← RhinoBlock

Privacy Policy

Last updated 4 August 2026

The short version

We have no user accounts and no database. We do not run analytics, advertising or tracking scripts of any kind. Your keys and your recovery phrase never leave your device. Most of what this page describes is data held by other companies whose services the app talks to, not by us.

What stays on your device

Stored in your browser, readable only by you, and never transmitted to us:

  • Your recovery phrase and private keys, encrypted at rest.
  • Names you give your accounts, and which accounts you have hidden.
  • Tokens you have imported, dismissed notices, and similar preferences.

Clearing your browser storage deletes all of it. If you have a recovery-phrase wallet and no copy of the phrase, that deletion is permanent and we cannot help you recover it.

What our servers see

The app calls a small number of routes on our own domain that forward requests to providers using our API keys. Handling those requests means our hosting provider (Vercel) processes, in ordinary server logs:

  • Your IP address and approximate country, used for security, rate limiting, and to block access from sanctioned jurisdictions.
  • The wallet address whose balances, tokens or quotes are being requested.

We do not build profiles from this, do not link it to an identity, and do not sell or share it for advertising.

If you use the sign-in wallet

Signing in with Google, email or a passkey means our login provider, Privy, handles your identity. Privy holds your email address or social account identifier and operates the secure enclave that stores that wallet’s keys. Their privacy policy governs that data. If you use a recovery-phrase wallet instead, none of this applies — there is nothing to sign in to.

Who else your requests reach

Using the app necessarily contacts third parties, which see your IP address and, where relevant, your wallet address. We name them rather than describing them in categories, because which company can see your wallet address is worth knowing. The providers we currently use are:

  • Alchemy and public RPC endpoints — balances, tokens and broadcasting transactions.
  • 0x and Squid — swap quotes and routing. Both screen wallet addresses against sanctions and illicit-activity lists.
  • Blockstream — Bitcoin balances, history and broadcasting.
  • CoinGecko — token prices.

Naming them means this list has to change when they do. If we replace a provider we will update this page, and the date at the top tells you when it last changed.

Blockchains are public and permanent

Anything you send on-chain — addresses, amounts, timing — is published on a public ledger by design. It is visible to anyone, it cannot be edited, and it cannot be deleted. That is a property of the networks themselves, not a choice we made, and no privacy policy can undo it. Treat your wallet address as public information.

Cookies

We set no advertising or analytics cookies. The app uses browser storage for the purposes listed above, and our login provider may set cookies necessary to keep you signed in.

Children

RhinoWallet is not intended for anyone under 18, and we do not knowingly collect their data.

Your rights

Depending on where you live you may have rights to access, correct, export or delete personal data held about you. Because we hold no accounts, the data that answers most such requests sits with Privy — requests about a sign-in wallet should be directed there. On-device data is deleted by clearing your browser storage, which you can do without asking us. On-chain data cannot be deleted by anyone.

Changes and contact

We may update this policy; the date at the top shows when it last changed. Privacy questions can be sent to the contact address published on rhinoblock.io.