This Privacy Policy describes how Yeetful, Inc., doing business as Pantessa (“Pantessa,” “we”), handles information when you use the Pantessa website, chat interface, dashboard, embeddable widget, SDK, and APIs (the “Service”). By using the Service you agree to this policy. It works alongside our Terms of Service.
1. Information we collect
Wallet and on-chain data. Your public wallet address, the Sign-In With Ethereum signatures you produce, consent signatures you provide for specific actions, and the on-chain records (amounts, assets, counterparties, transaction hashes) generated by transactions you sign. Blockchain data is public and permanent by design.
Sign-in and account data. When you sign in or create an embedded wallet, authentication is handled by Coinbase Developer Platform (“CDP”). Depending on the method, we or CDP receive: your email address (email sign-in), or basic profile details from Google or X single sign-on (such as your name, email, and a provider account identifier). We never receive your Google, X, or wallet password, and the embedded wallet’s private keys are held in CDP’s secure infrastructure, not by us.
What you type. The requests you write in the chat interface, the conversation history attached to your account, and any handle, branding, or link content you publish. When a request that involved money could not be completed, we log the text of that request together with a summary of the balances that were available, so we can find and fix the gap.
Usage and ledger data. API key metadata (we store only a hash of each secret, never the secret itself), spend grants and approvals, organizations and members, jobs and scheduled actions you create, receipts for settled and refused calls, and telemetry about transactions prepared, signed, or abandoned, including on sites that embed our widget.
Technical data. Server and request logs, your IP address, and a secure httpOnly session cookie for signed-in sessions. We use your IP address to apply rate limits and prevent abuse, and we store it in hashed form for that purpose. Where a fiat on-ramp provider requires it to determine whether it can serve you, your IP address may be sent to that provider. We also keep aggregate, privacy-preserving analytics about site usage.
Payment data. If you subscribe to a paid plan, payment is processed by Stripe. We receive subscription status and billing metadata; we do not receive or store your full card details. If you buy crypto through a fiat on-ramp, that purchase is handled by the on-ramp provider under its own policy, and we do not receive your payment details.
2. Single sign-on (Google, X) and email
Social sign-in (“SSO”) and email sign-in are provided through Coinbase CDP’s embedded-wallet authentication. When you choose “Continue with Google” or “Continue with X,” you authenticate with that provider, which returns a limited set of profile information (typically email, name, and an account identifier) used to create or sign you into your Pantessa embedded wallet. We use this only to authenticate you, create your account, and contact you about the Service. We do not post to your social accounts or access your contacts. Your use of Google or X is also governed by their own privacy policies, and your use of the embedded wallet by Coinbase’s privacy policy. You can use a self-custodied wallet instead if you prefer not to use SSO or email.
3. AI processing of your requests
The Service uses a third-party AI model provider to interpret what you ask for. The text of your request, and context such as which integrations you have enabled and the public balances we read for your wallet, may be sent to that provider so it can be understood and routed. We currently use Anthropic for this.
The model interprets your request and helps choose a route. It does not write the transaction: transaction data is generated by our own code from a fixed set of builders and independently re-checked before it is shown to you. Please do not paste private keys, seed phrases, or other secrets into the chat.
4. How we use information
- provide, operate, and secure the Service and your account;
- interpret your requests and prepare the transactions you ask for;
- enforce spend controls and produce receipts and ledgers;
- run jobs, schedules, and protective actions you have explicitly enabled;
- route calls to third-party services you select or that the engine selects;
- prevent fraud, abuse, and security incidents, and comply with law;
- diagnose failures — including reviewing requests that could not be completed — and improve the Service;
- understand usage in aggregate;
- send you transactional or service-related messages.
5. How information is shared
We share information only as needed to run the Service:
- Service providers and processors — including Coinbase CDP (authentication, embedded wallets, and fiat on-ramp), Stripe (subscription billing, and fiat on-ramp where used), Anthropic (AI processing of your requests), blockchain node and data providers, our database and hosting providers, email delivery, and analytics. They process data on our behalf or under their own terms as described here.
- Fiat on-ramp providers — when you choose to buy crypto, we pass the destination wallet address, the amount, the asset and network, and where required your IP address, so the provider can create the purchase. The provider collects your identity and payment information directly from you under its own policy; we do not receive it.
- Third-party services and venues — when your request or the routing engine calls a service, the request is transmitted to that service, which handles it under its own policies.
- Public blockchain — transactions are written to a public ledger and are visible to anyone and effectively permanent.
- Content you publish — links, handles, public pages, and shared conversations you create are visible to anyone who has the address.
- Legal and safety — when required by law or to protect rights, safety, and the integrity of the Service.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
6. On-chain data is public and permanent
Wallet addresses and transactions on the networks we support are public and cannot be deleted or altered by us or anyone else. The public activity surface shows network payments in an anonymized, aggregate form (wallets truncated, refusals shown only in aggregate), but the underlying chain data remains public. Consider this before transacting.
7. Cookies and sessions
We use a strictly-necessary, httpOnly session cookie to keep you signed in after a Sign-In With Ethereum signature, and privacy-preserving analytics. We do not use third-party advertising cookies and we do not track you across other websites.
8. Data retention
We keep information for as long as your account is active or as needed to provide the Service, then for the period required to meet legal, security, and accounting obligations. Logs and rate-limiting records are kept for a short period and then deleted or aggregated. On-chain records cannot be deleted.
9. Your choices and rights
You can disconnect your wallet, revoke API keys, revoke any authorization you granted for automated actions, delete chats, revoke links you published, and request deletion of account data by contacting us. We will honor applicable requests, except where data must be retained by law or exists immutably on-chain.
10. If you are in the EEA or the UK
Where the GDPR or UK GDPR applies, Yeetful, Inc. is the controller of the personal data described here. We rely on these legal bases:
- Performance of a contract — to provide the Service you asked for, including interpreting your requests and preparing transactions;
- Legitimate interests — to secure the Service, prevent fraud and abuse, diagnose failures, and improve the product, balanced against your rights;
- Legal obligation — to meet accounting, tax, and law-enforcement requirements;
- Consent — where we ask for it, which you can withdraw at any time.
You have the right to access, correct, erase, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. You also have the right to lodge a complaint with your local supervisory authority. Where we transfer personal data outside the EEA or the UK, we rely on appropriate safeguards such as Standard Contractual Clauses. To exercise any right, contact us at privacy@yeetful.com.
11. If you are in California
California residents have the right to know what personal information we collect and how we use and disclose it, to request deletion or correction, and not to be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioural advertising. Requests can be made at privacy@yeetful.com.
12. Security and breach notification
We use reasonable technical and organizational measures to protect information (for example, storing only hashes of API key secrets, hashing IP addresses used for rate limiting, and keeping sessions in httpOnly cookies). No method of transmission or storage is perfectly secure, and you are responsible for safeguarding your wallet and credentials. If we become aware of a breach affecting your personal data, we will notify you and any relevant supervisory authority as required by applicable law and without undue delay.
13. Children
The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect information from children.
14. International users
We and our providers may process information in countries other than yours, which may have different data-protection laws. Where required, we rely on appropriate safeguards for such transfers.
15. Changes
We may update this policy; we will revise the date above and, for material changes, provide additional notice where appropriate.
16. Contact
Privacy questions or requests: privacy@yeetful.com.
This page describes how the Service actually handles data, but it is not legal advice. Qualified counsel should review it and confirm the processor list and regional disclosures before you rely on it.