This Privacy Policy explains how LAR TECHNOLOGY JOINT STOCK COMPANY, the operator of InfraIO Pay and InfraIO Wallet (“we”, “us”) handle information in connection with the InfraIO Wallet mobile application (the “App”) and its related pages on infraio.xyz. The App is a self-custody wallet: it has no account, no email sign-in and no analytics, and we do not hold your keys or funds. It applies whether you use the App as an individual or on behalf of a business or other organisation; where an organisation uses the App, it is responsible for informing its own personnel about how their information is handled.

1. Information we do not collect

  • No account, name, email address, phone number or password is required or collected.
  • Your passkey and optional recovery phrase stay on your device and with your platform provider (iCloud Keychain or Google Password Manager). We never receive them.
  • The App contains no analytics, advertising or crash-reporting SDK, and does not track you across other apps or websites.
  • Your browser history in the App is stored on your device only and is not sent to us.
  • Push notifications are currently off. If they are enabled in a future version, we will update this policy and the App’s disclosures first.

2. Information we receive

None of this is linked to a name, email address or phone number, and none of it is used for advertising or tracking.

  • Your wallet record. When you create, add or recover a wallet, the App registers it with our wallet service: the wallet address, the public key and identifier of each passkey or device key that can approve it (never the private key), the wallet name you choose, the networks you activate, the tokens you add and the NFTs you hide. We use this to show your wallet on another device signed in to the same platform account, to recover access with your recovery phrase, and to prepare transactions.
  • Address book. Your address book is kept on your device and, when our service can be reached, synced with it so it is the same on your other devices: each contact’s name, addresses and any note you add. When you delete a contact it disappears from your synced address book; the deleted entry may remain in our systems for a period, and you can ask us to erase it (see section 9).
  • Transactions and history. When you send, swap, bridge or activate a network, the App sends the transaction to our service, which prepares it for you to approve with your passkey and submits the signed transaction to the network. Our service also indexes the public blockchain to show your balances, transaction history and NFTs, and checks the recipients you enter (for example whether an address is new, a contract or similar to one you have used) to warn you about likely mistakes.
  • Lookups. Names you resolve (such as alice.eth), tokens you search for and networks you request are sent to our service to answer the request.
  • Technical data. Like any online service, our servers receive your IP address, the app version and the time of each request. We keep this in server logs for security, abuse prevention and troubleshooting.
  • Bug reports you choose to send. If you send a report from the in-app bug-report sheet, we receive the diagnostics you chose to send: device model, operating system version, app version and a recent in-app log. It is not used for tracking or advertising. We use it only to find and fix problems. If you contact us by email, we receive the information you put in your message.

3. Information that goes to other parties

  • Public blockchain data. Wallet addresses, balances and transactions are public on the blockchain. Besides our service, the App reads this data from public RPC nodes and block explorers, and can submit your signed transactions to the network through them when our service is unavailable. Those services, and the blockchain itself, may see your address, your IP address and the requests you make, and transactions on a public blockchain are permanent and visible to anyone.
  • Third-party providers. If you use swap, bridge, staking or buy features (such as Velora, KyberSwap, LI.FI, Lido or Transak), your request, amounts and wallet address are sent to the provider you use, which handles data under its own privacy policy. If a provider requires identity verification or payment details, you give them directly to that provider; we do not receive them.
  • dApps and WalletConnect. If you connect to a decentralized application or website, it receives the information you approve, such as your public address, and handles it under its own policy.
  • Your platform provider. Apple and Google process passkey sync, app downloads and device features under their own privacy policies.

4. Permissions

  • Camera: to scan wallet-address and WalletConnect QR codes. Images are processed on your device.
  • Photo library: only when you choose a QR image to scan.
  • Face ID, Touch ID or device passcode: to approve transactions and unlock the App. Biometric data is handled by your operating system and is never available to us.

5. How we use information

We use the information we receive only to provide and maintain the App and its wallet service (including syncing your wallets and address book across your devices, preparing and submitting transactions, and warning you about risky recipients), diagnose and fix problems reported to us, respond to your messages, prevent abuse, and comply with applicable law and lawful requests. We do not sell personal data.

6. Legal bases (EEA / UK)

Where the GDPR or UK GDPR applies, we rely on your consent (for example when you choose to send a bug report), the performance of our agreement with you (the Terms) to provide the wallet service you request, our legitimate interests in maintaining and securing the App, and legal obligation, as appropriate to the processing activity.

7. Sharing

We do not sell personal data. We share information only with service providers acting on our behalf under confidentiality and security obligations, with authorities when required by law, subpoena or to protect rights and safety, and with successors in connection with a merger, acquisition or asset sale, subject to the protections of this policy.

8. Retention

We keep your wallet record and synced address book while you use the wallet service, and server logs, bug reports and correspondence only for as long as needed for security, to resolve the issue, meet legal obligations and resolve disputes. We cannot delete or alter data on a public blockchain.

9. Your rights

Depending on your jurisdiction you may have the right to access, correct, port, restrict or delete personal data we hold about you, and to object to processing. Because we do not operate accounts, we identify your data by your wallet address; we may ask you to prove you control the wallet before acting on a request. To exercise these rights, contact [email protected].

10. Security

Keys are created and protected by your device’s secure hardware, and the App uses encrypted connections (HTTPS/TLS) to the services it contacts. No system is perfectly secure. You are responsible for securing your device, platform account and recovery phrase.

11. International transfers

The services described above, and our own infrastructure, may process data outside your home country. Where required we put in place standard contractual clauses or equivalent safeguards.

12. Children

The App is not directed to children, and you must be at least 18 (or the age of majority where you live) to use it. We do not knowingly collect personal data from children.

13. Changes

We will post material changes here and update the “Last updated” date. Continued use after changes means you accept the updated policy.

14. Contact

Questions about this policy or data-subject requests: [email protected].