Oberton Wallet Privacy Policy

Version 2.0 · Effective date: August 2, 2026

This Privacy Policy explains how Товариство з обмеженою відповідальністю «БАЙТХАБ» (Limited Liability Company “BYTEHUB”) (“BYTEHUB,” “we,” “us,” or “our”) processes information in connection with the Oberton Wallet mobile application, the oberton.app website, and communications with customer support (together, the “Service”).

Oberton Wallet is a non-custodial crypto wallet. We do not custody or control your crypto assets, and we do not ask you to send us your seed phrase (recovery phrase), private keys, App passcode, or backup password. Anyone who gains access to a seed phrase or private keys may control the corresponding assets. We cannot recover lost keys or reverse or alter a record on a public blockchain.

1. Scope and Applicable Law

This Policy applies to the processing of information when you use the Oberton Wallet mobile application (the “App”), visit the oberton.app website, including its static legal pages, and communicate with us by email or through other official support channels.

We process personal data in accordance with the Constitution of Ukraine, Law of Ukraine No. 2297-VI “On Personal Data Protection,” and other applicable legal requirements. Individual service providers may also independently process data in accordance with the laws that apply to them and their own privacy policies.

The Ukrainian and English versions of this Policy have the same content. The Ukrainian version applies and, if there is a translation inconsistency, prevails for users in Ukraine and where Ukrainian law applies; the English version is intended primarily for users outside Ukraine. Mandatory requirements of the law of the user’s country prevail regardless of the language of the Policy.

2. Personal Data Controller and Contact Details

The personal data controller for processing determined by us is:

Товариство з обмеженою відповідальністю «БАЙТХАБ» (Limited Liability Company “BYTEHUB”)
Ukrainian company identification code (EDRPOU) 44264947
9 Karelska Street, Dnipro, Dnipropetrovsk Region, 49074, Ukraine
email: support@oberton.app

For data that remains only on your device or in a personal cloud account selected by you and that we cannot access, actual control is exercised by you and/or the relevant device or cloud service provider. Below, we clearly distinguish such local processing from data that may be transmitted to our servers or service providers.

3. Processing at a Glance

4. Categories and Sources of Information

Where this section uses words such as “for example,” “such as,” “including,” or “may include,” the corresponding list gives typical examples rather than an exhaustive list of event names or technical fields. It covers only data of a similar nature within the described category and expressly stated purpose. It does not mean that we may collect any information, place wallet secrets in analytics, or use data for a new incompatible purpose without an appropriate legal basis and advance update to this notice where an update is required by law.

4.1. Data We Do Not Intentionally Collect on Our Servers

We do not request or intend to collect the following on our servers:

Do not send seed phrases, private keys, passwords, passcodes, or other secrets in support requests. If you voluntarily send information that we did not request, we will receive the contents of that communication and may process it only to the extent necessary to respond, maintain security, comply with law, or delete it.

4.2. On-Device Wallet Data

To operate as a wallet, the App stores and processes on your device data that may include seed names, public wallet addresses, public keys, contacts, asset lists, token metadata, transaction history, App settings, notification preferences, and encrypted wallet data. Seed phrases and private keys are stored locally on your device using platform security mechanisms and App-level encryption where implemented. The mere fact that these data exist locally does not mean that we receive them on a server.

4.3. Diagnostic, Operational, and Product Analytics Data

Depending on the platform, App version, and enabled settings, we and our service providers may receive limited categories of technical, diagnostic, operational, and product analytics data. These may include, without limitation, crash reports and stack traces; performance, error, and stability metrics; App and operating-system versions; device model, platform, language, or locale; approximate time and technical status of an installation, launch, update, session, or feature action; technical logs; and interactions with screens, controls, buttons, and features. This helps identify and fix errors, investigate crashes, maintain the security and operation of the Service, verify that features work, and improve the product.

Typical examples of feature-use events include opening or closing the App; creating or restoring a wallet or asset; navigating to a screen; pressing a control or button; starting, completing, or encountering an error in sending, staking, or another feature; selecting a theme or network; contact or invoice operations; and WalletConnect events. Event parameters may include, without limitation, the event name and technical status, screen or feature, blockchain network, asset type, token symbol, chain ID, App version, platform, language, device model, a technical installation or session identifier, and limited operation attributes such as an amount or public depool address. Specific event names and parameter sets may change between versions within the categories and purposes described above.

We do not intend to place seed phrases, private keys, the App passcode, backup password, biometric template, or full content of a private communication in diagnostic or analytics events. We do not use these data for the purpose of learning your name. However, technical identifiers and public blockchain information may relate to an individual in certain circumstances and are therefore treated by us as potentially personal data. Before collecting a materially new category of data or using data for a separate purpose such as advertising attribution, profiling, or targeted marketing, we will update this Policy and, where required by law, request separate consent or provide another required choice mechanism.

4.4. Push Notification Data

If you enable transaction or signing notifications, the App may send our server a device token, Firebase Cloud Messaging token, Apple Push Notification service token, platform type, and the public wallet address or public signing address for which notifications are requested. These data are used to deliver notifications and manage notification subscriptions.

4.5. API and Network Requests

The App communicates with Oberton APIs and third-party network services to retrieve prices, token lists, remote configuration, version notices, blockchain data, transaction history, wallet connection data, and other operational information. Through the ordinary operation of internet protocols, these requests may include your IP address, headers containing a device token where required for App services, public wallet addresses, transaction hashes, token identifiers, chain IDs, and other data necessary to respond to the request.

4.6. Optional Cloud Backup

If you enable cloud backup, the App may create a backup containing selected seed phrases, wallet metadata, asset lists, contacts, public keys, and settings. Before it is sent to the cloud, the backup is encrypted locally with a password you choose. On iOS, the backup may be stored in your iCloud, and on Android, it may be stored in your Google Drive. We do not receive the backup password and cannot decrypt or restore the backup if you lose the password. The contents of the backup are stored in your cloud account according to your settings and Apple’s or Google’s rules, rather than on our servers.

4.7. Camera and Biometric Authentication

The App may request camera access to scan QR codes. Biometric authentication, including Face ID or fingerprint authentication, is performed by the operating system. We do not receive the biometric template. You can control access in your operating-system settings.

4.8. Website Data

When you visit oberton.app, the web server and infrastructure providers may automatically process standard request logs: IP address, browser type and version, device and operating-system type, requested URL or page, date and time of the request, referrer, response codes, and technical error details. These data arise from your browser and network connection and are needed to deliver pages, maintain availability, diagnose problems, and protect the website.

The website uses Google Fonts. To load the fonts, your browser may connect directly to Google servers, as a result of which Google receives the IP address and standard HTTP request details under its own privacy policy. The static pages containing this Policy use system fonts and do not themselves load Google Fonts.

4.9. Support Communications

When you contact us, we receive your email address, name or alias if you provide one, the content and subject of the message, attachments, and technical details you choose to provide. The sources of these data are you and the email or communications providers needed to deliver the message.

If you independently contact us or a community through a third-party messenger or social platform, its provider separately processes your account data, metadata, and message content under its own policy. We may receive the name or alias, username or account identifier, metadata, and message content made available through that channel. Such a channel is an official support channel only when it is expressly identified as official in the App, at oberton.app, or in an official Oberton Wallet app-store listing. Do not send seed phrases, private keys, passwords, passcodes, documents, or other sensitive information through messengers.

4.10. Public Blockchain Information

Public blockchains are transparent by design. When you use an address, make a transaction, interact with a smart contract, or receive tokens, the public address, balance, transaction hash and amount, timestamp, fees, and contract calls may be publicly available and stored indefinitely. This information comes from public blockchains, RPC nodes, indexers, and explorers. We cannot delete or alter a blockchain record.

4.11. Optional Third-Party Provider Features

If a particular version of the App allows you, at your initiative, to open or use a third-party swap, bridge, on-ramp, payment service, dApp, or another integrated feature, the independent provider may directly receive a public wallet address, transaction details or request, IP address, device information, account data, and, if required by that provider, identification (KYC) or payment data. The scope is determined by the selected feature and the provider’s policy. Merely launching such a feature does not mean that we receive those data; unless the interface expressly states otherwise, they are transmitted to the independent provider with which you interact. Review its terms and privacy policy before use.

4.12. Data Sources

Depending on the feature, we receive information:

5. Purposes and Legal Bases for Processing

Depending on the specific data and feature, we process information for the following purposes and on the following bases provided by Article 11 of Law of Ukraine “On Personal Data Protection”:

Where processing is based on consent, withdrawing it does not affect the lawfulness of processing performed before withdrawal. Refusing to provide data objectively required for a requested feature may make that feature unavailable; other features may remain available.

6. Providers and Third-Party Services

Depending on the platform, region, feature, and App version, we may use the services listed below. They may act as our personal data processors or as independent controllers for processing they determine themselves, and they apply their own terms and policies:

If a particular SDK or provider has been removed from the current build, it may still apply to older versions installed by users until they update. The exact provider set may change with features and platforms; we will reflect material changes in this Policy. Before using a new provider where doing so introduces a materially new data category, processing purpose, or international-transfer method, we will update the relevant information and provide any choice mechanism required by law.

7. Transfers and Disclosures of Information

We do not sell personal data. For the purposes described above, information may be transferred to:

In addition, your device may send requests directly to public blockchains and third-party services. Such direct transmission results from the feature you use and does not necessarily mean that we receive the data first.

8. International Data Transfers

Some providers, servers, or recipients may be located outside Ukraine, and their infrastructure may process data in other countries. The laws of those countries may differ from the laws of Ukraine.

Where we determine an international transfer of personal data, it is carried out subject to the conditions and legal bases established by Article 29 of Law of Ukraine “On Personal Data Protection” and applicable international treaties: to countries providing an adequate level of protection or, in other cases, with consent or another basis provided by law and taking into account available contractual, organizational, and technical safeguards. When you directly use iCloud, Google Drive, WalletConnect, a public blockchain, or another third-party service, the relevant provider may independently determine international transfers under its policy.

9. Retention

We retain data controlled by us no longer than reasonably necessary for the purposes described in this Policy, taking into account the nature and volume of the data, duration of feature use, security needs, provider settings, backup cycles, limitation periods, and legal obligations. Because these criteria depend on context and may change, we do not set a single fixed period for every category in this Policy.

Once a purpose no longer applies, we delete or anonymize data controlled by us or isolate them pending deletion if immediate deletion is not possible because of backups or a technical cycle, except where further retention is required or permitted by law.

10. Security

We use legal, organizational, and technical measures designed to protect personal data under our control against unlawful or accidental loss, destruction, access, alteration, or disclosure. Measures are selected in view of the nature of the data, means of processing, and available technologies. Nevertheless, no software, device, network, blockchain, smart contract, or cloud provider can be guaranteed to be secure or error-free.

You are responsible for securing your device, seed phrases, private keys, passcode, cloud accounts, and backup password. Do not send these secrets to us or third parties, and verify addresses, transactions, and signing requests before confirming them.

11. Your Personal Data Rights

Under Article 8 of Law of Ukraine “On Personal Data Protection,” you have the right to:

  1. know the sources from which your personal data are collected, the location of your personal data, the purpose of processing, and the location of the controller or processor, or authorize persons appointed by you to obtain this information, except in cases established by law;
  2. receive information about the conditions for granting access to personal data, including information about third parties to whom they are transferred;
  3. access your personal data;
  4. receive, no later than thirty calendar days after a request is received except in cases provided by law, a response as to whether your personal data are processed and receive the contents of those data;
  5. submit a reasoned demand objecting to the processing of your personal data;
  6. submit a reasoned demand to any controller or processor for amendment or destruction of your personal data if the data are processed unlawfully or are inaccurate;
  7. have your personal data protected against unlawful processing and accidental loss, destruction, or damage resulting from deliberate concealment, failure to provide or untimely provision, and against the provision of inaccurate information or information discrediting honor, dignity, and business reputation;
  8. complain about the processing of personal data to the Ukrainian Parliament Commissioner for Human Rights or to a court;
  9. use legal remedies if personal data protection law is violated;
  10. make reservations restricting the right to process your personal data when giving consent;
  11. withdraw consent to personal data processing;
  12. know the mechanism of automatic personal data processing;
  13. be protected from an automated decision that has legal consequences for you.

We do not make decisions about users that are based solely on automated processing of personal data controlled by us and have legal consequences for them. Rights may be restricted only in the cases and to the extent established by law.

12. How to Exercise Your Rights

Send a request to support@oberton.app with the subject line “Personal Data Request.” Describe the right you want to exercise and the data or feature concerned, and provide enough information to locate the relevant records and confirm that they relate to you. Never send your seed phrase, private keys, backup password, or passcode.

To avoid disclosing data to another person, we may ask you, proportionately to the risk, to confirm control of your email address, support-request identifier, device, or another related identifier. If the law requires additional request details or proof of identity, we will tell you what is needed. We will not ask for a seed phrase or private key.

Within no more than ten business days after receiving a request, we will tell you whether it will be fulfilled or state the legal ground on which the data may not be provided. The request will be fulfilled within thirty calendar days after receipt unless otherwise provided by law. A data subject receives access to data about himself or herself free of charge. Where permitted by law, we may refuse, restrict performance, or retain certain data and will explain the available appeal procedure.

We can fulfill a request only for data that we control and can reasonably link to you. Deleting a server-side record does not delete local data on your device, a backup in your iCloud or Google Drive, data held by an independent third-party controller, or an immutable public blockchain record. Those data must be controlled through the relevant device, account, or provider where deletion is technically and legally possible.

You may also contact the Ukrainian Parliament Commissioner for Human Rights or a court.

13. Your Settings and Choices

14. Children

The Service is not intended for children. A user must be at least 18 years old or any higher age of majority established by the law of the user’s jurisdiction. We do not knowingly collect children’s personal data. If you believe a child has provided personal data to us, email support@oberton.app; after appropriate verification, we will take the legally required measures concerning data under our control.

15. Third-Party Resources and Features

The Service may contain links to third-party websites, applications, dApps, protocols, or services. We do not determine their purposes and means of processing and are not responsible for their policies. Review a third-party resource’s terms and privacy policy before interacting with it. Public blockchains and smart contracts may disclose information independently of us.

16. Changes to This Policy

We may update this Policy periodically because of changes to the Service, providers, or law. The current version will be posted on this page with a new effective date. If changes materially affect processing, we will give additional notice in a reasonable and accessible manner where required by law. Previous versions may be provided on reasonable request if retained in our records.

17. Contact Us

For questions about this Policy or personal data processing, contact:

ТОВ «БАЙТХАБ» (BYTEHUB LLC)
Ukrainian company identification code (EDRPOU) 44264947
9 Karelska Street, Dnipro, Dnipropetrovsk Region, 49074, Ukraine
support@oberton.app