Skip to content
M5wallet
Test Beta

Last updated: 2026-09-08

Privacy Policy

M5wallet is self-custodial software. The design goal of this policy is that there is very little to write about, because the application is built so that we do not hold what would otherwise need protecting.

This document was drafted in good faith for a self-custodial wallet and follows common practice in this sector, but it has not been reviewed by a lawyer and two items are still unset: the legal entity that publishes M5wallet, and the governing jurisdiction. Have counsel complete and review it before launch.

M5wallet is published by [LEGAL ENTITY NAME AND REGISTERED ADDRESS — to be completed].

The English version of this document is the authoritative one. Translations are provided for convenience; if they conflict, the English text governs.

Who is responsible

The controller for any personal data described here is the entity that publishes M5wallet. Because the product is self-custodial, the amount of personal data involved is deliberately small — the sections below describe all of it.

Key material

We never receive your private key, because no private key is ever assembled. In a Fast Vault, our co-signer service stores one key share, encrypted with AES-256-GCM under a password that you choose and we do not store. That share cannot sign on its own and cannot be decrypted by us. In a Secure Vault, both shares are held on your own devices and we hold none. Ceremony traffic passing through our relay is encrypted end to end between the two parties.

What the services receive

Operating the wallet requires our services to receive some data in the ordinary course: blockchain addresses and transaction data when balances are fetched or a transaction is broadcast; swap parameters when a quote is requested; and standard server request metadata such as IP address, user agent and timestamp, which web servers record by default.

Sign-in

If you use Google sign-in, we receive the identifiers that Google returns for authentication. We use them to associate your session with your vault. We do not receive your Google password.

This website

To choose an initial language, this site checks for a country header from any content delivery network in front of it, and otherwise performs a geolocation lookup of your IP address using the third-party service ipapi.co. The result is cached by network prefix rather than by full address, and the lookup is skipped entirely once you have chosen a language, because your choice is stored in a NEXT_LOCALE cookie and always takes precedence. That cookie and your light or dark theme preference are the only things this site stores in your browser. There is no advertising or cross-site tracking on this site.

Legal bases for processing

Where the GDPR or UK GDPR applies, we rely on: performance of a contract, for the data required to operate the wallet you asked us to run (blockchain queries, swap quotes, sign-in); legitimate interests, for keeping the services secure, preventing abuse and diagnosing faults from server logs; and consent, where you have given it, which you may withdraw at any time. We do not rely on consent for anything the wallet needs in order to function.

How long data is kept

Server request logs are retained for a short operational period and then rotated out. A Fast Vault key share is stored for as long as the vault exists, because deleting it would destroy your ability to sign; it is removed when you delete the vault. Sign-in identifiers are kept while your session association exists. We do not build long-term behavioural profiles.

International transfers

Our services run on infrastructure that may be located outside your country, and the geolocation lookup described above sends your IP address to a third-party provider that may process it elsewhere. Where such a transfer involves personal data of people in the EEA or UK, it is made on the basis of appropriate safeguards such as the Standard Contractual Clauses.

How data is protected

Traffic to our services is encrypted in transit with TLS. Ceremony messages passing through our relay are additionally encrypted end to end between the two parties, so the relay carries ciphertext it cannot read. A Fast Vault share at rest is encrypted with AES-256-GCM under your password, which we do not store. Access to production systems is restricted. No system is perfectly secure, and we do not claim otherwise.

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent. To exercise any of these, contact us at the address below. You also have the right to complain to your local data protection supervisory authority. If you are a California resident, we do not sell or share personal information as those terms are defined by the CCPA and CPRA, and we do not discriminate against you for exercising your rights.

Your choices

You can use a Secure Vault so that no share is held by us at all. You can clear this site's cookies at any time. For questions about data we hold, contact us at the address below.

Children

M5wallet is not directed at children and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.

What we do not do

We do not sell personal data. We do not run advertising networks or cross-site trackers in the wallet. We do not ask for your Fast Vault password, your vault backup or any share material, and no member of our team will ever request them.

Changes

If this policy changes materially, the date at the top of this page changes with it.

Contact

Questions about this document, or requests concerning your data, can be sent to the project team at the address published on this site. We aim to respond within 30 days.