Privacy Policy
bWalletX is published by The Bitcoin Corporation Ltd and is based on the open-source Yours Wallet (MIT licence). It is not made, reviewed or endorsed by the Yours Wallet authors. This policy covers bWalletX (the full-feature app, Chrome extension and web wallet) and bWallet, the edition on the App Store and Google Play.
Summary
bWalletX is non-custodial: your private keys and recovery phrase never leave your device, and we can't move your money. To run chat, names, contacts and calls, our own service (bit-sign, operated by The Bitcoin Corporation Ltd) keeps the data listed under What our service keeps, linked to your wallet's identity key. If you use bChat on a phone, our push server also keeps your device's push token and notification settings so it can notify you (see Notifications). We use all of this only to run those features. We don't collect your email (unless you choose Continue with Google), phone number, location, advertising identifiers, analytics or crash reports, and we don't track you, sell your data or use it for advertising.
What stays on your device
- Your private keys and recovery phrase, encrypted with a key derived from your password and stored in the iOS Keychain (this device only, excluded from iCloud and device backups) or in Android storage encrypted with an Android Keystore key (excluded from Google backups).
- If you turn on Face ID, Touch ID or fingerprint unlock, a key to unlock your wallet is sealed behind your device's biometrics. Your biometric data itself is handled by the operating system and is never available to the app.
- Settings, recent sites and apps you open, chat history cached for bChat, and local caches.
What the app sends over the network
To work as a wallet, the app connects to these third-party services, all over HTTPS:
-
Wallet storage: by default, your wallet's transaction records (outputs, transactions and related
metadata, not your private keys) are synced to a remote wallet storage service operated by 1Sat
(
wallet.1sat.app). You can change the storage provider in Settings → Wallet Backup. - Blockchain services: address, balance, transaction and token lookups, and transaction broadcasts, go to BSV indexing services (1Sat APIs). Some address-history lookups (when you move funds in from another wallet), transaction checks and the BSV price history use the WhatsOnChain API, and transaction links open on WhatsOnChain. The BSV price comes from public price feeds.
- Wallet messaging: wallet-to-wallet messages use
messagebox.1sat.app. - Market, Media, Apps and Chat: trending tokens, collections, listings and ordinal media are loaded from 1Sat indexing and content services (ORDFS). The Apps tab lists bApps such as bChat, bMovies and bWriter; bChat and other bApps you open talk to their own services, which receive what you send them.
-
Names and payments to names: when you send to a $handle, paymail or OpNS name, or look up your own
name, the app asks 1Sat indexers (including OpNS), bit-sign and the paymail service of the address's domain
(for example HandCash for
@handcash.io) to resolve that name to a payment destination. Those services see the name being looked up. - Market and Chat: token and NFT listings, media and token rooms are loaded from 1Sat indexers. The Market's safety filter runs as part of that loading; if you use Report, the item is hidden on your device and, where a review service is configured, the item reference is sent to us for review.
-
Feed: public on-chain posts are loaded from a public bmap indexer and from our own bChat indexer
(
push.bwalletx.com/feed). Posting puts your post on the public blockchain. - $b assistant (optional): nothing is sent until you allow it in the app. In bWallet from the App Store and Google Play, $b uses your own AI provider key (Anthropic, OpenAI or OpenRouter) and your message and the recent conversation go straight from your phone to that provider. In bWalletX's pay-per-message mode, they go to our server (bitcoinchat.online), which passes them to Anthropic; our server also sees the payment's transaction id and your bChat sign-in, and Anthropic does not. Your keys, balances, addresses, contacts, chats and files are never sent. You can withdraw consent in Settings › b agent.
- Websites you open in the in-app browser receive the requests you make and the responses you approve. They're governed by their own privacy policies.
These services see your IP address and the public blockchain data needed to answer each request. Blockchain transactions are public by nature.
What our service keeps
Chat, names, contacts and calls run on bit-sign (bitcoinchat.online), operated by The Bitcoin
Corporation Ltd. When you use those features it stores:
- Your identifiers: your wallet's identity key, your $handle and your paymail name.
- Your name: the display name you choose.
- Messages: chat-room and direct messages you send, and room posts.
- Contacts: the contacts, friends and blocked users you keep in the app (not your phone's address book).
- Other content you create: bookmarks, and items you report for review.
- Wallet details for rooms and tickets: your wallet addresses and the token holdings needed to check access to token rooms and tickets.
Calls connect your device directly to the other person's; the service only helps the two devices find each other and doesn't record calls. All of this is used only to provide these features. It is not shared with third parties except the hosting providers that run the service, and it is never used for advertising or tracking. You can delete your account and this data from Settings (Delete account), or by contacting us.
Verified identity (KYC certificates)
Identity verification is optional. If you choose to verify, you are sent to bit-sign, which uses Veriff to check your identity document. bit-sign and Veriff keep the verification record under their own privacy policies. bit-sign then issues a private certificate that is stored in your wallet on your device. bWalletX does not upload that certificate anywhere by itself: you choose which details, if any, to reveal to an app or service, and only when you approve it.
Continue with X or Google (bWalletX only)
If you choose Continue with X or Continue with Google when creating an account, you sign in on X or Google in
your browser and our sign-in service (the bWalletX paymail server, run by The Bitcoin Corporation Ltd) receives
your X @name or Gmail address, your display name and your profile photo from them. The app uses these to fill in
your name and photo and, if you claim it, to register a verified paymail such as
yourname.x@bwalletx.com. We keep that registration so the paymail keeps working. We don't receive
your X or Google password, and we don't post anything or read anything else from your account. This option isn't
in bWallet from the App Store and Google Play.
Notifications
On-device alerts. If you allow notifications, the app shows local alerts about incoming transactions. They're generated on your device.
Push notifications (bChat). When you're signed in to bChat, the app registers your device with our push
server, push.bwalletx.com, run by The Bitcoin Corporation Ltd on a server we rent from Hetzner, so
you can be told about room mentions and direct messages while the app is closed. On a phone this is on by
default once you sign in to bChat, and your phone asks for permission first; in the web wallet and Chrome
extension it stays off until you turn it on. To do this the app sends:
- the device push token issued by your phone (or, in a browser, the Web Push subscription);
- the platform (iOS, Android, web or extension), the app (bWallet or bWalletX) and its bundle id;
- the bChat handle the device belongs to (your bChat sign-in);
- your notification preferences: message previews, quiet hours and your time zone, which kinds of alerts you want, and per-room settings (All, Mentions or Off).
We use this only to send you those notifications. The notification itself is delivered through Google Firebase Cloud Messaging (Android), Apple Push Notification service (iPhone) or your browser's push service, which receive the push token and the notification. Message previews are off by default: a notification then says only that you have something new, without the message text. If you turn previews on, the message text passes through those services to show it on your screen.
Turn push off or change previews, quiet hours and alerts in Settings › Notifications › Push notifications, or in your phone's notification settings. Turning push off, signing out of bChat or switching to another account removes this device's registration from our push server; uninstalling the app makes its push token stop working.
Testing waitlist (this website)
If you join the testing waitlist on this website, we collect your email address, the phone platform you chose (iPhone, Android or Either), the time you signed up, and your browser's user-agent string (to help spot abuse). This is stored by The Bitcoin Corporation Ltd in our own database and is used only to invite you to test bWallet and send testing updates. We do not sell it or share it for marketing. You can unsubscribe from any email, or ask us to delete your entry at any time using the contact details below.
Paid testers programme and tester check-ins
If you apply at bwalletx.com/testers, you sign in with Google and we keep
your Google-verified email address, name and profile photo, the Android phone model you type, the X or GitHub
name you give (optional), the BSV address you want to be paid to, the time you applied and your IP address (to
spot duplicate applications). It is stored by The Bitcoin Corporation Ltd on our server
(push.bwalletx.com, Hetzner) and used only to run the programme: approving testers, adding your email
to the Google Play test list, and paying you.
Tester check-ins. Only in the Google Play build, and only after you enter your tester code (or email) in Settings › Testing, the app sends one check-in a day while it is open: a random install id made on your phone, your tester code or email, which app store installed it (so we know it came from Google Play) and the app version. It sends nothing about your keys, addresses, balances or activity. Unlink in Settings › Testing to stop. Payment never depends on ratings or reviews. Ask us to delete your tester record at any time.
Your choices
- You can delete your account and the data our service keeps from Settings (Delete account).
- You can delete all app data on your device by signing out in Settings, or by uninstalling the app.
- You can turn biometric unlock off from the lock screen at any time.
- You can turn push notifications and message previews off in Settings › Notifications, and remove this device's push registration by signing out of bChat.
- You can withdraw consent for the $b assistant in Settings › b agent.
- You can change the remote wallet storage provider in Settings → Wallet Backup.
Children
The app is not directed at children under 13.
Changes
We'll post changes to this policy on this page, and in the source repository at github.com/b0ase/yours-mobile.
Contact
The Bitcoin Corporation Ltd: support@bwalletx.com, or open an issue at github.com/b0ase/yours-mobile/issues.