This Privacy Policy ("Policy") describes how Trader Wallet sp. z o.o. ("Trader Wallet", "we", "our", or "us") collects, uses, discloses, stores, transfers, and protects information in connection with the Trader Wallet mobile application for iOS and Android (the "App"), our website at traderwallet.app, our primary domain, which is also reachable at trader-wallet.com (the "Site"), and the backend services that support them (together, the "Services"). It also explains the rights you have over your personal data and how to exercise them, and it includes region-specific information for the European Economic Area, the United Kingdom, California and other US states, and other jurisdictions.
Trader Wallet is a non-custodial, multi-chain, hierarchical-deterministic Web3 wallet. This means your recovery phrase and private keys are generated and stored only on your device, are never transmitted to us, and cannot be recovered by us. We have engineered the Services to process the least personal data reasonably necessary to provide the features you choose to use. Certain optional features require us and certain service providers to process limited personal data; this Policy explains exactly what, why, for how long, and with whom.
Version 4.6.0 corrects what this Policy said about the partner referral programme, and it is a correction that takes something back rather than adding something new. The previous version said that a partner sees only a shortened wallet address and an amount, and that a partner does not see a referred user’s name or trades. The App now shows a partner, for every person who joined with their code, that person’s full wallet address, their handle and avatar, the date they joined, and their cumulative trading volume and number of trades — and it shows this whether or not that person has a public profile. Section 38 now says so plainly, and says what a partner is still not shown.
Version 4.6.0 also states two things this Policy had left the reader to work out. First, the word signed-in in this document does not mean registered: the App signs every installation in anonymously, with no e-mail address and no account, and that is enough to read everything called public here. Section 8 now says it in those words. Second, the comment mechanism described in Section 9 is attached to fifteen kinds of place, not only to the seven kinds of tradable asset previously listed: a clan’s wall is the clan’s chat, a trader’s profile carries a wall of its own, and duels, clan wars, leagues, seasons and the two leaderboards each carry one.
Version 4.5.0 describes comments attached to an asset. Until now a comment could only sit under one person's trade. The App now carries a public comment wall on every tradable thing in it — a token, a perpetual futures market, a spot pair, a Hyperliquid vault, a staking or lending market, and a prediction market — and anything you write there is published under your handle, display name, avatar and league exactly as a comment under a post is. Section 9 says what is stored and who can read it, Section 10 says how it is reported and moderated, and the retention table in Section 28 says how long it lives. Reading is open to any signed-in user; writing requires a public profile. If you have never turned on a public profile, you cannot have written one, and nothing in this version applies to you.
Version 4.5.0 also states plainly what the two deletion functions do to these comments, because they do different things: deleting your public profile removes them, while deleting your account strips your name from them and leaves the text standing so that replies written by other people do not break. That is the same rule already applied to comments under posts, now written down for asset comments too.
Version 4.4.0 describes a kind of content the App did not have before: a text post you write yourself about one of your own closed trades. Every earlier version of this Policy said that posts are produced automatically and that you do not write them. That is still true of the automatic posts, and it is no longer the whole picture. Section 9 now describes both kinds, what a written post stores, who can read it, and the limits that apply to it. The numbers in a written post are still taken from the exchange record of your trade and not from anything you type.
Version 4.3.0 corrects one statement and adds three. The correction is in Section 4: an earlier version said that we never access your photos beyond QR scanning, and that stopped being accurate when the App gained the ability to set an image you choose as the background of your balance card. That image is copied into the App's storage on your device and is never uploaded, and Section 4 now says so. The additions are the photo library row in the permissions table in Section 21, a description in Section 7.9 of the session key that the web terminal creates in your browser, and the naming of Hyperliquid vaults in Section 7.4 among the on-chain features that send your public address to a third party.
Version 4.2.2 names both domains on which the Services are reachable: traderwallet.app, our primary domain, and trader-wallet.com. Nothing else changed.
Version 4.2.1 also states, in Section 12, that the service fee we charge on Hyperliquid is recorded by the exchange and is publicly visible in its record of your fills. It adds Sections 7.7, 7.8, and 7.9, which describe processing that the App already performs and that earlier versions did not describe: connecting to third-party sites over WalletConnect, the optional encrypted copy of your recovery phrase stored when you sign in with Apple or Google, and the web trading terminal. It also adds Section 29A and corrects the retention table. The previous version stated that account data is deleted when you delete your account; that was not accurate, and Section 29A now lists what remains and how to have it erased.
Version 4.1.1 removes every reference to contests and prizes from Section 37, because there are no contests and no prizes, and brings Section 38 into line with the partner referral programme as it now operates.
Version 4.1.0 added Sections 37 and 38, which describe the data processed by the demo trading mode and by the partner referral programme.
Version 4.0.0 is a substantial revision. The previous version was written before the App contained a public trader profile, a trade feed, comments, likes, followers, clans, duels, and clan wars. Those features publish information about you to other people, and Sections 6 and 8 to 12 describe them in detail. If you have used the App only as a wallet and have never turned on a public profile, none of the processing in Sections 8 to 12 applies to you.
Please read this Policy together with our Terms of Service, which contain the rules that govern what you may publish, how content is moderated, and how you can contest a moderation decision. By downloading, accessing, or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Services.
To make this Policy easier to follow, the following terms have the meanings set out below.
The controller responsible for your personal data is Trader Wallet sp. z o.o., a limited-liability company registered in Poland (KRS 0001218226) with its registered office at ul. Złota 2-19, 15-016 Białystok, Poland. As we are established in the European Union, we are not required to appoint an Article 27 GDPR representative; for all privacy matters you may contact us directly using the details in Section 37.
This Policy applies to all users of the Services worldwide, on both iOS and Android, and to visitors of the Site. It covers all processing carried out by the App, the Site, and our backend, as well as the limited data shared with the third-party providers and blockchain networks needed to deliver the features you use. It does not apply to third-party websites, wallets, protocols, or services that we do not operate, which are governed by their own privacy policies (see Section 34).
Where the App hosts content published by users, we act as the provider of a hosting service within the meaning of Regulation (EU) 2022/2065 (the Digital Services Act). The obligations that follow from that role, including our point of contact, our notice-and-action mechanism, and the reasons we give for moderation decisions, are set out in our Terms of Service.
We designed the Services around a small set of principles, consistent with the data-protection concepts of privacy by design and by default:
Because Trader Wallet is self-custodial, the most sensitive information stays on your device. The following is never transmitted to us, our backend, or any third party, in any form:
Your recovery phrase (seed phrase / mnemonic) also stays on your device and is never sent to us in readable form. There is one exception, and it happens only if you choose it: if you create an encrypted cloud backup, an encrypted copy of your recovery phrase is stored on our backend. Section 4.1 describes exactly what that is and what we can and cannot do with it.
These are generated on your device and stored encrypted in the platform secure store (Android Keystore or iOS Keychain). We cannot read them, cannot move your funds, and cannot recover them if you lose them. We also do not collect government identification documents, and we do not perform identity verification ("KYC"). We do not collect biometric identifiers: biometric unlock is handled entirely by your device operating system and is never shared with us. We do not process payment-card or bank-account details; any in-app service fees are collected on-chain in cryptocurrency at the moment of a transaction, as described in our Terms of Service.
Publishing a public profile requires you to sign a one-time challenge message with your private key so that we can prove the address belongs to you. The signature is verified on our backend and the key itself never leaves your device; we store only the resulting binding between your address and your account identifier.
There is no "forgot password" for your recovery phrase and no way for us to restore it. If you lose your recovery phrase and lose access to your device, your funds are permanently lost. Always back up your recovery phrase offline and keep it private.
If you create a wallet by signing in with Apple or Google, or if you turn the backup feature on later, the App offers to store an encrypted copy of your recovery phrase on our backend so that you can restore your wallet on a new device. This is optional. If you do not use it, nothing about your recovery phrase ever leaves your device.
When you do use it, this is exactly what happens and exactly what we hold:
We cannot read it, and neither can our hosting provider. Decryption is possible only on a device where your backup password is entered. If you forget that password, the backup cannot be opened by anyone, including us: there is no recovery path and no override.
The backup is tied to the account you signed in with. If you delete your account, the backup is deleted with it and cannot be recovered. Before deleting an account the App requires you to open and save your recovery phrase, precisely so that deleting an account cannot cost you access to your funds. See Section 29.
To function, the App generates and caches certain data locally, inside the App's isolated storage. This data is not uploaded to us:
Uninstalling the App, clearing its data in your device settings, or performing a factory reset permanently deletes this local data. It does not delete anything you have already published: published data lives in our database and is removed only through the deletion function described in Section 29. If you have not backed up your recovery phrase beforehand, you will also lose access to your funds.
We treat blockchain wallet addresses processed through the public-profile and social features as personal data within the meaning of Article 4(1) GDPR, and we say so plainly rather than relying on the argument that an address is "just a number". This position follows the approach of the European Data Protection Board in its Guidelines 02/2025 on the processing of personal data through blockchain technologies: a public key or account address is personal data where the person behind it can be identified by means reasonably likely to be used.
In our case that linkability is not hypothetical, it is built into the product. Your public profile is stored in our database under your Ethereum-format address as the record key, and attached to that key are a unique handle, an optional display name, a biography, a status emoji, spoken languages, social links, an avatar, a league, a clan membership, and your complete published trading record. Anyone who knows the handle knows the address, and anyone who knows the address can read the profile. Where you additionally choose to publish your Bitcoin, Tron, or Solana addresses, those become linked to the same identity too.
Your profile record also carries an account identifier that ties the address to the account your installation of the App uses. Because that record is readable by other signed-in users of the App, two public addresses carrying the same identifier can be recognised as belonging to the same person. If you maintain more than one public profile and do not want them to be connectable, be aware of this before publishing a second one. We are documenting this openly rather than describing an ideal state; see also Section 28 for the controls available to you.
The consequence of treating addresses as personal data is that the rights in Section 30 apply to them: you can ask us what we hold under an address, ask us to correct it, and ask us to erase it. What we cannot do is erase anything from the blockchain itself, for the reasons in Section 24.
The features in this section are optional. If you choose to use them, the personal data described is processed by us and/or by the service providers listed in Section 22. Each subsection states what data is involved, why, and where it goes. The social features are large enough to warrant their own sections and are described in Sections 8 to 12.
You can use the wallet in Guest mode without an account. If you sign in, we use Firebase Authentication (Google) to authenticate you. Depending on the sign-in method, we process your email address (email sign-in), your Google or Apple account identifier and any display name you provide (social sign-in), and a Firebase user ID that identifies your account within our systems. Some features use an anonymous account tied to the installation rather than to an email address. We use this only to authenticate you and to associate optional features (such as saved AI chat history, or ownership of a published address) with your account. Signing in is not required to hold, send, receive, swap, or trade assets.
If you use the in-app AI assistant ("Grünwald"), the messages you send, and any voice input or images you submit for analysis, are transmitted through our backend to our AI provider, Anthropic, which generates the responses. If you are signed in, your chat history may be stored so the assistant can maintain context across sessions; you can delete it. Voice input is converted to text using your device's speech-recognition capability while you are actively using that feature.
Never enter your recovery phrase, private keys, or passwords into the AI assistant or anywhere else. No legitimate feature of Trader Wallet will ever ask for your recovery phrase.
If you enable notifications, we use Firebase Cloud Messaging and the Apple Push Notification service, which involves a device push token, to deliver alerts such as price, transaction, trading, and social notifications. Section 11 describes how push tokens are stored and how long they are kept.
When you use in-app token swaps, cross-chain bridges, staking, lending, deposits into and withdrawals from Hyperliquid vaults, perpetual-futures trading, prediction markets, or tokenized-asset features, the relevant public wallet address, token pair, network, and amount are sent to the third-party providers that source quotes and route or execute those actions (for example 0x, Jupiter, LI.FI, and Hyperliquid) and to blockchain RPC providers. As with any internet request, these providers can also observe your IP address and the addresses you query. We charge on-chain service fees for some of these features, as detailed in our Terms of Service. On Hyperliquid the fee we charge is recorded by the exchange itself and is publicly visible in its record of your fills, next to the exchange’s own fees. Your private keys are never shared; transactions are signed on your device.
Our backend runs on Vercel. When your device contacts our backend (to fetch prices, obtain a swap quote, proxy a blockchain RPC request, reach the AI assistant, or perform any social action), standard technical data is processed as part of the internet request, including your IP address, request timestamps, the endpoint called, and a user-agent string describing your app version and device type. We keep operational logs to the minimum needed for security, abuse prevention, and reliability, and we do not use them to build advertising or behavioral profiles.
If you email us or otherwise contact us, including to report content, to ask why a moderation decision was taken, or to contest one, we process your contact details and the content of your message to respond and to keep a reasonable record of the request.
The App can connect to third-party websites and applications using the WalletConnect protocol. When you scan a connection code or open a connection link, the App opens an encrypted WebSocket session with a WalletConnect relay operated by WalletConnect, Inc. (relay.walletconnect.org, with relay.walletconnect.com as a fallback). The relay carries the messages between your device and the connected site.
Approving a connection discloses to the connected site the wallet addresses and networks you select in the approval screen, and nothing else. Each subsequent request from that site — to sign a message or a transaction — is shown to you and is sent onward only if you approve it. Signing happens on your device; your recovery phrase and private keys are not transmitted to the relay, to us, or to the site.
The relay operator can observe the technical metadata of the session, including your IP address, the timing and size of messages, and the identifier of the session. Message contents are end-to-end encrypted between your device and the connected site, so the relay cannot read them. We do not receive the contents of these sessions and do not store a record of the sites you connect to.
What a connected site does with your address is governed by that site's own privacy policy, not by ours. You can end a session at any time from the connections screen in the App; ending it stops further requests from reaching you.
The App can create a wallet for you without showing you a recovery phrase to write down. If you choose that route, you sign in with Apple or Google, set a separate backup password, and the App stores an encrypted copy of your recovery phrase on our backend so that you can restore the wallet on another device.
The encryption happens on your device before anything is sent. A key is derived from your backup password using Argon2id; that key wraps a randomly generated data key; the data key encrypts the recovery phrase. Only the wrapped key, the encrypted phrase, the key-derivation parameters, and the creation and update timestamps are stored. Your backup password is never transmitted to us in any form — not the password, not a hash of it, and not a verification value. We cannot decrypt the stored copy, and neither can Google, whose Firestore service holds it. If you forget the backup password, the copy cannot be recovered by anyone, including us.
The stored record contains nothing that identifies the wallet: no address, no hash of an address, no list of networks, no handle. It is stored under your account identifier and can only be read by a device signed in to that account.
This feature is optional and applies only to accounts signed in with Apple or Google. A Guest account does not store a copy, because a Guest identifier does not survive reinstalling the App and a copy stored under it could never be restored. You can delete the stored copy at any time from the backup screen in Settings.
The copy is readable only by the account it was created under. If you delete your account, the copy remains in our database but becomes permanently unreachable, by you and by us alike. Export your recovery phrase before deleting your account. The App states this before you confirm deletion.
We operate a web trading terminal at traderwallet.app, our primary domain, which is also reachable at trader-wallet.com. The terminal does not hold keys. You connect a wallet to it over WalletConnect, exactly as you would connect any other site, and Section 7.7 describes what that involves. Requests to sign are approved in your wallet, on your device.
As with the App backend, standard technical data is processed when your browser contacts the terminal and the services behind it, including your IP address, request timestamps, and a user-agent string. The terminal does not carry the social features described in Sections 8 to 12.
The session key the terminal creates in your browser. Hyperliquid signs trading actions with a domain that no wallet can display meaningfully, so the exchange's own interface and every web terminal, including ours, trade with a separate key called an agent. When you activate trading in the terminal, your browser generates that key, you approve it once with a signature from your wallet, and the key is stored in your browser's sessionStorage under the address it belongs to. Three things follow, and each of them is a deliberate limit rather than a side effect. The key never reaches us or any server: it is created in your browser and stays there. It dies with the browser tab, because sessionStorage is cleared when the tab closes, so a shared or public computer keeps nothing after you leave. And it cannot move money: transfers between your spot and perpetual balances, deposits, and withdrawals are signed by your wallet, and the terminal refuses to sign them with the agent key even if asked to. If your browser blocks site storage, for example in a private window with storage disabled, the terminal says so and trading stays unavailable rather than failing silently.
The public profile is off by default. Nothing described in this section or in Sections 9 to 12 happens until you turn it on in Settings, claim a handle, and sign the ownership challenge with your wallet. Turning it on is the act by which you make the information below public; turning it off again stops your profile and your published trades from being shown, and Section 29 describes how to erase them entirely.
When your profile is public, our backend reads your trading record from Hyperliquid and stores a copy of it in our database, where it is readable by any signed-in user of the App. What becomes readable is:
Your addresses on Bitcoin, Tron, and Solana are published only if you switch that on separately, network by network. Your Ethereum-format address is your public identity on the leaderboard either way and cannot be hidden while the profile is public.
Throughout this Policy, signed-in does not mean registered. The App signs every installation in to Firebase automatically and anonymously, with no e-mail address, no password and no account of any kind, and that anonymous sign-in is enough to read everything this section and Sections 9 to 12 call public. In practice this means: anyone who installs the App, and anyone who can obtain the same public identifiers the App ships with, can read your public profile, your published trades, your statistics, your league and your comments. There is no approval step, no follower gate, and nothing you can set that limits it to a chosen group. If you would not put it on a public website, do not publish it here.
Please consider carefully what this means before you switch it on. Publishing your trading record links a permanent, publicly readable blockchain address to a name, a biography, and a complete record of how much you trade, how often you win, and how much you have made or lost. That combination is far more identifying than any of its parts. Section 24 explains why the on-chain half of it can never be undone.
Automatic posts are created without you. While your profile is public, our backend periodically examines your closed trades and turns them into posts in the trade feed without any further action on your part. A post carries your handle, display name, avatar, and league; the instrument, direction, execution price, size, notional value, realized profit and loss, fee, and timestamp of the trade; the transaction hash, order identifier and trade identifier of that trade; and a snapshot of the market at the moment the position closed, stored as candle data so that the App can draw the chart. Settlements of prediction markets are not treated as trades and do not become posts.
A post is visible to every signed-in user of the App, not only to your followers. The feed screen shows the traders you follow, but a post can also be reached from your profile or from a direct link, and the underlying access rule is "any signed-in user, provided the post is not hidden". Treat everything in a post as public.
A written post is one you compose yourself. If your profile is public, the App lets you pick one of your own closed trades, write text about it, and publish it. What is stored is the text you wrote, the same author details a comment carries (handle, display name, avatar, league), and the figures of the trade you picked. The figures are read by our backend from the exchange record of that trade and never from anything you type, so a written post cannot state a result that did not happen. A written post is visible to every signed-in user on the same terms as an automatic one, can be liked and commented on in the same way, and is deleted by the same profile-deletion and account-deletion functions. Publishing one does not remove or alter the automatic post about the same trade.
Under each post, other users may leave comments and likes, and you may do the same under theirs. A comment stores its text together with your handle, display name, avatar, and league, and is visible to every signed-in user. Replies are supported one level deep. The list of people who liked a post or a comment is readable by any signed-in user. Your own likes are additionally recorded in a private per-user document so the App can show you what you have already liked without re-reading every post; that document is readable only by you.
A comment can also be attached to an asset instead of to a post. Every tradable thing in the App — a token, a perpetual futures market, a spot pair, a Hyperliquid vault, a staking or lending market, and a prediction market — carries a public comment wall. What is stored is identical to a comment under a post: the text, your handle, display name, avatar and league, and the moment it was written, plus an identifier of the asset the wall belongs to. It is readable by every signed-in user who opens that asset. Reading a wall requires only that you are signed in; writing on one requires a public profile, which means an asset comment always carries a name you chose to publish. Replies go one level deep, likes work the same way, and the same private per-user document records which ones you liked.
Comment walls are not limited to tradable things. The same comment mechanism, storing exactly the same data, is attached to fifteen kinds of place in the App. Besides the seven kinds of asset named above, a wall exists on a clan, on a trader’s profile, on a duel, on a clan war, on a league, on a season, and on each of the two leaderboards, the all-time one and the seasonal one. Two of these carry an extra rule. A clan’s wall is the clan’s chat: its leader can restrict writing to members of that clan, and when they do, everyone can still read it. A trader’s profile wall belongs to that trader, who can switch comments on their own profile off; the owner of a wall can always write on it. Everything else is the same everywhere: the text, your handle, display name, avatar and league, the moment it was written, and an identifier of the place the wall belongs to, readable by every signed-in user who opens it.
A comment wall is public, not private. It is not a direct-message feature and there is no way to send a message to one person through it. Nothing you write there is confidential, and it can be read by anyone with the App, including people you have not met and search engines if we ever publish the walls on the Site. We recommend that you write nothing on one that you would not put on a public forum.
Two limits shape what is stored. Comments are capped at 500 characters, at 10 per hour per address counted across posts and asset walls together, and at 3 consecutive comments in the same place. A written post is capped at 5000 characters, at 10 written posts per day per address, and at one written post per trade. And links are removed before storage: any web address in a comment, and also in a display name, a biography, a clan name, or a clan biography, is stripped out before the text is written to our database, because links in a crypto application are the primary vector for fraud. The App tells you when your text was changed by this filter. The stripped text, not the text you typed, is what is stored and shown.
You may follow other public traders and be followed by them. Follower and following lists are visible on public profiles. You may block another user, which removes them from your view of search results and lists; blocking is described further in Section 28 and in our Terms of Service.
The App contains competitive features that publish additional information about you.
A clan is a group of public traders. Its name, emblem, biography, social links, leader, member count, aggregate statistics, and score are readable by any signed-in user, as is its member roster and its history. Your membership of a clan is shown on your profile. Clan invitations and join requests are readable only by the people they concern.
A duel is a head-to-head contest between two public traders over a chosen instrument pool and period. Its record stores both participants' addresses, the pool, the window, the resulting statistics for each side, and the outcome. A duel record is readable by its two participants; the outcome is reflected in the trader points shown on your public profile.
A clan war is the same contest between two clans. The record stores the two clans, the rosters frozen at the moment the war started, the window, the per-side statistics, and the outcome, and is readable by any signed-in user.
Results of duels and wars are delivered to the participants through the in-app inbox described in Section 11, and points awarded from them are written to the public profiles of the people who took part.
Social activity that concerns you produces an entry in an in-app inbox held on our servers under your address. Inbox entries cover likes and comments on your trades, replies to your comments, clan invitations and requests, duel challenges, acceptances, declines and results, and clan-war challenges and results. An entry records the type of event, the address and handle of the person who caused it, the post or contest it refers to, whether you have read it, and when it was created. The inbox is readable only by you.
If you have enabled notifications, the same events may also produce a push notification. To route it, we store your device push token in a separate record keyed by your address, together with the platform, your language, and the timestamp of registration. We keep at most five device tokens per address, newest first, and the oldest is dropped when a sixth device registers. A token is also stored in a reverse lookup so that a device which changes wallet stops receiving notifications for the previous one, and a token that the messaging provider reports as dead is removed. Neither record is readable by any user, including you; both are written and read only by our backend. You can turn notifications off at any time in your device settings or in the App's notification preferences, which stops the sending, and you can ask us to delete the stored tokens under Section 30.
The profile-deletion function described in Section 29 erases your profile, posts of both kinds including the text of any post you wrote, comments under posts, your comments on asset walls, likes, followers, blocks, consent record, stored push tokens and the contents of your in-app inbox. An earlier version of this Policy said the push tokens and inbox were not erased; that was accurate when it was written and is no longer the case.
Account deletion treats those comments differently, and deliberately. Deleting your account strips your address, handle, display name, avatar and league from every comment you left — under a post and on an asset wall alike — and leaves the text where it stands, marked as written by a deleted author. Removing the text itself would break the replies other people wrote underneath it. Deleting your profile, by contrast, removes your comments outright: there you are asking to stop being published, not asking to disappear from the service.
Any signed-in user can report a post, a comment under a post, or a comment on an asset wall. All three go into one moderation queue and are decided by the same process; there is no second queue that nobody reads. A report stores the reason chosen from a fixed list (spam, abuse or harassment, fraud or scam, sexual content, violence, or something else), any free-text detail you add, the address of the person reporting, the address of the person reported, the identifiers of the reported content, and, for a reported comment, a copy of its text. Reports are readable only by us and are used solely to moderate content. One report per person per item is counted, and a single address may file at most 20 reports in a day.
Content that accumulates reports from 8 different accounts is hidden automatically, pending review by a person. Hiding is a precaution and is not a finding against the author. When we review a report we may dismiss it, which restores the content and clears its report count; remove the content; or remove the content and suspend the author's right to publish. A suspension is recorded on the author's profile with its timestamp, hides that author's existing posts and their comments on asset walls, and prevents them from publishing, commenting, following, renaming themselves, or reporting others; it does not prevent them from reading. Section 18 explains how this interacts with your rights over automated decisions, and our Terms of Service explain how to obtain the reasons for a decision and how to contest it.
Before you can publish a comment, you must accept the publishing rules shown in the App. We record that acceptance on our servers, under your address, as a timestamp and a version number of the rules text. We keep this record because two application stores and the Digital Services Act require us to be able to show that the person who published content had agreed to rules prohibiting offensive content and abusive behaviour. Only the first acceptance is stored, so the recorded date remains the true one. This record is deleted when you delete your public profile.
The table below summarizes the categories of personal data we may process, whether we collect them, and why. We do not sell or share any of these categories for cross-context behavioral advertising, and we do not process special categories of personal data.
| Category | Collected? | Examples & purpose |
|---|---|---|
| Identifiers | Yes, if you use optional features | Email, Google/Apple ID, Firebase user ID, device push token, IP address — used for sign-in, notifications, and backend requests |
| Wallet addresses | Yes, if you publish a profile | Your Ethereum-format address as the key of your public profile, and any other-chain addresses you choose to publish — treated as personal data (Section 6) |
| Profile information | Only if you publish a profile | Handle, display name, biography, status emoji, languages, social links, avatar, league, clan |
| Trading and financial activity | Only if you publish a profile | Volume, profit and loss, win rate, ROI, trade count, individual trades with transaction hashes, open positions and orders — published to other users |
| User content | Yes, if you comment, write a post, or use the assistant | Comments and replies you write; the text of any post you write about your own trade; messages and images you submit to the AI assistant |
| Social graph | Only if you publish a profile | Who you follow, who follows you, clan membership, duel and war participation, likes you have given |
| Moderation data | Yes, if you report or are reported | Reports you file or receive, report counts, hidden flags, suspension status, record of accepting the publishing rules |
| Internet / network activity | Yes (minimal) | Backend request logs, app version, endpoint accessed — used for security and reliability |
| Approximate location | Inferred only | Coarse location may be inferred from your IP address; we do not collect GPS or precise location |
| Audio | Only when you use voice input | Voice input to the AI assistant, converted to text; not stored as audio by us |
| Special categories of data | No | We do not collect government IDs, biometrics, health, religion, precise location, or similar data |
| Marketing inferences / profiles | No | We do not build behavioral profiles for advertising and do not make marketing inferences about you |
We obtain personal data from the following sources:
We use personal data only for the following purposes:
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Providing core wallet functionality you request | Performance of a contract (Art. 6(1)(b)) |
| Account sign-in, AI assistant, push notifications | Consent (Art. 6(1)(a)), withdrawable at any time |
| Publishing your public profile, trading statistics, trades, positions and orders, and the automatic posts derived from them | Consent (Art. 6(1)(a)), given by turning the public profile on and withdrawable by turning it off or deleting the profile |
| Publishing your other-chain wallet addresses | Consent (Art. 6(1)(a)), given per network and withdrawable per network |
| Comments, likes, replies, posts you write about your own trades, follows, clans, duels, wars and the in-app inbox that serves them | Performance of a contract (Art. 6(1)(b)) — delivering the feature you asked for |
| Rate limits, link stripping, report handling, hiding content, and suspending the right to publish | Legitimate interests (Art. 6(1)(f)) in a safe and lawful service, and legal obligation (Art. 6(1)(c)) under the Digital Services Act |
| Storing the record that you accepted the publishing rules | Legitimate interests (Art. 6(1)(f)) in being able to demonstrate consent to the rules, and compliance with application-store requirements |
| Security, fraud and abuse prevention, reliability | Legitimate interests (Art. 6(1)(f)) |
| Responding to your enquiries, including complaints about moderation | Legitimate interests, or steps prior to a contract |
| Complying with legal obligations that apply to us | Legal obligation (Art. 6(1)(c)) |
| Establishing, exercising, or defending legal claims | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms. Where we rely on consent, you can withdraw it at any time (for example by signing out, disabling a feature, turning off the public profile, or deleting it); withdrawal does not affect processing that took place before it, and it cannot reach data that has already been recorded on a public blockchain.
We do not run advertising and we do not sell your data to marketers. We may send you service-related (transactional) messages that are necessary to operate the Services, such as security notices, moderation decisions, or important changes to these documents. If we ever offer an optional newsletter or promotional messages, they will be strictly opt-in and you will be able to unsubscribe at any time. We do not need your consent to send essential service messages, but we will not use your contact details for marketing without a lawful basis.
We do not build marketing or behavioral profiles, and we do not carry out automated decision-making that produces legal effects concerning you within the meaning of Article 22 GDPR. The AI assistant generates responses automatically, but it does not make decisions about you or your access to the Services; it is an informational tool only.
Two forms of automated processing do affect what is shown, and we describe them rather than leave them implicit. First, your published statistics, trader points, league, and season score are computed automatically from your trading record; they determine your position on the leaderboard and in the league structure, and they are visible to others. Second, content that is reported by 8 different accounts is hidden automatically, without a person having looked at it first, as described in Section 12. Automatic hiding is temporary and precautionary, is reversible, and is followed by human review; a suspension of the right to publish is never automatic and is always applied by a person. Our Terms of Service set out how to obtain the reasons for either measure and how to contest it, and you may in any case ask us to review a decision by writing to contact@trader-wallet.com.
To be unambiguous about our practices, we do not:
The App requests only the permissions needed for specific features. You can grant or revoke optional permissions at any time in your device settings.
| Permission | Why it is used | Optional? |
|---|---|---|
| Camera | Scanning QR codes containing wallet addresses. No images are captured, saved, or uploaded. | Yes |
| Microphone / speech recognition | Voice input for the AI assistant, used only while you are actively using voice input. | Yes |
| Photo library | Choosing one image as the background of your balance card. The image is copied into the App's storage on your device and is never uploaded. The App reads nothing else from your library. | Yes |
| Notifications | Delivering the push notifications you opt into, including social notifications. | Yes |
| Internet / network | Communicating with blockchains, providers, and our backend. Essential for the App to function. | Required |
We share the limited data described in this Policy only with the providers needed to deliver the features you use, and only to the extent necessary. Each provider operates under its own privacy policy and its own security and retention practices, which we do not control. This list may change as the App evolves; we keep it current and update the effective date when we make material changes.
| Provider | What it does | Data it may receive | Privacy policy |
|---|---|---|---|
| Google / Firebase | Sign-in (Authentication), database (Cloud Firestore) and push messaging (Cloud Messaging) | Email or account identifier, Firebase user ID, device push token, IP address, and all public-profile, feed, comment, clan and moderation data stored in our database | firebase.google.com/support/privacy |
| Anthropic | Generates AI-assistant responses | Your AI messages, voice-to-text input, and any images you submit | anthropic.com/legal/privacy |
| Vercel | Hosts our backend and website | IP address, request metadata, wallet addresses queried | vercel.com/legal/privacy-policy |
| Apple | Push notification delivery on iOS | Device push token and notification payload | apple.com/legal/privacy |
| CoinGecko | Prices, charts, and token icons | IP address, the assets you request | coingecko.com/en/privacy |
| 0x, Jupiter, LI.FI | Swap and cross-chain bridge quotes and routing | Wallet address, token pair, amount, IP address | See each provider's website |
| Hyperliquid | Perpetual futures and prediction markets; also the source from which we read the trading record of a published address | Wallet address, order data, IP address | See provider's website |
| RPC providers (e.g. Helius, TronGrid, public nodes) | Reading balances and broadcasting transactions | Wallet address, transaction data, IP address | See each provider's website |
| Blockchain explorers | Optional external links to view transactions | Whatever the linked page collects when you visit it | See each explorer's website |
| RevenueCat | Processes and validates in-app subscription purchases | Anonymous purchase identifier, store receipt data, platform and app version | revenuecat.com/privacy |
| Moralis | Reads NFT and token metadata for the addresses you view | Wallet address, network, IP address | moralis.io/privacy-policy |
| Third-party crypto purchase services | Buying cryptocurrency. These are independent services we are not partnered with; you leave the App to use them | Whatever that service collects from you directly. We do not receive it | See each service's website |
Other users of the App are not sub-processors: what you publish is disclosed to them because you chose to publish it, and once it has been seen, copied, or screenshotted by another person we cannot retrieve it.
We may also disclose personal data where required to comply with a valid legal obligation, including an order from a national authority under Article 10 of the Digital Services Act, to protect our rights or the safety of users, or in connection with a corporate transaction (such as a merger or asset transfer), in which case we will require the recipient to honor this Policy.
We may create aggregated or anonymized data that does not identify you (for example, the total number of installations or the number of transactions of a given type). Once data is truly anonymized, it is no longer personal data, and we may use and disclose it for any lawful purpose, including operating and improving the Services.
When you send, receive, swap, bridge, stake, lend, or trade on public blockchains, your wallet addresses, transaction amounts, timestamps, and counterpart addresses become part of a permanent, public ledger that anyone can view using a blockchain explorer. This information cannot be deleted, altered, or hidden, and it is outside our control. This is a fundamental property of public blockchains, not a feature of Trader Wallet.
Cryptocurrency addresses are pseudonymous, not anonymous. Your legal identity is not published on-chain, but if an address is ever linked to you, your associated on-chain activity can be traced back to you. Publishing a public profile in this App is precisely such a link: it ties your handle, your name, and your biography to an address whose entire history is permanently readable by anyone, and the posts in the feed carry the transaction hashes that make each trade findable on-chain. Deleting your profile removes our copy; it does not and cannot remove the underlying chain records or any copy a third party has already taken. Consider this before you publish, and consider using a separate address for anything you do not want associated with your public identity.
Some of our providers process data outside your country, including in the United States. Where personal data of users in the European Economic Area, the United Kingdom, or Switzerland is transferred internationally, that transfer is protected by an appropriate safeguard, such as the European Commission's Standard Contractual Clauses adopted by the relevant provider, or is necessary to perform the service you requested under Article 49(1)(b) GDPR. You may contact us for more information about the safeguards that apply. Content you publish is, by its nature, readable by users of the App anywhere in the world.
We keep personal data only for as long as needed for the purpose it was collected, then delete it or anonymize it. Specific retention criteria are set out below.
| Category | Retention |
|---|---|
| On-device data (keys, caches, settings) | Until you delete it or uninstall the App; controlled entirely by you |
| Account data (if you sign in) | Deleting your account in the App removes the authentication record itself. It does not currently remove the data stored under your account identifier; Section 29A states exactly what remains and how to have it erased |
| AI chat history (if signed in) | Until you delete the history. Deleting your account does not currently delete it (Section 29A); ask us and we will erase it |
| Public profile, statistics, mirrored trades, positions and orders | While your public profile exists; erased when you delete it (Section 29). Each refresh mirrors up to your 200 most recent executions and overwrites your positions and orders in full |
| Feed posts | Posts older than 90 days are removed in a maintenance pass. A post that carries comments is kept, because a conversation cannot be reconstructed, but its chart snapshot is deleted. All of your posts are erased when you delete your profile, whatever their age |
| Comments, replies and likes | Until you delete them, until the post they belong to is removed, or until you delete your profile. A comment you delete is marked hidden and stops being readable |
| Comments on an asset wall | Until you delete them, or until you delete your public profile. They are not removed by the 90-day pass that prunes posts: an asset wall is not tied to a trade and has no age at which it stops being relevant. Deleting your account does not remove them; it removes your name from them |
| Followers, following, clan membership, duels, wars | While your profile exists. Deleting your profile removes your follower and following lists, takes you out of your clan, voids your pending and active duels, and strikes you from the frozen rosters of active wars |
| Record of accepting the publishing rules | While your public profile exists; deleted with it |
| Reports and moderation records | Kept for as long as needed to moderate, to enforce our Terms of Service, and to establish, exercise, or defend legal claims. There is no automatic deletion of a report |
| In-app inbox entries | Kept until you ask us to delete them. They are not removed automatically and are not removed by profile deletion (Section 11) |
| Push tokens | Up to five per address, oldest evicted; a token is removed when it moves to another wallet, when the messaging provider reports it as dead, or on request. Not removed by profile deletion (Section 11) |
| Backend operational logs | Kept only for a short period for security and reliability, then deleted or anonymized |
| Support correspondence | For as long as needed to handle the matter and keep a reasonable record |
| Blockchain records | Permanent and public; not controlled by us |
Where we are required to retain certain data to comply with a legal obligation or to establish, exercise, or defend legal claims, we will retain it for the period required for that purpose.
We take reasonable and appropriate technical and organizational measures to protect personal data, including:
No method of transmission or storage is perfectly secure. If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and affected users where required by law, and we will take steps to mitigate the breach. You play an essential role in security: keep your device updated and protected, use a strong device lock, never share your recovery phrase, be alert to phishing, and avoid using the App on a jailbroken or rooted device.
You have direct, practical control over most processing:
The App contains a deletion function that erases the public footprint of an address. It is intended to give effect to your right to erasure under Article 17 GDPR for the data you have published, and it runs in stages because there may be thousands of documents to remove.
Deletion removes: your posts, together with the comments and likes underneath them; every comment you wrote under other people's posts, with their comment counts corrected; every like you gave anywhere, with the counts corrected; your mirrored trades, positions, and orders; your follower and following lists; your blocked-users list; the private records of what you liked and of your acceptance of the publishing rules; your rate-limit counters; your profile document itself; your claim on your handle, which becomes available to others again; and the binding between your address and your account. Your pending and active duels are voided rather than awarded to your opponent, you are removed from your clan (with leadership handed on, or the clan dissolved if you were its last member), and you are struck from the frozen rosters of any active clan war.
Deletion does remove your stored device push tokens and your in-app inbox entries; an earlier version of this Policy said otherwise, and that is no longer the case. It does not remove reports filed about your content, which we keep as a moderation record. It does not remove anything recorded on a public blockchain, which we cannot reach. And it does not remove copies that other users have already taken, or content already cached or indexed elsewhere.
Where an address has published an unusually large history, some mirrored records may remain in our database after the profile document itself has gone. They are no longer reachable by any user, because the access rules for them depend on a profile that no longer exists. Tell us if you want them removed as well and we will do it.
Deletion is irreversible, and it costs you your trader points and your league standing for good. The App says so before you confirm.
Deleting your account is a different action from deleting your public profile. Section 29 describes profile deletion. This subsection describes account deletion, and states plainly what it does and does not do today.
Account deletion re-authenticates you, erases the data held under your account identifier and under your wallet addresses, revokes our access token where the sign-in provider requires it, deletes the authentication record held by Firebase Authentication, and returns the App to a Guest session. Your wallet is unaffected: keys live on your device and are not part of the account.
The following are erased:
Three things are treated differently, and we say so plainly. Comments you left on other people’s posts are anonymised rather than deleted: everything identifying you is removed and the comment is marked as written by a deleted account, so that other people’s conversations do not fall apart around it. The device fingerprint recorded to limit abuse of one-per-device offers is retained, but your account identifier is erased from it, leaving an anonymous marker that no longer points at you or at any person.
The third is a record that one-time rewards have already been given to a wallet address. When a reward that can be claimed only once is granted, for example the month of Grünwald Max that comes with joining through a partner code, we write the address and the name of the reward into a register, and that register survives account deletion. Everything else that could show the reward had been given is erased along with the account, so without this register the same wallet could delete its account and claim the same one-time reward again, without limit. The register holds a wallet address and a list of reward names. It holds no account identifier, no handle, no name, no amount, and nothing that describes what you did in the App, and we use it for nothing except refusing a second grant of the same reward.
An unfinished duel is voided and no points are awarded to either side. If you were the only leader of a clan, leadership passes to the longest-standing remaining member; if you were its last member, the clan is dissolved.
Earlier versions of this Policy stated that account deletion did not erase this data, and at the time that was accurate. It changed in the version of the App released with this Policy update, and this section changed with it. If you deleted an account before that release and want the older records erased, email contact@trader-wallet.com and we will erase them by hand.
A standalone page describing how to delete your account, including how to do it if you no longer have the App installed, is published at traderwallet.app/delete-account.
If the GDPR applies to you, you have the right to:
Many of these you can exercise yourself in the App, using the controls in Section 28 and the deletion function in Section 29, which is usually faster than writing to us. For anything else, email contact@trader-wallet.com. To protect your data, we may need to verify your identity before acting on a request, for example by confirming control of the email address associated with your account or by asking you to sign a challenge message with the wallet address the request concerns. We will respond within the timeframes required by law (generally within one month, extendable for complex requests). Exercising your rights is free unless a request is manifestly unfounded or excessive.
Two limits are worth stating plainly. We cannot erase or rectify data recorded on a public blockchain, for the reasons in Section 24. And where content you published has already been seen or copied by other users, erasure from our database cannot reach those copies.
You also have the right to lodge a complaint with your local data-protection authority; in Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw.
If you are a California resident, the California Consumer Privacy Act, as amended, gives you rights over your personal information. This section serves as our notice at collection and describes those rights.
Categories collected. As set out in Section 13, we may collect identifiers, wallet addresses, profile information, trading and financial activity, user content, social-graph and moderation data, internet/network activity, coarse location inferred from IP, and audio (voice input). We do not collect sensitive personal information as defined by the CPRA.
No sale or sharing. We do not sell your personal information and do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. Accordingly, no "Do Not Sell or Share My Personal Information" action is necessary. Information you publish through the public profile and the feed is disclosed to other users because you chose to publish it, not because we sold it.
Purposes and disclosures. We use personal information for the business purposes in Section 15, and disclose it only to the service providers in Section 22, who are contractually limited to processing it on our behalf.
Your rights. You have the right to know, access, correct, and delete your personal information, and to not receive discriminatory treatment for exercising these rights. We do not offer financial incentives in exchange for personal information. To exercise your rights, email contact@trader-wallet.com; you may use an authorized agent, and we may verify your identity and the agent's authority.
If you are a resident of another US state with a comprehensive consumer-privacy law (such as Virginia, Colorado, Connecticut, Utah, Texas, or others as they come into effect), you may have rights similar to those described above, including the rights to access, correct, delete, and obtain a copy of your personal data, and to opt out of targeted advertising, sale, or certain profiling. We do not engage in targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects, so those opt-outs do not apply. To exercise applicable rights, contact us at contact@trader-wallet.com. Where a law provides an appeal process for a declined request, we will honor it.
Data-protection laws in other jurisdictions may grant you additional or similar rights, for example Brazil's LGPD, Canada's PIPEDA, the UK GDPR, Switzerland's FADP, and laws in Australia, Japan, and elsewhere. Regardless of where you live, you may contact us to ask about the personal data we hold and to exercise any rights available to you under your local law, and we will respond in accordance with that law.
The Services may contain links to third-party websites, protocols, blockchain explorers, or applications that we do not operate. This Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. We encourage you to read the privacy policy of any third-party service before using it. Links inside user-written text are removed before storage (Section 9), so a link that appears in a comment is not something we transmitted.
The Services are not directed to, and are not intended for, anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, or that a public profile belongs to a child, please contact us and we will take appropriate steps to delete it.
We may update this Policy as the Services and applicable laws evolve. When we make material changes, we will update the effective date and version at the top and, where appropriate, notify you in the App or on the Site. We encourage you to review this Policy periodically. Your continued use of the Services after changes take effect means you accept the updated Policy.
The App contains a demo trading mode in which trading is simulated. No order reaches an exchange and no funds move. The demo balance has no monetary value and cannot be bought, exchanged or withdrawn; the legal terms are in Section 44 of our Terms of Service. Demo mode offers no prize, reward or payment of any kind, and there is no contest attached to it.
What we store. A demo account is keyed by your wallet address — the same public identifier used by the public trader profile, and not your Firebase account identifier. Against that address we store the simulated balance, simulated open positions, closed simulated trades, the counters derived from them (number of trades, return, largest drawdown, days active), and the times at which you topped up or reset the account.
Why. To run the simulation, to show you your own results, and to produce the demo standings. The legal basis is performance of a contract (Article 6(1)(b) GDPR) for running the mode you asked for, and our legitimate interest (Article 6(1)(f)) in keeping the standings honest.
What is public. Demo standings show a wallet address, and, where you have a public profile, its handle and avatar, together with the simulated result. Demo results are never mixed into real results. They do not enter the real leaderboard, the leagues, the seasons, duels, clan metrics or the trade feed, and a demo trade never creates a post.
Abuse checks. To keep the standings honest, we check for signals that one person is running several demo accounts — for example several accounts bound to the same application account or the same notification token — and for accounts trading against each other. These checks never delete an account, hide anyone from the standings, or block anyone from the App, and they are not used to decide anything about money: there is no prize and no payment attached to demo mode.
Retention. Demo data is kept while the demo account exists and is deleted with it. Deleting your public profile does not by itself delete demo data; write to us if you want both removed.
If you join using a partner code, we store on your wallet address the fact that this code was used and when. The date matters beyond record-keeping: the partner’s share decreases with the age of each referral, and it is computed from that date. If you are a partner, we store your code, your wallet address as its owner, the number of users who joined with it, how many joined today, and the amounts accrued, requested and paid, together with the individual accrual records these are built from. Where you created the code yourself, we also store your own cumulative trading volume as it stood at that moment, taken from the same public exchange record that produces your league. That figure is kept as a record of when the code was made and is not used to decide anything.
Joining with someone’s partner code shows that person who you are on the blockchain and how much you trade. It is a disclosure of your data to another user, it happens as soon as the code is applied, and it does not depend on whether you have a public profile. If you do not want a particular person to see your wallet address and your trading volume, do not join with their code.
What a partner can see about each person who joined with their code. The list of referrals in the App shows the partner, for every user who joined with one of their codes:
This applies even if the referred user has no public profile. Turning the public trader profile off keeps a person off the leaderboard and out of the feed; it does not hide them from the partner whose code they used. The partner is the one person, apart from us, who is shown that user’s address, handle, join date and trading volume together in one place.
What a partner is still not shown. A partner does not see a referred user’s e-mail address, device, balances, open positions, open orders, individual trades, profit and loss, assistant conversations, or anything held on that user’s device. A partner cannot message a referred user through the App, and referred users are not shown to one another.
An earlier version of this Policy said less than this. It said that a partner sees only a shortened address and an amount, and that a partner does not see a referred user’s name or trades. That was accurate when it was written; the App has since added the referral list described above, and this section now states what it actually shows.
Sources. Amounts arising from perpetual-futures trading are computed from a record of collected fees published by the exchange, which is keyed by public wallet address. Amounts we have not yet independently verified are marked as such and are not paid out.
Legal basis. Performance of a contract with the partner (Article 6(1)(b) GDPR), and our legitimate interest (Article 6(1)(f)) in attributing fees correctly and in preventing fabricated referrals.
Retention. Accrual and payout records are kept for as long as required by accounting and tax law, because they are records of amounts we have paid.
For any question or request about this Policy or your personal data, contact the controller:
Trader Wallet sp. z o.o.
ul. Złota 2-19, 15-016 Białystok, Poland
Email: contact@trader-wallet.com
The same address is our single point of contact for users, for the authorities of the Member States, for the European Commission, and for the European Board for Digital Services under Articles 11 and 12 of the Digital Services Act. Correspondence may be in English or in Polish. Our Terms of Service describe how to report illegal content and how to contest a moderation decision.
We aim to respond to privacy enquiries within 30 days.