We can't sell what we never receive.

There is no account, so there is no profile. This policy lists — item by item, with its legal basis — the minimum that leaves your device.

Version 1.2 — effective 27 August 2026

Smartable Wallet Privacy Policy
Version 1.2, effective 27 August 2026

We cannot access what we never receive.

1. Who is responsible

The data controller for personal data described in this Privacy Policy is:

Controller: individual developer A. Shapialevich
Legal form: Sole proprietor operating within the limits of unregistered business activity (działalność nierejestrowana) as defined in Article 5(1) of the Polish Entrepreneurs’ Law Act of 6 March 2018 [1].

Address: A postal address will be published here when available. Until then, the controller operates as an individual under Polish law, within the limits of unregistered business activity (działalność nierejestrowana), and may be contacted via the email address above.

Email: hello@getsmartable.app

Website: https://getsmartable.app

If the publisher is operating as an individual before incorporation of a legal entity, the publisher’s legal and business details will be updated when applicable.

This email is used for privacy requests, including requests described in Section 11. We aim to respond within one month and within the time required by applicable law.

A data protection officer has not been appointed. This section will be updated if the legal conditions for appointing one become applicable.

Smartable Wallet is self-custody software. In the ordinary wallet configuration, Smartable does not create a Smartable account, user profile, email account, phone-number record or Smartable user ID.

Some optional third-party features may require authentication, identity verification or information to be provided directly to a third-party provider. Those features are governed by the provider’s own terms and privacy policy.

2. What never leaves your device

The following are not transmitted to Smartable or third-party infrastructure in plaintext:

  • your recovery phrase;
  • your private keys;
  • your wallet password;
  • your PIN;
  • signing keys derived from your password;
  • hardware-wallet private keys.

The application is designed so that these credentials are not transmitted to Smartable servers.

A signed transaction is different. After you approve a transaction, a signed transaction or signed authorisation may be transmitted to a blockchain node, relay, third-party provider, protocol or relayer for broadcast or processing.

A signed transaction does not contain your private key, recovery phrase or password. However, a signed transaction or authorisation may allow crypto-assets to be moved.

Smartable may receive and hold its own software and interface fee revenue in cryptocurrency where a route provides for such payment. That revenue is Smartable’s own revenue and is not user wallet data held on behalf of the user.

3. Optional encrypted and split backup

If you enable an optional encrypted cloud backup feature, recovery material may be encrypted and split locally before any share is uploaded.

Depending on the selected configuration, the application may:

  • encrypt recovery material locally;
  • create multiple encrypted shares;
  • upload selected encrypted shares to cloud providers chosen by you;
  • retain one share on your device;
  • require a threshold number of shares for recovery;
  • require a backup password or passphrase.

For a 2-of-3 configuration, any two valid shares may satisfy the configured SLIP-39 threshold. If the application imposes an additional requirement for a device-held share, that requirement will be explained in the backup and restore flow.

The plaintext recovery phrase, private keys and wallet password are not uploaded by Smartable as part of the intended backup design.

Encrypted shares are not intended to be usable by a cloud provider on their own. However, the security of your backup also depends on:

  • the strength of your backup password or passphrase;
  • the security of your devices;
  • the security of your cloud accounts;
  • the security of the selected cloud providers;
  • the protection of your shares;
  • the correctness of the recovery process.

Potential cloud providers may include:

  • Google Drive;
  • MEGA;
  • Backblaze B2.

The selected cloud provider may process uploaded encrypted shares, filenames, technical metadata, account identifiers and access logs under its own privacy policy.

Smartable does not receive your plaintext recovery phrase or password and does not provide a decryption service.

You are responsible for retaining:

  • the required shares;
  • the required backup password or passphrase;
  • any required recovery metadata;
  • access to the selected cloud account.

Losing the required password, passphrase, shares or metadata may make recovery impossible.

4. No account, no identity

In the ordinary wallet configuration, there is no Smartable sign-up, Smartable email account, phone-number record or Smartable user ID.

If you use Smartable Wallet without contacting us or using an optional third-party feature that requires identity verification, we generally do not know who you are.

A blockchain address is not necessarily anonymous. It may be personal data where it can reasonably be linked to an individual.

Smartable treats wallet addresses as potentially personal data even though the ordinary wallet flow is not intended to create a persistent user identity.

Optional providers may collect identity information directly from you. Examples include:

  • crypto purchase providers;
  • cash-out providers;
  • cloud storage providers;
  • Google authentication;
  • support services;
  • other providers that require identity verification.

5. What is processed, why and on what legal basis

DataPurposeLegal basisRetention
Public blockchain addressReading balances, asset information and transaction historyContract, Article 6(1)(b) GDPR, where applicableRelayed for the requested operation and not intentionally stored by Smartable where technically possible
Asset symbols and amountsDisplaying holdings and fiat valuesContract, Article 6(1)(b) GDPR, where applicableCached by asset where needed and not intentionally linked to a user identity
Source address, destination address, asset, amount and transaction dataPreparing transactions and obtaining quotesContract, Article 6(1)(b) GDPR, where applicableProcessed for the requested operation and handled according to applicable provider and infrastructure retention
Route and provider informationDisplaying, ranking or selecting available routesContract, Article 6(1)(b) GDPR, legitimate interests under Article 6(1)(f) GDPR, or another applicable basisProcessed for the requested operation and retained only as needed for support, security, accounting or legal obligations
Fee informationDisplaying, calculating, reconciling and accounting for Smartable and third-party fee componentsContract, Article 6(1)(b) GDPR, legal obligation or legitimate interests, as applicableRetained only as needed for the requested operation, support, accounting, security or legal obligations
Signed transaction or signed authorisationBroadcasting or processing a transactionContract, Article 6(1)(b) GDPR, where applicableMay be sent to a blockchain network, provider, protocol or relayer; confirmed blockchain transactions remain public and permanent
Rate-limit token or salted IP-derived valueProtecting infrastructure from abuseLegitimate interests, Article 6(1)(f) GDPRShort-lived for the current rate-limit window where technically possible
IP addressSecurity, abuse prevention, rate limiting and service operationLegitimate interests, Article 6(1)(f) GDPR, legal obligation where applicableRetained only for the period necessary for these purposes or legal obligations
Approximate country derived from IPApplying legal, sanctions or service restrictionsLegal obligation or legitimate interests, as applicableNot intentionally retained unless required for security or legal records
Hostname opened in the in-app browserChecking a hostname against a phishing-domain listLegitimate interests, Article 6(1)(f) GDPRNot intentionally stored or linked to a wallet address where technically possible
Encrypted backup shares and technical metadataProviding optional encrypted cloud backupContract, Article 6(1)(b) GDPR, where applicableStored by the selected cloud provider under its policy and until deletion, expiry or account removal
Google account and access token, if usedProviding optional Google Drive backupContract, Article 6(1)(b) GDPR or consent where applicableManaged according to Google’s services and until sign-out, revocation, deletion or expiry
Crash report, if enabledDiagnosing a specific software faultConsent, Article 6(1)(a) GDPRUntil the fault is closed or deletion is requested, subject to lawful retention
Device and application informationSecurity diagnostics, compatibility and crash diagnosisConsent, legitimate interests or another applicable basisRetained only as needed for the relevant purpose
Support correspondenceResponding to a requestLegitimate interests, Article 6(1)(f) GDPR, contract or another applicable basisUp to 24 months unless a longer period is legally necessary or deletion is requested
Service-fee revenue received by SmartableReceiving, reconciling and accounting for Smartable’s own revenueContract, legal obligation or legitimate interests, as applicableFor the period required by accounting, tax, security and legal obligations

Where processing is based on consent, you may withdraw consent at any time through the application where available or by contacting us.

Withdrawal does not affect processing carried out lawfully before withdrawal.

6. Who else may see your data

Most third-party calls may be sent through a Smartable proxy.

The proxy is intended to reduce direct transmission of your IP address to upstream providers. The proxy may still process the information required to provide the requested feature.

Depending on the feature, Smartable infrastructure may process:

  • public wallet addresses;
  • source and destination addresses;
  • asset identifiers;
  • token contract addresses;
  • amounts;
  • route information;
  • provider identifiers;
  • fee information;
  • transaction parameters;
  • signed transactions;
  • signed authorisations;
  • network and chain information;
  • technical error information.

Smartable infrastructure does not receive private keys, recovery phrases, passwords or signing keys as part of the intended design.

Potential providers may include:

  • chain data: Infura, Alchemy and public nodes;
  • transaction history and asset data: Alchemy and other indexers;
  • prices and asset identity: Coinpaprika, Coinbase, Kraken, DefiLlama and CoinGecko;
  • Bitcoin-family data: Blockchair, BlockCypher and Haskoin;
  • Zcash data: lightwalletd nodes;
  • swaps and bridges: 0x, LI.FI, THORChain, Jupiter, NEAR Intents and other providers;
  • network-specific routes: STON.fi, Stellar network liquidity, xExchange, Vestige, Sirius and other providers;
  • fiat on-ramps and off-ramps: MoonPay, Coinbase, Ramp Network and other providers;
  • phishing-domain data: the configured upstream provider;
  • hosting and infrastructure: Cloudflare, Fly.io and other providers;
  • optional encrypted backup: Google Drive, MEGA and Backblaze B2;
  • hardware-wallet or connection services: the relevant vendor or protocol.

Third-party providers operate under their own terms and privacy policies.

If you use a third-party feature, that provider may:

  • process additional information;
  • require identity verification;
  • retain data under its own policy;
  • use its own infrastructure;
  • process information outside the EEA;
  • provide additional privacy notices;
  • use its own cookies or analytics.

Direct asset-logo requests

If the application loads asset logos directly from hosts such as raw.githubusercontent.com or assets.coingecko.com, those hosts may see the device IP address and the logos requested.

The requested logos may reveal which assets the application is displaying, although they do not directly include a wallet address or transaction amount.

If a later release moves these requests behind the Smartable proxy, this section will be updated.

7. Transfers outside the EEA

Some Smartable infrastructure and third-party providers may be located outside the European Economic Area, including in the United States.

Where required, transfers may rely on:

  • an adequacy decision;
  • the EU–US Data Privacy Framework where the provider participates;
  • Standard Contractual Clauses;
  • another lawful transfer mechanism;
  • another lawful basis permitted by applicable data-protection law.

A blockchain transaction is broadcast to a public network of nodes worldwide. This international distribution is inherent to blockchain technology and is outside Smartable’s control.

8. What is public regardless of Smartable

Blockchain addresses, balances, token holdings and confirmed transactions may be public or publicly derivable depending on the network.

Anyone may read the relevant blockchain data.

Blockchain data may be linked to an individual by third parties.

Confirmed blockchain transactions cannot be erased by Smartable or by any other wallet provider.

For privacy-sensitive use, consider:

  • using separate addresses for separate purposes;
  • using your own RPC node where supported;
  • avoiding unnecessary public address reuse;
  • reviewing the privacy policy of every provider you use.

9. Analytics and crash reporting

The application is intended to contain no advertising analytics or user-behaviour profiling.

Crash reporting is optional and off by default.

If crash reporting is enabled, it is limited to diagnosing software failures and is configured not to send:

  • private keys;
  • recovery phrases;
  • passwords;
  • wallet addresses;
  • transaction paths;
  • transaction amounts;
  • screenshots;
  • breadcrumb trails containing wallet activity.

Crash reporting may still include technical information such as:

  • exception type;
  • stack trace;
  • application version;
  • operating-system version;
  • device model;
  • device configuration;
  • crash timestamp;
  • technical diagnostics.

This website does not intentionally use advertising trackers or analytics.

If third-party content, analytics, advertising, cookies or hosted resources are introduced, this section will be updated.

10. Security and privacy limitations

Smartable may provide:

  • phishing-domain checks;
  • address validation;
  • address-poisoning detection;
  • token approval monitoring;
  • transaction simulation;
  • typed-data review;
  • device-integrity checks;
  • screen-capture protection on supported platforms;
  • biometric or PIN protection.

These features reduce certain risks but do not guarantee that:

  • a site is safe;
  • a contract is safe;
  • a token is legitimate;
  • a provider is reliable;
  • a transaction will succeed;
  • a simulation is complete;
  • a device is uncompromised;
  • a private key will never be exposed by a compromised device;
  • a blockchain transaction will produce the expected result.

A successful security check or simulation is not a guarantee of safety.

An unavailable check or simulation is not evidence that a transaction is safe or unsafe.

A rooted, jailbroken or compromised device may alter what is displayed before signing or interfere with the application.

11. Your rights

Under the GDPR, you may have rights including:

  • access;
  • rectification;
  • erasure;
  • restriction of processing;
  • data portability;
  • objection to processing based on legitimate interests;
  • withdrawal of consent where processing is based on consent.

Send privacy requests to:

hello@getsmartable.app

Please use “Privacy” in the subject line.

We aim to respond within one month and within the time required by applicable law.

These rights do not allow Smartable to erase:

  • data permanently recorded on a public blockchain;
  • data held by an independent third-party provider where Smartable has no control over it;
  • data that must be retained under applicable law;
  • data required to establish, exercise or defend legal claims.

You may also complain to the supervisory authority in your country of residence, workplace or the place of the alleged infringement.

12. Automated processing and route selection

Smartable does not use profiling or automated decision-making that produces legal or similarly significant effects on you.

The application may automatically:

  • select technical fallbacks;
  • rank available routes;
  • select a route based on technical criteria;
  • reject malformed requests;
  • apply rate limits;
  • hide unavailable data;
  • display security warnings;
  • block known phishing domains;
  • restrict unsupported networks or providers.

These are operational, technical and security controls. They are not decisions about your eligibility, creditworthiness, insurance, employment or personal profile.

Where a route is automatically ranked or selected, the application may use criteria such as:

  • expected output;
  • estimated duration;
  • availability;
  • fees;
  • liquidity;
  • technical compatibility;
  • provider response;
  • security information.

13. Children

Smartable Wallet is not directed at children under 18.

We do not knowingly collect personal data from children.

Where Article 8 GDPR applies to an information-society service based on consent, applicable age and parental-consent requirements will apply.

14. Data security

Smartable uses technical and organisational measures intended to protect data processed through its infrastructure.

These measures may include:

  • encrypted transport;
  • access controls;
  • secret separation;
  • rate limiting;
  • logging restrictions;
  • sensitive-data redaction;
  • secure storage practices;
  • provider access controls;
  • security monitoring;
  • restricted production access.

No method of transmission or storage is completely secure.

You are responsible for protecting:

  • your device;
  • your wallet password;
  • your PIN;
  • your recovery phrase;
  • your backup shares;
  • your backup passphrase;
  • your cloud accounts;
  • your hardware wallet;
  • your email and support accounts.

15. Changes to this Privacy Policy

Material changes to this Privacy Policy will be announced in the application or on the website before they take effect where practicable.

Each version will carry its own effective date.

If required by law, Smartable will request renewed consent before applying a material change to consent-based processing.

16. Contact for privacy matters

For privacy questions or requests, contact:

hello@getsmartable.app

Please use “Privacy” in the subject line.

Support will never ask for your:

  • recovery phrase;
  • private key;
  • wallet password;
  • PIN;
  • backup passphrase;
  • full split-backup shares.

Any message requesting these credentials is not authorised by Smartable, regardless of the sender address.

Legal references

[3] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, General Data Protection Regulation:
EUR-Lex

[4] European Commission Implementing Decision (EU) 2023/1795 on the EU–US Data Privacy Framework:
EUR-Lex

[5] Article 8 GDPR:
EUR-Lex

Nothing on this website constitutes investment, financial, legal, or tax advice. All information is provided for informational purposes only. Smartable Wallet is non‑custodial, self‑custody software; you are solely responsible for your own decisions and for securing your private keys. Digital assets are volatile and can lose value. Past performance is not indicative of future results. Please view our Terms of Use for more information.

© 2026 Smartable™. Self-custody means you are responsible for your own keys. Non-custodial. Your keys never leave your device.