UBW Privacy Policy
Effective: 23 September 2026 • Pre-release Galaxy Store / Android policy
UBW is designed so that a seed phrase, BIP39 passphrase, WIF/private key, xprv, private descriptor, Vault password and signing credential are not sent to the UBW website, licensing service, analytics service or blockchain backend.
1. Scope and controller
This policy applies to Universal BTC Wallet & Recovery Suite (“UBW”), the Android application and this UBW support website. The project is currently in pre-release. Until a dedicated project mailbox is provisioned, privacy and support requests are accepted through the UBW Support page. This policy will be updated before any web-account service begins collecting account data.
2. Data handled by the Android app
3. Android permissions
The current release requests Internet for blockchain synchronization and store/billing services, and Camera for user-invoked QR scanning. Camera hardware is optional. The current manifest does not request location, microphone, contacts, SMS/MMS or phone-call permissions. Android backup is disabled for the application; UBW provides its own explicit encrypted Vault backup flow.
4. Third parties and data sharing
RevenueCat processes purchase/entitlement information and an anonymous customer identifier for the store build. UBW disables RevenueCat diagnostics and automatic device-identifier collection in its SDK configuration. RevenueCat may still process end-user technical and transaction information required to provide purchase services under its own privacy terms.
Samsung Galaxy Store or Google Play processes store account, checkout, payment and purchase records for the corresponding signed build. UBW does not receive payment-card details from the store.
Blockchain backends may receive public address/script queries needed for synchronization or recovery. A public backend can potentially correlate queried public wallet data with a network connection. UBW therefore exposes backend choices, including user-controlled/private backend paths where implemented and validated.
Hosting infrastructure processes normal network metadata required to deliver this website over HTTPS. The current informational website does not provide wallet login or wallet synchronization and does not receive wallet secrets.
5. Purposes and legal bases
Data is processed only as necessary to provide requested wallet functions, perform a purchase or restore a purchase, protect the application and user data, comply with applicable legal obligations, or where the user has explicitly chosen an operation such as QR camera access, public-backend synchronization, file import/export or a support export. Where consent is the applicable basis, it can be withdrawn for future processing by discontinuing the optional operation or permission.
6. Retention and deletion
Local wallet and application data remains on the user's device until the user deletes it, resets the relevant profile/Vault, or uninstalls the application, subject to Android storage behavior. Exported files remain wherever the user chose to save them. Purchase records and entitlement data are retained by the applicable store and RevenueCat according to their legal, fraud-prevention and service requirements. Public blockchain services may retain network/query logs according to their own policies; UBW cannot delete third-party logs that it does not control.
7. User rights
Depending on jurisdiction, users may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent, and complain to a competent data-protection authority. For data held only locally by UBW, the user controls that data through the device, Vault and export/delete functions. Requests concerning store or RevenueCat records may also need to be addressed to those providers because they control portions of those records.
8. Security
UBW separates wallet secrets from billing and web identity. Website authentication is not a Vault decryption key and is not intended to authorize Bitcoin signing. The website is served over HTTPS with HSTS and restrictive browser security headers. No system can guarantee absolute security; users remain responsible for protecting recovery material and verifying backups.
9. Children and regional requirements
UBW is not specifically directed at children. Users must satisfy the applicable age, financial, store and cryptocurrency rules in their jurisdiction. Regional store restrictions may apply.
10. Future web companion
The planned UBW web companion will be watch-only by design. It may display explicitly authorized public wallet information such as balances and public transaction history after account login and device pairing, but it is not intended to receive seed phrases, private keys or signing credentials. The privacy policy will be revised and users notified before any production account-data collection begins.
11. Policy changes
The effective date appears at the top of this page. Material privacy changes will be announced on this website and, once account/app notification infrastructure exists, through an appropriate in-app or account notice. The Galaxy Store privacy-policy URL will be kept current when the policy changes.
12. Contact
Current support channel: https://ubw.duckdns.org/support. A dedicated support/privacy mailbox on an UBW-controlled domain is being provisioned and will replace this interim contact before commercial store registration.