New Xendra Keys — shard your phrase, recover with any two. Read the note →

Legal

Privacy Policy

The short version: your keys and your recovery phrase never leave your device, we run no accounts, and the wallet works without you telling us who you are.

Version 3.6Effective 1 August 2026Controller Xendra Labs OÜReading time ~8 min

01The short version

We built Xendra so that using it well requires giving us almost nothing. There is no sign-up, no email, no KYC and no account. The parts of the app that touch money work entirely on your device.

Never collected

Your recovery phrase

Generated in the secure enclave, encrypted at rest, never transmitted in any form.

Never collected

Private keys or shards

Signing happens locally. Only finished signatures reach the network.

Never collected

Identity documents

No KYC, no selfie, no proof of address. We are not a custodian.

Optional

Crash and usage data

Off by default. You turn it on in Settings › Privacy, and you can turn it off again.

02Who is responsible

The data controller is Xendra Labs OÜ, Sepapaja 6, 15551 Tallinn, Estonia. Our data protection contact is contact@xendra.xyz.

We process personal data under the EU General Data Protection Regulation. Where we mention a legal basis below, it is one of: your consent, our legitimate interest in running secure software, or a legal obligation.

03What we actually collect

DataWhyLegal basisKept for
IP address at RPC and price requestsDelivering the response, blocking abuseLegitimate interestTruncated immediately, logs 72 hours
App version, OS version, device modelShipping the right update, reproducing bugsLegitimate interest30 days
Crash reportsFixing crashesConsent, off by default90 days
Anonymous feature countersDeciding what to buildConsent, off by default13 months, aggregated
Support messages you send usAnswering youLegitimate interest24 months
Bounty submissionsTriage and payoutContract6 years, accounting rules

Crash reports are scrubbed on device before they are sent: addresses, amounts, labels, contact names and anything that looks like a mnemonic are stripped or replaced with placeholders. If a report cannot be scrubbed with confidence, it is discarded rather than sent.

04What we deliberately avoid

  • No wallet-address telemetry. We do not log which addresses belong to which installation, and we do not build address graphs.
  • No advertising identifiers. No IDFA, no GAID, no fingerprinting scripts, no ad SDKs, ever.
  • No third-party analytics in the wallet. The optional metrics pipeline is ours and is described above.
  • No selling or renting data. Not to brokers, not to chain-analytics firms, not to anyone.

Verify, do not trust

Every network call the app can make is documented in the networking appendix, and the client is reproducible from source. Point it at a proxy and check.

05Blockchain data is public and permanent

When you broadcast a transaction it becomes part of a public ledger that we do not control and cannot edit. Addresses, amounts, timestamps and counterparties are visible to everyone, forever. This is a property of the networks, not a choice we made, and no privacy policy can undo it.

Analysis firms can and do link addresses to identities using exchange deposits, IP metadata and reuse patterns. If you need stronger separation, use separate accounts per purpose, avoid address reuse, and run your own RPC endpoints.

06Third parties your wallet talks to

By default the app fetches balances, prices and quotes through our proxy so that your IP address is not exposed directly to those providers. The proxy forwards the query, not your identity, and does not store the pairing between requests.

Where you choose to use an integrated on-ramp, that provider performs its own identity checks and becomes an independent controller of the data you give it. We receive only a status code for the order, never your documents.

App stores report install counts and crash rates to us in aggregate under their own privacy policies.

07Your rights

You may ask us to confirm what we hold about you, to give you a copy, to correct it, to delete it, to restrict or object to processing, or to port it elsewhere. You may withdraw consent for optional telemetry at any time in Settings, with no effect on the wallet.

Write to contact@xendra.xyz. We answer within 30 days. Because we hold so little, most requests are answered by telling you honestly that we have nothing tied to you.

You may also complain to your national supervisory authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

08Storage, transfers and security

Our servers are in Frankfurt and Helsinki. Backups stay in the European Economic Area. Where a sub-processor operates outside the EEA, we rely on the European Commission's standard contractual clauses.

Data in transit uses TLS 1.3 with certificate pinning in the mobile apps. Internal access is limited to named engineers, requires hardware keys, and is logged. Our security practices are described in the security overview.

09Children

Xendra is not for people under 18 and we do not knowingly process their data. If you believe a child has sent us personal data, write to us and we will delete it.

10Changes to this policy

We publish changes here with a new version number and effective date, and we announce material changes in the app at least 14 days ahead. Previous versions stay available at request.

Start holding your own keys.

iOS, Android, desktop and a browser extension — the same vault on all of them. Free, and it stays free.