Recupero
HomeAcademyFAQSign in
Get started
Legal

Privacy Policy

Last updated 29 July 2026

Contents

  1. Summary
  2. Who we are
  3. Information we collect
  4. How we use it
  5. Legal bases
  6. Service providers
  7. Blockchain data
  8. Retention
  9. Your rights
  10. Security
  11. International transfers
  12. Children
  13. Changes
  14. Contact

1Summary

To trace stolen funds we need two things: an account for you, and the blockchain addresses involved in your incident. Blockchain transaction data is already public — we read and analyse it. We do not sell your personal information, we do not use it for advertising, and we never publish anything about you or your case.

We never ask for your seed phrase, recovery phrase or private keys. Tracing does not require access to your wallet, and anyone who asks you for those is attempting fraud.

2Who we are

Recupero provides investigative software for tracing and recovering stolen digital assets. The data controller responsible for the information described here is legal entity name, registered at registered address.

3Information we collect

Information you give us

  • Account details — your email address, a password, and your name if you provide one. Passwords are stored only as a memory-hard cryptographic hash; we cannot read them.
  • Organization details — your organization name and the email addresses of team members you invite, together with their roles.
  • Case details — the wallet addresses, blockchain and approximate incident time you submit for each trace, plus any case reference or notes you add.

Information we generate

  • Trace results — the transfers, counterparty addresses, risk and sanctions labels, valuations and reports our engine derives from public blockchain data for your case.
  • Usage records — the number of traces you run, used to enforce plan quotas and to bill accurately.
  • Security records — an audit log of security-relevant events such as sign-ins, API-key creation and revocation, and membership changes.
  • Technical logs — request metadata (time, endpoint, response status) needed to operate and secure the service.

Information from third parties

  • Billing status — a customer identifier, subscription state and invoice history from our payment processor. We never receive or store your full card details.

4How we use it

  • To run traces and produce the reports and recovery paperwork you asked for.
  • To create and secure your account and organization, and to authenticate you.
  • To enforce plan quotas and rate limits, and to bill you correctly.
  • To send transactional email: verification, password reset, invitations and case notifications.
  • To detect, investigate and prevent abuse, fraud and security incidents.
  • To comply with legal obligations and respond to lawful requests.

We do not sell personal information, and we do not use your case data to train general-purpose models.

5Legal bases

Where the GDPR or similar law applies, we rely on: contract — to provide the service you signed up for; legitimate interests — to secure the platform, prevent abuse and improve reliability; legal obligation — for tax, accounting and lawful requests; and consent — for anything optional, which you may withdraw at any time. confirm applicable regimes with counsel

6Service providers

We use a deliberately small set of providers to run the service. Blockchain, sanctions and market-data providers receive addresses and asset identifiers in order to answer a query — they do not receive your account details or case narrative.

  • Cloud hosting and managed database — running the application and storing your data
  • Blockchain data providers — reading public on-chain transaction history
  • Market-data provider — historical asset valuations
  • Sanctions and attribution providers — screening addresses against sanctions and risk data
  • Payment processor — subscriptions, invoicing and card handling
  • Email provider — transactional email
  • AI provider — generating plain-English case summaries from your trace results confirm: enabled or disabled

7Blockchain data

Blockchain transactions are public and permanent by design. We read that public record; we do not and cannot alter or delete it. Note that an address you submit may itself be linkable to a person — including you. We treat the addresses you submit as confidential to your organization, but we cannot make the underlying chain data private.

8Retention

  • Case data and trace artifacts — retained for the retention window of your plan, then deleted automatically.
  • Account and organization records — kept while your account is open.
  • Billing and tax records — kept for the period the law requires after your account closes. retention period
  • Security audit logs — kept as an integrity record for audit-log retention period.

9Your rights

Subject to your jurisdiction, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to withdraw consent. You can delete your case data from the product, or contact us to request deletion of your account and associated data. We will respond within the period required by applicable law.

If you are in the EEA or UK you may also complain to your supervisory authority. If you are a California resident, we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising your rights.

10Security

  • All traffic is encrypted in transit (TLS).
  • Passwords are hashed with a memory-hard algorithm and are never stored or logged in plain text.
  • API keys are stored only as hashes, shown once at creation, and can be revoked immediately.
  • Each organization’s data is isolated, and access is scoped per organization and per role.
  • Sessions are re-validated against current membership, so removing a member revokes their access immediately.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to us at security@recupero.io confirm mailbox exists and we will work with you in good faith.

11International transfers

Our providers may process data in countries other than yours. Where required we rely on appropriate safeguards, such as the European Commission’s standard contractual clauses. confirm hosting regions and safeguards

12Children

The service is not intended for anyone under 18, and we do not knowingly collect information from children.

13Changes

We will update this policy as the service changes. The date at the top always reflects the current version, and we will notify account holders of material changes by email before they take effect.

14Contact

Privacy questions and data requests: see our contact page, or email legal@recupero.io.

FAQ · Privacy · Terms · Contact · © 2026 Recupero. All rights reserved.