Privacy Policy
Aether Wallet
This Privacy Policy explains what information Aether Wallet (operated by Erebos Lab) collects, how it is used, who it is shared with, and the choices you have. By using Aether Wallet you agree to the practices described here.
Data-safety summary
At a glance, here is the data the app collects, whether it is linked to your identity, and whether it is used to track you across other companies’ apps and websites.
| Data category | Linked to you | Used for tracking | Purpose |
|---|---|---|---|
| Blockchain Activity | No | No | Read from public blockchains to display your portfolio and activity. When the app fetches this data, third-party RPC and price providers may see the wallet address and your IP address. This data is not tied to a personal account. |
| Account & Contact Info (Optional) | Yes | No | Create an optional account, restore account settings, and provide cross-device sync. The wallet is fully usable signed-out; sign-in never becomes custody of your keys. |
| Contacts (Optional) | Yes | No | Match contacts who also use the app. Contacts are hashed on your device and never leave it in the clear. |
| User Content (Optional) | Yes | No | Provide the feature you choose, sync the content when cloud sync is enabled, and respond to support requests. |
| Advertising Data & Coarse Location | No | Yes | Display and measure free-tier ads. Tracking identifiers are used only after the required consent and App Tracking Transparency permission. |
| Usage Data | No | No | Operate app features, understand aggregate usage, and improve reliability. |
| Identifiers & Diagnostics | No | No | Deliver optional notifications, diagnose failures, measure performance, and keep the app working. |
| Purchases | Yes | No | Manage optional subscriptions via Apple/Google through RevenueCat. |
What we collect
Blockchain Activity
- Public wallet addresses, balances, token holdings, and transaction history
Read from public blockchains to display your portfolio and activity. When the app fetches this data, third-party RPC and price providers may see the wallet address and your IP address. This data is not tied to a personal account.
Account & Contact Info (Optional)
- User ID
- Name
- Email or Apple/Google sign-in identifier
Create an optional account, restore account settings, and provide cross-device sync. The wallet is fully usable signed-out; sign-in never becomes custody of your keys.
Contacts (Optional)
- SHA-256 hashes of contacts (only if you enable friend-matching)
Match contacts who also use the app. Contacts are hashed on your device and never leave it in the clear.
User Content (Optional)
- Profile fields, wallet labels, and content you submit to app features or support
Provide the feature you choose, sync the content when cloud sync is enabled, and respond to support requests.
Advertising Data & Coarse Location
- Advertising identifier (IDFA / Android Advertising ID)
- Ad interactions
- Approximate location inferred by the advertising provider
Display and measure free-tier ads. Tracking identifiers are used only after the required consent and App Tracking Transparency permission.
Usage Data
- Product interactions and feature usage
Operate app features, understand aggregate usage, and improve reliability.
Identifiers & Diagnostics
- Device model and OS version
- Push notification token (only if you enable push)
- Crash data
- Performance data
- Other diagnostic data
Deliver optional notifications, diagnose failures, measure performance, and keep the app working.
Purchases
- Subscription state for optional “Pro” features
Manage optional subscriptions via Apple/Google through RevenueCat.
What we do NOT do
- We never receive, store, or transmit your private keys, seed phrase, or wallet password — they are encrypted and stored only on your device (self-custody).
- Signing out never touches your wallet keys.
- Your contacts never leave your device (only salted hashes are used).
- No third-party analytics SDK currently transmits your data; in-app analytics stays on the device unless a provider is explicitly configured.
Third parties who process your data
We share data only with the processors below, each bound to use it only to provide their service to us. Items marked "unverified" are placeholders we must confirm and name before this policy is treated as final.
- Blockchain RPC & data providers (Alchemy, Helius, public RPC nodes, mempool.space) — Read balances, transactions, and NFTs from public chains — receive your wallet address and IP when queried
- CoinGecko, DefiLlama, GoPlus — Token prices, market/yield data, and security/approval scanning
- Jupiter, Across, Uniswap, Pimlico — Swaps, bridging, and account-abstraction bundling that you initiate
- Apple, Google, Web3Auth — Optional sign-in and optional social-recovery embedded wallet
- Supabase — Optional cloud sync and edge functions that hold vendor API keys; the app degrades to offline states without it
- Google AdMob — Consent-gated free-tier advertising and ad measurement
- RevenueCat — Optional subscription billing via Apple/Google
- Expo — Optional push notification delivery
- fiat on-ramp provider (MoonPay / Ramp / Transak) unverified — Optional buy-crypto widget — not yet configured; to be named before enabling.
How we use your information
- Operate and personalize the app and its core features.
- Maintain your account, authenticate sessions, and provide support.
- Process payments and manage subscriptions/entitlements.
- Keep the service secure and prevent fraud and abuse.
- Comply with legal obligations and enforce our Terms of Service.
- Improve the product through aggregated, de-identified analytics.
Data retention
We keep personal information only as long as needed to provide the service. Account data is retained while your account is active and for a short recovery window after deletion, then deleted or anonymized. Billing records are retained as required by tax and accounting law. Backups are purged on a rolling basis.
Your rights and choices
Depending on your jurisdiction you may access, correct, export, or delete your personal data, object to or restrict certain processing, and withdraw consent. You can delete your account and its server-side data from within the app, or by emailing us. We respond within 30 days.
Children’s privacy
The app is not directed to children under 13 (under 16 in the EEA/UK) and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
Security
We use industry-standard safeguards including TLS in transit, encryption at rest for sensitive fields, hashed passwords, least-privilege access, and audit logging. No system is 100% secure; please use a strong, unique password.
Changes to this policy
We may update this policy. Material changes will be reflected by a new "Last updated" date and, where required, announced in the app.
Contact
Privacy questions? Email support@ereboslab.com.