Privacy Policy

GFX Labs, Inc.

Last modified: October 23, 2025

This Privacy Policy explains how GFX Labs, Inc. ("GFX Labs", "GFX", the "Company", "we", "our", or "us") collects, uses, and shares the limited personal data collected by us and our third-party service providers in connection with Oku (oku.trade/app), oku.trade website and all of our other properties, products, and services (the "Products"). Your use of the Products is subject to this Privacy Policy as well as our Terms and Conditions.

Blockchain Privacy Generally. As a preliminary matter, please note that—by virtue of the public, immutable nature of blockchain technology—the holdings and transactions associated with your wallet address are publicly available and accessible to third parties. Such personal data includes, but is not limited to, your public sending address, the public address of the receiver, the amount sent or received, the crypto asset involved, and any other data a user has chosen to include in a blockchain transaction. Although this data is pseudonymous, third parties may still be able to associate transactions and addresses with a user's actual identity now or in the future, rendering it personally identifying under various privacy regulations. Moreover, data stored on a blockchain cannot be modified or deleted due to its inherent immutability. Before using any of our Products, please consider blockchain's inherent transparency in addition to how GFX itself collects, uses, and shares your personal data as described below.

High-Level Summary

  • GFX Labs is an incorporated company based in the United States that operates oku.trade among other Products.
  • As used in this Privacy Policy, "personal data" means any information that identifies, relates to, describes, or is capable of being associated with an identified or identifiable individual. This includes but is not limited to names, email addresses, wallet addresses, device data, online activity, IP addresses, geolocation data, and any other information classified as personal, nonpublic, or protected under relevant privacy laws.
  • As general rule, GFX Labs itself only collects and stores the wallet address you connect to our Products, the transaction hash of any transactions you make using our Products, and device information.
  • We also collect and store the email address you provide us for the few Products and/or features that require it.
  • We collect and store this data to help drive production vision—not to sell your data to advertisers.
  • GFX Labs does not collect and store other types of personal data unless you, for example, elect to participate in a promotional campaign, to receive communications from us, or use any third-party services within the Oku interface, in which case you may have to provide personal data like your name, date of birth, account ID, and home address.
  • In addition, some of our third-party service providers collect other forms of personal data on our behalf or for their own purposes as described in more detail below.
  • Any material changes to GFX's privacy practices will be reflected in an updated privacy policy.

Personal Data We Collect

When you interact with our Products, we collect only:

Publicly-Available Blockchain Data

When you connect your non-custodial blockchain wallet to the Products, we collect and log your blockchain wallet address to learn more about your use of the Products and to screen your wallet address against OFAC's Specially Designated Nationals list. We also collect the transaction hashes associated with any transactions you make via one of our Products.

Survey or Usability Data

If you participate in a survey or usability study with us, we will record any biographical data you directly provide to us (e.g., your name and email address) and the responses you provide to us.

Correspondence

We will receive any communications and information you provide directly to us via email, customer support, social media, or another support channel (such as Twitter or Discord), or when you participate in any surveys or questionnaires. If you specifically sign up to receive emails from us, we will store your email address to allow us to send you those emails.

Biographical Information

If you apply for a job with us, we collect personal data that you provide, such as your name, email, phone number, and work status, and any resume, cover letter, or free-form text you include.

Promotional Campaign Data

As part of our promotional campaigns, we may require the collection of certain personal data to facilitate reward distribution. This may include your mailing address and contact information solely for the purpose of shipping and handling the reward items. This personal data is used strictly for the fulfillment of the promotional campaign rewards.

Bridge.xyz Account Information

If you elect to use the Bridge.xyz API, we collect and store Bridge account-associated email addresses and Bridge-assigned IDs in order to assist Bridge in providing their services to you. Any other personal data collection associated with using the Bridge API is done by Bridge for its own purposes and is governed by the terms of Bridge's privacy policy.

Device Data

We collect device-related information, including device type, operating system, browser version, and system settings. This data helps us ensure compatibility with our Products, optimize performance, and enhance security.

Analytics by PostHog

We use PostHog to understand how users navigate and use the Oku interface so we can improve performance, usability, and security. In doing so, PostHog may collect technical identifiers and device information (including IP address) and usage information about your visit (such as referring URL, pages and content viewed, and interactions), often via first-party cookies or similar technologies. PostHog may also assign a pseudonymous user ID so we can understand feature usage over time. PostHog states it does not use third-party tracking services or third-party cookies (no retargeting) and does not track your browsing activity across third-party websites. For more info, see PostHog's privacy policy.

PostHog Session Replay

To diagnose issues and improve usability, we use PostHog's session replay features to capture page interactions (e.g., clicks, scrolls, and navigation flows) within Oku. We use PostHog's own session replay tooling for these purposes. For more info, see PostHog's privacy policy.

Third-Party Service Provider Collection

In addition to the data that we directly collect, our third-party service providers collect and process your personal data on our behalf to help us operate, improve, and secure our products. We partner with these third-party service providers to ensure a safe, reliable, and compliant user experience. Each provider is responsible for following industry-standard security practices and their respective privacy policies.

Cloudflare collects and processes your IP address on our behalf to ensure compliance with U.S. geographic sanctions. This service provides a protective layer between our site and potential threats while also helping us enforce restrictions that meet our legal obligations. For more information, please refer to Cloudflare's privacy policy.

Google Analytics is a web analytics service that tracks and reports website traffic. In this context, Google collects information that includes the number of visitors to our site, the pages they visited, where they come from, and other similar data. This information is processed to compile statistical reports on website activity. We do not directly collect, store, or process any personal data that Google uses to produce these reports. As such, the personal data collected is managed and stored by Google as per their privacy practices. For more details, please see Google's privacy policy.

Cookie3 provides analytics for Web3 applications, tracking user journeys, marketing performance, and audience segmentation. Cookie3 collects data from blockchain transactions, dApp interactions, website visits, and marketing campaigns, analyzing both on-chain and off-chain activity while maintaining privacy compliance. To learn more, please review Cookie3's privacy policy.

Firebase & Zitadel (User Authentication Providers). We use Firebase (in transition to Zitadel) to handle user authentication. These services store wallet addresses of Oku users who have confirmed their acceptance of our Terms and Conditions.

Bridge.xyz. If you onboard through Bridge.xyz via our interface, Bridge provides us with your name, email address, wallet address, and Bridge ID to facilitate transactions and compliance. Additional data collection by Bridge is subject to its privacy policy.

PostHog (Product Analytics) provides first-party analytics to help us measure feature usage, performance, and reliability across Oku, including limited technical identifiers (e.g., IP address) and usage information (e.g., referring URL, pages/content viewed, and interactions). PostHog states it uses first-party cookies only and does not use third-party tracking services (no cross-site retargeting). For more info, please see PostHog's privacy policy.

You can opt out of having your online activity and device data collected through these third-party services, including by:

  • Blocking cookies in your browser by following the instructions in your browser settings. For more information about cookies, including how to see the cookies on your device, manage them, and delete them, visit www.allaboutcookies.org.
  • Blocking or limiting the use of your advertising ID on your mobile device through the device settings.
  • Using privacy plug-ins or browsers. Certain browsers and browser extensions can be configured to block third-party cookies and trackers.
  • Using the platform opt-out provided by Google at https://adssettings.google.com. For more information on how Google Analytics collects and processes data, please visit their site at www.google.com/policies/privacy/partners/.
  • Google also offers an official browser add-on to prevent your data from being collected and used by Google Analytics. This tool is available at https://tools.google.com/dlpage/gaoptout/.
  • Using advertising industry opt-out tools on each device or browser where you use the Products, available at http://optout.aboutads.info and http://optout.networkadvertising.org.
  • PostHog uses first-party cookies to remember users and measure how Oku is used. PostHog indicates it does not use third-party tracking services and does not track users across third-party websites; accordingly, PostHog does not change behavior in response to browser "Do Not Track" signals. You can refuse cookies in your browser; some features may not work properly without them.

If you exercise applicable rights of access, deletion, portability, or objection, we will coordinate with our relevant third-party service provider (e.g., PostHog) to fulfill those requests with respect to analytics data processed on our behalf.

As our third-party service providers regularly update their privacy policies, you should review their most recent statements to remain informed about their data collection practices.

How We Store Personal Data that We Collect

We implement and maintain industry-standard security measures to protect the data we collect and process. Nevertheless, transmission via the internet is not completely secure, and we cannot guarantee the security of your personal data. To ensure the integrity and security of our infrastructure, we utilize Digital Ocean as our primary cloud storage provider. Digital Ocean does not independently collect or process user data—it solely provides storage services that enable us to manage and safeguard data securely.

All data stored with Digital Ocean is protected through access controls, encryption protocols, and monitoring tools to prevent unauthorized access or breaches. While we take reasonable steps to secure data, users should also take precautions, such as safeguarding their private keys and maintaining secure access to their blockchain wallets.

We retain analytics data for as long as reasonably necessary to fulfill the purposes described below, to comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type and context. PostHog describes its own retention approach and will coordinate deletion with us for verified requests.

How We Use the Personal Data Collected

We use the data we collect in accordance with any applicable terms in our Terms and Conditions and as required by law. We may also use personal data for the following purposes:

  • Providing the Products. We use the data we collect to provide, maintain, customize, and improve our Products and features of our Products.
  • Improving the Products. We use collected data to analyze trends, understand user behavior, and enhance the functionality and usability of our Products. This includes optimizing platform performance, refining user interfaces, improving transaction efficiency, and identifying areas where additional features or security measures may be needed.
  • Customer Support. We may use personal data to provide customer support for and answer inquiries about the Products.
  • Safety and Security. We may use data to protect against, investigate, and stop fraudulent, unauthorized, or illegal activity. We may also use it to address security risks, solve potential security issues such as bugs, enforce our agreements, and protect our users and Company.
  • Legal Compliance. We may use personal data as needed or requested by regulators, government entities, and law enforcement to comply with applicable laws and regulations.
  • Promotional Campaigns. For eligible participants in our promotional campaigns, we use the personal data provided (such as mailing addresses for reward items) solely for the purpose of reward fulfillment. This includes shipping the reward items and communicating with you about your participation in the campaign.

When We May Share Personal Data

  • With Service Providers. We may share with our third-party service providers (e.g., Bridge, PostHog) personal data necessary to such providers' provision of their services through the Oku interface. For promotional campaigns specifically, we may share the limited personal data required for reward fulfillment with third-party service providers involved in the shipping and handling of rewards.
  • With Our affiliates. We may share personal data with our affiliates and subsidiaries to support our business operations, enhance our Products, and facilitate compliance measures.
  • To Comply With Our Legal Obligations. We may share collected data in the course of litigation, regulatory proceedings, compliance measures, and when compelled by subpoena, court order, or other legal procedure. We may also share data when we believe it is necessary to prevent harm to our users, our Company, or others, and to enforce our agreements and policies, including our Terms and Conditions.
  • Safety and Security. We may share collected data to protect against, investigate, and stop fraudulent, unauthorized, or illegal activity. We may also use it to address security risks, solve potential security issues such as bugs, enforce our agreements, and protect our users, Company, and ecosystem.
  • Business Changes. We may transfer or share collected data to another entity in the event of a merger, acquisition, bankruptcy, dissolution, reorganization, asset or stock sale, or other business transaction.
  • With Your Consent. We may share your personal data whenever you provide us with your consent to do so.

Third-Party Links and Sites

We may integrate technologies operated or controlled by other parties into parts of the Products. For example, the Products may include links that hyperlink to websites, platforms, and other products and/or services not operated or controlled by us. Additionally, our Products may incorporate third-party APIs, such as the Bridge.xyz API, which provides on/off ramp and bridging services to Oku users who elect to use those services.

Please note that when you interact with these other parties—whether through API integrations within our website or through websites they operate—those parties may independently collect personal data, including for compliance with KYC/AML regulations, as in the case of Bridge.xyz. Their data collection practices are governed by their own privacy policies, and GFX Labs does not control how they use this data. You can learn more about how those parties collect and use your data by consulting their privacy policies and other terms. For more information on Bridge.xyz's privacy practices and personal data collection, see Bridge.xyz's privacy policy.

Wormhole NTT Platform

We also collect and process user personal data in connection with operating the Native Token Transfer ("NTT") platform on behalf of our branding partner, Wormhole. Our role in connection with the Wormhole NTT platform is primarily that of a service provider. We do not collect or store personal data from users of the Wormhole NTT platform at launch. No telemetry, tracking, or data collection systems are implemented on the platform at this time, and we do not receive any data unless a third-party dependency (such as reown/appkit) independently initiates collection beyond our control.

Anticipated Future Data Collection

We may, in the future, implement telemetry and diagnostic tools. This may include the collection of:

  • Blockchain wallet addresses
  • Console logs for diagnostic and error monitoring
  • Browser and device information (e.g., browser version, operating system, screen resolution)
  • Site performance data (e.g., page load times)
  • Aggregated geographic data (e.g., region or country based on IP address)

This data will be used solely to operate, secure, and improve the Wormhole NTT platform and related services.

Cross-Product Insights

We may use aggregated and de-identified insights derived from platform data to inform the development of other GFX Labs products and services. For instance, data about performance bottlenecks, geographic usage trends, or interface responsiveness may be compared across our platforms.

Subject to Change

As the platform evolves, we may collect additional types of data, such as in connection with proprietary RPC infrastructure or other product features. If this occurs, we will update this Privacy Policy accordingly and in advance of any new collection.

Age Requirements

The Products are specifically intended for a general audience and are not directed at children. We do not knowingly receive personal information (as defined by the U.S. Children's Online Privacy Protection Act, or "COPPA") from children. If you believe we have inadvertently collected personal information about a child under the age of 13, please contact us at legal@gfxlabs.io, and we will immediately delete such data.

Changes to This Policy

We may update this Policy from time to time. We will notify you of any changes by posting the new Policy on this page and updating the "Last modified" date at the top of each new Policy. Nevertheless, your continued use of the Products reflects your periodic review of this Policy and our Terms and Conditions and indicates your consent to them.

Contact Us

If you have any questions about this Privacy Policy, please contact us at:

legal@gfxlabs.io

social iconsocial iconsocial iconsocial iconsocial icon
In collaboration with:
© 2025 GFX Labs, IncOku Trade Build v1.0.23
Powered by Mava