Privacy Policy

Effective date: September 20, 2026

Swifun ("the App", "we", "us") is a self-custodial Solana wallet, a product of Abidon Labs LLC. This policy explains what the App handles, what never leaves your device, and what third parties process when you use it.

Contact: support@swifun.com

1. The Short Version

  • We never have your keys. Your private keys, recovery phrase, wallet PIN, and backup password are generated and held only on your device. We cannot receive, access, or recover them.
  • No accounts. There is no sign-up and no KYC. We do not know your name, and we do not sell personal information.
  • Your wallet does not depend on us. Your recovery phrase restores it in other wallet software at any time, whether or not our services are running.
  • Three things do reach infrastructure we control: messages you send us through in-app feedback (Section 6), short-lived records created when we cover a transaction's network fee for you (Section 4), and pseudonymous analytics and crash reports (Section 5).
  • Third-party services necessarily see your IP address and the public wallet addresses you query (Section 3).

2. What Stays on Your Device

The App keeps what it needs on your device rather than on our servers: your wallet key material, stored encrypted; your settings; and whatever it caches to stay fast. It also keeps diagnostic logs on your device; they stay local, except that error and warning entries go to our crash-reporting provider so failures can be diagnosed (Section 5).

Uninstalling deletes this local data. If you have not backed up your recovery phrase, uninstalling permanently destroys access to your wallet. We cannot recover it for you.

3. Third-Party Services

To show market data and execute trades, the App connects directly from your device to third-party providers. Like any internet service, they receive your IP address, standard request metadata, and the content of the request — typically public wallet addresses or token identifiers. We do not send them your identity; we never have it.

CategoryWhat it sees
Blockchain nodes — reading on-chain data, broadcasting your signed transactionsIP, wallet address(es), signed transactions
Market-data and trading providers — prices, charts, token information, quotes and routingIP, wallet address(es), tokens and trade parameters
Google (Firebase) — notifications, remote configuration, analytics and crash reporting (Section 5)IP, device and app information, a random app-instance identifier
Our support platform — in-app feedback threads (Section 6)IP, the message and screenshots you send
Hosting and edge-network providers — our website and the service in Section 4IP, standard request metadata

Transactions are signed on your device; only the signed transaction is transmitted, and it is destined for the public blockchain anyway. Solana is a public, permanent ledger: your addresses, balances, and transaction history are visible to anyone by design, independently of this App, and nothing in this policy can apply to data recorded on it.

These providers process data under their own privacy policies.

4. Our Own Services

Paying network fees for you. If you do not hold enough SOL for a transaction's network fee, the App can ask a service we operate to co-sign it and cover that fee, which you repay in the same transaction (Terms of Service, Section 5); the same service may relay a request when your device cannot reach a provider directly. Either way it sees your IP address and the request involved — a public wallet address, or the transaction to be co-signed — but never your private key, which cannot leave your device. It keeps short-lived records of this, tied to a wallet address or an IP address, to prevent abuse and to account for the fees it covers; they expire within days and are never shared or used to profile you.

The service creates no account for you.

5. Notifications, Analytics and Crash Reporting

The App uses Firebase (Google) to deliver push notifications, to fetch operational settings so we can respond to outages without shipping a new version, and to collect pseudonymous usage analytics and crash reports. Each of these transmits your IP address and basic device and app information to Google.

The analytics categories are: which screens and features you use; your app version, device and operating system; how the App was installed; whether an action such as a trade succeeded or why it failed, with the token it concerned and its approximate value; and, for crashes, stack traces and device state.

This is tied to a random identifier generated when you install the App, not to your identity. The App does not use your device's advertising ID or any identifier that follows you across other apps. Analytics events do not carry your wallet addresses, balances, or holdings, and we do not profile you. Diagnostic messages sent with a crash or error report may, however, contain public blockchain identifiers — a wallet address, transaction signature, token address, or amount — because that is what makes a failure diagnosable. Such data is already public on the Solana ledger (Section 3), and we use it only to fix the failure.

Your private keys and recovery phrase are never sent anywhere, in any report. Any diagnostic message mentioning key material is discarded in full before transmission. The App has no in-app switch to turn analytics off; uninstalling stops collection, and reinstalling generates a new random identifier not linked to the previous one.

6. In-App Feedback

The App has an optional "Help & feedback" screen where you can message the developer. Threads are stored on a support platform we control, are private to you and us, and are never published.

  • Stored: what you write, screenshots you attach, our replies, and basic diagnostic context (app version, build, platform, OS, device model, language) with the random identifier from Section 5.
  • Not attached: your wallet addresses, balances, holdings, keys or recovery phrase. Nothing about your wallet is added automatically, and threads are not linked to any blockchain identity. What you choose to send is up to you — a screenshot may show balances or addresses, so check before sending, and never paste your recovery phrase.
  • Identity: submitting creates an anonymous, credential-less session so only your device can read your own threads. No email, no password.
  • Retention: we keep a thread only while it is useful for support and product decisions, then delete it. You can ask us to delete yours at any time.

7. Optional Cloud Backup

If you back up your recovery phrase, it is encrypted on your device with a key derived from a password you choose, using current industry-standard algorithms that we may update over time, before it is uploaded. It goes to the app-private area of your own cloud storage account — which provider depends on your device and on what the App supports — not to our servers. The provider's sign-in is used solely to reach that area; the App does not read your other files, contacts, or messages, and you can delete backups from inside the App or through your provider's settings.

We never see your backup, your backup password, or your cloud account credentials. Your cloud provider processes this under its own privacy policy.

8. Camera and Photos

The camera is used only to scan QR codes, on-device. Photos are read or written only when you pick or save a specific image; there is no gallery scanning, and the App requests no photo-library permission.

9. Retention and Deletion

  • Records from the service in Section 4: expire automatically within days; we do not extend or archive them.
  • Feedback threads: kept only while useful, then deleted. Ask us at support@swifun.com to delete yours sooner; write from within the thread so we can identify it, since we have no other way to link it to you.
  • Analytics and crash data: retained by Google for a limited period set in its console, currently months rather than years.
  • Local data and cloud backups: delete by uninstalling, or through your cloud provider. Uninstalling also discards your anonymous feedback session, so you lose access to past threads.
  • Blockchain data: public and permanent; neither we nor anyone else can delete it.
  • If we stop operating: nothing you need in order to keep your assets is held by us.

10. Your Rights (GDPR, UK GDPR, CCPA and similar laws)

We hold very little about you, so most rights (access, rectification, erasure, portability) apply to data already under your direct control — on your device or in your own cloud account. For what we do hold: write to support@swifun.com about feedback threads and we will provide a copy or delete them. The records in Section 4 are short-lived and keyed to a blockchain address, and analytics data to a random install identifier — we have no mechanism to look you up in either. Requests about data held by third-party providers, including Google, should go to them.

Legal basis (GDPR). Where GDPR applies, processing is based on performance of the service you request (Art. 6(1)(b)) and our legitimate interest in keeping the App secure, functional, and free from abuse (Art. 6(1)(f)).

No sale, no targeted advertising, no profiling. We do not sell or share your personal information, do not use it for targeted or cross-context behavioral advertising, and do not use it for profiling or automated decisions producing legal or similarly significant effects. U.S. state privacy laws give you the right to opt out of each of these — here there is nothing to opt out of. No common standard yet governs "Do Not Track" signals, and the App does not respond to them.

You may contact us at support@swifun.com with any privacy question, and you have the right to lodge a complaint with your local data protection authority.

11. Children

The App is not directed at children and is intended only for users aged 18 or older. We do not knowingly collect information from children.

12. Security

Key material is stored using the platform's hardware-backed keystore where the device provides it, sensitive screens are configured to block screenshots and recording, and network connections are made over TLS. These measures are appropriate to the risk, but no security measure is absolute.

Protect your device, your PIN, and above all your recovery phrase — anyone who has it controls your funds, and we can never restore it for you.

13. International Data Transfers

We are based in the United States and the services above operate globally, so the limited data described here — principally your IP address and public wallet addresses — is processed in the United States and may be processed elsewhere, under data protection laws that may differ from those of your own country. Where data leaves the European Economic Area, the United Kingdom, or Switzerland, the providers we rely on do so under the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.

14. Changes and Contact

We will post any changes on this page and update the effective date above; material changes will be highlighted in the App's release notes.

Email: support@swifun.com