LearnRisk disclosureschain 4663

Security risks and 0xZAPS token disclosures.

OpenZaps narrows what an agent can do. It does not remove smart-contract, wallet, relayer, market, token, legal, or operational risk.

Transaction postureOwner-signed intents only

Primary risks

No external audit

The contracts and the interface have not been externally audited. They should not be treated as production-cleared for real funds. Depositing funds can result in total loss.

Onchain irreversibility

Transactions, approvals, swaps, and deposits cannot be reversed by OpenZaps once they are submitted onchain. Once an execution lands, nothing here can undo it.

Relayer and executor risk

A relayer, or any executor eligible to submit a recurring or triggered Zap, may fail, censor, delay, or submit at an unfavorable time inside the signed constraints. If no executor serves an intent, nothing runs. Each automated run also pays a fixed 1% of its measured output as a protocol fee.

Market risk

Slippage, liquidity, oracle movement, MEV, token volatility, and gas spikes can cause losses.

Token risk

0xZAPS is an ERC-20. It does not represent equity, revenue, yield, a redemption right, or a guarantee of protocol access. No return is implied.

User responsibility

Users must review wallet prompts, policy fields, amounts and spend limits, recipients, fees, and revocation paths before signing.

Request data and privacy

What the request desk stores

A Request a Zap submission stores the name and email you provide, project details, workflow, protocols or assets, trigger, safety limits, timeline, consent record, minimized campaign labels, and only the referring website's origin. OpenZaps derives a non-reversible abuse-control value from the request network address, but keeps it separately from lead records and never stores the raw address.

Why it is used

Authorized operators use this data only to assess the requested workflow, prevent form abuse, and reply about that request. A server-only email delivery provider forwards the submitted details to the designated OpenZaps operator mailbox so new requests can be reviewed promptly. That notification copy is separately processed and retained under the email delivery provider's and operator mailbox's policies; the database expiry below does not automatically delete an already-delivered email. Submission does not join a newsletter, authorize automated outreach, or grant any wallet or signing authority.

Privacy-minimized product analytics

OpenZaps uses Vercel Web Analytics to understand which public routes and product actions are useful. Query strings and URL fragments are removed before pageviews are sent, and EVM identifiers in route paths are replaced. Custom events contain at most two coarse labels. A controlled first-touch campaign label may remain in the current tab's session storage; raw campaign text, form contact fields, wallet addresses, transaction hashes, workflows, and project details are not sent as analytics event properties. Vercel receives limited standard request context needed to aggregate these events under its Web Analytics service.

X mention automation

Automated X mention ingestion is not active unless OpenZaps has separately enabled its official X API integration and compliance process. If activated, the service may process the numeric account, post, author, and conversation identifiers, source timestamp, a keyed one-way digest of the post text, a bounded policy classification, opt-out state, and delivery receipt. It does not retain the raw post text, username, display name, profile, link, or media. This data is used only to baseline the official mentions feed, suppress opted-out accounts, prevent duplicate replies, route ambiguous content to human review, and satisfy X deletion, protection, suspension, and withholding events. Protected and withheld observations are not retained.

X deletion and opt-out requests

Reply @0xzaps stop to an eligible mention to suppress automatic replies without receiving a public confirmation. To request deletion or correction of X-derived metadata, contact the official @0xzaps X account and ask to arrange a private channel. X compliance events are handled through the official provider path; automation remains paused after an erasure until absence is verified.

X storage and retention status

X mention ingestion remains disabled until OpenZaps has deployed an enforceable retention schedule and cleanup job, an official X compliance consumer, and deletion coverage for both Supabase records and deployment-pinned Vercel Workflow records. If the feature is activated later, X supplies the public source data, Supabase stores the minimized inbox and suppression records, and Vercel runs the API and workflow infrastructure. This notice will be updated with the enforced retention period before activation.

How long it remains

Request-desk database records expire after 180 days. A human-reviewed active design conversation may be renewed only within a fixed one-year maximum, and a closed request expires within 30 days. A daily retention job removes expired database records and short-lived abuse controls. Operators should delete the corresponding mailbox notification when its request is deleted; email-provider service records follow that provider's retention terms.

OpenZaps Discord app

Discord app terms

Effective August 1, 2026. These terms apply to the official OpenZaps Discord app in the OpenZaps server. The app provides deterministic educational responses to /ask, /openzaps, and /status, and it may publish source-reviewed OpenZaps updates through the configured public channel. It is not an AI chat agent, wallet, signer, executor, trading service, financial adviser, or security audit. Using a command does not connect a wallet, request a signature, submit or reverse a transaction, create or fund a Zap, or grant an agent any authority. OpenZaps contracts remain pre-audit.

Responses may be incomplete or become outdated and are provided without guaranteed availability. Use the app only in compliance with Discord's terms, community guidelines, and applicable law. Do not submit passwords, access tokens, private keys, seed phrases, wallet signatures, personal or sensitive information, or non-public vulnerability details in a command. Command text and the response may be visible in the Discord channel. Report vulnerabilities through GitHub private security reporting.

OpenZaps may limit, change, or disable the app to protect users or comply with platform requirements. Server administrators may remove it at any time. Nothing returned by the app is an offer, solicitation, investment recommendation, or guarantee. The effective date will change when these terms materially change.

Discord app privacy

Effective August 1, 2026. When a member invokes a command, Discord sends OpenZaps a signed interaction payload. It includes the command and option text and can include interaction, application, server, channel, and invoking-member identifiers; member, permission, and locale metadata; and a short-lived response token. OpenZaps uses this payload only to verify that the signed request belongs to the configured application and OpenZaps server, select a deterministic answer, and return that answer to Discord.

The deployed app does not read ordinary server messages or direct messages, connect to Discord's Gateway, use command text to prompt or train an AI model, build member profiles, target advertising, sell data, or contact members. OpenZaps does not persist the command question, member profile, username, or message content and does not intentionally write interaction payloads to its database or application logs; it processes them in memory for the request. Discord and Vercel necessarily process the payload and standard transport or security metadata under their respective policies. The command and response may remain visible in Discord according to the channel's settings.

OpenZaps retains only delivery-receipt metadata needed to prevent duplicate source-reviewed broadcasts; this receipt does not contain a member's command text. Because OpenZaps does not intentionally retain Discord interaction payloads, it normally has no application-level Discord record to delete. For access, correction, deletion, or privacy questions, contact the official @0xzaps account and ask to arrange a private channel. Requests concerning data retained by Discord must use Discord's privacy controls. Discord processes the interaction under its own terms and retention policies. This notice will be updated before the app stores Discord data or activates additional scopes.

No financial adviceNothing in OpenZaps is an offer, solicitation, investment recommendation, or guarantee.

The product is software for inspecting and constraining onchain execution. Users should get independent legal, tax, security, and financial advice before using any crypto protocol.