Privacy Policy

Version 1.3.0 · Effective August 13, 2026

Key Points

This summary is a reader aid. The full Policy below controls.

This Privacy Policy describes how Noesis ("Noesis", "we", "us", or "our") collects, uses, shares, and retains personal information when you use the Noesis application, website, or related services (collectively, the "Services"). It is incorporated by reference into our Terms of Service.

Noesis is a non-custodial cryptocurrency wallet and market-analysis tool. Your private keys and recovery phrase are generated and stored on your device. We never receive, store, or have the ability to access, recover, or reset them. This Privacy Policy explains the information we do handle and why.

1. Scope and Definitions

This Privacy Policy applies to the Noesis mobile application (iOS and Android), the public Noesis website, and any related Noesis-operated services. It does not apply to third-party services that you separately interact with through the Services, such as fiat on-ramp providers, market-data providers, or blockchain networks themselves; those providers have their own privacy notices.

"Personal Information" means information that identifies, relates to, or could reasonably be linked with you. It does not include de-identified or aggregated information that cannot reasonably be associated with you.

2. Information You Provide to Us

We collect the following directly from you:

3. Information Collected Automatically

We do not enable Firebase Analytics, Firebase Crashlytics, or any third-party advertising or attribution SDK in the iOS build. The app does not request the App Tracking Transparency prompt because it performs no tracking as defined by Apple.

4. How We Use Your Information

We use Personal Information to:

5. Third-Party Processors and Data Recipients

We rely on a defined set of third-party processors and data recipients to operate the Services. The list below is exhaustive as of the effective date of this Policy, with a single exception we cannot enumerate because we do not select its members — the image hosts that token issuers choose for their own logos, described at the end of this section. We will update this Policy when material changes are made.

Where an entry says we send your wallet address, that means the public address of a wallet on your device. A public address is pseudonymous rather than anonymous: it does not carry your name, but it is a persistent identifier that can be linked to on-chain activity, so we treat it as personal information throughout this Policy. Your private keys and recovery phrase are never sent to anyone, including every recipient named below.

Apple, Google, Anthropic, RevenueCat, Tatum.io, Jupiter, and 0x act on our behalf under contract and are limited to using your information for the purposes described in this Policy. Jupiter is named in that list for completeness only: as its entry above sets out, our use of Jupiter is a scheduled fetch of a public token list, and no information about you is sent to it. The block-explorer and blockchain-node providers named above — Etherscan, Blockscout, Routescan, Mempool Space, Litecoinspace, Blockchair, and XRPL Cluster — the market-data hosts CoinGecko, CoinMarketCap, and Coinbase, and the transfer-data feed Whale Alert are public services we query or subscribe to without an account or, in most cases, without any credential. We have no contract with them and cannot direct how they handle the addresses and queries we send, which is why we send them no account identifier, email address, or name. We name them here because a public wallet address is still personal information about you.

One category cannot be listed by name. Logos for Solana tokens are published by each token's own issuer on infrastructure that issuer chooses, such as a distributed-storage gateway or a code-hosting service. When your device displays one of those tokens it downloads the logo from wherever the issuer put it, so that host receives your device's IP address and the identity of the token displayed. We send no account identifier, wallet address, or email address, and these hosts are neither operated by nor contracted with Noesis. We are working to serve these images through our own infrastructure so that this category disappears.

When you separately and independently interact with a third-party service through the Services — for example, tapping a transaction to open it in a public block explorer, or completing a purchase on a payment provider's own checkout — your interaction with that service is governed by its own privacy notice, not by this Policy.

6. Information We Do Not Collect

The following are not collected, transmitted, or accessible to us:

7. Retention

8. Your Privacy Choices and Rights

You can exercise the rights described below at any time, subject to verification of your identity and to the exceptions provided under applicable law.

9. Account Deletion in Detail

You can delete your account at any time by tapping Settings → Delete Account. Doing so will:

On day thirty (30) of the grace window, an automated daily job permanently deletes your account row, your transaction-history records, and any remaining AI Chat audit entries tied to your account.

If you have used Sign in with Apple, you may also revoke Noesis through the Apple Settings → Apple ID → Sign in with Apple workflow. Apple will notify our server, and we will treat the revocation as an account-deletion request. The same cascade above applies.

10. International Data Transfers

Our backend infrastructure is operated in the United States. If you access the Services from outside the United States, your information will be transferred to, processed in, and stored in the United States or other jurisdictions where our processors operate.

For transfers of personal information from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on Standard Contractual Clauses approved by the European Commission (and the UK Addendum / Swiss equivalents where applicable) as a transfer mechanism.

11. Security

We use commercially reasonable administrative, technical, and physical safeguards to protect Personal Information, including encryption in transit (TLS), encryption at rest for our database, revocable session identifiers, hashed identifiers in logs, and least-privilege access controls on our production infrastructure.

No system is perfectly secure. The single most important security control for your wallet is your sole custody of your recovery phrase. We cannot recover or reset it, and we cannot reverse a transaction once it is broadcast.

If a security incident affects your Personal Information in a way that triggers a legal notification obligation, we will notify you and the relevant authorities consistent with applicable law (including, where applicable, within 72 hours under Article 33 of the GDPR).

12. Children

The Services are not directed to, or intended for use by, anyone under 18. Our Terms of Service set a minimum age of 18. We do not knowingly collect Personal Information from anyone under 18, and we do not knowingly collect Personal Information from children under 13 as that term is used in the Children's Online Privacy Protection Act. If you believe someone under 18 has provided Personal Information to us, contact us at the address in Section 15 and we will delete the account and the information.

13. Changes to this Policy

We may update this Privacy Policy from time to time. The "effective date" at the top of this Policy indicates when this version became effective. We will revise this Policy when our practices change in a way that affects how we collect, use, share, or retain Personal Information. We encourage you to review this Policy periodically.

When changes are material, we will use commercially reasonable efforts to notify you, including by posting a notice within the Services and, where required by law, requesting your renewed consent before applying the changed practices to you.

14. Additional Regional Disclosures

(a) California residents.

(b) Residents of the EEA, the United Kingdom, and Switzerland.

15. Contact

Questions, opt-out requests, or rights requests under this Privacy Policy should be directed to:

Noesis — Privacy
Email: admin@ckslabs.com
Mail: 202 N Cedar Ave, Suite #1, Owatonna, Minnesota 55060, United States