Privacy Policy

Last updated: January 1, 2026

Axxion Wallet ("Axxion", "we", "our", "us") respects your privacy. This Privacy Policy explains what personal information we collect, how we use and share it, and the choices you have. It applies to the Axxion Wallet mobile app, web app, and related services (collectively, the "Service"). This policy is designed to meet the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and the Apple App Store and Google Play developer policies.

1. Our Privacy-First Design

Axxion Wallet is a non-custodial wallet. We never store or transmit your private keys, seed phrase, passcode, or biometric data. Those values are generated and stored on your device only. We cannot access your wallet or your funds.

2. Information We Collect

Account information you provide: email address, display name, and optional profile photo when you create an account.

Wallet metadata (on your device): wallet labels, address book entries, asset preferences, and theme.

Support communications: messages, attachments, and contact details you share with our support team.

Device & usage data: IP address (used transiently, not stored beyond logs), device type, OS version, app version, crash reports, and coarse analytics on which features are used. We do not build advertising profiles.

Public blockchain data: when you transact, your public address and transaction data are recorded on public blockchains outside our control.

What we do NOT collect: private keys, recovery phrases, passcodes, biometrics (Face ID / Touch ID stays on your device), precise location, contacts, microphone, or camera roll (unless you explicitly share media in support chat).

3. How We Use Information

  • To provide, maintain, and secure the Service;
  • To authenticate you and prevent fraud or abuse;
  • To respond to support requests;
  • To send transactional notifications (e.g., activity alerts);
  • To comply with legal obligations;
  • To improve the Service through aggregated, non-identifying analytics.

4. Legal Bases (GDPR / UK GDPR)

We process personal data based on: (a) performance of a contract (providing the Service); (b) legitimate interests (security, fraud prevention, product improvement); (c) consent (where required, e.g., certain analytics); and (d) legal obligations.

5. How We Share Information

We share limited information with:

  • Infrastructure providers that host our backend, database, and file storage under strict contractual safeguards;
  • Market-data providers such as CoinGecko for prices and token metadata;
  • Sign-in providers such as Google, when you choose that option;
  • Authorities when required by valid legal process.

We do not sell your personal information and do not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.

6. Data Retention

We retain account and support data for as long as your account is active and for a limited period after deletion to meet legal, tax, and security obligations. You can delete your account at any time from Settings; on deletion, associated data is removed or anonymized within 30 days, except where retention is required by law.

7. Data Security

We apply industry-standard safeguards, including TLS encryption in transit, at-rest encryption of database and file storage, strict access controls, row-level security policies, and regular security reviews. No online system is 100% secure — protecting your recovery phrase is your responsibility.

8. International Transfers

Our providers may process data outside your country. Where required, transfers rely on Standard Contractual Clauses or an equivalent legal transfer mechanism.

9. Your Rights

Subject to applicable law, you may have the right to access, correct, port, restrict, or delete your personal information; to withdraw consent; and to lodge a complaint with your local data-protection authority. California residents have the specific rights described under the CCPA/CPRA (right to know, delete, correct, opt out of "sale" or "sharing", and non-discrimination). You can exercise these rights from Settings or by contacting support.

10. Children

The Service is not directed to children under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided us information, contact us and we will delete it.

11. Cookies and Similar Technologies

The web app uses only essential cookies and local storage required for authentication and preferences. We do not use third-party advertising cookies or cross-site tracking.

12. Apple App Tracking Transparency

We do not track you across apps or websites owned by other companies. No App Tracking Transparency permission is required.

13. Google Play Data Safety

All data collected in-app is encrypted in transit. You can request deletion of account data from Settings. A summary of collected data types and purposes is available in our Google Play Data Safety form.

14. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified in-app or by email. The "Last updated" date reflects the latest revision.

15. Contact Us

To exercise your rights or ask about this Policy, contact us via the in-app support chat or the Help Center.