Privacy Policy

Legal Document

Privacy Policy

Last updated: March 1, 2026 • Effective: March 1, 2026 • Version 3.1

🔒 CripViz is built on a privacy-first architecture. Your private keys and wallet contents are NEVER accessible to us. We collect the minimum data necessary to operate the service.

01. Introduction

CripViz, Inc. (“CripViz,” “we,” “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our iOS mobile application and related services. This policy complies with CCPA, GDPR, UK GDPR, and other applicable privacy laws worldwide.

02. Information We Collect

Account & Profile Information: For paid services, we collect your email address, username, and subscription preference. We do not require your real name, address, or government ID for basic wallet use.

Usage & Analytics Data: We collect anonymized, aggregated app usage data that cannot be linked back to you individually.

Device Information: Device type, OS version, and app version for performance optimization. We do not collect IDFA without explicit consent.

Payment Information: Processed entirely through Apple’s App Store. We never see or store your credit card or banking information.

03. How We Use Your Information

We use information we collect to provide and improve the Services, process subscription payments, send service communications, monitor usage patterns, detect fraudulent activity, comply with applicable laws, and send opt-in marketing communications (easily revocable). We do not sell your personal information for advertising purposes.

04. Information We Do NOT Collect

The following sensitive data is NEVER collected by CripViz, by design:

  • ✔ Private keys — generated and stored only on your device
  • ✔ Seed phrases / recovery phrases — never transmitted to our servers
  • ✔ Wallet balances or transaction history — all blockchain data is fetched directly by your device
  • ✔ Government-issued ID or KYC documents (except Institutional customers where legally required)
  • ✔ Social Security Numbers or tax identification numbers
  • ✔ Biometric data (Face ID/Touch ID results stay within Apple’s Secure Enclave)

05. Information Sharing & Disclosure

We do not sell, rent, or trade your personal information. We may share information with trusted service providers under contractual data processing agreements; when required by law; in connection with a merger or acquisition (with prior notice); or with your explicit consent.

06. Data Security

Our security program includes: AES-256 encryption at rest; TLS 1.3 in transit; SOC 2 Type II certified infrastructure (renewed annually); regular third-party penetration testing; bug bounty program with rewards up to $50,000; and 24/7 security monitoring. We will notify you within 72 hours of a data breach affecting your personal information.

07. Data Retention

We retain account data for the duration of your account plus 3 years; anonymized usage analytics for up to 36 months; support communications for 2 years; and financial records for 7 years as required by law. You may request deletion at any time, subject to legal retention requirements.

08. Your Rights & Choices

You have the right to: access your personal information; correct inaccurate data; delete your data (“right to be forgotten”); receive your data in portable format; opt out of marketing communications; and restrict processing in certain circumstances. Contact [email protected] — we respond within 30 days.

09. Cookies & Tracking

Our website uses essential cookies and optional analytics cookies manageable via our cookie banner. The CripViz iOS app uses privacy-preserving analytics with no advertising identifiers. We comply fully with Apple’s App Tracking Transparency (ATT) framework and do not request tracking permission.

10. Third-Party Services

Services integrate with: public blockchain RPC endpoints; DEX aggregators (1inch, Paraswap); market data providers (CoinGecko); AWS cloud infrastructure (ISO 27001, SOC 2 certified); and encrypted customer support platforms. We vet all third-party providers for equivalent privacy standards.

11. International Data Transfers

CripViz is headquartered in the United States. For transfers from the EEA and UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and UK ICO, and the EU-U.S. Data Privacy Framework where applicable.

12. Children’s Privacy

The Services are not directed to children under 18. We do not knowingly collect personal information from minors. If you believe we have collected information from a minor, contact us immediately at [email protected].

13. California Privacy Rights (CCPA)

California residents have rights to: know about personal information collected; delete personal information; opt out of sale or sharing (note: we do not sell personal information); non-discrimination for exercising privacy rights; correct inaccurate information; and limit use of sensitive personal information. Submit requests to [email protected] with “CCPA Request” in the subject line.

14. European Privacy Rights (GDPR)

Our legal bases for processing: Contract (providing Services); Legitimate Interests (analytics, security, fraud prevention); Legal Obligation (compliance); Consent (marketing). EU/UK DPO: [email protected]. EU Representative: DP-Dock GmbH, Ballindamm 39, 20095 Hamburg, Germany.

15. Changes to This Policy

We update this policy periodically. Material changes are communicated via in-app notice, updated “Last Updated” date, and email to paid subscribers. Your continued use of the Services after policy changes constitutes acceptance.

16. Contact Us

CripViz, Inc. — Privacy Team
548 Market Street, PMB 12345, San Francisco, CA 94104, USA
Email: [email protected] • DPO: [email protected]