Who we are
AutoAirdrops Labs, Inc. (“AutoAirdrops”, “we”, “us”) is a Delaware corporation headquartered at 1200 Brickell Avenue, Suite 800, Miami, FL 33131, USA. We operate the website autoairdrops.io and the AutoAirdrops autonomous airdrop operator (the “Service”).
What we do NOT collect
Private keys. AutoAirdrops is non-custodial. Your wallet's seed phrase and private keys never touch our servers. Every onchain action is signed locally by your wallet or hardware device.
Funds. We never hold, escrow, or custody your tokens. Airdrop rewards are delivered by the relevant protocol directly to the wallet address you connect.
Personal data we don't need. We don't ask for your government ID, residential address, phone number, or biometric data. AutoAirdrops never runs KYC.
What we do collect
Account data. Email address, password hash, and (optionally) display name when you create an account.
Wallet addresses. Public wallet addresses you connect. We treat these as identifiers — not secrets — and use them to coordinate onchain operations.
Usage telemetry. Aggregated metrics about which agent features are used, error rates, and performance. Never wallet balances or transaction contents.
Billing data. There is no billing. The app is free for Ventureship operators and we never process a payment through this product. If you ever wire a third-party RPC or sponsor a relay, those providers are governed by their own privacy policies.
Communications. Messages you send us via support@autoairdrops.io or in-app chat. We use these to help you and to improve the product.
How we use your data
- To operate the Service and route agent actions to your wallets.
- To send you transactional emails (receipts, security alerts, dropped-agent notifications).
- To improve the product via aggregated, anonymized analytics.
- To comply with applicable law and respond to valid legal requests.
Cookies & similar technologies
We use a minimal set of first-party cookies for authentication and session management. We do not deploy advertising trackers, cross-site scripts, or third-party analytics that fingerprint you across sites.
Sharing & processors
We share data only with vetted subprocessors that help us run the Service:
- Stripe — payment processing.
- Postmark — transactional email.
- Cloudflare — edge networking and DDoS protection.
- AWS — managed runtime (us-east-2, eu-west-1, ap-southeast-1).
We do not sell, rent, or trade your data. Ever.
Your rights
You can request export or deletion of your account data at any time by emailing privacy@autoairdrops.io. We fulfill requests within 30 days. If you're in the EEA, UK, or California, you have additional rights under GDPR/UK-GDPR/CCPA — including portability, objection, and restriction of processing.
Security
We encrypt data in transit (TLS 1.3) and at rest (AES-256). Session tokens are rotated on every privileged action. We are SOC 2 Type II audited annually and run a public bug bounty via Immunefi with payouts up to $250,000. Report vulnerabilities to security@autoairdrops.io.
Children
AutoAirdrops is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact privacy@autoairdrops.io and we will delete it.
International transfers
Data may be processed in the United States, European Union, or Singapore depending on your region. We rely on Standard Contractual Clauses (SCCs) for transfers out of the EEA/UK. A copy is available on request.
Changes to this policy
If we change this policy in a material way, we will email you and surface a banner in the operator console at least 30 days before the change takes effect. The history of revisions is available at autoairdrops.io/privacy/history.
Contact us
Privacy questions, deletion requests, or data export: privacy@autoairdrops.io
AutoAirdrops Labs, Inc., Attn: Privacy Officer, 1200 Brickell Avenue, Suite 800, Miami, FL 33131, USA.