Privacy Policy
Bankirr is a read-only, non-custodial portfolio tracker. This policy explains what data we collect, why, and what we deliberately never collect — starting with your private keys.
1. Information We Collect
We collect the minimum needed to run the Service:
- Email address — used to sign you in via a one-time code sent to your inbox, and — if you join a product waitlist (for example the iOS app) — to notify you when that product is available. We do not use it for unrelated marketing without your consent.
- Wallet addresses and ENS names — the public addresses you add to track. These are public on-chain identifiers, not secrets.
- Anonymous device ID — a randomly generated identifier used to associate app settings and sessions with your device, without identifying you personally.
- Apple original transaction ID — for users who subscribe via the iOS App Store, Apple provides an original transaction identifier so we can validate and manage your subscription status.
- Request metadata — IP address, user-agent, and the API paths / public wallet addresses you look up, retained for a limited period so we can operate, secure, and debug the Service. We do not use this for advertising.
2. Information We Do Not Collect
We never collect or have access to private keys or seed phrases, your legal name, or your payment card details. Payments are handled entirely by Apple (App Store) or Stripe — we never see or store your card number.
3. How We Use Information
We use the information above only to operate the Service: authenticating sign-in, fetching and displaying on-chain balances and positions for the addresses you add, and validating active subscriptions. We do not use your data to build advertising profiles.
4. Third-Party Services
The Service relies on a small set of infrastructure providers to function:
- Blockchain RPC providers (such as Alchemy) — we send them only the public wallet addresses you track, in order to read balances and on-chain activity. They never receive your email, private keys, or any identifying information about you.
- Apple App Store — processes iOS subscription payments and provides subscription status via Apple's standard mechanisms.
- Stripe — processes card payments made directly on bankirr.xyz.
5. No Ads, No Selling Data, No Tracking
We do not run advertising in the Service, we do not sell or rent your data to third parties, and we do not embed third-party analytics or advertising trackers that follow you across other apps or sites.
6. Data Storage and Security
Data is stored on our server infrastructure (hosted on providers including Railway and Cloudflare) with industry-standard security practices. No method of transmission or storage is 100% secure, but we take reasonable measures to protect the limited data we hold.
7. Data Retention and Deletion
We retain your account data for as long as your account is active. Request metadata (IP, API path, looked-up wallet addresses) is kept for up to 90 days and then deleted automatically. You can request deletion of your account and associated data at any time by emailing friend@bankirr.xyz. We will process deletion requests within a reasonable time, except where we are required to retain certain records by law.
8. Your Rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you. To exercise any of these rights, contact us at the email address below.
9. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
11. Contact
Questions about this policy or your data? Reach us at friend@bankirr.xyz.