Smartable Wallet Privacy Policy
Version 1.5, effective 18 September 2026
We cannot access what we never receive.
Spis treści
- Who is responsible
- What never leaves your device
- Optional encrypted and split backup
- No account, no identity
- What is processed, why and on what legal basis
- Who else may see your data
- Transfers outside the EEA
- What is public regardless of Smartable
- Analytics and crash reporting
- Security and privacy limitations
- Your rights
- Automated processing and route selection
- Children
- Data security
- Changes to this Privacy Policy
- Contact for privacy matters
1. Who is responsible
The data controller for personal data described in this Privacy Policy is:
Controller: individual developer A. Shapialevich
Legal form: Sole proprietor operating within the limits of unregistered business activity (działalność nierejestrowana) as defined in Article 5(1) of the Polish Entrepreneurs’ Law Act of 6 March 2018 [1].
Address: A postal address will be published here when available. Until then, the controller operates as an individual under Polish law, within the limits of unregistered business activity (działalność nierejestrowana), and may be contacted via the email address above.
Email: hello@getsmartable.app
Website: https://getsmartable.app
If the publisher is operating as an individual before incorporation of a legal entity, the publisher’s legal and business details will be updated when applicable.
This email is used for privacy requests, including requests described in Section 11. We aim to respond within one month and within the time required by applicable law.
A data protection officer has not been appointed. This section will be updated if the legal conditions for appointing one become applicable.
Smartable Wallet is self-custody software. In the ordinary wallet configuration, Smartable does not create a Smartable account, user profile, email account, phone-number record or Smartable user ID.
Some optional third-party features may require authentication, identity verification or information to be provided directly to a third-party provider. Those features are governed by the provider’s own terms and privacy policy.
2. What never leaves your device
The following are not transmitted to Smartable or third-party infrastructure in plaintext:
- your recovery phrase;
- your private keys;
- your wallet password;
- your PIN;
- signing keys derived from your password;
- hardware-wallet private keys.
The application is designed so that these credentials are not transmitted to Smartable servers.
A signed transaction is different. After you approve a transaction, the signed transaction is transmitted for broadcast by one of two paths:
- directly from your device, for a send of a coin, token or NFT on any network the application supports and for a transaction you approve in the in-app dApp browser or over WalletConnect: it goes to a public node of that network and does not pass through Smartable's infrastructure;
- through Smartable's infrastructure, for a swap, a bridge or cross-chain transfer, a token approval or its revocation and a separate payment of Smartable's fee: it goes to Smartable's proxy, which passes it to a blockchain node.
On Ethereum and BNB Smart Chain the transaction is by default sent, on either path, to a private transaction relay that passes it to block builders instead of announcing it publicly, to reduce the risk of a pending transaction being front-run. This can be switched off in the application's settings, does not apply to a network you have pointed at your own node, and the relays are named in section 6 of this Privacy Policy. On neither path is a transaction that went to a relay passed on to a public node: if the relay does not answer, the application tells you the result is not yet known and checks the network for it. Sending publicly instead is your own choice, made by switching private broadcast off before another attempt. A signed transaction is sent once, and not sent again after an unclear answer, on either path. In every case the transaction is not submitted to a swap provider, protocol or relayer as an order.
A signed transaction does not contain your private key, recovery phrase or password. However, a signed transaction or authorisation may allow crypto-assets to be moved.
Important: Before signing, carefully check the network, recipient, asset, amount, permissions, provider, route, fees and expected result. A confirmed transaction, token approval or other blockchain authorisation may be irreversible and may result in permanent loss of crypto-assets.
Smartable may receive and hold its own software and interface fee revenue in cryptocurrency where a route provides for such payment. That revenue is Smartable’s own revenue and is not user wallet data held on behalf of the user.
This description applies to the supported application versions and configurations described in the documentation. Users remain responsible for reviewing the security of their device, operating system, hardware wallet and any third-party software or service they use.
3. Optional encrypted and split backup
If you enable an optional encrypted cloud backup feature, recovery material may be encrypted and split locally before any share is uploaded.
Depending on the selected configuration, the application may:
- encrypt recovery material locally;
- create multiple encrypted shares;
- upload selected encrypted shares to cloud providers chosen by you;
- retain one share on your device;
- require a threshold number of shares for recovery;
- require a backup password or passphrase.
For a 2‑of‑3 configuration, any two valid shares may satisfy the configured SLIP‑39 threshold. If the application imposes an additional requirement for a device-held share, that requirement will be explained in the backup and restore flow.
The plaintext recovery phrase, private keys and wallet password are not uploaded by Smartable as part of the intended backup design.
Encrypted shares are not intended to be usable by a cloud provider on their own. However, the security of your backup also depends on:
- the strength of your backup password or passphrase;
- the security of your devices;
- the security of your cloud accounts;
- the security of the selected cloud providers;
- the protection of your shares;
- the correctness of the recovery process.
Potential cloud providers may include:
- Google Drive;
- MEGA;
- Backblaze B2.
The selected cloud provider may process uploaded encrypted shares, filenames, technical metadata, account identifiers and access logs under its own privacy policy.
Smartable does not receive your plaintext recovery phrase or password and does not provide a decryption service.
You are responsible for retaining:
- the required shares;
- the required backup password or passphrase;
- any required recovery metadata;
- access to the selected cloud account.
Losing the required password, passphrase, shares or metadata may make recovery impossible.
4. No account, no identity
In the ordinary wallet configuration, there is no Smartable sign-up, Smartable email account, phone-number record or Smartable user ID.
If you use Smartable Wallet without contacting us or using an optional third-party feature that requires identity verification, we generally do not know who you are.
A blockchain address is not necessarily anonymous. It may be personal data where it can reasonably be linked to an individual.
Smartable treats wallet addresses as potentially personal data even though the ordinary wallet flow is not intended to create a persistent user identity.
Optional providers may collect identity information directly from you. Examples include:
- crypto purchase providers;
- cash-out providers;
- cloud storage providers;
- Google authentication;
- support services;
- other providers that require identity verification.
5. What is processed, why and on what legal basis
The legal basis stated below depends on the feature, the parties involved and the actual processing performed. Where a third-party provider processes data for its own purposes and determines how it is processed, that provider may act as an independent controller under its own privacy policy.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Public blockchain address | Reading balances, asset information and transaction history | Contract, Article 6(1)(b) GDPR, where applicable | Relayed for the requested operation and not intentionally stored by Smartable where technically possible |
| Asset symbols and amounts | Displaying holdings and fiat values | Contract, Article 6(1)(b) GDPR, where applicable | Cached by asset where needed and not intentionally linked to a user identity |
| Source address, destination address, asset, amount and transaction data | Preparing transactions and obtaining quotes | Contract, Article 6(1)(b) GDPR, where applicable | Processed for the requested operation and handled according to applicable provider and infrastructure retention |
| Route and provider information | Displaying the available routes you choose between | Contract, Article 6(1)(b) GDPR, legitimate interests under Article 6(1)(f) GDPR, or another applicable basis | Processed for the requested operation and retained only as needed for support, security, accounting or legal obligations |
| Fee information | Displaying, calculating, reconciling and accounting for Smartable and third-party fee components | Contract, Article 6(1)(b) GDPR, legal obligation or legitimate interests, as applicable | Retained only as needed for the requested operation, support, accounting, security or legal obligations |
| Signed transaction or signed authorisation | Broadcasting a transaction | Contract, Article 6(1)(b) GDPR, where applicable | Sent to a blockchain network, directly or through Smartable's infrastructure; confirmed blockchain transactions remain public and permanent |
| Rate-limit token or salted IP-derived value | Protecting infrastructure from abuse | Legitimate interests, Article 6(1)(f) GDPR | Short-lived for the current rate-limit window where technically possible |
| IP address and technical request data, such as request time, requested hostname or route, and security-event data | Operating and protecting Smartable-operated websites, APIs and optional services; applying configured WAF rules, rate limits and access restrictions | Legitimate interests, Article 6(1)(f) GDPR; legal obligation, Article 6(1)(c) GDPR, where a specific applicable obligation requires the processing | Retained only as needed for the relevant security or legal purpose, according to the applicable infrastructure logging settings and retention periods |
| Approximate country derived from the IP address presented to Smartable's infrastructure | Applying configured geographic, legal, provider and security restrictions to Smartable-operated services; asking an optional on-ramp provider which assets it offers in that country, for which only the country code is sent, without the IP address | Legitimate interests, Article 6(1)(f) GDPR; legal obligation, Article 6(1)(c) GDPR, where a specific applicable obligation requires the processing | Processed to make the access decision; may also be retained in security records where logging is enabled. The provider's list of assets is cached by country, not by person |
| Receiving addresses, chosen asset, device IP address and a random purchase reference | Starting a purchase or sale you request with an on-ramp or off-ramp provider, and showing its status | Contract, Article 6(1)(b) GDPR; legitimate interests, Article 6(1)(f) GDPR, in binding the session to your device so that nobody else can use it | Sent by Smartable's proxy to that provider for the request and not stored by Smartable; the reference is kept on your device |
| Hostname opened in the in-app browser, or named by a dApp connecting over WalletConnect | Checking it against a phishing-domain list | The check runs on your device against a list the application carries; the hostname is not sent to Smartable or to anyone else | Not transmitted |
| Encrypted backup shares and technical metadata | Providing optional encrypted cloud backup | Contract, Article 6(1)(b) GDPR, where applicable | Stored by the selected cloud provider under its policy and until deletion, expiry or account removal |
| Google account and access token, if used | Providing optional Google Drive backup | Contract, Article 6(1)(b) GDPR or consent where applicable | Managed according to Google's services and until sign-out, revocation, deletion or expiry |
| Crash report, if enabled | Diagnosing a specific software fault | Consent, Article 6(1)(a) GDPR | Until the fault is closed or deletion is requested, subject to lawful retention |
| Device and application information | Security diagnostics, compatibility and crash diagnosis | Consent, legitimate interests or another applicable basis | Retained only as needed for the relevant purpose |
| Support correspondence | Responding to a request | Legitimate interests, Article 6(1)(f) GDPR, contract or another applicable basis | Up to 24 months unless a longer period is legally necessary or deletion is requested |
| Service-fee revenue received by Smartable | Receiving, reconciling and accounting for Smartable's own revenue | Contract, legal obligation or legitimate interests, as applicable | For the period required by accounting, tax, security and legal obligations |
Where processing is based on consent, you may withdraw consent at any time through the application where available or by contacting us.
Withdrawal does not affect processing carried out lawfully before withdrawal.
6. Who else may see your data
Requests take one of two paths.
Reads of public blockchain data — balances, and on some networks transaction lists — may be sent directly from your device to public nodes published by the networks themselves and by independent operators. The application carries a list of those nodes and tries them in order. See Direct requests to the networks' own nodes below.
Some requests use only the direct path. The in-app dApp browser, WalletConnect connections and sending a coin, token or NFT on any network the application supports send everything they need from your device, including the signed transaction, and never through the Smartable proxy; see dApps, WalletConnect and EVM sends, Sending bitcoin, litecoin, dogecoin and bitcoin cash and Sending on other networks below.
Everything else may be sent through a Smartable proxy: any request that needs a credential Smartable holds; the broadcast of a transaction you sign for a swap, a bridge or cross-chain transfer, a token approval or its revocation or a separate payment of Smartable's fee; and, outside the direct-only features above, any read the direct nodes could not answer.
The proxy is intended to reduce direct transmission of your IP address to the providers behind it. It does not do so for the direct path. The proxy may still process the information required to provide the requested feature.
Depending on the feature, Smartable infrastructure may process:
- public wallet addresses;
- source and destination addresses;
- asset identifiers;
- token contract addresses;
- amounts;
- route information;
- provider identifiers;
- fee information;
- transaction parameters;
- signed transactions;
- signed authorisations;
- network and chain information;
- technical error information.
Smartable infrastructure does not receive private keys, recovery phrases, passwords or signing keys as part of the intended design.
Potential providers may include:
- chain data: Infura, Alchemy, dRPC, Ankr, Tenderly and other node providers, and public nodes;
- transaction history and asset data: Alchemy and other indexers;
- prices and asset identity: CoinGecko, Coinbase, Kraken and DefiLlama, and exchange rates from ExchangeRate-API — the prices that value your portfolio, and what its tokens are, are worked out on your device, as described under "Prices shown for your portfolio" and "The market list and the token catalogue";
- Bitcoin-family data: Blockchair, BlockCypher, Haskoin, BitPay's Bitcore API, mempool.space, an independently operated mempool.space mirror, Blockstream and litecoinspace.org;
- Zcash data: lightwalletd nodes;
- swaps and bridges: 0x, LI.FI, THORChain, Jupiter and other providers;
- network-specific routes: STON.fi, Stellar network liquidity, xExchange, Vestige, Sirius and other providers;
- fiat on-ramps and off-ramps: Coinbase and other providers — when you start a purchase or sale, Smartable's proxy sends the provider the receiving addresses and asset you chose and your device's IP address, which the provider requires to bind the session to you, and later a random reference generated on your device, to show that purchase's or sale's status. The provider processes this data, and the identity and payment data it collects from you directly, as an independent controller under its own terms;
- phishing-domain list: MetaMask's public
eth-phishing-detectlist, fetched by Smartable infrastructure and delivered to the application as a signed update — the sites you open are checked on your device and are not sent to anyone; - WalletConnect connections: Reown's WalletConnect relay network, which carries messages between the application and a dApp or agent session you choose to connect. The messages are encrypted end to end between those two, so the relay cannot read them; it can see your device's IP address, the connection's identifier and when messages pass;
- crash reporting, only if you switch it on: Sentry (Functional Software, Inc.), in its EU data region;
- QR-code scanning on Android: Google ML Kit, which reads the camera image on your device. According to Google, ML Kit sends Google device information, app information, performance metrics and error codes for diagnostics and usage analytics; the contents of a scanned code are not among them. Google operates this under its own terms, and the application has no setting that turns it off;
- private transaction relays, on the networks where the application offers them: Flashbots Protect and MEV Blocker on Ethereum, 48 Club and PancakeSwap MEV Guard on BNB Smart Chain;
- hosting, delivery and security infrastructure: Cloudflare and other providers — for requests to Smartable-operated websites and APIs, Cloudflare may process IP addresses, approximate location derived from IP addresses, request metadata and security-event data to deliver those services and apply configured WAF, rate-limiting and geographic access rules;
- optional encrypted backup: Google Drive, MEGA and Backblaze B2;
- hardware-wallet or connection services: the relevant vendor or protocol.
Third-party providers operate under their own terms and privacy policies.
Smartable's own operational alerts are delivered to the publisher through Telegram. They describe the state of Smartable's infrastructure and of its fee collection, and contain no wallet address, amount, transaction or other information about a user.
AI tools. The application sends nothing to an AI provider and has no connection to any AI tool. If you use Analyze with AI, the text you choose to share — network names, public addresses and the task you selected — goes to the app you pick in your device's share sheet, or wherever you paste it, and what that app or its provider does with it is governed by their terms and privacy policy. A public address can be linked to its publicly visible on-chain activity.
Agent Wallet. An Agent Wallet is processed like any other wallet in the application: its recovery phrase and private keys stay on your device as described in section 2, and its public addresses are read through the same infrastructure as any other wallet's. No AI provider receives anything about it unless you share its addresses yourself through Analyze with AI.
If you use a third-party feature, that provider may:
- process additional information;
- require identity verification;
- retain data under its own policy;
- use its own infrastructure;
- process information outside the EEA;
- provide additional privacy notices;
- use its own cookies or analytics.
The total amount you may pay or lose in connection with a route may include the source amount, the Smartable software and interface fee, third-party or protocol components, source-chain network fees, destination-chain network fees, approval or permit transaction fees, relayer costs, bridge costs and other route-specific deductions. The final amount received may therefore differ from the quoted amount.
Provider roles
Where a third-party provider processes data on documented instructions from Smartable and for the purposes described in this Privacy Policy, it acts as a processor. Where a provider determines its own purposes and means (for example fiat on-ramps that collect identity data directly from you), it acts as an independent controller under its own privacy policy.
The following table summarises typical provider types, the data they may process and their role under data-protection law. The actual role depends on the specific provider, feature and processing activity.
| Provider type | Typical role | Data | Role |
|---|---|---|---|
| RPC/node provider | relays blockchain requests | addresses, calldata, IP | verify controller/processor |
| Crash provider | diagnostics | stack trace, device data | processor or controller |
| Cloud backup | stores encrypted shares | shares, metadata | processor/controller |
| Fiat on/off-ramp | KYC and payment | identity/payment data; from Smartable's proxy: receiving addresses, asset, IP address, purchase reference | independent controller |
| Analytics, if introduced | telemetry | event/device data | processor/controller |
For each active provider, Smartable maintains an internal record of processing that identifies the provider's role, the categories of data, purposes of processing, transfer safeguards and retention periods.
Direct requests to the networks' own nodes
Where the application reads a network's own public nodes directly, that node operator may see:
- the IP address of your device;
- the public wallet address being read;
- which network the request is for, and what kind of request it is;
- the time of the request.
The operator does not receive your recovery phrase, private keys, wallet password or PIN. A read request contains no signed transaction. Where the application sends a transaction to such a node itself — a send on any network, and a dApp or WalletConnect request on an EVM network — the operator also receives the signed transaction. For an EVM transaction it also receives its details before you confirm it, because the application asks the node to estimate its fee and preview its effect; on some other networks, described below, the same is true of a send.
This is a change from earlier versions, and it moves in two directions at once:
- Smartable infrastructure receives less. These reads no longer pass through it, so it does not process the wallet addresses they carry.
- The node operator receives more. It sees your device rather than Smartable infrastructure.
The node operators are independent third parties, each under its own terms and privacy policy. They are public infrastructure rather than services Smartable contracts with, and no credential of yours or of Smartable's is sent to them. The list carried in a given release is part of the application's published source.
Requests that need a credential Smartable holds continue to go through the proxy, because that credential cannot be placed in the application. These include transaction history on EVM networks, NFT data and some network-specific services. Broadcasting the other signed transactions — a swap, a bridge or cross-chain transfer, a token approval or its revocation and a separate payment of Smartable's fee — also goes through the proxy. On Ethereum and BNB Smart Chain, while private transaction broadcast is on, the proxy sends it to one of the private relays named below rather than announcing it publicly, and never on to a public node if the relay does not answer.
You can replace this for any network by setting your own node endpoint in the application. That network then uses only the endpoint you set — neither the public nodes above nor the Smartable proxy, including its spare hosts.
dApps, WalletConnect and EVM sends
The in-app dApp browser, WalletConnect connections, the Send screen and sending an NFT on an EVM network work entirely from your device. The list of NFTs you hold is still read through the Smartable proxy, because it needs a credential Smartable holds. None of their requests passes through Smartable infrastructure — not the network reads, not the transaction preview, not the transaction itself, and not the prices used to value it. If no public node can be reached, the request fails and nothing is sent; it is not passed to Smartable instead.
For each request a dApp or a connected session makes, and for each send, on an EVM network, the application contacts the network's public nodes directly. Such a node operator may see:
- the IP address of your device;
- the public wallet address;
- the reads the dApp or the Send screen needs;
- the details of a transaction you are being asked to approve — sender, recipient, amount and data — before you approve it, because the application asks a node to estimate its fee and to preview what it would do;
- the signed transaction, once you approve it.
When you type an ENS name as a recipient, or paste an address that has one, the application looks the name up on Ethereum's public nodes in the same way; the node operator may see the IP address of your device and the name or address being looked up.
On Ethereum and BNB Smart Chain, while private transaction broadcast is switched on, the signed transaction is sent instead to a private transaction relay: Flashbots Protect, or MEV Blocker if Flashbots Protect cannot be reached, on Ethereum; 48 Club, or PancakeSwap MEV Guard, on BNB Smart Chain. The relay may see the IP address of your device and the signed transaction.
If you have set a password for large sends, the application values the transaction or the send before asking for it. It asks DefiLlama (coins.llama.fi) for the prices of the assets leaving your wallet — the request contains the network, the token contract addresses and the name of the network's own coin, not your wallet address or any amount — and, if your display currency is not the US dollar, Coinbase's public exchange-rate table (api.coinbase.com), which receives nothing but the request.
These operators are independent third parties under their own terms and privacy policies. Because these requests do not reach Smartable infrastructure, the IP-address-based restrictions described in section 8 are not applied to them by that infrastructure; section 8 applies to your use of these features all the same.
Sending bitcoin, litecoin, dogecoin and bitcoin cash
A bitcoin send works entirely from your device. The application asks the public Bitcoin explorers it carries — Blockstream (blockstream.info), mempool.space and a mempool.space mirror operated independently (mempool.emzy.de) — for the current fee rates, for the unspent coins of the addresses you are sending from and, when a hardware wallet signs, for the earlier transactions those coins came from; and it sends the signed transaction to one of them. None of this passes through Smartable infrastructure. If none of them can be reached, nothing is sent.
A litecoin, dogecoin or bitcoin cash send works the same way, with that network's public explorers: litecoinspace.org and BlockCypher for litecoin, Blockchair and BlockCypher for dogecoin, and Blockchair, Haskoin and BitPay's Bitcore API for bitcoin cash, where only Blockchair or Bitcore is sent the transaction. After a bitcoin cash swap deposit, the application asks Bitcore and Haskoin whether the network has the transaction, sending them its transaction identifier; until one of them finds it, the application does not report the deposit as sent. Finding it shows that the network has received the transaction, not that it is in a block.
Such an operator may see the IP address of your device, the addresses you are sending from, and the signed transaction. If you have set a password for large sends, the application values the send by asking DefiLlama and, if your display currency is not the US dollar, Coinbase's public exchange-rate table, as described above.
These operators are independent third parties under their own terms and privacy policies, and the IP-address-based restrictions described in section 8 are not applied to these requests by Smartable infrastructure; section 8 applies to your use of this feature all the same.
Sending on other networks
A send on Solana, the XRP Ledger, Cardano, Aptos, Sui, Movement, NEAR, Stellar, Algorand, Tezos, Polkadot, Cosmos, Filecoin, MultiversX, Kaspa, Zcash, TRON or TON works entirely from your device. The application reads what it needs to build the transaction — balances, account state, fees — from that network's public nodes, and sends the signed transaction to one of them. None of this passes through Smartable infrastructure. If none of them can be reached, nothing is sent.
Such a node operator may see the IP address of your device, the address you are sending from and the signed transaction. On Filecoin and TRON the application also asks a node to estimate the fee of, or to build, the unsigned transaction before you confirm it, and on Aptos, Movement and Cosmos it asks a node to simulate the transaction after you confirm it and before it is sent, so those operators may see its details — sender, recipient and amount — before it is sent. If you have set a password for large sends, the application values the send by asking DefiLlama and, if your display currency is not the US dollar, Coinbase's public exchange-rate table, as described above.
These operators are independent third parties under their own terms and privacy policies, and the IP-address-based restrictions described in section 8 are not applied to these requests by Smartable infrastructure; section 8 applies to your use of this feature all the same.
Direct asset-logo requests
If the application loads asset logos directly from hosts such as raw.githubusercontent.com, assets.coingecko.com or coin-images.coingecko.com, those hosts may see the device IP address and the logos requested.
The requested logos may reveal which assets the application is displaying, although they do not directly include a wallet address or transaction amount.
If a later release moves these requests behind the Smartable proxy, this section will be updated.
Prices shown for your portfolio
The prices and exchange rates the application uses to value your portfolio and its transaction history are requested by your device directly, not through Smartable infrastructure:
- CoinGecko (
api.coingecko.com), Coinbase (api.coinbase.com) and Kraken (api.kraken.com) receive the identifiers or exchange tickers of the coins being valued; - DefiLlama (
coins.llama.fi) receives the networks and token contract addresses your wallet holds a balance of, and the identifiers of coins the others did not price; - if your display currency is not the US dollar, ExchangeRate-API (
open.er-api.com), Coinbase and Kraken are asked for exchange rates.
These requests do not contain your wallet address, your balances or any amount. Each provider may see your device's IP address alongside the coins and tokens asked about, which may indicate which assets the application is displaying. Token contract prices are never requested in test mode.
What a token is — its name, its image and whether CoinGecko's catalogue lists it — is worked out on your device from CoinGecko's public catalogue; nothing about the tokens you hold is sent for it. Prices used for swaps and cross-chain transfers are obtained by Smartable infrastructure.
These providers are independent third parties under their own terms and privacy policies.
The market list and the token catalogue
The Markets screen, an asset's price chart, and the list of tokens the application checks your wallet for are worked out on your device directly, not through Smartable infrastructure:
- CoinGecko (
api.coingecko.com) receives requests for pages of its market list — when you open or refresh the Markets screen, and about once a week for the ranking the list of tokens to check is made from — and for its catalogue of which coins exist on which networks, downloaded in full about once a week; and, when you open the market figures of an asset, that asset's identifier; - Coinbase (
api.exchange.coinbase.com) and Kraken (api.kraken.com) receive a request for their whole list of trading pairs, which the application uses to decide which assets it can draw a price chart for; - when you open an asset's price chart, Coinbase (
api.exchange.coinbase.com), and Kraken (api.kraken.com) if Coinbase has no chart for it, receive that asset's exchange ticker and the period shown. For an asset neither exchange trades, the chart is requested through Smartable's proxy, which receives the asset's identifier and the period and asks CoinGecko for it.
These requests do not contain your wallet address, your balances, any amount or the tokens you hold, and apart from the asset whose figures or chart you open they name nothing specific to you. Each provider may see your device's IP address. These providers are independent third parties under their own terms and privacy policies.
7. Transfers outside the EEA
Some Smartable infrastructure and third-party providers may be located outside the European Economic Area, including in the United States.
Where required, transfers may rely on:
- an adequacy decision;
- the EU–US Data Privacy Framework where the provider participates;
- Standard Contractual Clauses;
- another lawful transfer mechanism;
- another lawful basis permitted by applicable data-protection law.
A blockchain transaction is broadcast to a public network of nodes worldwide. This international distribution is inherent to blockchain technology and is outside Smartable’s control. This description of blockchain broadcasting is separate from transfers of personal data by Smartable. Depending on the network, transaction data may be distributed globally by the network itself. Smartable does not control the recipients, locations or retention practices of independent network participants.
You may contact us using the details in section 16 to request information about the specific transfer safeguards applicable to a particular provider or processing activity.
8. What is public regardless of Smartable
Blockchain addresses, balances, token holdings and confirmed transactions may be public or publicly derivable depending on the network.
Anyone may read the relevant blockchain data.
Blockchain data may be linked to an individual by third parties.
Confirmed blockchain transactions cannot be erased by Smartable or by any other wallet provider.
For privacy-sensitive use, consider:
- using separate addresses for separate purposes;
- using your own RPC node where supported;
- avoiding unnecessary public address reuse;
- reviewing the privacy policy of every provider you use.
Some supported networks offer optional privacy features. For example, Zcash may allow users to use privacy-preserving transaction types. Depending on the network, transaction type and user choices, not all transaction activity, balances or asset holdings may be publicly viewable or publicly derivable. Smartable processes only the information made available through the blockchain interfaces, nodes, indexers or other providers used for the relevant feature. Smartable does not control the privacy settings or visibility rules of an external blockchain.
9. Analytics and crash reporting
The application is intended to contain no advertising analytics or user-behaviour profiling.
This website does not intentionally use advertising trackers or analytics.
If third-party content, analytics, advertising, cookies or hosted resources are introduced, this section will be updated.
Crash reporting is optional and off by default. It is activated only after you enable it in the application, except where a separate technical diagnostic process is strictly necessary for security or service operation and applicable law permits it.
If crash reporting is enabled, it is limited to diagnosing software failures. Reports are sent to Sentry (Functional Software, Inc.), which receives them in its EU data region and acts as Smartable's processor.
The crash-reporting configuration is intended to exclude the following data and is tested against the supported application versions. Technical metadata may still reveal information indirectly in exceptional cases.
Crash reporting is configured not to send:
- private keys;
- recovery phrases;
- passwords;
- wallet addresses, and names that resolve to one, such as ENS or NEAR account names;
- transaction paths;
- transaction amounts;
- screenshots;
- breadcrumb trails containing wallet activity.
Crash reporting may still include technical information such as:
- exception type;
- the exception's message, with anything shaped like an address, a key, a transaction identifier or an amount removed before it is sent;
- stack trace;
- application version;
- operating-system version;
- device model;
- device configuration;
- crash timestamp;
- technical diagnostics.
Because crash reporting is off until you switch it on, crash reports are processed on the basis of your consent under Article 6(1)(a) GDPR, as stated in the table in section 5. You may withdraw that consent at any time by disabling crash reporting in the application; withdrawal does not affect reports already sent.
Crash reports are retained only for as long as necessary to diagnose and fix the relevant issue, and are deleted thereafter unless a longer retention period is required by law.
10. Security and privacy limitations
Smartable may provide:
- phishing-domain checks;
- address validation;
- address-poisoning detection;
- token approval monitoring;
- transaction simulation;
- typed-data review;
- device-integrity checks;
- screen-capture protection on supported platforms;
- biometric or PIN protection.
These features reduce certain risks but do not guarantee that:
- a site is safe;
- a contract is safe;
- a token is legitimate;
- a provider is reliable;
- a transaction will succeed;
- a simulation is complete;
- a device is uncompromised;
- a private key will never be exposed by a compromised device;
- a blockchain transaction will produce the expected result.
A successful security check or simulation is not a guarantee of safety.
An unavailable check or simulation is not evidence that a transaction is safe or unsafe.
A rooted, jailbroken or compromised device may alter what is displayed before signing or interfere with the application.
11. Your rights
Under the GDPR, you may have rights including:
- access;
- rectification;
- erasure;
- restriction of processing;
- data portability;
- objection to processing based on legitimate interests;
- withdrawal of consent where processing is based on consent.
Send privacy requests to:
hello@getsmartable.app
Please use “Privacy” in the subject line.
We aim to respond within one month and within the time required by applicable law.
These rights do not allow Smartable to erase:
- data permanently recorded on a public blockchain;
- data held by an independent third-party provider where Smartable has no control over it;
- data that must be retained under applicable law;
- data required to establish, exercise or defend legal claims.
You may also complain to the supervisory authority in your country of residence, workplace or the place of the alleged infringement.
We may ask for information reasonably necessary to verify your identity and protect personal data before responding to a request. We will not ask you to provide a recovery phrase, private key, password, PIN or signing credential.
12. Automated processing and route selection
Smartable does not use profiling or automated decision-making that produces legal or similarly significant effects on you.
The application may automatically:
- select technical fallbacks;
- reject malformed requests;
- apply rate limits;
- hide unavailable data;
- display security warnings;
- block known phishing domains;
- restrict unsupported networks or providers.
These are operational, technical and security controls. They are not decisions about your eligibility, creditworthiness, insurance, employment or personal profile.
The application does not rank or select a swap or bridge provider for you. Which provider is used is your explicit choice — see section 6.11.
13. Children
Smartable Wallet is not directed at children under 18.
We do not knowingly collect personal data from children.
Where Article 8 GDPR applies to an information-society service based on consent, applicable age and parental-consent requirements will apply.
14. Data security
Smartable uses technical and organisational measures intended to protect data processed through its infrastructure.
These measures may include:
- encrypted transport;
- access controls;
- secret separation;
- rate limiting;
- logging restrictions;
- sensitive-data redaction;
- secure storage practices;
- provider access controls;
- security monitoring;
- restricted production access.
No method of transmission or storage is completely secure.
You are responsible for protecting:
- your device;
- your wallet password;
- your PIN;
- your recovery phrase;
- your backup shares;
- your backup passphrase;
- your cloud accounts;
- your hardware wallet;
- your email and support accounts.
15. Changes to this Privacy Policy
Material changes to this Privacy Policy will be announced in the application or on the website before they take effect where practicable.
Each version will carry its own effective date.
If required by law, Smartable will request renewed consent before applying a material change to consent-based processing.
16. Contact for privacy matters
For privacy questions or requests, contact:
hello@getsmartable.app
Please use “Privacy” in the subject line.
Support will never ask for your:
- recovery phrase;
- private key;
- wallet password;
- PIN;
- backup passphrase;
- full split-backup shares.
Any message requesting these credentials is not authorised by Smartable, regardless of the sender address.
Legal references
[3] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, General Data Protection Regulation:
EUR-Lex
[4] European Commission Implementing Decision (EU) 2023/1795 on the EU–US Data Privacy Framework:
EUR-Lex
[5] Article 8 GDPR:
EUR-Lex