Transparency Report

We believe you deserve to know exactly how Valta operates — where funds go, what data we hold, and how the platform is run. No spin, no marketing numbers.

See a Real Audit Receipt

Every policy decision on Valta can be turned into a public, verifiable link like this one.

A real event, from Valta's own account

Blocked a $10.00 spend attempt — exceeded the $3.00 per-transaction limit

Real hash-chained decision, not staged for this page — view the live page →

Beta Disclosure

Valta is currently in closed beta. This means the platform, APIs, and features are still being refined. We may experience downtime, breaking changes, or data migrations. We will always communicate significant changes via email and the changelog.

During beta: core platform features are free. Paid agent subscriptions are the only live billing. All other billing begins at full launch.

Our Policies, Plainly Stated

No legal jargon. Here's exactly what we do and don't do.

Your Data

We store your email, name, and wallet activity to operate the platform.
We do not sell your data to third parties. Ever.
We use Supabase (PostgreSQL) hosted on AWS us-east-1 for data storage.
You can request a full export or deletion of your data by emailing privacy@valta.co.

Your Funds

USDC balances are held in your Valta wallet — not pooled or lent out.
Deposits are non-custodial on-chain; your balance reflects confirmed blockchain state.
We deduct agent subscription fees monthly from your wallet with notification.
Refund requests are handled within 5 business days via support@valta.co.

What We Can See

Admins can view account balances and transaction history for support purposes.
We can read bot/agent conversation logs for debugging when you report an issue.
We do not read your messages proactively — only if you open a support ticket.
All admin access is logged and audited with timestamps and email attribution.

Third-Party Services

AI models: DeepSeek V4-Pro (primary), OpenAI GPT-4o-mini (fallback). Your prompts are sent to these providers to generate agent responses.
Payments: Alchemy for USDC on-ramp. Paystack for card billing.
Infrastructure: Vercel (hosting + edge network), Supabase (database), Cloudflare Turnstile (bot protection on signup).
Analytics: We use Google Analytics, PostHog, and Cloudflare Web Analytics for aggregate product/traffic analytics. We also run a self-hosted visitor identification tool that resolves the company behind anonymous visits to valta.co from IP address (via IPinfo.io) — unlike a third-party vendor, the result is stored in our own database rather than an external company's platform. This runs without an explicit consent prompt today. If you'd rather not be identified this way, use a browser's privacy/tracking-protection mode.

Security

All data in transit is encrypted via TLS 1.3.
Passwords are hashed with bcrypt; we never store plaintext credentials.
Two-factor authentication (TOTP) is available and recommended for all accounts.
We run regular security reviews and have a responsible disclosure programme. See our security page.

Changelog & Communication

All platform changes are documented on our public changelog.
Breaking changes and billing updates are communicated by email at least 7 days in advance.
System incidents are reported in real time on status.valta.co.
We publish this transparency report and keep it live — not a PDF that goes stale.

How Our Agents Are Built

We believe you should know exactly how the AI agents on this platform are trained and shaped.

Model — DeepSeek V4-Pro

Agent conversations run on DeepSeek V4-Pro as the primary model, with OpenAI's GPT-4o-mini as an automatic fallback if DeepSeek is unavailable. We are not running our own foundation model.

System Prompt — Identity & Live Context

Each agent's personality, financial domain rules, and guardrails are defined in a system prompt built at runtime — which also injects your live wallet balances, recent transactions, spending patterns, connected apps, and your own instructions. This is how the agent gets current context, not a separately trained model per agent.

We're honest about this: we are not spending millions on GPU pre-training, and we have not fine-tuned a model yet. Today's agents run on prompt engineering alone. Fine-tuning on real (anonymized, opt-in) usage data is on our roadmap, not live — we'll update this page the day it ships.

Think the agent should know something it doesn't? Or want it to be able to do something new? Submit it to the Agent Roadmap. We review every submission — good ideas get shipped.

Questions? Contact us directly.

We're a small team and we actually read these.