Privacy
Privacy Policy
Last updated: October 6, 2026
This policy covers the RSoft AI Sponsor mobile app and the website rsoft-agentic-bank.com, both operated by RSoft Latam (La Paz, Bolivia). The app lets a person answer for an AI agent: approve the credit it asks for, set its limits, pause it and talk to it. The app never holds money and never holds your private keys for any wallet other than the signing key it creates on your phone.
What we collect
- Account: the email address and password you sign up with. Passwords are hashed by our authentication provider; we never see them.
- Sponsor key: the public address of the signing key the app creates on your phone. The private key stays in your phone's secure hardware (Keychain on iOS, Keystore on Android) and never leaves it.
- Agents: the wallet addresses of the AI agents you follow or sponsor, and the names you give them.
- Mailbox: the messages you send to your agents through the bank's mailbox and their replies.
- Decisions: every approval, rejection, pause, resume, limit change and unlink you sign, with its timestamp. These are the bank's audit trail for the agent you answer for.
- Device: a push notification token (so the app can tell you when an agent asks for approval), the platform and app version.
- Preferences: language and theme.
- Linked chats: if you link an external agent by URL, that URL and the conversation. An API key you type for it stays on your phone only.
What we do not collect
- No money, balances or payment methods: the app reads public blockchain data about the agents you watch; it never custodies funds.
- No contacts, photos, location, microphone or camera.
- No advertising identifiers and no third-party analytics or tracking SDKs.
Why we use it
- To sign you in and keep your agents, chats and preferences across phones.
- To route notifications to the phone of the person who answers for an agent.
- To keep the record of what you approved: the bank needs to show who authorized what.
- To operate, secure and improve the service. We do not sell personal data and we do not use it for advertising.
Where it lives and who sees it
- Supabase (hosting of accounts and app data, servers in the United States).
- Amazon Web Services (the bank's API).
- Expo push service, Apple Push Notification service and Firebase Cloud Messaging (delivery of notifications; they receive the push token and the notification text).
- Public blockchain networks (Base): wallet addresses and the signatures that bind a sponsor to an agent are public and permanent by design. Never put personal information in a wallet address or an agent's name.
- We share data only with these providers, as needed to run the service, or when the law requires it.
How long we keep it
- Account data, agents, chats and preferences: until you delete your account.
- Push tokens: removed when you sign out or delete the account.
- Signed decisions: kept as part of the bank's audit trail for as long as the agent's history is kept, because they document who authorized a loan. They are linked to your sponsor address, not to your email.
- On-chain records cannot be deleted by anyone.
Security
- All traffic uses TLS. Sessions and keys are stored in the phone's secure storage. Every decision requires your fingerprint or face on the device and is signed locally; the server verifies the signature and never has the key.
Your rights
- You can see and edit your agents, chats and preferences in the app, and sign out from any phone.
- You can ask for a copy of your data or have your account deleted: see the account deletion page.
- The service is for people 18 and older. We do not knowingly collect data from minors.
Changes
- If this policy changes in a way that matters, the app and this page will say so, with the date above updated.
