How LITHO Deals collects, uses, and protects information on the Lithosphere and KaJ Labs deals platform
Last updated: 19 July 2026
This Privacy Policy explains how KaJ Labs, on behalf of the Lithosphere ecosystem, collects, uses, discloses, and safeguards information in connection with LITHO Deals (the “Portal”). It applies to the authenticated portal, its wallet sign-in flow, its data room, and any contact, chat, or ticket requests submitted inside the platform. It does not apply to third-party sites you may reach through the Portal, including the OTC execution desk operated by Ignite, which maintain their own privacy practices.
This policy covers wallet-based authentication, session handling, access to deal and diligence documents, and any support, chat, or contact requests submitted inside the platform. Access to the Portal is gated, so most functionality described here is only available to users who have connected a wallet and completed sign-in.
We collect the following categories of information:
Wallet and authentication data. Your public wallet address, the signed authentication message (Sign-In with Ethereum or Sign-In with Thanos), signature, and related session metadata (timestamps, session identifiers, and, where applicable, IP address and browser/device information used to secure the session).
Contact and request data. Name, email address, preferred contact method, project of interest, subject, message content, and wallet address (if connected) when you submit a ticket, chat request, or email through the Portal.
Usage and technical data. Information about which documents or sections of the data room you access, and standard technical logs (such as request timestamps, IP address, and user agent) generated by our hosting and security infrastructure.
We do not collect private keys, seed phrases, passwords, or custody of your digital assets. We do not knowingly collect government ID numbers, financial account numbers, or other sensitive identifiers through the Portal itself; such information, if ever required for eligibility or compliance checks, is collected through separate, dedicated verification processes and is outside the scope of this policy.
We use the information described above to: authenticate you and maintain your session; grant or restrict access to deals, documents, and platform features; operate the OTC and deal-request workflow; respond to support, chat, and contact requests; route requests to the appropriate internal team; monitor, secure, and troubleshoot the Portal; comply with applicable law, sanctions screening, and eligibility requirements; and maintain records of platform activity for audit and compliance purposes. We do not use your information for third-party advertising, and we do not sell personal information.
Sign-in is performed by signing a message with your wallet (Sign-In with Ethereum / Sign-In with Thanos); we never see or store your private keys. Wallet connections are brokered through WalletConnect-compatible infrastructure, which may process your wallet address and connection metadata under its own privacy terms. Once authenticated, your session is maintained using a signed, HTTP-only session cookie. You can end a session at any time by logging out or disconnecting your wallet.
Support, chat, and deal-related requests submitted inside the Portal may be forwarded to internal LITHO/KaJ Labs teams through configured channels, which can include email (via our email delivery provider), Telegram (via the Telegram Bot API), and WhatsApp (via Twilio). The content of your request — including your name, email, wallet address, and message — is transmitted to these providers solely to deliver your request to the appropriate team and is not used by us for any other purpose.
The Portal uses a secure, HTTP-only session cookie that is strictly necessary to keep you signed in and is not used for advertising or cross-site tracking. Wallet-connection infrastructure may also use local storage or similar mechanisms in your browser to remember your connected wallet and improve reconnection speed. We do not currently use third-party advertising or analytics cookies on the Portal.
We do not sell your personal information. We share information only: with service providers that help us operate the Portal (email delivery, Telegram, Twilio/WhatsApp, wallet-connection infrastructure, and hosting/infrastructure providers), each of which processes data solely to provide their service to us; with counterparties or partners in a specific deal, where necessary to facilitate a transaction you have requested to participate in; where required to comply with law, regulation, legal process, or a governmental request; and to protect the rights, property, or safety of the Portal, its users, or others. Any such recipients are only provided the information necessary for the relevant purpose.
We retain wallet, session, and request data for as long as reasonably necessary to operate the Portal, support your access, meet compliance and recordkeeping obligations, and resolve disputes. Retention periods vary by data type and may be extended where required by law, audit, or an active or anticipated legal matter. When information is no longer needed for these purposes, we take reasonable steps to delete or anonymize it.
We use technical and organizational measures designed to protect information processed by the Portal, including encrypted transport (HTTPS), signed and HTTP-only session cookies, and access controls limiting who can view diligence materials and request data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding access to your wallet and its signing credentials.
Depending on your jurisdiction, you may have rights to request access to, correction of, or deletion of your personal information, to object to or restrict certain processing, or to receive a copy of your data in a portable format. You can disconnect your wallet or stop using the Portal at any time to end data collection associated with your session. To exercise any of these rights, contact us using the details below; we may need to verify your request before acting on it.
The Portal and its service providers may process and store information in countries other than your own. Where we transfer information across borders, we take steps intended to ensure it receives an adequate level of protection consistent with applicable law.
The Portal is not directed to, and is not intended for use by, individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us information, please contact us so we can take appropriate action.
We may update this Privacy Policy from time to time to reflect changes to the Portal or our practices. Material changes will be reflected by updating the “Last updated” date above, and, where appropriate, through additional notice inside the Portal. Continued use of the Portal after a change takes effect constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at [email protected], or through the contact and support options available inside the authenticated Portal.