Privacy Policy

This policy explains what information Salmon Wallet processes, why it uses it, who receives it, and what control the user retains.

Last updated: September 1, 2026

1. Controller and scope

GeekOcean Labs Ltd, a company incorporated in the British Virgin Islands (“Salmon”, “we”, “us”, or “our”), is the controller responsible for the processing described in this Privacy Policy.

This Policy applies to https://www.salmonwallet.io (the “Site”), the mobile application, browser extension, and the features Salmon makes available through them (together, the “Services”).

This Policy is a notice and does not turn use of the Services into consent for processing that requires an affirmative choice. Where consent is required, we request it separately.

For questions or to exercise privacy rights, write to help@salmonwallet.io.

2. Self-custody and data that stays on the device

Salmon is a self-custodial wallet. Private keys and the recovery phrase are generated and stored encrypted on the user’s device. The Wallet does not transmit them to Salmon, and Salmon does not request, intentionally collect, store, or reconstruct them. Salmon cannot access Digital Assets, recover a Wallet, reverse a transaction, or block someone who obtains the keys.

The Wallet does not require an account, registration, name, email address, or identity verification to create or import a wallet.

If you enable biometric protection, the operating system performs verification and tells the Wallet only whether it succeeded. Salmon does not receive a face, fingerprint, or biometric template. When you scan a QR code, the image is processed on the device and is not sent to Salmon.

Technical providers used to query blockchain networks or broadcast a transaction do not receive your private keys or recovery phrase from Salmon. Every transfer is reviewed, authorized, and signed by the user on the user’s device before it is broadcast.

3. Information we process

Information you provide

We receive your email address and message content when you request support, exercise a right, or contact us. The Wallet does not obtain that email automatically or link it to a wallet unless you voluntarily include that information. Do not send private keys or recovery phrases; Salmon does not need them to provide support.

Public blockchain information

To display balances, transactions, assets, and digital collectibles, the Wallet queries public information associated with blockchain addresses. Addresses and transactions are pseudonymous but may be personal data when they can be linked to a person. Blockchains are public networks independent of Salmon. Salmon cannot change or delete information recorded on them.

Technical requests and operational logs

When a request passes through Salmon infrastructure, we may process its IP address, date, time, request type, technical response information, and any blockchain address or transaction data included in it.

We use this information to deliver the response, apply rate limits, maintain security, detect abuse, and diagnose failures. Request logs stored in Amazon CloudWatch are retained for 30 days and then deleted under the retention configuration, unless they must be preserved longer to investigate an incident or comply with law.

Salmon does not create personal profiles or per-account histories from these logs. During retention, however, one log entry may contain both an IP address and the blockchain address queried.

Site data and cookies

The Site may process basic technical information needed to deliver pages and protect infrastructure. Google Analytics activates only after the visitor accepts analytics cookies. If the visitor does not accept, the Site does not load Google Analytics.

When enabled, Google Analytics may process cookie identifiers, IP address, browser and device type, pages viewed, links used, referring site, and approximate visit duration. Visitors can withdraw consent through Site cookie settings or remove cookies in the browser. Rejecting analytics does not prevent essential use of the Site.

Optional analytics inside the Wallet

Usage analytics in Wallet applications are off by default. They start only after an affirmative choice during onboarding or in Settings and can be disabled at any time.

When enabled, analytics use a random installation identifier separate from wallet addresses and identity; transmit only an allow-listed set of events and technical properties; prohibit keys, recovery phrases, blockchain addresses, balances, and exact amounts; use only a broad range when an event needs an amount reference; send events first to Salmon and then server-to-server to Google Analytics 4; and do not place a Google SDK, cookie, or advertising identifier in the Wallet. Google does not receive the user’s IP address through that server-side forwarding.

Withdrawing consent stops collection and deletes the installation identifier. Earlier aggregated events cannot be linked to a future installation.

4. How Wallet features use data

Balances, Activity, and Collectibles

Salmon uses infrastructure providers to query balances, histories, and digital collectibles recorded on blockchain networks. Depending on network, availability, and request type, they include Triton One, Helius, and Blockdaemon for Solana and Bitcoin data.

These queries may include a blockchain address because the provider needs to know which public information to return. When a request passes through Salmon infrastructure, the provider may receive the queried address and Salmon may record the technical data described in section 3. When the device connects directly, the provider may also receive the user’s IP address. Salmon does not control records created by an independent provider under its own policy.

Names, images, and files associated with tokens or Collectibles may be obtained from asset registries or public content gateways. Those services may receive the IP address and public identifier of the requested content.

Market information

Salmon uses CoinGecko to obtain general market information. Requests made by Salmon infrastructure identify an asset, currency, or period, but do not deliberately include the Wallet address, balances, or transfer amount.

Sending assets

Every transfer is initiated and signed on the user’s device. To broadcast it, the Wallet sends the signed transaction data to the relevant network, either directly or through Salmon infrastructure and a technical provider. The provider may receive the signed transaction and, on a direct connection, the IP address. A signed transaction contains public information needed by the network, but does not contain the private key or recovery phrase.

Salmon does not keep an account history because the Wallet does not require an account. Data may appear temporarily in 30-day operational logs when a request passes through Salmon infrastructure. Blockchains and independent providers may keep their own records for different periods.

5. Purposes and legal bases

We do not use Wallet data for targeted advertising, credit evaluation, or sale of personal information. We do not deliberately link optional analytics to blockchain addresses, keys, balances, or user identity.

  • Providing the Services: responding to requests, displaying requested public information, broadcasting transactions signed by the user, and providing support. Where applicable, the basis is performance of the Terms and Conditions or taking action at the user’s request.
  • Security and operations: applying limits, preventing abuse, investigating errors, and protecting systems and users. The basis is our legitimate interest in operating a secure service, balanced against user rights.
  • Optional analytics: understanding Site or Wallet operation and use when the user has consented. Consent may be withdrawn at any time.
  • Compliance and claims: complying with legal obligations, responding to valid requests, and establishing, exercising, or defending rights. The basis is legal obligation or legitimate interest, as applicable.

6. Who receives information

Providers processing information on Salmon’s instructions must use it to provide the contracted service and protect it appropriately. Blockchain networks, providers receiving direct connections, and other independent services may process information under their own policies.

We do not sell personal information or share it for cross-context behavioral advertising.

  • Blockchain and market providers, including Triton One, Helius, Blockdaemon, and CoinGecko.
  • Amazon Web Services, including CloudWatch logging infrastructure.
  • Google Analytics 4, only for the analytics described in this Policy.
  • Professional advisers, authorities, or courts when necessary to comply with law or protect rights.
  • A successor in a merger, acquisition, reorganization, or asset transfer, subject to confidentiality and legally required notices.

7. Retention and deletion

Backups may retain data for a limited additional period before being overwritten. Information recorded on a blockchain or held by an independent third party cannot be deleted by Salmon.

  • CloudWatch request logs: 30 days, unless preservation is needed for an incident or legal obligation.
  • Correspondence and support: while the matter is open and afterward for the time needed for follow-up, security, claims, or legal obligations.
  • Consent preference: stored locally while needed to remember the choice and changeable through the relevant settings.
  • Wallet analytics installation identifier: until the user withdraws consent or deletes application data.
  • Analytics events: for the period configured in Google Analytics 4 and, where applicable, afterward in aggregated form or without a link to an active installation.

8. International transfers

Salmon is incorporated in the British Virgin Islands; its infrastructure operates primarily in the United States; and the named providers may process information in other countries whose protections may differ from those where you live.

Where law requires safeguards for a transfer under Salmon’s control, we use recognized mechanisms, contractual commitments, or other appropriate measures. Transfers inherent in a public blockchain or initiated directly by the user to a third party are also governed by that network architecture or third party’s policy.

9. Security

Salmon applies reasonable technical and organizational measures to protect information it controls against loss, unauthorized access, alteration, or disclosure. No system or transmission can guarantee absolute security.

Self-custody limits the data and funds Salmon can protect: security of your device, password, private keys, and recovery phrase is your responsibility. Salmon cannot detect or remedy use by someone who obtains them.

10. User rights and choices

Depending on applicable law, you may request access, a copy, correction, deletion, restriction of or objection to processing, and portability of certain data. You may withdraw consent without affecting earlier lawful processing and may complain to the competent data-protection authority.

To exercise a right, write to help@salmonwallet.io. We may request reasonable information to verify identity and scope. We will respond within the applicable legal period and explain any limitation.

Salmon can act only on information under its control. We cannot identify Wallet data from a person if we never received that link, erase a public blockchain, or delete records independently controlled by a third party.

11. Children

The Services are not directed to minors, and Salmon does not knowingly collect personal information from children. If you believe a child provided information, write to help@salmonwallet.io so we can investigate and delete it where appropriate.

12. Third-party services and links

This Policy governs only processing by Salmon. Sites, applications, blockchains, protocols, app stores, and independent providers maintain their own rules. Review them before using those services.

Apple and Google may process information relating to downloads, updates, or use of their stores under their own policies. Salmon does not necessarily receive all information those platforms collect.

13. Changes to this Policy

Salmon may update this Policy for legal, technical, or operational changes. We will publish the current version and date. If a change materially affects processing of information already collected, we will provide legally required notice and request new consent where appropriate.

14. Contact

The controller is GeekOcean Labs Ltd, British Virgin Islands. For privacy questions, complaints, or requests, write to help@salmonwallet.io.