Legal & Compliance
Privacy Policy
Last updated: September 17, 2026
1. Overview & Business Identity
This Privacy Policy explains how meirei CORE LTD(“Meirei,” “we,” “us”) collects, uses, shares, and protects personal information when you use our AI-native investment mandate terminal and web service at https://meirei.app(the “Service”). It applies in addition to our Terms of Service and Cookie Policy.
We strictly respect global privacy frameworks including the Nigeria Data Protection Act 2023 (NDPA) and the General Data Protection Regulation (GDPR) in our role as a data controller. We operate a non-custodial interface; your private keys remain exclusively under your control.
2. Information we collect
You give us:
- Account & contact: your WhatsApp phone number, display name, and any name or label you set in chat.
- Identity verification: where required for compliance, your full legal name, date of birth, residential address, BVN/NIN, government ID details and images, and a selfie for liveness check. Collected through our identity-verification partner.
- Transaction instructions:the messages you send us — including amounts, recipient names or addresses, memos, and natural-language phrases like “send him the same as last week.”
- Payment details: bank-account details where you cash out to NGN, and wallet addresses you send to or receive from.
- PIN / authentication: a PIN or other factor you set, stored only as a salted hash.
- Support: anything you tell us when you contact support.
We collect automatically:
- Usage & device data from our confirmation web pages: IP address, approximate location derived from IP, browser and OS, timestamps, and pages visited.
- Transaction metadata: onchain transaction hashes, block timestamps, balances, and counterparty addresses (public blockchain data).
- Cookies & similar: strictly necessary cookies on the confirmation flow to secure your session; we do not use advertising cookies.
From third parties: we receive verification outcomes from our KYC provider, settlement data from the OKX X Layer network (Chain ID 196), and messaging metadata (e.g. delivery state) from Meta / WhatsApp and Twilio.
3. Why we use it (and the legal basis)
| Purpose | Legal basis (NDPA / GDPR) |
|---|---|
| Run the Service — create wallets, parse your messages, quote and settle transactions, show balances. | Performance of a contract with you. |
| Identity verification, sanctions / AML screening, fraud detection, transaction monitoring, and record-keeping. | Compliance with a legal obligation; legitimate interest in preventing fraud and financial crime. |
| Customer support, debugging, and improving the Service. | Legitimate interest in operating and improving the Service. |
| Sending you transactional messages on WhatsApp (confirmations, alerts). | Performance of a contract. |
| Sending product updates or marketing. | Your consent — you can withdraw at any time. |
4. Who we share it with
We share personal information only as needed:
- Service providers / processors acting on our instructions, including:
- Meta Platforms (WhatsApp Business) — messaging delivery.
- Twilio — messaging infrastructure.
- Circle — issuer of the USDC stablecoin.
- OKX X Layer network (Chain ID 196) — blockchain settlement. User operations and tokenized equity swaps settle non-custodially onchain.
- Supabase — application database and authentication infrastructure.
- SumSub & Chainalysis — identity verification, AML sanctions screening, and compliance monitoring.
- Public blockchains. Wallet addresses and transaction amounts are written to public ledgers that anyone can view. They are not anonymous.
- Regulators, courts, law enforcement where we are legally required to disclose, or to protect rights, safety, or property.
- Successors in a merger, acquisition, or reorganisation — subject to this Policy.
We do not sell your personal information.
5. International transfers
Some of our processors operate outside Nigeria (for example, in the United States or the European Union). Where personal data is transferred outside Nigeria, we rely on lawful transfer mechanisms under the NDPA, including adequacy decisions or contractual safeguards with the recipient.
6. How long we keep it
We keep personal information for as long as your account is active and for as long as we are required to keep records under applicable financial-services law — typically at least five years after the end of the relationship or the date of a transaction, whichever is later. We may retain limited records longer where needed to defend legal claims or comply with regulators.
Onchain data we have submitted (transaction hashes, addresses, amounts) cannot be deleted by us — that is a property of public blockchains, not a choice we make.
7. How we protect it
We use encryption in transit (TLS), encryption at rest for sensitive fields, hashed PINs, scoped database access, audit logging, and short lived confirmation tokens to reduce the risk of unauthorised access. No system is perfectly secure — keep your WhatsApp account and device protected, and never share your PIN or confirmation link with anyone.
8. Your rights
Subject to the NDPA (and, where applicable, the GDPR), you have the right to:
- access the personal information we hold about you;
- have inaccurate or incomplete information corrected;
- request deletion of your personal information, where we are not required to keep it;
- object to or restrict certain processing, including direct marketing;
- request portability of information you provided to us; and
- withdraw consent where we relied on it.
To exercise these rights, message us in chat or email privacy@meirei.app. For a deletion request specifically, see our Data Deletion page. You can also lodge a complaint with your supervisory authority.
9. Age Consent & Protection of Children (Strictly 18+)
Meirei is strictly restricted to individuals who are at least 18 years of age and possess full legal capacity to enter into binding financial agreements. We do not knowingly solicit, collect, or process personal data from children or minors under 18.
If we discover or have reason to suspect that an individual under 18 has accessed the platform, created a wallet profile, or submitted mandates, all associated session data, identity mappings, and chat history will be permanently deleted immediately. Parents or guardians who believe a child has accessed the service may notify us at privacy@meirei.app for prompt removal.
10. Communication Controls & Unsubscribe Mechanisms
We respect your communication preferences. You can opt out of non-critical automated status messages at any time:
- Chat Platforms (WhatsApp / Telegram): Reply “STOP”, “UNSUBSCRIBE”, or “PAUSE” in the chat thread to instantly halt proactive notifications and price alerts.
- Email Notifications: Every automated email dispatch contains a one-click “Unsubscribe” link in the footer. Alternatively, email privacy@meirei.app with the subject “Unsubscribe”.
11. Third-Party SDK Audit & Zero Dark Patterns
We conduct continuous operational security audits on all third-party software development kits (SDKs) and RPC dependencies:
- OKX Onchain OS & DEX Aggregator: Sourcing decentralized liquidity across X Layer without custodial custody.
- Supabase / PostgreSQL: Self-contained relational database enforcing Row Level Security (RLS) on all user tables.
We strictly reject dark patterns: there are zero hidden recurring charges, zero artificial countdown timers, and no pre-checked consent checkboxes. All trade legs and fees are explicitly previewed prior to 2FA challenge authorization.
12. Corporate Contact Details
For privacy questions, GDPR/NDPA inquiries, or to contact our Data Protection Officer:
meirei CORE LTD
Entity: Meirei Core Protocol Ltd.
Data Protection Email: privacy@meirei.app
Legal & Compliance: legal@meirei.app
Registered Office: Meirei Global Operations, Victoria Island, Lagos & Decentralized Protocol Infrastructure