Legal
Privacy Policy
This Privacy Policy explains how Hope Street Strategies LLC (“Scrypt Wallet,” “we,” “us,” or “our”) handles information in connection with the Scrypt Wallet web application, browser and mobile applications, the Scrypt ID sign-in service, this website, and related services (together, the “Services”).
Scrypt Wallet is a self-custodial (non-custodial) wallet. You alone hold your private keys and secret recovery phrase. We cannot access your wallet, move or freeze your funds, or approve transactions on your behalf. Because of this design, we collect far less information than a custodial exchange or bank would.
The short version
- We never receive your private keys, secret recovery phrase / recovery key, wallet password, or PIN. They are created and stored on your device.
- You can use the core wallet without giving us your name, email, or phone number.
- Public blockchains are public. Your wallet addresses, balances, and transactions are permanently recorded on-chain by the networks themselves — not by us — and we cannot alter or delete them.
- We use a small number of service providers (hosting, blockchain nodes and indexers, analytics, crash reporting, push notifications, email) to run the Services.
- Features you choose to use — swaps, bridging, buy/sell on-ramps, WalletConnect dApps — are operated by third parties under their own privacy policies.
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
- You can opt out of product analytics and marketing messages at any time.
1. Information we collect
a. Information you provide to us
- Account information. If you create a Scrypt Wallet / Scrypt ID account, we store an account identifier and, if you choose to add one, an email address (used for account recovery, security notices, and support). Providing an email is optional; some recovery and notification features are unavailable without one.
- Profile and preferences. Optional display name, avatar, selected networks, currency and language preferences, and other in-app settings.
- Address book. Labels and blockchain addresses you choose to save for reuse.
- Watched addresses. Public wallet addresses you associate with your account so we can display balances and detect and notify you of incoming transactions.
- Litecoin MWEB privacy mode. If you enable MWEB privacy features for Litecoin, a view-only scan key is stored on our servers so we can detect your MWEB balance and incoming MWEB transactions. This key cannot authorize spending or move funds.
- Rewards activity. If you take part in a points or rewards program, we record the qualifying actions you take in the app, linked to your account.
- Support and feedback. Messages, bug reports, and any information you include when you contact us or post in our community channels.
b. Information collected automatically
- Device and app data. Device or browser type, operating system, app or extension version, screen size, language, and similar technical attributes.
- Log and usage data. Requests made to our servers, timestamps, referring pages, features used, and diagnostic events.
- IP address. Processed transiently to route requests, apply rate limiting, protect against abuse and denial-of-service attacks, and derive approximate location for compliance and geo-restriction. We do not use your IP address for advertising.
- Approximate location. Coarse location (country / region) inferred from IP address, used to determine feature availability in your jurisdiction.
- Analytics events. Product-analytics events about how the app is used (for example, which screens are opened or which actions succeed or fail), which you can opt out of.
- Crash and error diagnostics. Stack traces and technical context when the app encounters an error.
- Cookies and local storage. See Section 6.
c. Blockchain information
When you use the wallet, we query public blockchain nodes and third-party indexing services to show you public on-chain data associated with your addresses — balances, token holdings, transaction history, and network fees — and we broadcast the transactions you sign to the relevant network. This information is inherently public and, once confirmed, is permanently recorded on the blockchain by the network itself. We do not control public blockchains and cannot change or erase data recorded on them.
d. Information from third parties
- Blockchain infrastructure providers (RPC nodes, indexers, explorers) that return on-chain data for your addresses.
- Market-data providers that supply token prices and metadata.
- Swap, bridge, and on-ramp partners that return quotes and transaction status for activity you initiate, and, for buy/sell on-ramps, a status result and (from their KYC process) limited confirmation data. Identity documents and full payment details you submit to an on-ramp provider go to that provider, not to us.
- Analytics, crash-reporting, push-notification, and email providers acting on our behalf.
- Sign-in providers if you choose to authenticate through a third party; we receive only the identifiers needed to link the login to your account.
2. Information we never collect
We do not collect, receive, transmit, or store:
- Your private keys or signed-transaction signing material;
- Your secret recovery phrase, recovery key, or individual coin keys;
- Your wallet password, PIN, or passcode;
- Biometric data used to unlock your device or the app (this stays on your device).
These are generated on your device and remain under your control. We will never ask you for your secret recovery phrase or private keys. Anyone who does is trying to steal your funds.
3. How we use information
- Operate the wallet. Display balances, prices, and history; construct unsigned transactions for you to review; broadcast transactions you sign; enable notifications you turn on.
- Enable features you request. Route swap, bridge, on-ramp, and dApp-connection requests to the third-party providers you choose.
- Support. Respond to your questions and troubleshoot issues.
- Security and integrity. Authenticate accounts, apply rate limits, detect and prevent fraud, abuse, and attacks, and keep the Services reliable.
- Improve the product. Understand aggregate usage and diagnose errors to fix bugs and prioritize features.
- Communicate. Send service, security, and transactional messages; send product or marketing messages where permitted (you can opt out).
- Legal and compliance. Meet legal obligations, enforce our terms, apply jurisdictional restrictions, and establish, exercise, or defend legal claims.
5. Third-party services and links
The Services integrate optional features operated by independent third parties. When you use them, you interact with those parties directly and may disclose information to them, including your wallet address, IP address, and transaction parameters. Categories include:
- Token swap providers (in-app and link-out);
- Cross-chain bridge services, including Scrypt Bridge;
- Fiat buy/sell on-ramp and off-ramp providers, which perform their own identity verification and payment processing;
- WalletConnect and the dApps or websites you connect your wallet to;
- Block explorers and market-data sites we link to;
- App distribution platforms (for example, app stores) through which you install our mobile apps.
We do not control and are not responsible for the privacy practices of these third parties. Review their policies before using their services.
6. Cookies and local storage
We and our providers use cookies, similar technologies, and on-device storage for:
- Strictly necessary purposes — keeping you signed in, maintaining session state, load balancing, and security.
- Preferences — remembering settings such as theme, selected network, active wallet, and language.
- Analytics — measuring aggregate usage and performance (optional; see Section 7).
The wallet application also stores data in your browser or device storage (for example,
localStorage and IndexedDB) to hold encrypted wallet data and per-device
session information so the app works. Clearing this storage removes locally saved wallet
data from that device — make sure your secret recovery phrase is backed up first.
You can control cookies through your browser settings. Because we honor opt-outs through the mechanisms above and via Global Privacy Control where required, we do not separately respond to browser “Do Not Track” signals.
7. Your choices
- Analytics. You can disable product analytics in the app’s privacy settings, and through your browser or operating-system controls.
- Push and in-app notifications. Manage these from your profile settings in the app and from your device’s notification settings.
- Marketing email. Use the unsubscribe link in any marketing message, or contact us. We may still send non-promotional service and security messages.
- Account data. You can edit profile details and saved addresses in the app, and you can request deletion of your account (see Section 12 and Section 13).
- Local data. You can remove locally stored wallet data by clearing app or site storage on your device.
8. Data retention
We keep information for as long as needed for the purposes described in this policy. In general:
- Account and profile data is retained while your account is active and for a limited period afterward, then deleted or anonymized, unless a longer period is required for legal, security, or dispute-resolution reasons.
- Server logs and security data are retained for a short period appropriate to their purpose.
- Analytics data is retained in aggregated or de-identified form.
- Support correspondence is retained as needed to provide support and keep records.
- Blockchain data cannot be deleted by us; it persists on public networks independently of your account.
9. Security
We use technical and organizational measures designed to protect information we hold, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Because the wallet is self-custodial, the security of your funds depends on you keeping your secret recovery phrase and device secure. If you lose your recovery phrase, we cannot recover it or your funds for you.
10. International data transfers
We operate in the United States, and information we process may be transferred to, stored, and processed in the United States and other countries whose data-protection laws may differ from those in your jurisdiction. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission’s Standard Contractual Clauses and the UK Addendum. You may contact us for more information about these safeguards.
11. Children’s privacy
The Services are not directed to children, and we do not knowingly collect personal information from anyone under 18 years of age. If you believe a child has provided us with personal information, contact us at privacy@scryptwallet.io and we will delete it.
12. U.S. state privacy rights
Depending on your state of residence (including California, and states such as Colorado, Connecticut, Virginia, Utah, Texas, and Oregon), you may have some or all of the following rights, subject to exceptions in the law:
- To know or access the personal information we have collected about you and how we use and disclose it;
- To request correction of inaccurate personal information;
- To request deletion of your personal information;
- To opt out of the sale of personal information or its use for targeted advertising — we do not do either;
- To limit use of sensitive personal information;
- To not be discriminated against for exercising these rights;
- To appeal a denial of your request.
Categories of information and disclosure
This serves as our California “notice at collection.” In the past 12 months we have collected and disclosed the following categories for the purposes described in this policy:
| Category (CCPA) | Examples | Disclosed to |
|---|---|---|
| Identifiers | Account ID, email (if provided), public wallet address, IP address, device identifiers | Service providers; third-party features you use; legal/safety recipients |
| Internet or network activity | App usage events, log data, diagnostics | Analytics and crash-reporting providers |
| Geolocation data | Approximate (country/region) location from IP address | Service providers; used for compliance |
| Commercial / transaction information | On-chain transactions you make; swap, bridge, and on-ramp activity you initiate | Blockchain networks; the relevant third-party provider |
| Customer records / contact data | Email address, support correspondence | Email and support-tooling providers |
We do not sell or share personal information, and we do not knowingly process sensitive personal information for purposes that require an opt-out. We retain each category as described in Section 8.
How to exercise your rights
Submit a request to privacy@scryptwallet.io. We will verify your request, typically by confirming control of the account or email address associated with the information. You may use an authorized agent, who must provide proof of authorization. If we deny your request, you may appeal by replying to our response; if you are unsatisfied with the outcome, you may contact your state attorney general.
Note on non-custodial limits. We can delete or correct account-side information we hold, but we cannot alter or erase transactions, addresses, or balances recorded on public blockchains, and we cannot access data held only on your device.
13. EEA, UK, and Swiss privacy rights
If you are in the European Economic Area, the United Kingdom, or Switzerland, the following applies.
Controller
Hope Street Strategies LLC is the controller of personal data processed through the Services. Contact details are in Section 15.
Legal bases
- Performance of a contract — to provide the wallet and the features you request.
- Legitimate interests — to secure the Services, prevent abuse and fraud, understand and improve the product, and communicate with you; balanced against your rights.
- Consent — for optional analytics, certain cookies, and marketing messages, where required. You may withdraw consent at any time.
- Legal obligation — to comply with applicable law.
Your rights
Subject to conditions in the GDPR / UK GDPR, you may request access, rectification, erasure, restriction of processing, and portability of your personal data, and you may object to processing based on legitimate interests. To exercise these rights, contact privacy@scryptwallet.io. You also have the right to lodge a complaint with your local supervisory authority (in the EEA, see the EDPB members list; in the UK, the ICO; in Switzerland, the FDPIC).
As with U.S. requests, our ability to act is limited for data recorded on public blockchains and for data held only on your device.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. If changes are material, we will provide additional notice through the Services or by other means. Your continued use of the Services after an update takes effect means you accept the revised policy.
15. Contact us
Questions, requests, or complaints about this policy or your information:
- Email: privacy@scryptwallet.io
- Entity: Hope Street Strategies LLC (Scrypt Wallet)
- Community & support: Telegram · X / Twitter
A postal address for formal notices is available on request.
↑ Back to top
Open wallet