Effective date: August 8, 2026. Applies to Alloca (app-v2 / app.alloca.io).
Alloca ("Alloca", "we", "us") is an AI-native fintech application operated by Moneyture Pte. Ltd. (UEN 202321395E, Singapore) that lets users authenticate with an embedded wallet or social/email login, fund a card via on-chain USDT top-ups on the Arbitrum network, and use an AI "Concierge" chat feature.
This Privacy Policy explains what information we collect, how we use it, who we share it with, and what choices you have. It applies to the Alloca web application (app-v2, served at app.alloca.io) and any related services we operate. It does not apply to third-party sites or apps that we merely link to.
By creating an account or using Alloca, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the app.
Wallet and on-chain data: your wallet address(es), and the transaction hashes, amounts, timestamps, and status of on-chain top-ups and other transactions you make through Alloca's smart-contract deposit rail ("Gatherer") on Arbitrum, as recorded and indexed by our off-chain indexer service.
Authentication data: identifiers provided by our authentication partner, Privy, including your Privy user ID and the email address, phone number, or social-login identifier you used to sign in, as well as embedded-wallet metadata needed to operate your account.
Concierge chat data: the content and history of messages you send to and receive from the AI Concierge feature, including any financial questions, instructions, or context you share in that chat.
Usage, device, and log data: IP address, browser and device type, operating system, pages and features visited, timestamps, referring/exit pages, and similar diagnostic and analytics data collected automatically as you use the app.
Referral data: referral codes you use or generate, and the association between a referring account and a referred account for the purposes of our referral program.
We do not knowingly collect passwords or private keys for embedded wallets — these are managed by Privy's infrastructure and are not stored by Alloca in plaintext.
To provide the core product: operating your card, wallet, and balance features; authenticating you; processing on-chain top-ups; and running the Concierge chat, including sending your chat content to our AI/LLM provider so it can generate responses.
To administer the Concierge whitelist: verifying the $5 whitelist top-up, approving or denying Concierge access, and tracking your available chat credits.
To detect and prevent fraud, abuse, and other risks, and to meet applicable compliance, anti-fraud, and legal obligations, including reviewing on-chain transaction patterns.
To analyze, maintain, and improve the app, including through aggregated product analytics and error diagnostics.
To communicate with you about your account, transactions, support requests, and (where you have opted in) product updates, including via Telegram or email support channels.
We retain your account information (such as your Privy identifiers, wallet address, chat history, and usage data) for as long as your account is active, and for a reasonable period afterward as needed to comply with legal, accounting, tax, or regulatory obligations, resolve disputes, and enforce our agreements.
Blockchain transaction data is different: because Alloca's on-chain top-ups are recorded on the Arbitrum network, that data is public, permanent, and immutable by design. Once a transaction is confirmed on-chain, Alloca has no technical ability to alter or delete it — including in response to an account-deletion or erasure request — because it exists on a decentralized public ledger outside of our control.
Privy — provides authentication and embedded-wallet infrastructure and processes the identifiers and credentials you use to log in.
The Arbitrum network and on-chain indexers — the Arbitrum blockchain is a public, decentralized ledger; any address that interacts with our smart contracts, and the resulting transaction data, is publicly visible and is also read by our off-chain indexer to update your in-app balance.
Yandex Metrika — a third-party analytics service (including session recording / "webvisor" and click-map features) that we use to understand how the app is used and to improve it. Yandex Metrika may set cookies and collect usage data such as pages visited, clicks, and approximate device/browser information.
Our Concierge AI/LLM provider — processes the content of your Concierge chat messages in order to generate responses; message content may be transmitted to and temporarily processed by this provider's infrastructure.
Payment and card-processing partners — where applicable, partners that help process card funding, settlement, or related financial operations may receive the transaction data necessary to complete those operations.
We do not sell your personal information to third parties.
Subject to applicable law, you may request access to, correction of, or deletion of the off-chain personal data we hold about you (for example, your stored email/contact identifier, chat history, or account metadata).
You may opt out of non-essential analytics tracking and non-essential communications (such as marketing messages) at any time; some transactional or security-related communications cannot be opted out of while your account remains active.
As described in Section 4, we cannot delete or alter on-chain transaction data once it has been confirmed on the Arbitrum network — this is a technical limitation of public blockchains, not a policy choice.
To exercise any of these rights, contact us at info@alloca.io. We will respond within a reasonable timeframe and may need to verify your identity before acting on your request.
We use reasonable technical and organizational measures to protect your information, including encryption of data in transit and access controls limiting who within our team can access account and chat data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not claim compliance with any specific security certification at this time.
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal or operational reasons. If we make material changes, we will update the effective date above and, where appropriate, notify you in-app or by email. Continued use of Alloca after a change becomes effective means you accept the revised policy.
If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact us at info@alloca.io.
Moneyture Pte. Ltd. · UEN 202321395E · Registered in Singapore