Privacy Policy

Last updated: September 1, 2026

Axxion Wallet ("Axxion", "we", "our", "us") respects your privacy. This Privacy Policy explains what personal information we collect, how we use and share it, and the choices you have. It applies to the Axxion Wallet mobile app, web app, and related services (collectively, the "Service"). This policy is designed to align with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and the Apple App Store and Google Play developer policies.

1. Our Privacy-First Design

Axxion Wallet is a non-custodial wallet. Your private keys, recovery (seed) phrase, passcode, and biometric data are generated and stored on your device only. Where an encrypted copy of your recovery phrase is backed up through the Service, it is encrypted before it leaves your device and we cannot decrypt it. We cannot access your wallet or move your funds.

2. Information We Collect

Contact information (linked to you): email address and, optionally, your display name, when you create an account or contact support.

Financial information (linked to you): public wallet addresses you add or create, token balances, transaction history, and swap activity associated with your account, used to display and operate your wallet.

Sensitive information (linked to you): an encrypted backup of your recovery phrase if you enable backup, and security settings you configure (such as auto-lock and app-lock preferences). Biometrics (Face ID / Touch ID) never leave your device.

Customer support content (linked to you): messages, attachments, and contact details you share with our support team.

Other user content (linked to you): optional profile photo (avatar), wallet labels, asset preferences, and theme settings.

Browsing history (linked to you): decentralized applications (dApps) you connect to through the in-app browser, so you can manage and disconnect them.

Identifiers (linked to you): your account user ID and push-notification device tokens used to deliver alerts you enable.

Usage data (linked to you): product interaction data such as feature usage and a presence heartbeat used to show support availability. We do not build advertising profiles.

Diagnostics (not linked to you): crash reports, performance data, and app version / OS version information used to fix bugs and keep the Service reliable.

Public blockchain data: when you transact, your public address and transaction data are recorded on public blockchains outside our control.

What we do NOT collect: unencrypted private keys or recovery phrases, passcodes, biometric templates, precise location, your contacts, or your microphone and camera roll (unless you explicitly share media in a support conversation).

3. How We Use Information

  • To provide, maintain, and secure the Service (app functionality);
  • To authenticate you and prevent fraud or abuse;
  • To respond to support requests;
  • To send transactional and account notifications you enable, such as activity and price alerts, by push notification and email;
  • To comply with legal obligations;
  • To improve the Service through aggregated, non-identifying analytics.

4. Tracking

We do not track you across apps or websites owned by other companies, and we do not use your data for targeted advertising. No App Tracking Transparency permission is required on iOS. The web app uses only essential cookies and local storage required for authentication and preferences; we do not use third-party advertising cookies or cross-site tracking.

5. Legal Bases (GDPR / UK GDPR)

We process personal data based on: (a) performance of a contract (providing the Service); (b) legitimate interests (security, fraud prevention, product improvement); (c) consent (where required, e.g., optional notifications); and (d) legal obligations.

6. How We Share Information

We share the minimum necessary data with vetted service providers that process it on our behalf:

  • Cloud infrastructure provider (Lovable Cloud) that hosts our backend, database, authentication, and file storage under strict contractual safeguards;
  • Google, when you choose "Sign in with Google";
  • Resend, our transactional email provider, which processes your email address to deliver account and notification emails;
  • Push notification services (Apple Push Notification service and browser Web Push services), which process device tokens to deliver notifications you enable;
  • Public market-data providers (e.g., CoinGecko, Binance, Coinbase), which receive anonymous price queries and no personal information;
  • Authorities, when required by valid legal process.

We do not sell your personal information and do not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. None of our service providers collect data from the app for their own advertising or tracking purposes.

7. Data Security

We apply industry-standard safeguards, including TLS 1.2+ encryption in transit, encryption at rest for database and file storage, strict access controls, row-level security policies, and regular security reviews. Access to production systems is restricted and logged. No online system is 100% secure — protecting your recovery phrase is your responsibility. Our Security Practices page describes our controls in detail, including responsible disclosure.

8. Data Retention

Account data is kept while your account is active. Support conversations are kept for 24 months, security and fraud-prevention logs for up to 24 months, and diagnostic logs for 90 days, after which data is deleted or irreversibly anonymised. On account deletion, associated personal data is removed or anonymized within 30 days, except where retention is required by law. Note that data recorded on public blockchains cannot be deleted by us.

9. International Transfers

Our infrastructure providers may process data in the United States and the European Union. Where required, transfers out of the EEA or UK rely on the European Commission's Standard Contractual Clauses together with appropriate technical safeguards.

10. Your Rights

Subject to applicable law, you may have the right to access, correct, port, restrict, or delete your personal information; to withdraw consent; and to lodge a complaint with your local data-protection authority. California residents have the specific rights described under the CCPA/CPRA (right to know, delete, correct, opt out of "sale" or "sharing", and non-discrimination). You can exercise these rights from Settings or by contacting us.

11. Account and Data Deletion

You can delete your account and personal data at any time from Settings or by email. Full details of what is removed, what is retained, and how long it takes are on our Account & Data Deletion page. Deletion is also available to users who have not created an account by contacting us.

12. Children

The Service is rated 18+ and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that a child has provided us information, we delete the account and its data. See our Child Safety Standards.

13. Google Play Data Safety

All data collected in-app is encrypted in transit. You can request deletion of account data from Settings. A summary of collected data types and purposes is available in our Google Play Data Safety form, which mirrors the categories described in this Policy.

14. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified in-app or by email. The "Last updated" date reflects the latest revision.

15. Contact Us

To exercise your rights or ask about this Policy, contact us via the in-app support chat, the Help Center, or privacy@axxionpocket.com.