# Security and privacy

- **Sign-in** is passwordless via Privy (email code, Google, X, wallet). We store your email, an opaque user id and any wallet you signed in with. No private keys ever touch our systems.
- **OAuth for MCP clients** follows the MCP authorization spec: PKCE, short-lived access tokens (1 h), rotating refresh tokens (30 days), revocation. Approve once per app; disconnect any time from the dashboard.
- **API keys** are shown once and stored hashed. Revoke individually.
- **Data access** is read-only. No tool can trade, sign or move funds.
- **Usage records** keep the tool name, arguments summary, cost and timing for your dashboard and billing.
- **Payments** are processed by Stripe; we never see card numbers.

Questions: [@StalkHQ](https://x.com/StalkHQ).
