Reference
Security and privacy
- Sign-in is passwordless via Privy (email code, Google, X, wallet). We store your email, an opaque user id and any wallet you signed in with. No private keys ever touch our systems.
- OAuth for MCP clients follows the MCP authorization spec: PKCE, short-lived access tokens (1 h), rotating refresh tokens (30 days), revocation. Approve once per app; disconnect any time from the dashboard.
- API keys are shown once and stored hashed. Revoke individually.
- Data access is read-only. No tool can trade, sign or move funds.
- Usage records keep the tool name, arguments summary, cost and timing for your dashboard and billing.
- Payments are processed by Stripe; we never see card numbers.
Questions: @StalkHQ.
Last modified on