Oberton Wallet Privacy Policy
Version 2.0 · Effective date: August 2, 2026
This Privacy Policy explains how Товариство з обмеженою відповідальністю «БАЙТХАБ» (Limited Liability Company “BYTEHUB”) (“BYTEHUB,” “we,” “us,” or “our”) processes information in connection with the Oberton Wallet mobile application, the oberton.app website, and communications with customer support (together, the “Service”).
Oberton Wallet is a non-custodial crypto wallet. We do not custody or control your crypto assets, and we do not ask you to send us your seed phrase (recovery phrase), private keys, App passcode, or backup password. Anyone who gains access to a seed phrase or private keys may control the corresponding assets. We cannot recover lost keys or reverse or alter a record on a public blockchain.
1. Scope and Applicable Law
This Policy applies to the processing of information when you use the Oberton Wallet mobile application (the “App”), visit the oberton.app website, including its static legal pages, and communicate with us by email or through other official support channels.
We process personal data in accordance with the Constitution of Ukraine, Law of Ukraine No. 2297-VI “On Personal Data Protection,” and other applicable legal requirements. Individual service providers may also independently process data in accordance with the laws that apply to them and their own privacy policies.
The Ukrainian and English versions of this Policy have the same content. The Ukrainian version applies and, if there is a translation inconsistency, prevails for users in Ukraine and where Ukrainian law applies; the English version is intended primarily for users outside Ukraine. Mandatory requirements of the law of the user’s country prevail regardless of the language of the Policy.
2. Personal Data Controller and Contact Details
The personal data controller for processing determined by us is:
Товариство з обмеженою відповідальністю «БАЙТХАБ» (Limited Liability Company “BYTEHUB”)Ukrainian company identification code (EDRPOU) 44264947
9 Karelska Street, Dnipro, Dnipropetrovsk Region, 49074, Ukraine
email: support@oberton.app
For data that remains only on your device or in a personal cloud account selected by you and that we cannot access, actual control is exercised by you and/or the relevant device or cloud service provider. Below, we clearly distinguish such local processing from data that may be transmitted to our servers or service providers.
3. Processing at a Glance
- We do not collect or store your seed phrases, private keys, App passcode, biometric templates, or backup password on our servers.
- The wallet and related data are primarily processed locally on your device.
- To operate specific features, we and our providers may process technical, diagnostic, and operational data.
- If you enable push notifications, push tokens and public addresses needed to deliver transaction or signing-request notifications may be processed.
- If you enable cloud backup, the backup is encrypted locally with a password you choose and then stored in your own iCloud or Google Drive account, depending on the platform. We do not receive the backup password.
- Public addresses, balances, transactions, and smart-contract interactions may be publicly available on a blockchain by design and are outside our control.
4. Categories and Sources of Information
Where this section uses words such as “for example,” “such as,” “including,” or “may include,” the corresponding list gives typical examples rather than an exhaustive list of event names or technical fields. It covers only data of a similar nature within the described category and expressly stated purpose. It does not mean that we may collect any information, place wallet secrets in analytics, or use data for a new incompatible purpose without an appropriate legal basis and advance update to this notice where an update is required by law.
4.1. Data We Do Not Intentionally Collect on Our Servers
We do not request or intend to collect the following on our servers:
- seed phrases, recovery phrases, or private keys;
- your App passcode or biometric data;
- your cloud backup password;
- passport data, government identification documents, postal address, or other identity verification documents;
- payment card data.
Do not send seed phrases, private keys, passwords, passcodes, or other secrets in support requests. If you voluntarily send information that we did not request, we will receive the contents of that communication and may process it only to the extent necessary to respond, maintain security, comply with law, or delete it.
4.2. On-Device Wallet Data
To operate as a wallet, the App stores and processes on your device data that may include seed names, public wallet addresses, public keys, contacts, asset lists, token metadata, transaction history, App settings, notification preferences, and encrypted wallet data. Seed phrases and private keys are stored locally on your device using platform security mechanisms and App-level encryption where implemented. The mere fact that these data exist locally does not mean that we receive them on a server.
4.3. Diagnostic, Operational, and Product Analytics Data
Depending on the platform, App version, and enabled settings, we and our service providers may receive limited categories of technical, diagnostic, operational, and product analytics data. These may include, without limitation, crash reports and stack traces; performance, error, and stability metrics; App and operating-system versions; device model, platform, language, or locale; approximate time and technical status of an installation, launch, update, session, or feature action; technical logs; and interactions with screens, controls, buttons, and features. This helps identify and fix errors, investigate crashes, maintain the security and operation of the Service, verify that features work, and improve the product.
Typical examples of feature-use events include opening or closing the App; creating or restoring a wallet or asset; navigating to a screen; pressing a control or button; starting, completing, or encountering an error in sending, staking, or another feature; selecting a theme or network; contact or invoice operations; and WalletConnect events. Event parameters may include, without limitation, the event name and technical status, screen or feature, blockchain network, asset type, token symbol, chain ID, App version, platform, language, device model, a technical installation or session identifier, and limited operation attributes such as an amount or public depool address. Specific event names and parameter sets may change between versions within the categories and purposes described above.
We do not intend to place seed phrases, private keys, the App passcode, backup password, biometric template, or full content of a private communication in diagnostic or analytics events. We do not use these data for the purpose of learning your name. However, technical identifiers and public blockchain information may relate to an individual in certain circumstances and are therefore treated by us as potentially personal data. Before collecting a materially new category of data or using data for a separate purpose such as advertising attribution, profiling, or targeted marketing, we will update this Policy and, where required by law, request separate consent or provide another required choice mechanism.
4.4. Push Notification Data
If you enable transaction or signing notifications, the App may send our server a device token, Firebase Cloud Messaging token, Apple Push Notification service token, platform type, and the public wallet address or public signing address for which notifications are requested. These data are used to deliver notifications and manage notification subscriptions.
4.5. API and Network Requests
The App communicates with Oberton APIs and third-party network services to retrieve prices, token lists, remote configuration, version notices, blockchain data, transaction history, wallet connection data, and other operational information. Through the ordinary operation of internet protocols, these requests may include your IP address, headers containing a device token where required for App services, public wallet addresses, transaction hashes, token identifiers, chain IDs, and other data necessary to respond to the request.
4.6. Optional Cloud Backup
If you enable cloud backup, the App may create a backup containing selected seed phrases, wallet metadata, asset lists, contacts, public keys, and settings. Before it is sent to the cloud, the backup is encrypted locally with a password you choose. On iOS, the backup may be stored in your iCloud, and on Android, it may be stored in your Google Drive. We do not receive the backup password and cannot decrypt or restore the backup if you lose the password. The contents of the backup are stored in your cloud account according to your settings and Apple’s or Google’s rules, rather than on our servers.
4.7. Camera and Biometric Authentication
The App may request camera access to scan QR codes. Biometric authentication, including Face ID or fingerprint authentication, is performed by the operating system. We do not receive the biometric template. You can control access in your operating-system settings.
4.8. Website Data
When you visit oberton.app, the web server and infrastructure providers may automatically process standard request logs: IP address, browser type and version, device and operating-system type, requested URL or page, date and time of the request, referrer, response codes, and technical error details. These data arise from your browser and network connection and are needed to deliver pages, maintain availability, diagnose problems, and protect the website.
The website uses Google Fonts. To load the fonts, your browser may connect directly to Google servers, as a result of which Google receives the IP address and standard HTTP request details under its own privacy policy. The static pages containing this Policy use system fonts and do not themselves load Google Fonts.
4.9. Support Communications
When you contact us, we receive your email address, name or alias if you provide one, the content and subject of the message, attachments, and technical details you choose to provide. The sources of these data are you and the email or communications providers needed to deliver the message.
If you independently contact us or a community through a third-party messenger or social platform, its provider separately processes your account data, metadata, and message content under its own policy. We may receive the name or alias, username or account identifier, metadata, and message content made available through that channel. Such a channel is an official support channel only when it is expressly identified as official in the App, at oberton.app, or in an official Oberton Wallet app-store listing. Do not send seed phrases, private keys, passwords, passcodes, documents, or other sensitive information through messengers.
4.10. Public Blockchain Information
Public blockchains are transparent by design. When you use an address, make a transaction, interact with a smart contract, or receive tokens, the public address, balance, transaction hash and amount, timestamp, fees, and contract calls may be publicly available and stored indefinitely. This information comes from public blockchains, RPC nodes, indexers, and explorers. We cannot delete or alter a blockchain record.
4.11. Optional Third-Party Provider Features
If a particular version of the App allows you, at your initiative, to open or use a third-party swap, bridge, on-ramp, payment service, dApp, or another integrated feature, the independent provider may directly receive a public wallet address, transaction details or request, IP address, device information, account data, and, if required by that provider, identification (KYC) or payment data. The scope is determined by the selected feature and the provider’s policy. Merely launching such a feature does not mean that we receive those data; unless the interface expressly states otherwise, they are transmitted to the independent provider with which you interact. Review its terms and privacy policy before use.
4.12. Data Sources
Depending on the feature, we receive information:
- directly from you when you configure a feature or contact support;
- automatically from the App, device, browser, and network connection when you use the Service;
- from public blockchains and related infrastructure;
- from platforms and providers with which the Service interacts, including Apple, Google, Firebase, Amplitude, and WalletConnect, to the extent of the enabled features.
5. Purposes and Legal Bases for Processing
Depending on the specific data and feature, we process information for the following purposes and on the following bases provided by Article 11 of Law of Ukraine “On Personal Data Protection”:
- Providing the Service and fulfilling a user request: operating core wallet features; displaying balances, prices, tokens, transactions, and network status; making network requests; connecting through WalletConnect; providing enabled notifications; and creating or restoring an optional backup. The legal basis is entering into and performing a transaction to which the user is a party, or taking steps at the user’s request before entering into a transaction.
- Consent and user choice: processing for optional features, device permissions, analytics, or other operations where consent is required by law or platform rules. The legal basis is your consent, which you can withdraw for the future.
- Reliability, diagnostics, and improvement: analyzing crashes, performance, and limited feature events; fixing errors; and evaluating Service health. The legal basis is our legitimate interest in maintaining and improving the Service where that interest is not overridden by the user’s fundamental rights and freedoms; where the law requires consent, we rely on consent.
- Security and abuse prevention: protecting the App, website, APIs, users, and our rights; investigating technical incidents; and preventing fraud or abuse. The legal basis is our legitimate interests and, in exceptional cases, the protection of vital interests.
- Support and communications: receiving, reviewing, and handling requests, responding, and maintaining related correspondence. The legal basis is performing a transaction or taking steps at your request, as well as our legitimate interest in properly responding to requests.
- Legal obligations and defense of claims: complying with obligations established by law, responding to lawful requests from competent authorities, and establishing, exercising, or defending legal claims. The legal basis is the need to comply with an obligation imposed by law and our legitimate interest in protecting rights.
Where processing is based on consent, withdrawing it does not affect the lawfulness of processing performed before withdrawal. Refusing to provide data objectively required for a requested feature may make that feature unavailable; other features may remain available.
6. Providers and Third-Party Services
Depending on the platform, region, feature, and App version, we may use the services listed below. They may act as our personal data processors or as independent controllers for processing they determine themselves, and they apply their own terms and policies:
- Firebase, including Firebase Crashlytics, Firebase Analytics, Firebase Cloud Messaging, and related Google services, for diagnostics, analytics, and push notifications;
- Amplitude for product analytics in versions where it is enabled;
- Google, including Google Play Services, Google Sign-In, Google Drive, and Google Fonts, for Android platform features, optional backup, and webfont delivery;
- Apple, including iCloud and Apple Push Notification service, for iOS platform features, optional backup, and push notifications;
- WalletConnect for wallet connection features;
- Telegram and other third-party communication platforms, if you independently contact us through a channel that we expressly identify as official;
- hosting, content delivery network, and email providers for operating the website, APIs, and support;
- blockchain RPC nodes, indexers, explorers, price and token metadata services, and similar infrastructure providers for displaying wallet data and broadcasting transactions.
If a particular SDK or provider has been removed from the current build, it may still apply to older versions installed by users until they update. The exact provider set may change with features and platforms; we will reflect material changes in this Policy. Before using a new provider where doing so introduces a materially new data category, processing purpose, or international-transfer method, we will update the relevant information and provide any choice mechanism required by law.
7. Transfers and Disclosures of Information
We do not sell personal data. For the purposes described above, information may be transferred to:
- service providers that help operate the App, website, and APIs; analyze crashes; deliver notifications; provide support, backups, blockchain infrastructure, or wallet connection features;
- Apple, Google, or another provider that you select or activate for an on-device feature;
- public authorities, courts, or other persons if disclosure is required by applicable law, a valid court order, or another binding lawful request;
- professional advisers or other parties where reasonably necessary to protect rights, safety, users, or the Service;
- a successor in connection with a reorganization, merger, asset sale, or other change of control, in compliance with data protection law.
In addition, your device may send requests directly to public blockchains and third-party services. Such direct transmission results from the feature you use and does not necessarily mean that we receive the data first.
8. International Data Transfers
Some providers, servers, or recipients may be located outside Ukraine, and their infrastructure may process data in other countries. The laws of those countries may differ from the laws of Ukraine.
Where we determine an international transfer of personal data, it is carried out subject to the conditions and legal bases established by Article 29 of Law of Ukraine “On Personal Data Protection” and applicable international treaties: to countries providing an adequate level of protection or, in other cases, with consent or another basis provided by law and taking into account available contractual, organizational, and technical safeguards. When you directly use iCloud, Google Drive, WalletConnect, a public blockchain, or another third-party service, the relevant provider may independently determine international transfers under its policy.
9. Retention
We retain data controlled by us no longer than reasonably necessary for the purposes described in this Policy, taking into account the nature and volume of the data, duration of feature use, security needs, provider settings, backup cycles, limitation periods, and legal obligations. Because these criteria depend on context and may change, we do not set a single fixed period for every category in this Policy.
- Local wallet data remain on your device until you delete them, reset the App, or uninstall the App, subject to device and backup settings.
- An encrypted backup is stored in your iCloud or Google Drive according to your actions, settings, and the relevant provider’s rules.
- Push tokens and related public-address subscriptions are retained while the feature is enabled or as long as needed for its operation, security, and troubleshooting.
- Diagnostic and analytics data are retained according to reasonable operational needs and the relevant provider’s retention settings.
- Website and API logs are retained to the extent needed for operation, diagnostics, security, and abuse investigations.
- Support correspondence is retained while the request is handled and afterward to the extent needed for related support, security, disputes, or legal compliance.
- Public blockchain records may remain available indefinitely; we do not control their retention.
Once a purpose no longer applies, we delete or anonymize data controlled by us or isolate them pending deletion if immediate deletion is not possible because of backups or a technical cycle, except where further retention is required or permitted by law.
10. Security
We use legal, organizational, and technical measures designed to protect personal data under our control against unlawful or accidental loss, destruction, access, alteration, or disclosure. Measures are selected in view of the nature of the data, means of processing, and available technologies. Nevertheless, no software, device, network, blockchain, smart contract, or cloud provider can be guaranteed to be secure or error-free.
You are responsible for securing your device, seed phrases, private keys, passcode, cloud accounts, and backup password. Do not send these secrets to us or third parties, and verify addresses, transactions, and signing requests before confirming them.
11. Your Personal Data Rights
Under Article 8 of Law of Ukraine “On Personal Data Protection,” you have the right to:
- know the sources from which your personal data are collected, the location of your personal data, the purpose of processing, and the location of the controller or processor, or authorize persons appointed by you to obtain this information, except in cases established by law;
- receive information about the conditions for granting access to personal data, including information about third parties to whom they are transferred;
- access your personal data;
- receive, no later than thirty calendar days after a request is received except in cases provided by law, a response as to whether your personal data are processed and receive the contents of those data;
- submit a reasoned demand objecting to the processing of your personal data;
- submit a reasoned demand to any controller or processor for amendment or destruction of your personal data if the data are processed unlawfully or are inaccurate;
- have your personal data protected against unlawful processing and accidental loss, destruction, or damage resulting from deliberate concealment, failure to provide or untimely provision, and against the provision of inaccurate information or information discrediting honor, dignity, and business reputation;
- complain about the processing of personal data to the Ukrainian Parliament Commissioner for Human Rights or to a court;
- use legal remedies if personal data protection law is violated;
- make reservations restricting the right to process your personal data when giving consent;
- withdraw consent to personal data processing;
- know the mechanism of automatic personal data processing;
- be protected from an automated decision that has legal consequences for you.
We do not make decisions about users that are based solely on automated processing of personal data controlled by us and have legal consequences for them. Rights may be restricted only in the cases and to the extent established by law.
12. How to Exercise Your Rights
Send a request to support@oberton.app with the subject line “Personal Data Request.” Describe the right you want to exercise and the data or feature concerned, and provide enough information to locate the relevant records and confirm that they relate to you. Never send your seed phrase, private keys, backup password, or passcode.
To avoid disclosing data to another person, we may ask you, proportionately to the risk, to confirm control of your email address, support-request identifier, device, or another related identifier. If the law requires additional request details or proof of identity, we will tell you what is needed. We will not ask for a seed phrase or private key.
Within no more than ten business days after receiving a request, we will tell you whether it will be fulfilled or state the legal ground on which the data may not be provided. The request will be fulfilled within thirty calendar days after receipt unless otherwise provided by law. A data subject receives access to data about himself or herself free of charge. Where permitted by law, we may refuse, restrict performance, or retain certain data and will explain the available appeal procedure.
We can fulfill a request only for data that we control and can reasonably link to you. Deleting a server-side record does not delete local data on your device, a backup in your iCloud or Google Drive, data held by an independent third-party controller, or an immutable public blockchain record. Those data must be controlled through the relevant device, account, or provider where deletion is technically and legally possible.
You may also contact the Ukrainian Parliament Commissioner for Human Rights or a court.
13. Your Settings and Choices
- You may choose not to enable push notifications or disable them in the App or operating-system settings.
- You may choose not to create a cloud backup and may disable or delete an existing backup through the App or your iCloud or Google Drive account.
- You may withdraw camera or biometric authentication permissions in device settings, but the relevant features may stop working.
- Where required by applicable law or platform rules, you may give, withhold, or withdraw consent to optional analytics using a setting available in the relevant App version or another offered mechanism. The availability of such a control depends on the platform, version, and applicable requirements.
- You may delete a wallet or clear local data in the App, but this does not delete public blockchain records and may not delete a separate cloud backup.
- You may contact us about deleting data controlled by us, such as support correspondence or server-side push notification records, subject to lawful exceptions.
14. Children
The Service is not intended for children. A user must be at least 18 years old or any higher age of majority established by the law of the user’s jurisdiction. We do not knowingly collect children’s personal data. If you believe a child has provided personal data to us, email support@oberton.app; after appropriate verification, we will take the legally required measures concerning data under our control.
15. Third-Party Resources and Features
The Service may contain links to third-party websites, applications, dApps, protocols, or services. We do not determine their purposes and means of processing and are not responsible for their policies. Review a third-party resource’s terms and privacy policy before interacting with it. Public blockchains and smart contracts may disclose information independently of us.
16. Changes to This Policy
We may update this Policy periodically because of changes to the Service, providers, or law. The current version will be posted on this page with a new effective date. If changes materially affect processing, we will give additional notice in a reasonable and accessible manner where required by law. Previous versions may be provided on reasonable request if retained in our records.
17. Contact Us
For questions about this Policy or personal data processing, contact:
ТОВ «БАЙТХАБ» (BYTEHUB LLC)Ukrainian company identification code (EDRPOU) 44264947
9 Karelska Street, Dnipro, Dnipropetrovsk Region, 49074, Ukraine
support@oberton.app