Privacy Policy
Last updated: August 25, 2026
Evertrend LLC, a Wyoming, USA limited liability company (“Evertrend,” “we,” “us,” or “our”), operates the BWallet mobile application and the bwallet.cash website (together, the “Services”). This Privacy Policy explains what information we collect, how we use it, and the choices you have. It's part of the same agreement as ourTerms of Service — please read both.
1. Our Product, In Brief
BWallet is a self-custody wallet: your recovery phrase and private keys are generated and encrypted entirely on your own device and are never transmitted to us. We cannot see them, recover them, or move your on-chain assets on your behalf. Most of what this policy covers instead is the optional account layer built on top of that wallet — your DID identity, email sign-in, chat, and the rewards program — which does involve data on our servers.
2. Information We Collect
2.1 Information you provide
- Email address — used to sign in. We store it encrypted (AES-256-GCM) plus a one-way HMAC lookup value used only to find your account by email; we never store it in plain text, and the lookup value cannot be reversed back into an email address.
- Nickname — a display name you choose or that we generate for you.
- Optional account-protection factors — if you choose to set them: a DID password (stored as a salted hash, never the password itself), a TOTP authenticator secret (stored encrypted), a one-time recovery code (stored as a hash), a wallet address you sign a challenge with, or a backup email address (stored the same encrypted way as your primary email).
- Referral code — another user's public ID, if you enter one when signing up.
- Support requests — anything you send us at [email protected].
2.2 Information generated automatically
- DID / account ID — a random public identifier assigned to your account, also used as your chat handle and referral code. It is not derived from your email and does not reveal it.
- Session token — created when you sign in; it stays valid until you log out or we suspend the account for a Terms violation.
- IP address — hashed before storage and used only to rate-limit sign-in/verification-code requests against abuse. We do not store your raw IP address.
- Device identifier for the rewards program — the app generates a random identifier stored locally on your device and sends it, hashed, when you check in for the daily rewards program. This exists solely to detect one device being used to farm multiple accounts' sign-up rewards; it is never used to track you across other features, and check-in works fine even if this signal isn't sent.
- Public wallet addresses — when you use in-app features like balance lookups, swaps, or WalletConnect, your public address (never your private key) is sent to the relevant service provider to perform that action. See Section 5.
- Push notification tokens — a device-level token issued by Apple or Google, used only to deliver notifications to your device.
2.3 Information we do not collect
- Your private keys or recovery phrase — these never leave your device, encrypted or otherwise.
- Government ID, KYC documents, or any identity-verification data.
- Phone numbers.
- Precise device location.
We also do not run any analytics, advertising, or crash-reporting SDK in the app or on this website — there is no third-party tracking pixel or behavioral-analytics tool collecting data about how you use BWallet.
2.4 Chat and calls
Chat and voice/video calling are a beta feature and are not currently end-to-end encrypted. Messages and call metadata are processed and stored on our own, self-hosted messaging server, in a form our systems can technically access. End-to-end encryption is on our roadmap but not yet shipped — please don't send sensitive personal, financial, or confidential information over chat or calls until it is. This is separate from your encrypted address book, which genuinely is end-to-end encrypted: the encryption key is derived on your device from your own recovery phrase, and our servers only ever see ciphertext.
3. How We Use Information
We use the information above to:
- Create and secure your account, and let you sign in and recover access to it;
- Operate the rewards program described in Section 4, including detecting abuse;
- Provide chat, calling, swap, and other in-app features you choose to use;
- Respond to support requests;
- Detect, investigate, and prevent fraud, abuse, and security incidents;
- Comply with legal obligations; and
- Send you service-related communications (e.g. security notices). We do not send marketing email.
4. Rewards Program (BCC/BAI) Data
If you participate in the optional BCC/BAI rewards program, we additionally record: your referral relationships (captured once at sign-up and not editable afterward), your claimable and withdrawn token balances, and, if you use the staking feature, your staked amount. Reward balances are tracked in an off-chain database ledger tied to your account until you actively withdraw them on-chain. Staked BCC is held at a project-controlled address rather than your own wallet — see Section 6 of ourTerms of Service for what that means. Device-fingerprint data collected under Section 2.2 may be reviewed by our team, or trigger an internal flag, if your account's check-in pattern looks like coordinated multi-account abuse.
5. Third-Party Service Providers
Some in-app features necessarily share limited data with outside services to work at all. We don't control these services' own data practices — review their policies directly if you have concerns.
| Service | What it's used for | What it can see |
|---|---|---|
| Google Sign-In | Optional login method | Your Google account email, via the standard OAuth handshake |
| Google Firebase Cloud Messaging | Push notifications (Android) | Your device's push token |
| Apple Push Notification service | Push notifications (iOS) | Your device's push token |
| Alchemy | Balance, NFT, and transaction-history lookups | Your public wallet address and request IP |
| 0x / SideShift | Token swaps and cross-chain bridging you initiate | The addresses and amounts involved in that swap |
| WalletConnect | Connecting BWallet to third-party dApps you choose to use | Your wallet address and the session you approve; the dApp itself receives whatever it requests once connected |
Our chat/calling infrastructure (a Matrix-protocol server and a LiveKit media server) is self-hosted by us, not a third party — see Section 2.4 above for what that means for message and call privacy.
6. How We Share Information
We share information only:
- With the service providers in Section 5, as needed to provide the feature you're using;
- If required by law, subpoena, or legal process, or to protect our rights, users, or the public;
- In connection with a merger, acquisition, or sale of assets (you'll be notified if this materially changes how your data is handled); or
- With your explicit consent.
We do not sell your personal information.
7. Data Security
Email addresses and other sensitive fields are encrypted at rest (AES-256-GCM); passwords and recovery codes are stored as salted hashes, never in plain text; and — as covered above — your wallet's private keys never reach our servers at all. No system is perfectly secure, and we can't guarantee absolute security, but the account layer is built so that a database compromise alone would not expose your wallet or, for most fields, your email address.
8. Data Retention
Sessions are permanent until you log out or your account is suspended. Account and rewards data is retained for as long as your account is active, plus a reasonable period afterward for legal, security, and dispute-resolution purposes, unless you request deletion under Section 9.
9. Your Rights and Choices
You can update your nickname and manage your optional security factors directly in the app. To access, correct, or delete the personal data we hold about your account, email[email protected] from the address on your account (or otherwise prove you control the DID in question). We currently handle deletion requests manually rather than through a self-service button in the app; we will act on a verified request within a reasonable time, except where we're required or permitted to retain certain data (e.g. transaction records for legal compliance, or fraud-review records). Deleting your account does not affect your local wallet or any assets already on-chain — those exist independently of us.
10. Region-Specific Disclosures
If you are in the European Economic Area or UK: you have the right to access, correct, delete, or restrict our use of your personal data, to receive a copy of it in a portable format, to object to certain processing, and to lodge a complaint with your local data-protection authority. Contact us at [email protected] to exercise these rights.
If you are a California resident: you have the right to know what personal information we collect, to request its deletion, to correct inaccurate information, and to non-discriminatory treatment for exercising these rights. As stated above, we do not sell or share personal information for cross-context behavioral advertising.
11. Children's Privacy
The Services are not directed to, and are not intended for use by, anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact [email protected] and we will delete it.
12. International Data Transfers
We are based in the United States and our infrastructure may be located in different countries than you are. By using the Services, you understand that your information may be processed in the United States or other countries whose data-protection laws may differ from those of your home jurisdiction.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We'll update the “Last updated” date above, and for material changes we'll provide a more prominent notice (e.g. in the app or on this site). Continued use of the Services after a change takes effect means you accept the updated policy.
14. Contact Us
Evertrend LLC (Wyoming, USA)
Email: [email protected]
Website: bwallet.cash