Privacy Policy
Last updated: August 13, 2026
1. Introduction
SELV Wallet (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cryptocurrency wallet service and its web, Telegram Mini App, browser extension, and Discord bot access points.
By using SELV Wallet, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Non-Custodial Nature
SELV Wallet is non-custodial: signing keys are generated and used client-side, and SELV servers cannot sign for you. Telegram Mini App users may explicitly opt into a cross-device backup containing an encrypted seed and password-wrapped key in Telegram CloudStorage. Telegram receives no plaintext seed, password, private key, or raw unwrapping key through that backup.
2.2 Information We Do Collect
- Telegram User ID: We collect your Telegram user ID to link your wallet to your Telegram account.
- Discord User ID and username: If you choose to connect Discord, we collect your Discord user ID and username solely to link your Discord account to your existing SELV wallet, so read-only commands (balance, portfolio) and optional notifications can reach the right account. We never create a wallet from Discord, never request your Discord password, and never read your Discord messages or server content. You can disconnect Discord at any time, which deletes this link.
- Transaction Data: Blockchain transaction hashes and public wallet addresses for transaction history display.
- Operational telemetry: Production routes may emit sampled error, log, trace, and performance diagnostics after the shared redaction boundary, except the dedicated recovery-export realm where Sentry, telemetry, replay, and breadcrumbs are disabled; default PII and session replay are disabled everywhere. Vercel Speed Insights is disabled on seed, backup, unlock, signing, send, swap, and vault flows.
- Web request metadata: Our hosting and security providers receive the client IP address, User-Agent, requested path, and timing needed to serve and protect non-Telegram web requests.
- Browser-extension data: The extension stores encrypted key material, public addresses, settings, and session state in
chrome.storage.local. Its content script runs on all HTTPS pages so sites can request wallet connections, and its notification permission can report transaction outcomes. For a connected site, the extension processes the connected-site origin and request, account addresses you approve, chain, and transaction or message content submitted for approval. - Optional Telegram encrypted backup: If you opt in, Telegram CloudStorage stores the encrypted seed and password-wrapped data-encryption key for cross-device restore. Possession permits offline password guessing. Security settings let you retain or delete and verify removal of the backup.
3. How We Use Your Information
We use the collected information for the following purposes:
- To provide and maintain our wallet service
- To display your transaction history and wallet balances
- To improve and optimize our service
- To detect and prevent fraud or security threats
- To communicate important updates about the service
- To comply with legal obligations
4. Data Security
Security controls reduce risk but do not make wallet software risk-free:
- TLS protects data sent between the client and HTTPS services.
- AES-256-GCM encrypts supported local key-storage formats.
- Automated gates check defined signer-isolation, secret-scanning, dependency, and documentation invariants. They are partial controls, not a formal third-party audit; see /security and SECURITY.md for the current posture.
- The server is not designed to store private keys or recovery phrases.
5. Detailed Data-Flow Inventory
The entries below identify what each current product flow processes, why it is needed, who receives it, where it persists, how long it remains, how deletion works, and the relevant user or security controls. A provider may act under its own privacy policy and legal obligations.
Account, service, security, and diagnostics
- Data
- Account and public-wallet identifiers; sessions; audit events; coarse network prefix and browser family; path and request timing on non-Telegram web requests; redacted error and device/browser diagnostics. Production routes may emit sampled error, log, trace, and performance diagnostics after the shared redaction boundary, except the dedicated recovery-export realm where Sentry, telemetry, replay, and breadcrumbs are disabled; default PII and session replay are disabled everywhere.
- Purpose
- Authenticate users, operate the service, enforce rate limits and anti-replay controls, investigate abuse, and diagnose failures.
- Recipients and boundaries
- SELV service database — Account, session, audit, notification, and operational records.
- Vercel — Web hosting, routing, request logs, and DDoS protection. Privacy policy.
- Upstash — Short-lived hashed rate-limit and anti-replay identifiers. Privacy policy.
- Sentry — Sampled diagnostics from production routes after shared redaction, excluding the dedicated recovery-export realm; default PII and session replay are disabled. Privacy policy.
- Firebase / Google Cloud — Legacy authentication identifiers, hosting metrics, and request logs when that path is used. Privacy policy.
- Persistence
- Account, session, notification, and audit records may be stored in the SELV database. Hosting, security, and diagnostics providers may retain their own operational records.
- Retention
- Operational audit records expire after 90 days. Authentication and security audit records expire after 365 days unless a documented legal hold applies. Upstash entries expire automatically. Provider retention follows the provider settings and policy.
- Deletion
- Request access, correction, export, or deletion at privacy@selvwallet.com. Account deletion removes audit records without a legal hold; held records remain until the hold is released.
- Controls
- Sensitive wallet flows may emit strictly redacted diagnostics, except the dedicated recovery-export realm where telemetry is disabled. Production routes may emit sampled error, log, trace, and performance diagnostics after the shared redaction boundary, except the dedicated recovery-export realm where Sentry, telemetry, replay, and breadcrumbs are disabled; default PII and session replay are disabled everywhere.
Telegram Mini App identity and notifications
- Data
- Telegram user ID, chat ID, username, first name, last name, language code when supplied, Mini App initData verification fields, link codes and expiry, and notification message/status metadata.
- Purpose
- Verify Telegram sessions, link the correct SELV account, resolve wallet recipients, and deliver requested wallet notifications.
- Recipients and boundaries
- SELV service database — Linked Telegram profile and notification records.
- Telegram — Mini App authentication, CloudStorage when enabled, and bot message delivery. Privacy policy.
- Persistence
- Linked profile and notification records are stored in the SELV database. Telegram stores its own account, bot, and Mini App records.
- Retention
- The link remains while the Telegram integration is active or until the account record is deleted, subject to legal or security retention. Verification codes expire.
- Deletion
- Disconnect supported linked services where available or request unlinking, export, or deletion at privacy@selvwallet.com. Telegram-controlled records follow Telegram controls.
- Controls
- Telegram initData is verified before account-linked actions; the server never receives the wallet recovery phrase or private signing key.
Optional Discord account link
- Data
- Discord user ID and username from the OAuth identify scope.
- Purpose
- Link read-only balance, portfolio, and optional notification commands to the correct SELV account.
- Recipients and boundaries
- SELV service database — Discord-to-SELV account link.
- Discord — OAuth authentication and bot interaction. Privacy policy.
- Persistence
- The account link is stored in the SELV database.
- Retention
- The link remains until disconnected or the linked account is deleted.
- Deletion
- Disconnecting Discord deletes the link; requests may also be sent to privacy@selvwallet.com.
- Controls
- The integration requests the identify scope, does not request a Discord password or wallet key material, and does not read unrelated server content.
Wallet reads, transaction history, and blockchain broadcast
- Data
- Public wallet addresses, token accounts and balances, transaction hashes and payloads, signed transaction bytes, UTXOs, fee and nonce/sequence data, and RPC request metadata. Public networks permanently expose transaction effects.
- Purpose
- Read balances and history, estimate bounded network fees, verify transactions, and broadcast transactions the user signed locally.
- Recipients and boundaries
- Public blockchains — Solana, EVM networks, TON, and Bitcoin permanently record transactions.
- Configured RPC operators — Helius, QuickNode, Solana Foundation, Alchemy, Infura, Ankr, LlamaRPC, PublicNode, Cloudflare, Base, Polygon, Arbitrum, Optimism, Avalanche, Binance, Forno, Toncenter, Mempool.space, Blockstream, and environment-configured replacements process the public address, state, fee, simulation, or broadcast request for their network.
- Blockchair — Bitcoin public-address and transaction-history requests.
- Chain explorers — Opening an explorer link discloses the viewed public address or transaction and normal web-request metadata.
- Persistence
- SELV may store public addresses and transaction history records. RPCs and explorers may log requests. Signed transactions are permanently stored by public networks after broadcast.
- Retention
- SELV transaction records remain while needed for wallet history or legal obligations. Public-chain data cannot expire; provider logs follow provider policies.
- Deletion
- SELV-controlled history and account links can be requested for deletion. Public-chain records and provider-controlled logs cannot be deleted by SELV.
- Controls
- Private keys and recovery phrases remain client-side. Transaction verifiers bind reviewed effects before local signing; providers receive only public or signed transaction material needed for the request.
Token swap quotes and routing
- Data
- Public wallet address, chain, input and output token addresses, amount, slippage, route and quote parameters, and unsigned transaction templates.
- Purpose
- Obtain executable swap quotes and routes, then verify the returned transaction before local signing.
- Recipients and boundaries
- Jupiter — Solana swap quotes, route metadata, and transaction templates. Privacy policy.
- 1inch — EVM swap quotes, token pairs, route metadata, and transaction calldata. Privacy policy.
- Persistence
- SELV does not deliberately persist quote requests beyond operational records and transaction history; routing providers may log requests under their policies.
- Retention
- SELV and provider retention follows the operational and provider policies described for the relevant request.
- Deletion
- Request deletion of SELV-controlled account or transaction links at privacy@selvwallet.com; provider-controlled logs require the provider’s process.
- Controls
- Client verifiers bind route output, token pair, recipient, amount limits, calldata, and fees before signing. A quote is not authority to sign.
Card issuing and card transactions (disabled unless approved)
- Data
- If cards are enabled: user and wallet IDs, cardholder name, nickname, card brand/type, encrypted card number and PIN where applicable, expiry, provider card ID/status, limits and controls, spend amount/currency/status, merchant name/category/location and optional geolocation, decline reason, rewards, and card activity timestamps. CVV is not stored by SELV.
- Purpose
- Issue and manage cards, apply user controls and limits, authorize and reconcile card spending, and show card history.
- Recipients and boundaries
- SELV service database — Encrypted card, control, provider-reference, and transaction records.
- Gnosis Pay — Card issuance and transaction processing fields when this provider is enabled. Privacy policy.
- Highnote — Card issuance and transaction processing fields when this provider is enabled. Privacy policy.
- Persistence
- Card, encrypted PAN/PIN, provider reference, limits, merchant, spend, and transaction records may be stored in the SELV database and by the enabled provider.
- Retention
- Records remain while needed to operate an enabled card program, resolve disputes, prevent fraud, or meet provider and legal obligations. No production provider is enabled by default.
- Deletion
- Request closure, export, or deletion at privacy@selvwallet.com. Transaction, dispute, fraud, and legally required records may need to remain; provider copies follow provider processes.
- Controls
- The feature is default-off. Provider activation requires separate legal, privacy, claims, region, security, and operational approval; CVV is not persisted by SELV.
Fiat on-ramp and off-ramp
- Data
- Destination wallet address, network and asset, fiat/crypto amount and currency, provider and provider transaction ID, fee and status fields, and identity/payment data entered directly in a provider widget.
- Purpose
- Prepare and reconcile a user-requested crypto purchase or sale and account for fees and transaction status.
- Recipients and boundaries
- SELV service database — Provider reference, expected destination/network/currency, amount, fee, and status records.
- Stripe — Fiat on-ramp; may receive destination wallet address, destination network and currency, requested fiat or crypto amount, Stripe customer identifier when supplied, client IP address for non-Telegram web requests, identity and payment information entered directly into the Stripe widget. Available only where both SELV region gating and Stripe allow the session. Privacy policy.
- MoonPay — Fiat on-ramp; may receive destination wallet address, selected crypto and fiat currencies, requested fiat amount, identity and payment information entered directly into the MoonPay widget. Availability and payment methods depend on MoonPay and the user region. Privacy policy.
- Transak — Fiat on-ramp; may receive destination wallet address, destination network and crypto currency, selected fiat currency and requested amount, identity and payment information entered directly into the Transak widget. Availability and payment methods depend on Transak and the user region. Privacy policy.
- Ramp Network — Fiat on-ramp; may receive destination wallet address, selected crypto asset and fiat currency, requested fiat amount, identity and payment information entered directly into the Ramp widget. Availability and payment methods depend on Ramp and the user region. Privacy policy.
- Persistence
- SELV stores on/off-ramp transaction, provider-reference, amount, fee, and status records. Providers store transaction, identity, and payment records under their own policies.
- Retention
- SELV keeps records while needed for reconciliation, support, accounting, fraud prevention, and legal duties; providers apply their own retention.
- Deletion
- Request SELV-controlled data at privacy@selvwallet.com. Identity or payment records entered with a provider are controlled through that provider, subject to legal retention.
- Controls
- SELV sends only fields needed to initialize the selected provider flow. Provider availability and identity/payment processing remain subject to provider and region rules.
Local wallet storage and optional encrypted Telegram backup
- Data
- Encrypted wallet key material, encrypted seed backup, password-wrapped data-encryption key, public addresses, settings, and session state. The browser extension also processes connected-site origins, requested chains, accounts, transactions, and messages.
- Purpose
- Keep a self-custodial wallet usable on the device and, only when selected, support encrypted cross-device restore through Telegram CloudStorage.
- Recipients and boundaries
- User device storage — IndexedDB, platform secure storage, or chrome.storage.local, depending on client.
- Telegram CloudStorage — Optional encrypted backup selected by a Telegram Mini App user. Privacy policy.
- Connected websites — Receive only approved public accounts, chain context, and signatures or responses for requests the user approves.
- Persistence
- Encrypted wallet data remains on the device until erased. An opted-in encrypted backup remains in Telegram CloudStorage until replaced or deleted.
- Retention
- Device and optional cloud copies remain under the user’s storage choices; session secrets expire or are cleared by the client.
- Deletion
- Erase the wallet or extension data locally. Telegram security settings can retain, delete, and verify removal of the optional cloud backup.
- Controls
- The server is not designed to receive plaintext recovery phrases or private keys. Cloud backup is opt-in and encrypted, but possession permits offline password guessing.
We do not sell personal data. We update this inventory when a product adds a user-linked persistence model or outbound recipient.
6. Data Retention and Deletion
Operational audit records expire after 90 days. Authentication and security audit records expire after 365 days. A daily deletion job removes expired records. A record may remain past its expiry only under a documented legal hold.
Audit records store a coarse network prefix and browser family instead of a full IP address or User-Agent version. Public blockchain transactions are permanent and cannot be deleted by SELV. Extension keys and settings remain in chrome.storage.local until you erase the wallet or remove its local data.
No self-service deletion or export workflow is currently implemented. To request access, correction, export, account deletion, or withdrawal of optional consent, email privacy@selvwallet.com. Account deletion removes audit records that are not under a legal hold. We will identify data that can be returned or deleted, held records that must be retained, and public-chain records outside our control.
7. Your Rights
Depending on your jurisdiction, you may ask to access, correct, export, or delete personal data, object to processing, or withdraw consent. These rights are not a promise that every requested record can be changed: public blockchain history cannot be erased, and legal retention duties may apply.
8. Children's Privacy
SELV Wallet is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the “Last updated” date. Continued use of the service after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions about this Privacy Policy, please contact us:
- Email: privacy@selvwallet.com