ZELYO.
The Protocol How it Works Contact
Open the App arrow_outward
Folio · Privacy Policy

Privacy Policy

How Zelyo handles information — and, by design, what stays strictly private. This policy explains what we collect, what we never see, and the rights you hold over your own data.

Contents

  • 1 · Introduction
  • 2 · Information We Handle
  • 3 · What Stays Private
  • 4 · How We Use Information
  • 5 · Sharing
  • 6 · Data Retention
  • 7 · Data Security
  • 8 · Cookies
  • 9 · Your Rights
  • 10 · Third-Party Links
  • 11 · Changes to This Policy
  • 12 · Contact Us
event Effective date · March 18, 2026

1. Introduction

Zelyo (“we,” “us,” “our”) is a privacy-preserving credential protocol built on the Stellar network. We issue, hold, and verify cryptographic credentials in zero knowledge. This Privacy Policy describes how the Zelyo website at zelyo.one and the application at app.zelyo.one (together, the “Service”) handle information, and — uniquely — what we never receive.

Zelyo is operated by Artisam Labs. By accessing or using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.

In one line

The chain records only an anonymous seal. Your private attributes stay with you.

2. Information We Handle

We handle the following categories of information:

  • Account information. The email address and Stellar address you provide when you register as an issuer or holder.
  • Credential metadata. The public identifiers associated with a credential — issuer, scope, Merkle root, and leaf index — but not the private attribute values themselves.
  • On-chain records. Nullifiers, bound addresses, and verification results written to the Stellar ledger. These are public by nature of a public blockchain.
  • Usage data. Pages visited, browser type, device information, and IP address, collected in server logs for security and abuse prevention.
  • Cookies. Essential and optional cookies, described in Section 8.

3. What Stays Private

Zelyo is built so that the most sensitive data never reaches us. When you generate a zero-knowledge proof, the proving happens in your browser. Your private attributes — name, grade, course, issue date, and any predicate inputs — are transformed locally into a proof and a nullifier.

We do not transmit, store, or log your private credential attributes. We cannot read what we never receive. Verification confirms a fact about you without revealing the underlying data.

4. How We Use Information

  • To operate the Service — issuing credentials, publishing roots, and recording sealed attestations on-chain.
  • To process and verify zero-knowledge proofs, and to return verification results.
  • To prevent fraud, Sybil attacks, and abuse, including nullifier reuse detection.
  • To provide support and respond to your inquiries.
  • To improve the Service and maintain security and audit logs.
  • To comply with legal obligations where required.

5. Sharing Your Information

We do not sell or rent personal data. We share information only:

  • With infrastructure providers (hosting, database, and blockchain RPC services) under confidentiality and data-processing terms;
  • When required by law or valid legal process, to the minimum extent necessary;
  • To protect our rights, investigate fraud, or defend against claims.

On-chain nullifiers and bound addresses are, by design, publicly readable on the Stellar ledger. This is a feature of the protocol, not a disclosure by us.

6. Data Retention

We retain account and audit-log information only as long as needed for the purposes described here or as required by law. Server logs are retained for a limited period for security and abuse analysis. On-chain records — nullifiers, roots, and attestations — are permanent and cannot be deleted by us; this is an inherent property of a public blockchain.

7. Data Security

We use technical and organizational safeguards appropriate to the sensitivity of the information we hold. The strongest protection, however, is architectural: your private attributes are processed client-side and are never transmitted to our servers. No method of transmission over the internet is fully secure, but zero-knowledge proofs are designed so that the data itself never leaves your device.

8. Cookies

The Service uses three types of cookies:

  • Essential cookies — required for the Service to function, including your cookie consent choice.
  • Analytics cookies — help us understand which pages are read, so we can improve them. Optional and only set if you accept them.
  • Preference cookies — remember display choices such as reduced-motion preferences. Optional.

You can manage or disable cookies through your browser controls. The cookie consent prompt lets you accept or decline optional cookies at any time.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate data;
  • Request deletion of your personal data, subject to legal retention obligations;
  • Withdraw consent for optional cookies or marketing;
  • Opt out of analytics at any time.

To exercise any of these rights, write to hello@artisam.xyz. Note that we cannot alter or delete public on-chain records, as they are not under our control.

10. Third-Party Links

The Service may link to external sites — including the Stellar explorer, wallet providers, and the Chrome Web Store. We are not responsible for the privacy practices or content of those sites. Please review their policies separately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page with an updated effective date. Continued use of the Service after changes signifies acceptance of the revised policy.

12. Contact Us

Questions about this policy or your data? Address your correspondence to the keeper of the ledger:

Correspondence

hello@artisam.xyz
Zelyo · A protocol of Artisam Labs

© A.D. MMXXVI Zelyo · A protocol of Artisam Labs.
Home Privacy Terms Contact