ana
fi
ProductTrustCompliancePricingPartnersAbout
Launch app
ProductTrustCompliancePricingPartnersAbout

Privacy Policy

Anafi Solutions Inc. Last updated: 15 September 2026

This Privacy Policy explains what personal data Anafi Solutions Inc., 8 The Green, Suite R, Dover, Kent County, DE 19901, USA (“Anafi”, “we”, “us”) collects when you use ana.fi, app.ana.fi, the Anafi API, the Anafi policy language and authorization runtime, and related services (the “Services”), how we use it, and what rights you have. It should be read with our Terms of Service.

Anafi is the controller of the personal data described here. Partners that provide on-ramp, off-ramp, banking, or settlement services are independent controllers of the data they collect from you, including identity-verification data; their privacy policies govern that data.

1. Data we collect

Data you give us

  • Contact data. Name, email address, company, role, and message content when you request a demo, join a waitlist, subscribe to updates, contact us, or open an account.
  • Account data. Login identifiers and settings for app.ana.fi and API access, including API keys we issue to you.
  • Policy data. The rules you define in a Policy: recipients (wallet addresses, payment references, or Partner account identifiers), amounts, limits, schedules, and any labels or notes you attach. Policy data may include personal data about third parties (for example, a recipient’s name or bank reference) that you enter; you are responsible for having the right to provide it.
  • Business data. For business customers and integrators: company details, billing information, and the details of your authorised users.

Data collected automatically

  • Wallet and on-chain data. Wallet addresses you connect, delegations and session keys you grant, and the public on-chain transactions executed under a Policy. On-chain data is public and permanent by nature.
  • Runtime data. Logs of Policy evaluations (the request, the decision, the reason, and a timestamp), which we keep for security, debugging, and auditability of the runtime. Where the runtime executes inside a trusted execution environment, evaluation inputs are processed there and only the outcome and attestation are logged outside it.
  • Technical data. IP address, browser and device type, operating system, language, referring URL, pages visited, and timestamps, collected through server logs and Google Analytics.
  • Cookies. See Section 8.

Data from other sources

  • Partners. Status signals from Partners (for example, whether an off-ramp transaction was accepted, completed, or declined) tied to a transaction reference. We do not receive your identity-verification documents from Partners.
  • Screening providers. Results of wallet-address screening against sanctions and risk lists.
  • Public blockchains. Transaction history for addresses you connect, read from public chain data.

We do not collect private keys or seed phrases and never ask for them.

2. Why we use your data and on what basis

Purpose Data Legal basis (GDPR/UK GDPR)
Provide the Services, evaluate and execute Policies Account, Policy, wallet, runtime data Performance of a contract
Respond to enquiries, demo requests, support Contact data Contract / legitimate interest
Security, fraud prevention, abuse detection Technical, runtime, screening data Legitimate interest; legal obligation
Sanctions and legal compliance Wallet, screening data Legal obligation; legitimate interest
Billing and accounting Account, business, transaction data Contract; legal obligation
Product analytics and improvement Technical data (aggregated where possible) Legitimate interest; consent where required for cookies
Product updates and marketing Contact data Consent, or legitimate interest for existing customers, with opt-out
Establishing or defending legal claims Any of the above Legitimate interest

We do not sell personal data and do not use it for automated decisions that produce legal or similarly significant effects on you. Policy evaluation is deterministic execution of rules you wrote; it is not profiling.

3. Who we share data with

  • Partners — to the extent needed to initiate and track a transaction you have instructed (typically a transaction reference, amount, destination, and wallet address). Partners then process your data under their own policies.
  • Service providers — hosting, TEE infrastructure, email delivery, analytics, customer support, error monitoring, address-screening, and payment processing, acting on our instructions under data-processing agreements. A list of current sub-processors is available on request.
  • Public blockchains — transactions executed under a Policy are broadcast to the relevant network and are public.
  • Professional advisers — lawyers, accountants, auditors, and insurers, under confidentiality.
  • Authorities — where required by law, regulation, court order, or to protect our rights or the safety of others.
  • Corporate transactions — a buyer or successor in a merger, acquisition, financing, or asset sale, subject to this Policy.

4. International transfers

Anafi is established in the United States and uses service providers in the United States and the European Union. Where personal data of EEA, UK, or Swiss residents is transferred outside those areas, we rely on the European Commission’s Standard Contractual Clauses (and the UK addendum) or another lawful transfer mechanism. Copies are available on request.

5. Retention

Data Retention
Contact and account data For the life of the account, then 12 months
Policy data (off-chain) Until you delete the Policy, then 90 days in backups
Runtime evaluation logs 18 months
Technical logs 90 days
Billing and compliance records As required by law, typically 7 years
On-chain data Permanent; outside our control

We may keep data longer where needed for a legal claim, an investigation, or a legal obligation.

6. Blockchain data

Transactions executed under a Policy are recorded on public blockchains. They are visible to anyone, cannot be altered or deleted by Anafi, and may be linked to you by third parties. Rights to erasure and rectification do not apply to on-chain data. Before creating a Policy, consider that recipient addresses, amounts, and timing will be public.

7. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and receive a copy;
  • correct inaccurate data;
  • delete data (subject to Section 6 and legal retention requirements);
  • restrict or object to processing, including for direct marketing;
  • receive your data in a portable format;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with a supervisory authority (in the EEA, the authority of your country of residence; in the UK, the ICO).

California residents have, under the CCPA/CPRA, the rights to know, delete, correct, and to opt out of sale or sharing of personal information, and the right not to be discriminated against for exercising them. Anafi does not sell or share personal information as defined by the CCPA. Residents of other US states with comprehensive privacy laws have similar rights.

To exercise any right, email k@anafi.cc. We will verify your identity (typically by confirming control of the email or wallet address on record) and respond within the period required by law, normally 30 days. You may use an authorised agent where the law permits.

8. Cookies and analytics

ana.fi and app.ana.fi use:

  • Strictly necessary cookies — session, security, and preference cookies needed for the site and app to work. No consent required.
  • Analytics cookies — Google Analytics (Google LLC), which sets cookies to measure how visitors use the site (pages viewed, session duration, approximate location, device type). IP addresses are anonymised. Google processes this data under its own terms; see Google’s privacy policy and its opt-out add-on at tools.google.com/dlpage/gaoptout. Analytics cookies are loaded only after you consent where consent is required (EEA, UK, Switzerland).

We do not use advertising or cross-site tracking cookies. Where consent is required, a banner asks for it and you can change your choice at any time via the “Cookie settings” link in the footer. Most browsers also let you block or delete cookies.

9. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, logging, and isolation of the authorization runtime in trusted execution environments. Smart contracts and runtime components are subject to independent security audits. No system is fully secure; you are responsible for securing your wallet, keys, and devices.

10. Children

The Services are not directed to anyone under 18 and we do not knowingly collect data from them. If you believe a minor has provided us data, contact k@anafi.cc and we will delete it.

11. Third-party sites

The Services link to Partner sites, block explorers, documentation, and social platforms. Their privacy practices are their own.

12. Changes

We may update this Policy. The current version is always at ana.fi/privacy with its “last updated” date. Material changes will be notified by email or in-app notice at least 7 days before taking effect.

13. Contact

Anafi Solutions Inc. 8 The Green, Suite R, Dover, Kent County, DE 19901, USA k@anafi.cc

ana
fi
NON-CUSTODIAL DELEGATIONS FOR STABLECOINS
PLATFORM
ProductPricingApp ↗
SECURITY
Trust & SecurityAuditability & Compliance
COMPANY
About UsPartners
CONTACT
hi@ana.fiRequest a Demo ↗Telegram ↗
© 2026 Anafi Solutions Inc. Non-custodial software only — not a bank, custodian, or money transmitter. Third-party services under their own terms. Not financial advice.
LegalPrivacyTerms & Conditions