# Privacy Policy

Last updated: September 23, 2026

**In short:** No account, no email, no KYC required. Your keys and recovery phrase never leave your device. We don’t sell or share your personal data.

## 1. Who we are

This Privacy Policy explains how STAGE AND STYLE COLLECTIVE LLC, 2103 Condor Ct, Redmond, Oregon 97756-8281, United States (“Oath”, “we”, “us”) handles personal data when you use the Oath app and website (the “Service”). We are the data controller for the limited personal data described here.

Contact: care@oathwallet.org.

## 2. Our approach

Oath is designed to work without collecting personal data. We do not require an account, name, email address, phone number or identity documents to use the Service.

## 3. Data that never leaves your device

The following are stored only on your device, encrypted by iOS, and are never sent to us:

- Your recovery phrase and private keys
- Entropy you create with dice, coin flips or digits
- Your wallet names, labels and settings
- Biometric data — Face ID and Touch ID are handled entirely by iOS; we never receive it

## 4. Passkeys

If you enable passkey restore, the passkey is created and stored by your Apple account and synced end-to-end encrypted through iCloud Keychain under Apple’s privacy policy. We cannot read or use it.

## 5. Data processed to provide the Service

To show balances, prices and history and to broadcast transactions, the app connects to blockchain nodes and price-data services. These requests can reveal:

- Your public wallet addresses and transactions (which are public on blockchains by design)
- Your device’s IP address and basic technical information (such as app version and device type)
- Your chosen display currency and language

## 6. Optional diagnostics

If you choose to share analytics with app developers in iOS settings, Apple may provide us with aggregated crash reports and performance data that do not identify you. You can change this at any time in Settings › Privacy & Security › Analytics & Improvements.

## 7. Support requests

If you contact care@oathwallet.org, we process your email address and the contents of your message to respond. Never include your recovery phrase or private keys.

## 8. Why we process data (legal bases)

Where laws such as the EU/UK GDPR apply, we rely on:

- Performance of a contract — to provide the Service you request (connecting to networks, showing prices)
- Legitimate interests — to keep the Service secure, prevent abuse and fix bugs, balanced against your rights
- Consent — for optional diagnostics, which you can withdraw at any time
- Legal obligation — where we must comply with applicable law

## 9. What we don’t do

We do not sell personal data, “share” it for cross-context behavioural advertising, build advertising profiles, use third-party ad trackers, or make decisions about you based solely on automated processing that produce legal effects.

## 10. Sharing with service providers

We may use a small number of service providers (such as blockchain node providers, price-data providers, hosting and email providers) who process data on our behalf under written contracts that require confidentiality and security. We may disclose information where required by law or to protect rights and safety, and we will resist over-broad requests where the law allows.

## 11. International transfers

Our providers may process data in countries other than yours. Where required, we protect transfers with appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms.

## 12. Retention

Network and price requests are not stored by us beyond what our providers need for security logs (typically no longer than 30 days). Support emails are kept only as long as needed to resolve your request, then deleted, unless we must keep them by law.

## 13. Security

We use industry-standard measures, including on-device encryption, the iOS Secure Enclave and encrypted connections. Our source code is public at github.com/devdasx/oath-wallet so anyone can review how your data is handled.

## 14. Your rights

Depending on where you live, you may have the right to access, correct, delete or port your personal data, to object to or restrict processing, and to withdraw consent. Because most data stays on your device, deleting the app removes it. To exercise any right, email care@oathwallet.org. We will respond within the time required by law and will not discriminate against you for exercising your rights.

You also have the right to complain to your local data-protection authority.

## 15. Regional information

We aim to meet the requirements of privacy laws worldwide, including:

- European Union, EEA and United Kingdom — GDPR and UK GDPR
- United States — CCPA/CPRA (California) and other state privacy laws; we honour Global Privacy Control signals, and we do not sell or share personal information
- Brazil — LGPD
- Canada — PIPEDA and applicable provincial laws
- Australia — Privacy Act 1988 and the Australian Privacy Principles
- Japan — APPI · South Korea — PIPA · Singapore — PDPA · Thailand — PDPA
- India — Digital Personal Data Protection Act 2023
- China — PIPL
- Saudi Arabia — PDPL · United Arab Emirates — PDPL · Türkiye — KVKK
- South Africa — POPIA · Nigeria — NDPA · Kenya — Data Protection Act

## 16. Children

The Service is not directed to children under 13 (or under 16 where required by local law), and we do not knowingly collect their personal data. If you believe a child has contacted us, email care@oathwallet.org and we will delete the information.

## 17. Deleting your data

To delete data on your device, delete the Oath app (your funds stay on the blockchain and can be restored with your recovery phrase). To delete support correspondence, email care@oathwallet.org from the address you used.

## 18. Changes to this policy

We will post any changes here and update the “Last updated” date. For material changes, we will notify you in the app before they take effect.

Questions: care@oathwallet.org
