01. Privacy-First Web3 Philosophy
Permit Protocol (“we”, “our”, or “us”) operates a non-custodial decentralized application interface. Unlike traditional banking or Web2 SaaS platforms, you do not need to create an account, provide an email address, submit government-issued identification, or link a credit card to use the protocol.
You interact with Permit solely by connecting your self-custodial cryptographic wallet (such as via RainbowKit, MetaMask, Coinbase Wallet, or WalletConnect).
02. Information We Do Not Collect
We believe in data minimization. We never request, collect, or store:
- Your real name, postal address, or physical location.
- Your email address, phone number, or social media handles.
- Your private keys, seed phrases, or wallet passwords.
- Your credit card, bank account, or fiat payment credentials.
03. Public Blockchain Data
When you deploy a payment policy, sign an EIP-712 permission envelope, or execute a transaction, certain cryptographic data is submitted to public distributed ledger networks (such as Arbitrum One).
By their nature, public blockchains are transparent, immutable, and accessible to anyone. Public blockchain data includes:
- Your public wallet address.
- Recipient contract or wallet addresses.
- Transaction timestamps, token types, and transaction amounts.
- On-chain cryptographic hashes and permission status.
Because this data is permanently recorded on decentralized blockchains, it cannot be modified, deleted, or removed by Permit.
04. Local Browser Storage
To provide a responsive interface experience, our web application may store lightweight client-side preferences in your browser's local storage (such as localStorage or session state).
This data is stored solely on your device and is not transmitted to our servers. It includes:
- Your preferred connected wallet connector type.
- UI display preferences and theme settings.
- Temporary client-side caching of policy lists to reduce RPC query latency.
You can clear this data at any time through your browser's developer settings or cache clearance options.
05. Third-Party RPC Providers & Infrastructure
When you interact with the Permit interface, your browser communicates with RPC (Remote Procedure Call) node providers to read and broadcast transactions to the Arbitrum blockchain.
These RPC providers (such as public Arbitrum RPCs or private infrastructure providers) may receive standard network connection metadata, including your IP address and requested blockchain query. Their handling of this information is governed by their respective privacy policies. You may configure custom RPC endpoints inside your Web3 wallet at any time.
06. Data Security & Sovereignty
Because we do not operate centralized accounts or store custody assets, the security of your interactions with Permit rests on cryptographic mathematics.
Your private keys remain encrypted inside your wallet software. Permit contracts can only move tokens when a valid signature meeting all policy parameters (spending cap, recipient, cadence) is mathematically proven on-chain.
07. Policy Updates
We may periodically update this Privacy Policy to reflect technical enhancements, architectural updates, or regulatory developments. Any updates will be posted directly to this page with an updated “Last Updated” date.
08. Questions & Contact
If you have questions regarding this Privacy Policy or our decentralized architecture, please explore our developer documentation at permit.io/developer or reach out through our community channels.