Privacy policy · draft · 18 September 2026

What we see, and what we cannot. 

This is written from the actual list of systems Dark runs and talks to, not from a template. It is a draft pending review by counsel; the facts in it are current.

01 · The principle

Dark is designed not to know.

Your keys are generated on your device and never leave it. Your USDG balance and the amounts you send to other Dark users are encrypted on chain with keys only you hold. The contents of a disclosure link are encrypted with a key that lives in the link itself and is never sent to us. Nothing below changes that.

What follows is the honest remainder: the metadata any service sees by existing, and the third parties your device contacts for features that are not private by nature.

02 · What our servers see

Request metadata, not contents.

When you…Our servers recordWhy
Sign inyour address, the time, and the IP address of the requestto issue a session and to rate-limit abuse
Look up an accountthat the request was madeaddresses and IPs are not written to logs on these routes
Use our blockchain relaythe requests your wallet makes, incl. signed transactionsyou can point the wallet at any other endpoint instead
Create a disclosure linkthat your signed-in account uploaded a blob of a given size, when, and when it was fetched, expired or revokedto serve and revoke it
Turn on payment notificationsthe link between your device's push token and your account, and when that account receives a paymentonly if you opt in; payloads never contain amounts or addresses
Trade a tokenised stockyour stated country of residence and the country your IP resolves towe are required to refuse some residents
Use the assistantnothing is stored; text is relayed to Anthropic with addresses strippedthe assistant runs there

Some stored identifiers — the owner of a disclosure, an eligibility record — are keyed by a keyed hash of your address rather than the address itself. This protects against a stolen database, not against us: we hold the key.

03 · What they cannot see

No key, no way.

DataWho can read it
Your vault balanceyou
The amount of a private paymentsender and recipient
A payment notesender and recipient
The contents of a disclosurewhoever holds the link
Your recovery phrase or keysyou

There is no Dark key, no support key and no auditor key that decrypts anything.

We cannot comply with a request to read a balance because we cannot read one.

04 · Third parties

Who your device talks to, and when.

Each of these is contacted for a specific feature. Where a feature is not private, we say so in the app before you use it.

PartyContacted whenThey receive
DigitalOceanany request to our APIhosts our servers and database
Vercelyou open darkwallet.cash or the web apphosts the site; standard access logs
Alchemyyour wallet uses our relaythe relayed blockchain requests
The public Robinhood Chain RPCyou choose it, the app falls back to it, or you open a disclosure linkyour IP and the requests, like any public node
Anthropicyou use the assistantyour messages with addresses stripped, relayed through our servers; never audio, never your IP
Apple or Googleyou speak to the assistantyour voice, if your phone's built-in speech recognition runs in the cloud; the text it produces is what reaches the assistant
LI.FIyou request a swap quotethe tokens, amounts and addresses in the quote
GMGN, Blockscout, CoinGecko, DexScreeneryou view market or explorer datathe token or address you asked about
Expo, Apple, Googleyou enable notificationsa push token; payloads carry no amounts or addresses
Google Fontsyou open the marketing pagesyour IP. Never on the disclosure viewer, which loads no third-party resources.

05 · The blockchain

Public by design, forever.

Robinhood Chain is a public ledger. Your address, your deposits and withdrawals, your ETH balance, and every transaction you send — including private ones, minus their amounts — are visible to anyone, permanently, and are not under our control or subject to deletion.

A disclosure link reveals your address to whoever opens it.

Everything already public about that address is then visible to them too.

06 · Retention

Short, and stated.

DataKept for
Server logs14 days
Sessions24 hours, or until you sign out
Sign-in nonces and rate-limit countersminutes
Disclosure ciphertextuntil it expires or you revoke it; a revoked or expired record answers 'gone' for 30 days, then is deleted
Push tokensuntil you turn notifications off or the platform reports the device gone
Residence attestation90 days
Assistant messagesnot stored

07 · Your choices

Most of this is optional.

Use your own endpoint

Settings → Network lets you replace our relay with any endpoint. Our servers then see nothing your wallet does on chain.

Skip the features that are not private

Swaps, market data, the assistant and notifications each contact a third party and are each off until you use them.

Leave entirely

You can withdraw everything without any Dark server, using the open-source exit tool described in the docs. Sign out and nothing about you remains on our servers beyond the retention periods above.

08 · Contact

Questions.

team@darkwallet.cash. This policy will be revised on review by counsel and again at mainnet launch; the date at the top is the date the facts were last checked.