Effective Date: February 10, 2026 · Last Updated: February 10, 2026
1. Introduction
Insfers Inc., a Delaware corporation (“Insfers,” “we,” “us,” or “our”), is committed to protecting your privacy and being transparent about our data practices. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you use our self-custodial digital wallet mobile application, website, and associated services (collectively, the “Services”).
1.1 What Insfers Is and Is Not
Insfers provides ONLY non-custodial wallet software. We are:
A technology company that provides self-custodial wallet software
A tool that helps you manage your own cryptographic keys on your device
An interface to interact with public blockchain networks
Insfers is NOT:
A financial institution, bank, or money services business
A licensed money transmitter or payment processor
A custodian of your digital assets or funds
A broker, exchange, or trading platform
An intermediary in transactions between users
Primary Focus: Our Services are designed primarily for stablecoins (USDC and similar assets) and are intended for self-custody of these digital assets.
1.2 Self-Custodial Privacy Architecture
CRITICAL PRIVACY PROTECTION: Your private keys, seed phrases, and digital assets are generated, stored, and controlled EXCLUSIVELY by you on your device.
Insfers NEVER has access to:
Your private keys or seed phrases
The contents of your wallet
Your wallet balances or holdings
The details of transactions you execute on blockchain networks
The ability to view, control, or recover your digital assets
This self-custodial architecture provides fundamental privacy protections. However, to provide certain optional features and comply with legal obligations, we may collect limited personal information as described in this Privacy Policy.
1.3 Agreement and Scope
This Privacy Policy applies to all users of the Services. By downloading, installing, accessing, or using the Services, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree, you must not use the Services.
This Privacy Policy is incorporated into our Terms of Service. Capitalized terms not defined here have the meanings in the Terms of Service.
1.4 Mobile Application Privacy
Our mobile application is distributed through the Apple App Store and Google Play Store. Your use is also subject to:
Apple's privacy policies and App Store terms for iOS users
Google's privacy policies and Play Store terms for Android users
Apple and Google are third-party beneficiaries of this Privacy Policy with respect to the mobile application.
2. Information We Collect
2.1 Minimal Data Collection Philosophy
Because we are a non-custodial wallet provider (not a financial services company), we collect significantly less personal information than traditional financial applications. We collect only what is necessary to:
Provide the wallet software interface
Enable optional features you choose to use
Comply with applicable laws
Secure your account and prevent fraud
2.2 Information You Provide Directly
Account Registration (Basic):
Email address (required for account creation and communications)
Optional: Phone number (for two-factor authentication if you enable it)
Optional: Display name or username
For Business/Enterprise Accounts:
Business name and business address
Authorized user information
Customer Support:
Content of your messages and inquiries
Device and app information for troubleshooting
Screenshots you voluntarily provide
Records of our communications
Surveys and Feedback (Optional):
Your responses to surveys
Feedback about features
Demographic information you choose to share
2.3 Information Collected Automatically
Device and Technical Information:
IP address and approximate location (country/city level)
Device type, model, operating system
Mobile device identifiers (where permitted by OS)
Browser type and version
Screen resolution and language preferences
Mobile carrier and internet service provider
How you access the Services (mobile app, web browser, API)
Usage Analytics:
Features you use and frequency of use
Session dates, times, and duration
Navigation patterns and button clicks
Error messages and crash reports
Performance metrics (load times, response times)
High-level wallet usage patterns (frequency of use only)
We do NOT collect or access: your wallet balances or holdings, details of specific blockchain transactions you make, the types or amounts of digital assets you hold, your transaction history beyond general usage frequency, or your private keys or seed phrases.
Cookies and Local Storage:
For our website, we use:
Session cookies (expire when you close browser)
Persistent cookies (for preferences and authentication)
Analytics cookies (to understand website usage)
For our mobile application:
Local storage to securely store encrypted data ON YOUR DEVICE
Your encrypted private keys stored locally (never transmitted to us)
You can control cookies through browser settings. Mobile app local storage is necessary for the app to function.
2.4 Information from Third-Party Services (Optional)
If you CHOOSE to use optional third-party integrations, we may receive information from:
Identity Verification Services (for optional fiat services):
Identity confirmation and verification status
Fraud detection screening results
Anti-money laundering screening results
Fiat On/Off-Ramp Providers (if you use them):
Transaction information and verification status
Payment processing information
These third-party services are: OPTIONAL — you choose whether to use them. They are operated by INDEPENDENT companies, not Insfers, and are subject to their own privacy policies. They are licensed entities that handle regulated activities. We do not provide these services ourselves — we only provide the software interface to connect you with these independent providers.
2.5 Blockchain Network Information
Because you interact directly with public blockchain networks, certain information is permanently recorded on those networks:
Your wallet addresses (public keys)
Transaction amounts and timestamps
Gas fees paid
Smart contract interactions
Counterparty addresses
This blockchain data is publicly visible to anyone, permanently recorded (immutable), NOT controlled by Insfers, pseudonymous (not directly identifying without additional information), and cannot be deleted or modified. You should carefully consider privacy implications before using public blockchains.
2.6 Sensitive Personal Information
We collect sensitive information ONLY when:
Required by law (e.g., tax reporting)
Necessary for optional services you request (e.g., fiat conversions)
You provide explicit consent
Potentially sensitive information includes:
Government ID numbers (only if using third-party fiat services requiring them)
Financial account information (processed by payment partners, not stored by us)
Precise geolocation (only if you enable location services)
Biometric information (processed by third-party identity services, not us)
We implement additional security for sensitive information and limit access strictly.
2.7 Children's Privacy
The Services are NOT intended for anyone under 18 years of age. We do not knowingly collect information from minors. If we discover we have collected information from someone under 18, we will delete it promptly.
If you believe we have information from a minor, contact us immediately at privacy@insfers.com.
3. How We Use Your Information
3.1 Primary Purposes
Providing the Wallet Software:
Creating and managing your account
Authenticating your identity when you log in
Providing customer support
Enabling features you choose to use
Generating usage analytics
Communicating about your account
We do NOT use your information to: access, monitor, or control your wallet; view your private keys or digital assets; track your blockchain transactions; or control your funds in any way.
Security and Fraud Prevention:
Monitoring for suspicious account activity
Detecting and preventing fraud, phishing, and unauthorized access
With your consent: newsletters and product updates
You can opt out of marketing emails but will still receive necessary transactional messages.
3.2 Optional Third-Party Services
If you CHOOSE to use optional third-party services (like fiat conversions), your information is used to:
Facilitate identity verification required by those services
Enable fiat currency transactions
Comply with third-party legal obligations
Remember: These services are provided by independent third parties, not by Insfers.
3.3 Legal Compliance
When required by law, we use information to:
Comply with legal obligations and court orders
Respond to law enforcement requests
Meet regulatory requirements
Maintain required records
Protect legal rights
Prevent illegal activity
3.4 What We DON'T Do With Your Information
Sell your personal information for money
Use your information for cross-context behavioral advertising
Share your information for targeted advertising
Access your wallet contents or private keys
Monitor your blockchain transactions
Track your digital asset holdings
4. Legal Basis for Processing (For International Users)
For users in the EEA, UK, and other jurisdictions requiring a legal basis:
Contract Performance: Processing necessary to provide the Services under our Terms of Service.
Legitimate Interests: Processing for business operations, security, fraud prevention, and service improvement (balanced against your rights).
Consent: Processing where you've provided explicit consent (marketing, certain optional features).
Legal Obligations: Processing required by law (court orders, regulatory requirements).
Vital Interests: Processing to protect life or safety (rare emergency situations only).
5. How We Share Your Information
5.1 Third-Party Service Providers (Limited and Controlled)
We share information ONLY with service providers who help us operate the Services:
Infrastructure and Hosting:
Cloud hosting providers (for servers and databases)
Content delivery networks
Data storage providers
Operations:
Customer support platforms
Email and communications services
Analytics providers (for usage analytics only)
Security:
Security and fraud prevention services
Threat detection services
Professional Services:
Lawyers, accountants, and auditors (when necessary)
These providers are contractually bound to protect your information, may only use information for specified purposes, must comply with privacy laws, and are vetted by us for security and privacy practices.
5.2 Optional Third-Party Services (Your Choice)
If you CHOOSE to use optional third-party integrations:
Identity Verification Services:
Receive information needed to verify your identity
Act as independent data controllers
Have their own privacy policies
Fiat Conversion Providers:
Licensed financial service providers
Receive information needed to process fiat transactions
Operate independently from Insfers
YOU SHOULD REVIEW the privacy policies of any third-party services you choose to use.
5.3 Legal Requirements and Protection of Rights
We may disclose information when we believe in good faith it's necessary to:
Comply with applicable laws and regulations
Respond to subpoenas, court orders, or legal process
Investigate fraud, security threats, or illegal activity
Protect the rights, property, or safety of Insfers, users, or the public
Enforce our Terms of Service
Defend against legal claims
Where legally permitted, we will notify you before disclosure. Some laws prohibit us from notifying you (e.g., national security matters).
5.4 Business Transfers
If Insfers is involved in a merger, acquisition, sale of assets, or bankruptcy:
Your information may be transferred to the successor entity
We will notify you before transfer
The successor must honor this Privacy Policy unless you consent otherwise
5.5 With Your Consent
We may share information with third parties when you:
Specifically consent to sharing
Direct us to share with specific services
Use features designed for sharing
5.6 Aggregated and De-Identified Data
We may share aggregated, anonymized data that cannot identify you for industry statistics, research, analysis, and business intelligence. This de-identified data is not personal information and may be shared without restriction.
5.7 What We DON'T Share
Sell your personal information for money
Share your information for targeted advertising
Provide your information to data brokers
Share your private keys (we don't have them)
Share your wallet contents (we can't access them)
Share your blockchain transaction details (we don't collect them)
6. International Data Transfers
Insfers is based in the United States. When you use the Services, your information may be transferred to and processed in the United States. The U.S. may have different privacy laws than your jurisdiction.
For EEA/UK/Swiss Users:
We implement appropriate safeguards for international transfers:
Standard Contractual Clauses (EU-approved)
EU-U.S. Data Privacy Framework compliance (where applicable)
Your private keys generated and stored ONLY on your device (never on our servers)
Device-level security (biometrics, passcodes) protects your encrypted keys
Strong authentication (passwords, 2FA)
Automatic session timeouts
Regular security testing and audits
Administrative Security:
Role-based access controls (need-to-know basis)
Employee confidentiality agreements
Security awareness training
Incident response procedures
Regular access reviews
Physical Security:
Reputable cloud providers with comprehensive physical security
24/7 monitoring and surveillance
Restricted access with multi-factor authentication
Environmental controls
SOC 2 and ISO 27001 compliance
7.2 Your Security Responsibilities
YOU must:
Keep your account credentials confidential
Use strong, unique passwords
Enable two-factor authentication
Securely store your seed phrase offline
NEVER share your seed phrase or private keys with ANYONE
Keep your device and app updated
Be vigilant against phishing and scams
If you believe your account is compromised, contact us immediately at security@insfers.com.
7.3 Security Limitations
No system is 100% secure. While we implement industry-standard security, we cannot guarantee absolute security. You provide information at your own risk.
8. Account Deletion and Data Retention
We respect your right to control your personal data and provide a clear process for account deletion.
8.1 How to Request Deletion
You may request deletion of your account at any time from within the application by navigating to Settings > Delete Account. To confirm your request, you will be required to enter your account credentials.
8.2 Deletion Process
Once a deletion request is submitted:
Your account is immediately marked for deletion and access may be restricted.
Your data is not permanently deleted right away. Instead, it is placed in a secure retention state for a period of 30 days.
8.3 Cancellation Option
During this 30-day period, you may cancel your deletion request at any time by logging into your account and selecting Cancel Account Deletion. If the deletion request is cancelled, your account and data will be fully restored.
8.4 Permanent Deletion
If the deletion request is not cancelled within 30 days:
Your personal data will be permanently deleted or irreversibly anonymized from our systems.
This action cannot be undone.
8.5 Data Retention and Legal Obligations
We retain information only as long as necessary for legitimate purposes and legal requirements.
Data Type
Retention Period
Account Information
Active use + up to 7 years after closure
Identity Verification (if applicable)
5–10 years after relationship ends (AML/KYC)
Transaction Information (if applicable)
Up to 7 years (financial regulations)
Blockchain Information
Permanently recorded (we cannot delete it)
Customer Support
3 years after resolution
Usage Analytics
18 months (individual) / indefinite (aggregated)
Certain information may be retained where required for:
Legal compliance
Fraud prevention
Enforcement of our terms and policies
Such retained data will be limited to what is strictly necessary and handled in accordance with applicable laws.
8.6 Audit and Security Logging
We may retain limited records of deletion requests (such as timestamps and actions taken) for security, auditing, and compliance purposes. These logs do not contain sensitive personal data.
8.7 Contact for Account Deletion
If you are unable to access your account and wish to request deletion, you may contact us at support@insfers.com, and we will assist you in completing the process.
9. Your Rights and Choices
9.1 California Residents (CCPA/CPRA)
Right to Know: Request information about data we've collected about you (past 12 months).
Right to Delete: Request deletion of your personal information (subject to legal exceptions).
Right to Correct: Request correction of inaccurate information.
Right to Opt-Out: We don't sell information or share for behavioral advertising, but you can opt out of any such activities.
Right to Limit Sensitive Information: Limit use of sensitive information to necessary purposes.
Right to Non-Discrimination: We won't discriminate against you for exercising your rights.
9.2 European Users (GDPR)
Right to Access: Access your personal data and processing information.
Right to Rectification: Correct inaccurate or incomplete data.
Right to Erasure: Request deletion in certain circumstances.
Right to Restriction: Restrict processing in certain circumstances.
Right to Data Portability: Receive your data in portable format.
Right to Object: Object to processing based on legitimate interests or direct marketing.
Right to Withdraw Consent: Withdraw consent anytime (doesn't affect prior lawful processing).
Right to Complain: Lodge a complaint with your supervisory authority.
You'll still receive necessary transactional messages.
10. Cookies and Tracking Technologies
10.1 What We Use
Essential Cookies:
Authentication and session management
Security and fraud prevention
Functional Cookies:
Preferences and settings
Language and display options
Analytics Cookies:
Usage patterns and feature adoption
Performance metrics
Error tracking
Mobile App Local Storage:
Encrypted private keys (stored ON YOUR DEVICE)
App preferences and settings
10.2 Your Control
Browser cookies: Control through browser settings. Disabling may affect functionality.
Mobile app storage: Required for app to function and secure your keys.
We do NOT use tracking for targeted advertising.
11. Third-Party Services and Links
11.1 Third-Party Services
When you use optional third-party integrations (fiat services, identity verification), they have their own privacy policies, act as independent data controllers, and you should review their privacy policies to understand their practices.
11.2 Third-Party Links
Our Services may link to third-party websites:
We don't control or review third-party sites
Their privacy policies apply when you visit them
Review their policies before providing information
11.3 Blockchain Explorers
Third-party blockchain explorers display public blockchain data. They are not operated by Insfers, are subject to their own privacy policies, and display publicly available blockchain information.
12. Children's Privacy
The Services are for adults 18+ only. We don't knowingly collect information from anyone under 18. If we learn we've collected information from a minor, we'll delete it promptly.
Parents/guardians: If your child provided information to us, contact privacy@insfers.com immediately.
13. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in practices, technologies, or legal requirements.
Material changes:
"Last Updated" date will change
We'll provide notice via email, in-app notification, or website notice
30 days' advance notice for material changes
Your continued use after changes take effect constitutes acceptance. If you don't agree to updates, stop using the Services.
14. California-Specific Disclosures
14.1 Categories of Personal Information Collected (Past 12 Months)
Identifiers: Name, email, IP address, device identifiers
Commercial Information: Transaction history with fiat services (if used)
Internet Activity: Usage patterns, interactions with Services
Geolocation: Approximate location from IP address
Professional Information: Business account information (if applicable)
Sensitive Information: Government IDs (if using fiat services), financial account info (processed by partners), precise geolocation (if enabled), biometric info (processed by third parties)
California residents may use authorized agents with:
Written authorization or power of attorney
Proof of authorization
Direct identity verification may be required
14.8 Response Timeframes
Acknowledgment: Within 10 business days
Response: Within 45 days (may extend with notice)
15. App Store-Specific Provisions
15.1 Apple App Store Users
Apple Acknowledgments:
This Privacy Policy is between you and Insfers, not Apple
Apple is not responsible for the Services or this Privacy Policy
Apple has no obligation regarding privacy inquiries
Apple and its subsidiaries are third-party beneficiaries with enforcement rights
Apple Privacy Practices:
Apple may collect information through the App Store (subject to Apple's privacy policy)
Insfers does not control Apple's data practices
15.2 Google Play Store Users
Google Acknowledgments:
This Privacy Policy is between you and Insfers, not Google
Google has no responsibility regarding compliance or data practices
Google is a third-party beneficiary with enforcement rights
Google Privacy Practices:
Google may collect information through Google Play (subject to Google's privacy policy)
Insfers does not control Google's data practices
15.3 App Permissions
The mobile app may request device permissions:
Camera: For QR code scanning (optional)
Notifications: For alerts and updates (optional)
Biometrics: For authentication (optional)
Storage: For encrypted key storage (required)
You can manage permissions through device settings.
16. Nevada Residents
Nevada residents may opt out of the sale of personal information. While we don't sell information as defined by Nevada law, you may submit an opt-out request:
Substantive response: Within legal timeframes (Section 9.3)
17.1 Complaints
If you have a privacy complaint:
Contact us first so we can attempt to resolve it
California residents: California Privacy Protection Agency (cppa.ca.gov, 916-710-5000)
European residents: Your local data protection authority
Other jurisdictions: Your local privacy regulator
17.2 Dispute Resolution
Disputes arising from this Privacy Policy are subject to the dispute resolution provisions in our Terms of Service, including mandatory arbitration (if Insfers elects it), class action waiver, and governing law (California).
18. Key Definitions
Personal Information / Personal Data
Information that identifies, relates to, or could reasonably be linked with you.
Sensitive Personal Information
Financial accounts, government IDs, precise geolocation, biometric data.
Processing
Any operation on personal information (collection, use, storage, disclosure).
Services
The Insfers Wallet mobile application, website, and associated services.
Third-Party Services
Independent service providers (identity verification, fiat conversion, etc.).
Self-Custodial
You control your private keys; we cannot access them.
Non-Custodial
We do not hold or control your digital assets.
Private Key
Cryptographic key controlling access to your digital assets.
Seed Phrase
Words used to generate and recover your private keys.
Blockchain
Public distributed ledger network.
Stablecoin
Digital assets designed to maintain stable value (e.g., USDC).
Acknowledgment and Consent
BY USING THE SERVICES, YOU ACKNOWLEDGE:
You have read and understand this Privacy Policy.
Insfers is a non-custodial wallet provider — we do NOT have access to your private keys or digital assets, do NOT provide financial services, money transmission, or custodial services, and are NOT a licensed financial institution.
Your private keys are stored ONLY on your device. Insfers CANNOT access, view, or recover your keys or assets. You have sole responsibility for securing your seed phrase.
Blockchain transactions are publicly visible and permanent. Insfers does not control blockchain data. Blockchain addresses are pseudonymous but may be linked to identity.
Third-party services are independent from Insfers, have their own privacy policies, and you choose whether to use them.
We collect limited personal information as described. We do NOT collect your wallet contents or transaction details, and do NOT sell your information or use it for behavioral advertising.
You have privacy rights as described in Section 9 and can exercise them by contacting us.
Information may be processed in the United States with appropriate safeguards for international users.
Disputes are subject to Terms of Service dispute resolution provisions, which may include arbitration and class action waiver.
This Privacy Policy may be updated with notice. Continued use after updates constitutes acceptance.
IF YOU DO NOT AGREE WITH THIS PRIVACY POLICY, DO NOT USE THE SERVICES.