ovlo

Privacy policy

We built ovlo without accounts or emails on purpose. This page explains exactly what we do process, why, and for how long.

Last updated September 2026

What we collect

To perform a swap

  • The assets, networks and amounts you selected
  • The receiving address and, if provided, refund address
  • The deposit address and transaction hashes involved
  • Status updates from the liquidity partner executing the swap

All of this is public-blockchain data or data you supply to complete the transaction. It is stored so your status page works and so support can help you.

To keep the service running

  • A salted, truncated hash of your IP address at the moment a swap is created, for rate limiting and abuse prevention. The raw IP is not stored.
  • Standard server logs (request paths, timing, error codes) retained for up to 30 days. Logs redact secrets and addresses where practical.

What we don't collect

  • No names, emails, phone numbers or identity documents
  • No accounts or passwords
  • No third-party analytics, advertising pixels or tracking cookies

Cookies and local storage

The public site sets no cookies. Your browser's local storage remembers your last selected asset pair for convenience; you can clear it at any time. The administrative area, used only by our staff, uses a session cookie.

Who else sees your data

To execute a swap we send the swap parameters (assets, amount, addresses) to the liquidity partner that performs it. They process this data under their own terms and may perform compliance screening as required by law. Blockchain transactions are public by nature.

Retention

Swap records are kept for as long as needed to support the swap, resolve disputes and meet legal obligations, and are then deleted or anonymised.

Your rights

Because we hold no identity data, we usually cannot link records to a person. If you can demonstrate control of an address involved in a swap, you may request the related records or their deletion (subject to legal retention) at legal@ovlo.lol.

Security

All traffic is encrypted in transit. Provider credentials for your swap are encrypted at rest. Administrative access is password-protected, rate-limited and audit-logged, and is read-only.