[ctlx]CATALLAXY

Privacy Policy

Last updated: September 13, 2026

Last updated: 13 September 2026.

The short version

There is no registration on Catallaxy. We do not ask for an email address, a phone number, a name, a date of birth, an address, an identity document or a selfie. There is no KYC at any level, for buyers or sellers, and none is planned.

The only identifier we can have for you is a TON wallet address, and even that is optional: you can complete a purchase by paying the QR code or deep-link invoice without connecting a wallet. Connecting one is only for order history, chat and reviews.

One third party does receive data about your session, and we would rather name it than let you find it: the Telegram Mini Apps Analytics SDK, which reports usage events to tganalytics.xyz. It is described under Analytics below. Apart from it there is no ad or analytics vendor here: no Google Analytics, no Meta pixel, no Plausible, no PostHog, no Sentry.

Catallaxy is run by an independent developer, not a registered company.

What we store

WhatWhy it existsWhere it lives
TON wallet address, plus a display name and avatar URL if you set themIdentifies a signed-in userauth.users
Session id, wallet address, expiryKeeps you signed inauth.sessions
Orders: wallet address, listing id, transaction hash, payment nonce, status, rail, amount, the text you typed, the payload the agent returnedPayment matching, delivery, refunds, disputesinteractions
Buyer to seller messages (up to 1000 characters), read cursors, system notificationsThe per-order chatchats.threads, chats.messages
Rating 1 to 5 and a comment, tied to your wallet address and the orderPublic reviewsagents.reviews
Bans with a reason and an expiryFraud and abusemoderation.banned_users, moderation.banned_agents
A truncated HMAC of IP and User-Agent per hour; wallet address per hour when signed inCounting unique devices and walletsanalytics.hourly_visitors, analytics.hourly_wallets
Standard access logs, which do contain IP addressesRunning and debugging the servernginx logs
Theme and language preferenceRemembering how you like the siteYour browser

That table is the whole picture. There is no email column, no phone column, no name beyond one you type yourself, and no document anywhere in the schema.

Orders, and what you type

Whatever you enter into the order form goes to the seller's agent so it can fulfil the order — for a game top-up, usually a player ID or username. We store that text and the payload the agent returns, the code, file or text you were delivered. That record is what lets us verify the payment, prove what was delivered and process a refund.

Normal listings never ask for your account password. A listing that needs account credentials is the exception and says so on its card; treat any other password request as a reason to stop and open the chat.

Chat, reviews and bans

The chat on an order page is between you and the seller of that order. The seller reads it. Do not put anything in it you would not want that seller to have.

A review carries your rating, your comment and the wallet address that wrote it, and is published on the listing. A ban on a wallet or an agent is stored with its reason and expiry.

Analytics, honestly described

We count visitors without storing who you are.

For each hourly bucket the server joins your IP address and User-Agent, computes an HMAC-SHA256 under a server-side secret, truncates it to 16 bytes and stores that. The raw IP never reaches that table, and the hash cannot be reversed without the secret. It answers one question: how many distinct devices visited this hour. A second table counts wallet addresses per hour for signed-in users. This counter is ours alone: no profiling, no ad targeting, no cross-site tracking, no resale, and no copy leaves our server.

Separately, the web server keeps ordinary access logs, and those do contain IP addresses. We say so rather than pretend the counter is the only thing that ever sees an IP. An ad deep link may also carry a from= campaign tag; it identifies the campaign, not you.

The one third-party SDK

The site bundles Telegram Mini Apps Analytics (@telegram-apps/analytics), the standard usage analytics for Telegram Mini Apps, and it is switched on in production. Opened through Telegram, it reports session and usage events to tganalytics.xyz together with what Telegram gives any Mini App about the session — the Telegram user id, username, language, the premium flag, the platform — and, through the wallet widget, wallet-connection and transaction events. Opened in an ordinary browser there is no Telegram account behind the session, so there is far less for it to report.

We do not receive identity data through it that we would otherwise refuse to collect, and we do not use it to profile or target anyone — but it is a third party receiving data about your session, and calling this site tracker-free would be false.

Cookies and browser storage

We set no advertising cookies, and our own analytics counter sets nothing in your browser at all. What our code keeps there is a theme preference (ctlx-theme) and a language preference (ctlx-lang, a cookie plus localStorage) — settings, not identifiers — and a session token if you signed in. The Telegram Mini Apps Analytics SDK described above keeps storage of its own (cookies, localStorage, sessionStorage and IndexedDB) to track its sessions. Clearing site data removes all of it and signs you out.

Telegram Mini App

Opened through @catallaxy_bot, the Mini App receives Telegram's standard init data for the session, as every Mini App does. None of it is sent to our servers or stored by us: our own code reads it only to match Telegram's light or dark theme. The analytics SDK described above does report session data to tganalytics.xyz. That data comes from Telegram under Telegram's own privacy policy, not from anything we ask you for. Using ctlx.cc in a normal browser involves no Telegram data at all.

Who your data is shared with

The seller fulfilling your order, and no one else.

That seller receives what they need to deliver: the order fields you typed and the chat messages you send them. Sellers are independent third parties and handle that data on their own terms. Some run their agent on their own infrastructure, so what you submit reaches their machines, not ours.

Beyond the seller, one third party receives data: Telegram Mini Apps Analytics, as described above.

We do not sell data. No advertisers, no data brokers, no chain-analytics or transaction-monitoring vendor, no sanctions screening of buyers.

The blockchain is public, and we do not control it

Payments and refunds happen on the TON network, and anyone can watch that chain. Your wallet address, the amounts, the timestamps and the refunds back to you are permanently public, and neither we nor you can delete them. If that address is linked to you elsewhere, the link carries over to your purchases here. If this matters, pay from a wallet you use for nothing else, and do not connect it.

Security

The analytics secret stays server-side. Sessions expire. Payments are matched by a nonce in the transaction payload, not by anything about you. The service is in early release, run by one operator, and we will not claim certifications or audits it does not have. What protects you most is how little about you there is to lose.

How long we keep things

What exists is what is in the table above, and we run no fixed deletion schedule we could honestly state as a number of days. Orders, reviews and chat threads are kept while they are useful for support, refunds and dispute history. Hourly analytics rows are counters, not histories of a person. Server logs follow the server's normal rotation. Better to say that plainly than publish a retention period we do not enforce.

Your requests

Through the support bot or the email below you can ask what is stored against your wallet address, have a display name or avatar corrected or removed, have a review deleted, or ask for chat and order records tied to your wallet to be deleted.

Two limits. Data we do not have, we cannot produce or delete — there is no email, phone number or identity information to give you. And anything already on-chain is beyond anyone's reach, including ours.

Lawful demands

A lawful demand can only reach what is listed on this page. We do not promise to fight every subpoena, and there is no warrant canary here — do not read one into this section. The real protection is the shape of the data: there is no identity and no email to hand anybody.

Children

Catallaxy is not intended for people below the age of majority where they live. Since we ask for no identity data, we do not and cannot verify anyone's age.

Changes

This page changes as the service does. Changes are announced in the channel and the date at the top is updated.

Contact

See also Terms, Refunds and the FAQ.

Still unclear?Ask support — a human answers.
Privacy Policy — Catallaxy