GGatewayRPC control plane
English简体中文

On this page

  1. 1. Scope and responsible party
  2. 2. Information processed
  3. 3. Sources of information
  4. 4. How information is used
  5. 5. Cookies and local storage
  6. 6. Disclosures and third parties
  7. 7. Retention
  8. 8. Security
  9. 9. Data location and international transfers
  10. 10. Your choices and rights
  11. 11. Children
  12. 12. Changes and contact
Back to sign in

Privacy

Privacy Policy

This policy explains how information is processed when you use the Gateway console and RPC infrastructure.

Last updated: July 20, 2026

1. Scope and responsible party

This Privacy Policy applies to the Gateway deployment you access. The organization or person providing that deployment (the "Operator") is responsible for its privacy practices. The Operator may be identified in your invitation, order, deployment notice, or by your workspace administrator.

Gateway can be self-hosted. In a self-hosted deployment, the organization running it determines what information is collected, where it is stored, how long it is retained, and which infrastructure providers can process it. This policy describes the standard product behavior; deployment-specific notices or agreements may provide additional details and control if they conflict.

2. Information processed

Depending on how the deployment is configured and how you use it, Gateway may process the following categories of information:

  • Account information, such as email address, role, account status, and—when supplied by Google—name, profile image, Google account identifier, and verified-email status.
  • Authentication and security information, such as password hashes (not plaintext passwords), session token hashes, login time, IP address, user agent, OAuth state, security events, and rate-limit signals.
  • Workspace configuration, such as applications, application keys, gateways, chains, networks, endpoint details, provider identifiers, and encrypted endpoint authentication secrets.
  • Operational records, such as service logs, configuration changes, provider synchronization failures, and diagnostic information generated while operating and securing the Service.

3. Sources of information

Information comes from you and your workspace administrators, from the browser or client connecting to the Service, from Google when you choose Google sign-in, and from infrastructure providers you configure for discovery or connection management.

The Service does not require advertising trackers. A particular Operator may add monitoring or analytics outside the standard product; if so, that Operator is responsible for disclosing those tools.

4. How information is used

The Operator may process information to:

  • authenticate users, maintain sessions, administer accounts, and provide workspace permissions;
  • manage applications, gateways, endpoints, and provider synchronization;
  • protect credentials, detect abuse, investigate incidents, troubleshoot errors, and maintain reliability;
  • support users, enforce agreements, comply with legal obligations, and establish or defend legal claims; and
  • analyze aggregate performance and improve the Service without using RPC payloads for advertising profiles.

5. Cookies and local storage

Gateway uses an essential, HTTP-only session cookie to keep you signed in and a short-lived OAuth state cookie to protect the Google sign-in flow. These cookies are used for authentication and security, not cross-site advertising.

Your browser may also retain ordinary technical data needed by the web application. Blocking essential cookies can prevent sign-in or other authenticated features from working.

6. Disclosures and third parties

The Operator may disclose information to workspace administrators and authorized personnel; hosting, database, cache, network, security, support, and other processors used to run the deployment; Google when you use Google sign-in; and the upstream blockchain providers selected for your traffic.

Information may also be disclosed when reasonably necessary to comply with law, respond to lawful process, protect users or systems, investigate abuse, or complete a merger, financing, reorganization, or transfer of the Service with appropriate safeguards.

The standard Gateway product does not sell personal information or share it for cross-context behavioral advertising.

7. Retention

Retention depends on the deployment configuration, operational needs, security requirements, and applicable agreements. Account and workspace configuration is generally retained while the account or deployment remains active. Sessions remain until they expire, are revoked, or are deleted. Logs may have a separate Operator-configured retention period.

The Operator may retain limited information longer where required for security, backups, legal compliance, dispute resolution, or enforcement. Deletion from active systems may not immediately remove data from protected backups, which is removed or overwritten under the Operator's backup lifecycle.

8. Security

Gateway is designed to support controls such as hashed passwords and session tokens, HTTP-only cookies, encrypted endpoint and provider credentials, access roles, credential rotation, and security logging. The Operator is responsible for configuring, hosting, monitoring, and maintaining its deployment securely.

No storage or transmission method is completely secure. Protect your account, application keys, provider credentials, and devices, and notify the Operator promptly if you suspect unauthorized access.

9. Data location and international transfers

Data is stored and processed in locations chosen by the Operator and its infrastructure providers. Requests may also be sent to upstream providers in other jurisdictions. Where required, the Operator is responsible for using an appropriate transfer mechanism and providing deployment-specific location information.

10. Your choices and rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, or obtain a copy of personal information, or to object to or withdraw consent for certain processing. These rights can be limited where processing is required for security, contract performance, legal obligations, or the rights of others.

Contact your workspace administrator or the Operator to make a request. The Operator may need to verify your identity and authority. If your account is managed by an organization, that organization may need to handle the request as the responsible party.

11. Children

The Service is technical infrastructure intended for organizations and developers. It is not directed to children, and the Operator does not knowingly seek personal information from children who cannot legally consent to this processing in their jurisdiction.

12. Changes and contact

This policy may be updated to reflect product, legal, or operational changes. The updated date will appear above, and material changes may be communicated through the Service or your workspace administrator.

For privacy questions, requests, or complaints, contact the Operator identified by your organization or deployment administrator. You may also have the right to complain to the data protection authority in your jurisdiction.

Also read

Terms of Service

Terms of Service