KYKY Wallet Privacy Policy
Effective 12 August 2026
KYKY Wallet is self-custody software published by KYKY Labs. This policy covers the iPhone and browser clients, KYKY Names, public profiles, and optional first-party services. KYKY Labs does not receive your recovery phrase or wallet private keys. Supported clients encrypt stored wallet key material locally; while a client is unlocked, the signing material needed for an approved action remains within that client's local wallet boundary. We do not use advertising SDKs, behavioral analytics, cross-app tracking, or sell personal data.
Browser extension
The browser client stores its encrypted vault in extension storage. While the wallet is unlocked, signing material remains inside the extension's local wallet boundary. A website receives a public account only after you grant that origin access. Transaction and signature requests are relayed to and reviewed through the extension's approval surface; the website does not receive your recovery phrase or private key.
Data you choose to publish
If you claim a KYKY Name, the service stores the signed public profile you submit: handle, display name, optional bio and avatar, wallet addresses, and optional messaging public keys. This information is linked to the controller address and is public by design. Resolving a name sends the queried handle to KYKY's registry.
Encrypted messages
KYKY chat encrypts message contents on your device. The relay stores ciphertext that it cannot decrypt, but it necessarily stores the sender address, recipient address, timestamp, and an optional transaction reference so the intended conversation can be delivered. The current relay is append-only and does not offer per-message server deletion.
Payments and service security
When an exact-payment feature is available and you choose to use it, KYKY processes the signed request and the minimum App Attest, replay, quota, and settlement-attempt facts needed to authorize the request, prevent duplicate execution, and investigate service abuse. These facts are used for app functionality and security, never advertising or tracking.
Third-party networks
The wallet talks directly to the blockchain RPC, explorer, market-data, swap, bridge, and image endpoints required by the feature you select. Those providers receive ordinary network information such as your IP address and the public wallet address, transaction, token, or symbol being requested, under their own policies. KYKY public profile pages may fetch an avatar from the URL its owner published.
Retention and your choices
Local wallet data remains on your device until you remove the wallet. Releasing a KYKY Name removes it from public resolution immediately and starts a 30-day anti-takeover quarantine. The current service retains the complete signed profile and controller in its non-public name row after release, and its append-only transparency log permanently retains the handle, controller, record hash, and timestamps. A later valid claim may overwrite the name row, but not the transparency log.
The current chat relay retains encrypted message rows and their routing metadata indefinitely so participants can synchronize history; it does not yet offer per-message or account-level server deletion. Short-lived payment challenges are pruned after expiry, while App Attest keys, counters, replay bindings, settlement claims, and security logs may be retained indefinitely to prevent duplicate execution and investigate abuse.
You can release your KYKY Name and remove all local wallet data from the app. Those actions do not delete remote chat, transparency, or security records, and this version has no authenticated remote-deletion endpoint. For non-sensitive questions use the KYKY support page. That page currently provides general guidance, not a channel for confidential submissions. Never post a recovery phrase, private key, personal message, vulnerability detail, or other secret in a public channel.
Changes
Material changes will be published at this permanent URL with a new effective date.