Privacy Policy
Key Points
This summary is a reader aid. The full Policy below controls.
- We do not have your private keys or recovery phrase. Ever.
- We name every third-party processor we use in Section 5.
- Delete your account anytime. You have 30 days to change your mind by signing back in — then permanent removal.
- No GPS. We derive only an approximate country from your IP address, to apply geographic restrictions.
- AI Chat prompts are logged for safety review; default storage is hashed. Your recent conversation text is cached for up to 7 days so the assistant can follow the thread (see Sections 2 and 7).
- No analytics SDK, no advertising SDK, no attribution SDK.
- Your GDPR and CCPA rights are described in Sections 8 and 14.
This Privacy Policy describes how Noesis ("Noesis", "we", "us", or "our") collects, uses, shares, and retains personal information when you use the Noesis application, website, or related services (collectively, the "Services"). It is incorporated by reference into our Terms of Service.
Noesis is a non-custodial cryptocurrency wallet and market-analysis tool. Your private keys and recovery phrase are generated and stored on your device. We never receive, store, or have the ability to access, recover, or reset them. This Privacy Policy explains the information we do handle and why.
1. Scope and Definitions
This Privacy Policy applies to the Noesis mobile application (iOS and Android), the public Noesis website, and any related Noesis-operated services. It does not apply to third-party services that you separately interact with through the Services, such as fiat on-ramp providers, market-data providers, or blockchain networks themselves; those providers have their own privacy notices.
"Personal Information" means information that identifies, relates to, or could reasonably be linked with you. It does not include de-identified or aggregated information that cannot reasonably be associated with you.
2. Information You Provide to Us
We collect the following directly from you:
- Account identifiers. When you sign in with Apple, we receive an opaque Apple user identifier ("Sign in with Apple" sub claim) and a verified email address if you choose to share one. Your display name, if Apple supplies it on first sign-in, is also stored. Apple-issued private-relay email addresses are treated the same as any other email. When you sign in with Google instead, we receive your Google account identifier together with the name and email address associated with that Google account.
- Wallet addresses. When you import or register a public wallet address for watching or sending, we store the address. We do not request, receive, or have the ability to receive your private keys or recovery phrase — those are generated and held exclusively on your device.
- Consent records. When you accept the Terms of Service or Risk Disclaimer, we store the version you accepted and the timestamp as audit-trail evidence.
- Content you submit to AI features. When you use the in-app AI Chat or related analysis features, the text of your prompts is processed by our AI provider (see Section 5) and an audit log entry is recorded. By default the recorded entry stores a one-way hash of your prompt and a separate one-way hash of the model output. Raw prompt and response text are recorded in that audit log only when the operator has explicitly enabled raw-input audit logging for incident-investigation or safety-review purposes; this flag is off by default. Separately from the audit log, the text of your recent messages and the assistant's replies is held in a short-term conversation cache so the assistant can follow the thread across turns. That cache is keyed to your account, expires seven (7) days after your last message in a conversation, is capped at the most recent messages, and is erased when you delete your account or clear the conversation in the app. Retention is set out in Section 7.
- Support communications. When you contact us at the address in Section 15, we receive the email address you write from and the contents of your message.
3. Information Collected Automatically
- Subscription state. If you purchase a Noesis subscription through the Apple App Store or Google Play Store, we receive a server-to-server snapshot of your subscription plan, status, period, and entitlement from our subscription-management processor (RevenueCat). We do not receive your full payment card details from the app stores.
- Push-notification token. If you enable push notifications, the operating system issues a push token that we store in order to deliver price-alert notifications. The token is rotated and revoked by the operating system if you disable notifications or uninstall the app.
- Session metadata. When you sign in, we store a session identifier, the IP address your session was first and last seen from, your device's user-agent string, and last-seen and last-used timestamps, so that we can secure your session and revoke compromised sessions. We do not store your wallet credentials in session records.
- Wallet activity. For wallet addresses you register, we query public blockchain data on your behalf and cache balance and transaction-history snapshots so that the app can show them efficiently.
- Device and app information. Requests the app makes to our servers carry your device's user-agent string, which identifies the device model family, the operating-system version, and the Noesis app version. We store it with your session record so that we can support you and detect unusual sign-ins.
- Country inferred from IP address. Our servers derive an approximate country or region from the IP address of each request. We use it only to apply the geographic restrictions in Section 2 of the Terms of Service, to meet sanctions obligations, and to route AI requests to a supported region. We do not derive your city, street, or precise position, we do not use GPS or Wi-Fi positioning, and we do not retain an inferred country beyond the session and log retention periods in Section 7.
- Error and diagnostic data. Our backend records server-side error and performance logs for requests the app makes. These contain a request identifier, the endpoint, the error, and a pseudonymous account or session identifier, and are retained as described in Section 7. We do not run a crash-reporting SDK in the app. Crash reports you choose to share with Apple through iOS are governed by Apple's privacy policy; we see only the aggregated reports Apple makes available to us in App Store Connect.
We do not enable Firebase Analytics, Firebase Crashlytics, or any third-party advertising or attribution SDK in the iOS build. The app does not request the App Tracking Transparency prompt because it performs no tracking as defined by Apple.
4. How We Use Your Information
We use Personal Information to:
- Operate the Services, including creating and maintaining your account, broadcasting the pre-signed transactions you submit, and serving market-data and AI-analysis responses.
- Send you the push notifications and emails you have opted in to receive, including price alerts and transactional messages such as receipts and security notices.
- Maintain the security of the Services, including detecting and responding to abuse, fraud, and unauthorized access; maintaining audit logs of AI prompts and outputs for safety review; and complying with our legal obligations.
- Improve the Services, including diagnosing reproducible errors that you report to us and tuning AI-analysis prompts and guardrails based on aggregated audit-log review.
- Comply with applicable law and respond to lawful requests, including from courts, regulators, and law enforcement with valid jurisdiction.
5. Third-Party Processors and Data Recipients
We rely on a defined set of third-party processors and data recipients to operate the Services. The list below is exhaustive as of the effective date of this Policy, with a single exception we cannot enumerate because we do not select its members — the image hosts that token issuers choose for their own logos, described at the end of this section. We will update this Policy when material changes are made.
Where an entry says we send your wallet address, that means the public address of a wallet on your device. A public address is pseudonymous rather than anonymous: it does not carry your name, but it is a persistent identifier that can be linked to on-chain activity, so we treat it as personal information throughout this Policy. Your private keys and recovery phrase are never sent to anyone, including every recipient named below.
- Apple, Inc. — Sign in with Apple identity verification, Apple App Store payments, and Apple server-to-server account-deletion notifications. We receive your opaque Apple sub identifier and, on first sign-in only, the email address and the name you choose to share. At sign-in we exchange Apple's authorization code for a refresh token; when you delete your account we send that refresh token to Apple's token-revocation endpoint, so that Noesis is removed from the Sign in with Apple list on your Apple ID.
- Google LLC (Sign in with Google) — Google identity verification when you choose that sign-in method. We receive your Google account identifier and the name and email address associated with that account.
- Google LLC (Firebase Cloud Messaging) — Push notification delivery and app-installation registration. We send your device push token and the alert text, which names the coins you have chosen to track and the price condition that triggered the alert; on iOS, Google relays that text onward to Apple for delivery. The Firebase SDK in the app also registers an installation identifier with Google each time the app starts.
- Google LLC (Vertex AI and the Gemini API) — AI provider for in-app AI features, including AI Chat, portfolio analysis, and your AI Daily Brief. A request may be served through either Vertex AI or the Gemini API depending on regional availability. We send the text of your AI Chat prompts and the earlier turns of that conversation, a summary of your portfolio composition and its value, and, for your Daily Brief, the first name on your account. We do not send your wallet addresses, private keys, recovery phrase, wallet credentials, or signing material — those never leave your device.
- Anthropic PBC — AI provider for the same in-app AI features. We use more than one AI provider, and we do not commit to which one handles any particular request: a given request may be sent to Anthropic rather than to Google, and which provider serves it can change over time and by request type as we tune the Services for quality, capability, and availability. Anthropic is not a standby that is used only when Google is unavailable — it is used during normal operation. Where a request is served by Anthropic, the data sent is the same as the Google AI entry: the text of your AI Chat prompts and the earlier turns of that conversation, a summary of your portfolio composition and its value, and, for your Daily Brief, the first name on your account. Separately, for the small number of AI Chat questions that require a live market-data lookup, we send Anthropic the text of your latest question by itself, without the earlier turns of the conversation and without your portfolio, so that the model can decide which CoinGecko lookups to perform; see the CoinGecko entry below for what is then sent onward to CoinGecko. In all cases we do not send your wallet addresses, private keys, recovery phrase, wallet credentials, or signing material — those never leave your device. Anthropic does not use data submitted through its API to train its models.
- Google LLC (Cloud Run, Cloud SQL, Memorystore, Cloud Logging, Cloud Storage, Cloud Text-to-Speech) — Backend hosting, database, caching, and logging infrastructure for the Services, and narration and storage for your AI Daily Brief audio. To produce the audio we send the text of your personalized brief, which describes the coins you hold and their recent performance, to be synthesized into speech, and we store the resulting audio file under an object name containing your account identifier. Your device then downloads that file directly from Google, which receives your device's IP address.
- RevenueCat, Inc. — Subscription and entitlement management. We send your account identifier to create and look up your subscriber record, to apply any trial entitlement, and to delete that record when you delete your account; we receive webhook events and a snapshot of your plan, status, and period. The RevenueCat SDK in the app also sends your App Store or Google Play purchase receipt directly from your device. We do not send wallet addresses, private keys, or your recovery phrase.
- Tatum.io — Blockchain RPC, transaction-broadcast, and address-monitoring provider. We send your public wallet addresses to read balances, token holdings, and transaction history, and we send the pre-signed transaction bytes you produced on your device when you broadcast. So that we can notify you of incoming transfers, we also register your address with Tatum together with our own callback address, which Tatum stores. We do not send account identifiers, email addresses, or private keys. Tatum does not serve transaction history for every network — see the block-explorer entries below.
- TronGrid — TRON-network RPC, transaction construction, and broadcast. For native TRON (TRX) transfers, and for TRC-20 token transfers on builds where that path is enabled, we send your TRON address to assemble the unsigned transaction and to broadcast the version you signed on your device. We do not send private keys.
- Etherscan — EVM block-explorer data provider. We send your public wallet address and the chain and account query we need in order to show your Ethereum, Polygon, and BNB Smart Chain transaction history and to calculate your Ethereum and Polygon cost basis. We do not send account identifiers, email addresses, or private keys.
- Blockscout — Public block-explorer data provider. We send your public wallet address and the account query we need in order to show your Base, Arbitrum, and Optimism transaction history and to calculate your cost basis on those networks, and to retrieve Ethereum and Polygon internal transfers when our primary explorer is unavailable. For Base, Arbitrum, and Optimism this is the only source of your transaction history. We do not send account identifiers, email addresses, or private keys.
- Routescan — Public block-explorer data provider for the Avalanche and BNB Smart Chain networks. We send your public wallet address and the account query we need in order to show your Avalanche transaction history and to calculate your Avalanche cost basis, and to request BNB Smart Chain internal transfers. For Avalanche this is the only source of your transaction history. We do not send account identifiers, email addresses, or private keys.
- Mempool Space and Litecoinspace — Public block-explorer data providers for the Bitcoin and Litecoin networks respectively. We send your public Bitcoin or Litecoin address, and the transaction identifiers needed to page through its history, in order to calculate your cost basis. We do not send account identifiers, email addresses, or private keys.
- Blockchair — Public block-explorer data provider for the Dogecoin network. We send your public Dogecoin address, and the block ranges needed to page through its history, in order to calculate your cost basis. We do not send account identifiers, email addresses, or private keys.
- XRPL Cluster — Public XRP Ledger node provider. We send your public XRP Ledger address in order to read its transaction history and calculate your cost basis. We do not send account identifiers, email addresses, or private keys.
- CoinGecko — Market-data provider and coin-image host. Our servers send coin symbols, contract-address queries, and the text you type into the in-app search box; we do not send account identifiers or wallet addresses. Your device also downloads coin images directly from CoinGecko, which therefore receives your device's IP address and the identity of the coins displayed to you. For a small number of AI Chat questions that our standard market data cannot answer — a token identified only by a contract address, a ranked list of movers, an older date range, or on-chain and decentralized-exchange figures — our server allows the AI model to query CoinGecko directly. In that case CoinGecko receives the specific lookups the model chose to perform, such as a coin identifier, a date range, or a network, and nothing else: your question is not forwarded to CoinGecko, and neither is your account identifier, your wallet address, or your portfolio.
- Whale Alert — Source of the large-transfer flow data shown in Whale Pulse. This is a one-way feed: our servers subscribe to Whale Alert's public transfer stream and store the resulting market-wide events. We send Whale Alert nothing about you — our servers transmit only our own subscription settings, such as which chains and symbols to stream and the transfer size to stream above. No account identifier, email address, or wallet address of yours is sent. Your device contacts Whale Alert only if you tap the "Data provided by Whale Alert" attribution link in Settings → About & Data Sources, which opens the vendor's own site inside the app; Whale Alert then receives your device's IP address for that page.
- CoinMarketCap — Coin-logo image host and crypto-news source. Your device requests a coin's logo directly from CoinMarketCap when we have no other image for that coin, so CoinMarketCap receives your device's IP address and the identity of the coin displayed; separately, our servers request news articles by coin identifier. We do not send account identifiers, wallet addresses, or email addresses.
- Coinbase, Inc. — Market-data provider for price charts. We send a trading-pair identifier and a candle interval. We do not send account identifiers, wallet addresses, or email addresses.
- Jupiter — Solana token registry and token metadata. Our servers fetch a public list of verified Solana tokens on a schedule to populate token names, symbols, icons, and decimals. We send no wallet address, account identifier, or email address, and no request is made to Jupiter when you request a swap quote or swap.
- 0x — Solana- and EVM-network swap routing and quotes. When you request a swap quote on Solana or on an EVM chain, including the indicative price shown as you type an amount, we send your wallet (taker) address and the input and output token addresses and amounts so 0x can return a price and route and the instructions used to build the unsigned swap transaction you sign on your device. We do not send your private keys, which never leave your device.
Apple, Google, Anthropic, RevenueCat, Tatum.io, Jupiter, and 0x act on our behalf under contract and are limited to using your information for the purposes described in this Policy. Jupiter is named in that list for completeness only: as its entry above sets out, our use of Jupiter is a scheduled fetch of a public token list, and no information about you is sent to it. The block-explorer and blockchain-node providers named above — Etherscan, Blockscout, Routescan, Mempool Space, Litecoinspace, Blockchair, and XRPL Cluster — the market-data hosts CoinGecko, CoinMarketCap, and Coinbase, and the transfer-data feed Whale Alert are public services we query or subscribe to without an account or, in most cases, without any credential. We have no contract with them and cannot direct how they handle the addresses and queries we send, which is why we send them no account identifier, email address, or name. We name them here because a public wallet address is still personal information about you.
One category cannot be listed by name. Logos for Solana tokens are published by each token's own issuer on infrastructure that issuer chooses, such as a distributed-storage gateway or a code-hosting service. When your device displays one of those tokens it downloads the logo from wherever the issuer put it, so that host receives your device's IP address and the identity of the token displayed. We send no account identifier, wallet address, or email address, and these hosts are neither operated by nor contracted with Noesis. We are working to serve these images through our own infrastructure so that this category disappears.
When you separately and independently interact with a third-party service through the Services — for example, tapping a transaction to open it in a public block explorer, or completing a purchase on a payment provider's own checkout — your interaction with that service is governed by its own privacy notice, not by this Policy.
6. Information We Do Not Collect
The following are not collected, transmitted, or accessible to us:
- Your private keys, recovery phrase, or signing material. These are generated on your device using the BIP-39 standard and stored in your device's secure storage (the iOS Keychain or Android Keystore), configured to remain on that device only so they are never synced to iCloud or any other cloud backup. They are never transmitted to our servers, and an automated check runs on every backend build to confirm our servers contain no code that could receive, store, or reconstruct them.
- Biometric templates. The app uses the platform biometric APIs only to receive a yes/no authentication result; no biometric template ever crosses the platform boundary.
- Precise location. The app does not request location permission and does not collect GPS, Wi-Fi, or Bluetooth-derived location. The only location signal we have is the approximate country or region inferred from your IP address, which is described in Section 3.
- Contacts, photos, microphone, or files outside the app sandbox. The app does not request these permissions.
- Camera content, except for QR-code scanning of wallet addresses, which happens on-device and does not record or transmit images.
- Advertising or attribution identifiers. The iOS build does not link or integrate any advertising or attribution SDK and does not present the App Tracking Transparency prompt.
7. Retention
- Account record. We retain your account record for as long as your account is active. When you delete your account, it is first marked as deleted (a soft delete) and a 30-day grace window begins. During the grace window your account is inaccessible but not yet permanently erased, and signing back in cancels the deletion as described in Section 9. After 30 days, an automated daily job permanently erases it and the remaining data described below.
- Operational records. The following are hard-deleted immediately when you delete your account: alerts, alert trigger events, notification deliveries, device push tokens, wallet addresses, your subscription mirror, user devices, user sessions, any founding-member enrollment record, and your cached AI Chat conversations.
- Transaction history. The transaction-history records we maintain for your registered addresses are retained through the 30-day grace window so that an authorized restore can be serviced if you sign back in during that window, and are then permanently deleted by the same automated daily job that removes the account record.
- AI Chat audit logs. AI Chat audit entries (prompt hash, output hash, and metadata) are retained for thirteen (13) months from creation and then permanently deleted by an automated job, regardless of account state. This retention exists to support incident investigation and safety review of AI behavior. If you delete your account during this period, entries tied to your account are removed on day 30 of the deletion grace window or at the thirteen-month mark, whichever comes first.
- AI Chat conversation cache. The text of your recent AI Chat messages and the assistant's replies is held in a short-term cache keyed to your account so the assistant can follow the thread. Each conversation expires seven (7) days after your last message in it, and only the most recent messages in a conversation are kept. Clearing a conversation in the app removes it immediately, and deleting your account erases every cached conversation in the same request rather than waiting for expiry.
- Consent evidence. Records of which version of the Terms of Service and Risk Disclaimer you accepted, and when, are retained as append-only legal evidence for the life of the account row. They are deleted on day 30 along with the rest of the account row.
- Backups. Encrypted database backups are retained for up to thirty-five (35) days. Backups containing deleted records are aged out on the same schedule as live backups; we do not perform targeted record deletion within backups.
- Logs. Operational logs may contain pseudonymous identifiers and are retained for up to thirty (30) days for incident-investigation purposes.
8. Your Privacy Choices and Rights
You can exercise the rights described below at any time, subject to verification of your identity and to the exceptions provided under applicable law.
- Access your account information by viewing your profile and subscription state in Settings.
- Delete your account through Settings → Delete Account. Deletion triggers the cascade described in Section 7, including detaching your subscription mirror at our subscription processor and invalidating your sessions. A 30-day grace window applies before permanent deletion.
- Cancel a subscription through the App Store or Google Play Store account that purchased it. Subscription cancellation through your platform is independent of account deletion.
- Withdraw consent for, or object to, particular processing where required by applicable law by contacting us at the address in Section 15.
- Correct or restrict the processing of your personal information where required by applicable law by contacting us at the address in Section 15. Note that your name and email are supplied by your Apple or Google sign-in; corrections to those values may also need to be made with that provider.
- Portability. You may request a machine-readable export of the personal information you provided to us by contacting us at the address in Section 15.
- Lodge a complaint with the data-protection authority in your country of residence if you are in the European Economic Area, the United Kingdom, or Switzerland.
9. Account Deletion in Detail
You can delete your account at any time by tapping Settings → Delete Account. Doing so will:
- Soft-delete your account record, beginning a 30-day grace window. During the grace window your account is inaccessible: your subscription is detached from our records, and incoming subscription-renewal events from the platform are ignored. You can cancel the deletion by signing back in with the same Apple or Google account before day 30, which restores your account and your transaction history but not the records we hard-delete immediately. On day 30 the deletion is permanent and cannot be undone.
- Hard-delete, immediately, your alerts, alert trigger events, notification deliveries, device push tokens, wallet addresses, your subscription mirror, user devices, sessions, and any founding-member enrollment record.
- Detach your subscriber record at our subscription processor (RevenueCat). Cancelling the underlying subscription with the App Store or Google Play Store is a separate action you take through your platform account.
- Revoke your Sign in with Apple token. If you signed in with Apple, we call Apple's token-revocation endpoint as part of the deletion, so Noesis is removed from the Sign in with Apple list on your Apple ID and Apple stops sending us events about you. You do not have to do anything in Apple's settings for this to happen.
- Invalidate all active sessions across all your devices.
On day thirty (30) of the grace window, an automated daily job permanently deletes your account row, your transaction-history records, and any remaining AI Chat audit entries tied to your account.
If you have used Sign in with Apple, you may also revoke Noesis through the Apple Settings → Apple ID → Sign in with Apple workflow. Apple will notify our server, and we will treat the revocation as an account-deletion request. The same cascade above applies.
10. International Data Transfers
Our backend infrastructure is operated in the United States. If you access the Services from outside the United States, your information will be transferred to, processed in, and stored in the United States or other jurisdictions where our processors operate.
For transfers of personal information from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on Standard Contractual Clauses approved by the European Commission (and the UK Addendum / Swiss equivalents where applicable) as a transfer mechanism.
11. Security
We use commercially reasonable administrative, technical, and physical safeguards to protect Personal Information, including encryption in transit (TLS), encryption at rest for our database, revocable session identifiers, hashed identifiers in logs, and least-privilege access controls on our production infrastructure.
No system is perfectly secure. The single most important security control for your wallet is your sole custody of your recovery phrase. We cannot recover or reset it, and we cannot reverse a transaction once it is broadcast.
If a security incident affects your Personal Information in a way that triggers a legal notification obligation, we will notify you and the relevant authorities consistent with applicable law (including, where applicable, within 72 hours under Article 33 of the GDPR).
12. Children
The Services are not directed to, or intended for use by, anyone under 18. Our Terms of Service set a minimum age of 18. We do not knowingly collect Personal Information from anyone under 18, and we do not knowingly collect Personal Information from children under 13 as that term is used in the Children's Online Privacy Protection Act. If you believe someone under 18 has provided Personal Information to us, contact us at the address in Section 15 and we will delete the account and the information.
13. Changes to this Policy
We may update this Privacy Policy from time to time. The "effective date" at the top of this Policy indicates when this version became effective. We will revise this Policy when our practices change in a way that affects how we collect, use, share, or retain Personal Information. We encourage you to review this Policy periodically.
When changes are material, we will use commercially reasonable efforts to notify you, including by posting a notice within the Services and, where required by law, requesting your renewed consent before applying the changed practices to you.
14. Additional Regional Disclosures
(a) California residents.
- Categories of personal information we collect, the purposes for which they are used, and the categories of processors with which they are shared are described in Sections 2 through 5 above.
- We do not sell or share your personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
- You have the right to know, delete, correct, and limit the use of sensitive personal information, and to opt out of certain sharing. Exercise these rights by contacting us at the address in Section 15. We will not discriminate against you for exercising your rights.
(b) Residents of the EEA, the United Kingdom, and Switzerland.
- Controller. Noesis is the controller of the Personal Information described in this Policy.
- Legal bases. We rely on the following legal bases: performance of a contract (Article 6(1)(b)) for operating the Services you request; legitimate interests (Article 6(1)(f)) for security, fraud prevention, audit logging, and product improvement (balanced against your fundamental rights); consent (Article 6(1)(a)) where we ask for it (for example, before sending non-transactional marketing email, which we do not currently do); legal obligation (Article 6(1)(c)) where applicable.
- Rights. You have the rights of access, rectification, erasure, restriction, portability, and objection under Articles 15-22 of the GDPR, exercisable as described in Section 8. You may lodge a complaint with your local supervisory authority.
- International transfers. See Section 10.
15. Contact
Questions, opt-out requests, or rights requests under this Privacy Policy should be directed to:
Noesis — Privacy
Email: admin@ckslabs.com
Mail: 202 N Cedar Ave, Suite #1, Owatonna, Minnesota 55060, United States