Blockwright Wallet — Privacy Policy
What happens to information when you use Blockwright Wallet. The agreement about the application itself is in the Terms of Use. The website and the education platform have their own documents.
The short version
- We run no servers, no accounts and no analytics. There is no Blockwright profile, because there is nothing for one to hold.
- Your recovery phrase and keys are created on your phone and never leave it.
- The app asks public blockchain services for balances. Those services see your IP address and the addresses you ask about. Section 3 names every one of them.
- Blockchain transactions are public and cannot be reversed or deleted.
01What is this policy about?
It explains what information exists when you use Blockwright Wallet, who can see it, and what you can do about it. It describes the version of the application published on the effective date above.
Most privacy policies are long because the product collects a great deal. This one is long because explaining honestly why nothing is collected takes more words than claiming it.
02What information do we collect?
None.
That is the complete answer. The rest of this section exists so you can check it rather than take it on faith.
2.1 Information you give us
There is nothing to give. The application has no sign-up, no login, no email field, no phone number, no profile and no support form. You never identify yourself to it.
2.2 Information the application creates on your device
| What | Where it lives | Does it reach us? |
|---|---|---|
| Recovery phrase | Your device's secure storage — iOS Keychain, Android Keystore | No. Never transmitted |
| Private keys | Derived from the phrase, same secure storage | No. Never transmitted |
| Your addresses | Derived from the keys, on the device | No |
| Application settings | Device storage | No |
2.3 Usage and diagnostic information
The application contains no analytics library, no crash-reporting service and no advertising SDK of any kind. There is no tracking identifier, no advertising identifier, no session recording and no telemetry.
The source code is closed, and we do not offer it as proof. The claim is checkable anyway, just from the outside: put the phone behind a proxy and watch where the application goes. The list of addresses in section 3 is complete — nothing else will appear.
2.4 Device permissions
- Network access — required to ask blockchain services for balances and to broadcast transactions.
- Clipboard — used at the moment you copy an address or paste a recovery phrase, and at no other time.
- Device language — read to pick the interface language. Not transmitted.
The application does not request your contacts, your location, your camera, your microphone, your photos, or your files.
03What do other people see?
We collect nothing, but the application cannot show a balance without asking someone. Those requests go from your phone directly to independent public services:
| Service | Why it is contacted | What its operator can observe |
|---|---|---|
mempool.space | Bitcoin balances, unspent outputs, fee estimates, broadcasting transactions | Your IP address, the Bitcoin addresses you query, the transactions you broadcast |
ethereum-rpc.publicnode.com | Ethereum balances and transaction broadcasting, over JSON-RPC | Your IP address, the Ethereum addresses you query, the transactions you broadcast |
etherscan.io | Opened in your browser only when you tap a link to view a transaction | Your IP address and which transaction you opened |
These operators are not us. They handle what reaches them under their own policies. They receive addresses and an IP address; they never receive your recovery phrase, your keys, your name or your email, because the application does not have them to send.
To reduce what these operators can infer, use a VPN or route traffic through Tor. Support for a blockchain node of your own choosing is a feature we consider reasonable and intend to add.
App stores (not yet in operation). Google Play, and the Apple App Store in future, record installs, updates, ratings and — only if you have enabled it in your own device settings — crash reports and usage statistics. That collection is performed by Google and Apple under their policies and your settings, not by us. What reaches us is an aggregate install count in a developer console, with no personal data in it.
04How do we use your information?
We do not, because we do not have any. There is no profile to build, nothing to personalise, nothing to sell, nothing to train a model on, and no advertising business anywhere in this project.
05How is your information shared?
We share nothing, because we hold nothing. We have never sold data, and the design of the product makes it impossible for us to start without rebuilding it.
Information reaches other parties only in the ways described in section 3, and only from your device.
06What about the blockchain?
This deserves its own section, because it is where expectations about privacy most often break.
- Every transaction you make is written to a public ledger that anyone can read, permanently.
- Addresses are pseudonymous, not anonymous. If an address is ever connected to you — by an exchange, by a payment to someone who knows you, by a public post — everything that address has ever done can be connected to you as well.
- Transactions cannot be reversed, edited or deleted by us, by you, or by anyone.
- No right described in section 9 can be exercised against a blockchain. When we say we cannot delete it, that is a property of the technology, not a refusal to help.
07How long is information kept?
Nothing of yours is kept by us at any point, so there is no retention period to state.
On your device, the recovery phrase and keys remain in secure storage until you delete the application or erase them yourself. Deleting the application removes the keys from the device — if you have not written the recovery phrase down, that is permanent loss.
If you write to us by email, we keep the message while the conversation is useful and then delete it.
08How do we respond to legal requests?
If we receive a valid and binding legal demand, we will comply with it. In practice the truthful response to almost any demand about a wallet user is that we hold nothing responsive — no account, no identity, no address list, no log of your activity. We cannot hand over what does not exist, and the product is deliberately built so that it does not exist.
09How can you manage or delete your information?
Because we hold nothing, there is nothing for us to show you or to erase. Everything is on your device and under your control; uninstalling the application removes it.
You may still write to legal@blockwright.dev with any request, and we answer within 30 days. For requests about the blockchain itself, see section 6.
10Who is responsible, and how do you contact us?
Blockwright is built and run by one person, working under a pseudonym. There is no company, no legal entity and no staff. The project takes no account details from you and operates no user database, so there is nothing about you here for anyone to be entrusted with.
To the extent that anything described in this document is personal data under a law that applies to you, the person operating Blockwright is answerable for it and can be reached here:
- Privacy and legal: legal@blockwright.dev
- Everything else: hi@blockwright.dev
- Telegram: https://t.me/blockwright_dev
- Source code: https://github.com/blockwrightdev
11How will you know if this policy changes?
The version number and effective date at the top change, and the change is recorded in the table at the end. A substantive change — a new recipient, a new category of information, a new purpose — is announced on the Telegram channel before it takes effect, not quietly afterwards.
Supplements — your region
S1European Economic Area and the United Kingdom (GDPR, UK GDPR)
Controller. The person operating Blockwright, contactable at legal@blockwright.dev.
What is processed. As set out in section 2, nothing reaches us. The processing that exists happens on your own device, by software running for your own purposes.
Lawful basis. Where processing does occur, it is necessary to perform the service you asked for — Article 6(1)(b). We rely on legitimate interests for nothing, because we pursue no interest of our own in your data.
Your rights. You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your national supervisory authority. Our honest answer to an access request will be that we hold no personal data about you.
International transfers. The services in section 3 operate globally, so a request from your device may be answered by a server outside your country. We transfer nothing ourselves.
Automated decision-making. There is none.
S2California and other United States state privacy laws
We do not sell or share personal information, as those terms are defined by the California Consumer Privacy Act, and never have. We do not use or disclose sensitive personal information for any purpose that would require an opt-out.
In the twelve months before the effective date of this document we collected no categories of personal information from users of the application.
You have the right to know, to delete, to correct, and not to be discriminated against for exercising those rights. Write to legal@blockwright.dev. As above, the answer to a "right to know" request will be that there is nothing to know.
S3Everywhere else
Some countries grant rights similar to those above; some restrict cryptocurrency entirely. We apply the protections in this document to everyone, everywhere, whether or not a local law requires it — it costs us nothing, because the answer is identical in every jurisdiction: we hold nothing.
Determining whether you may lawfully use a non-custodial wallet where you live remains yours.
Version history
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-09-18 | First published version. |
| 1.1 | 2026-09-19 | Correction: the source is not open yet — the verifiability claim became a commitment; marked what does not work before release. |
| 1.2 | 2026-09-19 | The source is closed and is not planned to open: the commitment is gone, replaced by a way to check the claim from outside. |