Privacy Policy

Last Updated: August 23, 2026

This Privacy Policy (the "Policy") explains how BSV Association ("BSV Association", the "Company", "we", "us" or "our") collects, uses, and shares data in connection with the BSV Association web browser app mobile.bsvb.tech, desktop.bsvb.tech and all of our other related properties, products, and services (the "Services"). Your use of the Services is subject to this Policy as well as our Terms of Service.

Data We Collect

We do not maintain user accounts, and we do not ask you for your name or any other identifying information in order to use the Services. When you interact with the Services, we collect only:

Our browser does not collect or transmit your browsing history, cookies, web beacons, or other tracking data to us. Any cookies or similar technologies you may encounter are set by the websites you visit, and those practices are governed by the privacy policies of those websites. The browser may store certain information locally on your device, such as browsing history and bookmarks, solely to provide core browser functionality. This information remains on your device and is not communicated to us. You may delete your history or bookmarks at any time through the browser settings.

Encrypted Wallet Backup

A wallet's recovery phrase alone is not enough to rebuild that wallet. Records such as change outputs and received-payment receipts carry derivation data that exists only in the wallet's own database, so a device that is lost, wiped, or replaced can leave funds unspendable even when the recovery phrase was kept safely. To prevent that outcome, the app maintains an encrypted backup of the wallet database on a server operated by BSV Association.

This feature is enabled by default. Unless you turn it off, the app periodically uploads an encrypted copy of your wallet database as your wallet changes. You can disable it, and you can delete what has already been uploaded, at any time — see Your Control below.

What is uploaded

The backup covers the contents of your wallet database. Before anything leaves your device it is encrypted, so the data below is only ever transmitted to and held by us in encrypted form:

Your browsing history, bookmarks, and the contents of the websites you visit are not part of the backup and are never uploaded. Your recovery phrase, your private keys, and your vault passphrase are never transmitted, in any form.

Encryption, and why we cannot read your backup

The backup is encrypted on your device using AES-256-GCM. The encryption key is derived on your device from cryptographic material associated with your wallet's private key, using a process designed so that only your wallet can reproduce the encryption key. The encryption key is never transmitted to us, and we do not possess or have access to it. Accordingly, the data we store consists of encrypted ciphertext that we do not have the technical means to decrypt. We cannot read, analyze, index, or otherwise access the contents of your backup, whether for our own purposes or on behalf of any third party. We also cannot use the backup to recover or reconstruct your wallet or its private keys. Without the wallet's underlying recovery material (which may be restored using your recovery phrase or printed backup shares) the backup cannot be decrypted or used to restore your wallet by us or any other person who does not possess the necessary recovery material.

Your backup is stored under a pseudonym

Backups are not stored under your wallet's identity key, and the backup service has no field for storing your wallet identity key. Instead, the app derives a separate public key that is used solely to address and authenticate your backup, and that key is provided to the backup service. Because the relationship between the two keys is established by a cryptographic derivation that requires your wallet's private key, a party who observes your backup pseudonym cannot derive your wallet identity key from it, and a party who knows your wallet identity key cannot derive your backup pseudonym. A separate pseudonym is derived for each blockchain network, so backups made on different networks are associated with separate, unlinkable backup identifiers.

What the service can observe

Although we cannot read your backup, operating the Service exposes certain information to us. Such information incudes:

Whether there is any new information to transmit is determined on your device. If there is nothing new to transmit, the app does not contact the Backup Service. Accordingly, data is transmitted only when there is a change to your wallet that requires an updated backup, rather than continuously while the app is open. The app may also contact the Backup Service when you restore a wallet to a new device or delete a backup.

Your control

We retain an account's encrypted backup until it is deleted, either by you or by the app superseding older copies with a more recent one in the ordinary course of keeping the backup current.

How We Use Data

We use the data we collect in accordance with your instructions, including any applicable terms in our Terms of Service, and as required by law. We may also use data for the following purposes:

How We Share Data

We may share or disclose the data we collect:

We do not share your information with any third parties for any marketing purposes whatsoever.

Third Party Cookies

We use services provided by third parties that employ tracking technologies to collect information about your use of the Services and our interactions with you. You can opt out of having your online activity and device data collected through these third-party services, including by:

Third-Party Links and Sites

We may integrate technologies operated or controlled by other parties into parts of the Services. For example, the Services may include links that hyperlink to websites, platforms, and other services not operated or controlled by us. Please note that when you interact with these other parties, including when you leave the Site, those parties may independently collect information about you and solicit information from you. You can learn more about how those parties collect and use your data by consulting their privacy policies and other terms.

Security

We implement and maintain reasonable administrative, physical, and technical security safeguards to help protect data from loss, theft, misuse, unauthorized access, disclosure, alteration, and destruction. Nevertheless, transmission via the internet is not completely secure and we cannot guarantee the security of information about you. You are responsible for all of your activity on the Services, including the security of your blockchain network addresses, cryptocurrency wallets, and their cryptographic keys.

Age Requirements

The Services are intended for a general audience and are not directed at children. We do not knowingly receive personal information (as defined by the U.S. Children's Privacy Protection Act, or "COPPA") from children. If you believe we have received personal information about a child under the age of 18, please contact us at support@bsvassociation.org.

Disclosures for European Union Data Subjects

We process personal data for the purposes described in the section titled "How We Use Data" above. Our bases for processing your data include: (i) you have given consent to the process to us or our Service Providers for one or more specific purposes; (ii) processing is necessary for the performance of a contract with you; (iii) processing is necessary for compliance with a legal obligation; and/or (iv) processing is necessary for the purposes of the legitimate interested pursued by us or a third party, and your interests and fundamental rights and freedoms do not override those interests.

Your rights under the General Data Protection Regulations ("GDPR") include the right to (i) request access and obtain a copy of your personal data, (ii) request rectification or erasure of your personal data, (iii) object to or restrict the processing of your personal data; and (iv) request portability of your personal data. Additionally, you may withdraw your consent to our collection at any time.

In relation to the encrypted wallet backup, these rights can be exercised directly in the app and take effect without needing to contact us. Wallet > Settings > Private backup allows you to withdraw from the processing at any time by turning off Back up to server, and to obtain erasure by tapping Delete backup from server, which deletes every copy the service holds for your backup pseudonym. Because the backup is encrypted with a key we do not hold and is stored under a pseudonym that we cannot link to you, we are not able to identify, produce, rectify, or export the contents of a particular person's backup on request; the app itself is the only means by which that data can be read or removed.

To exercise any of your rights under the GDPR, please contact us at support@bsvassociation.org. We may require additional information from you to process your request. Please note that we may retain information as necessary to fulfill the purpose for which it was collected and may continue to do so even after a data subject request in accordance with our legitimate interests, including to comply with our legal obligations, resolves disputes, prevent fraud, and enforce our agreements.

Changes to this Policy

If we make material changes to this Policy, we will provide you with notice through the Services or by other appropriate means. We encourage you to review this Policy periodically to stay informed about how we collect, use, disclose, and protect your information. Your continued use of the Services following the effective date of any changes constitutes your acknowledgment of the updated Policy, to the extent permitted by applicable law.

Contact Us

If you have any questions about this Policy or how we collect, use, or share your information, please contact us at support@bsvassociation.org.