← Back to home

Privacy Policy

Last updated: March 28, 2026 · Designed with GDPR & CCPA principles in mind

1. Data We Collect

Account data: Email address, hashed password, 2FA settings.

On-chain data: Public wallet address, transaction hashes. On-chain data is public by nature of blockchain technology.

Usage data: App interaction logs for security purposes (IP hash, device fingerprint, session duration).

We do NOT collect: Private keys, seed phrases, personal financial information beyond what you voluntarily provide.

2. How We Use Data

3. Data Retention

Account data is retained while your account is active and for 5 years after deletion for legal compliance. On-chain data is permanent by nature of blockchain technology.

4. Your Rights (GDPR / CCPA)

Access

Request a copy of all personal data we hold about you

Rectification

Correct inaccurate personal data in your account

Erasure

Delete your off-chain account data (on-chain data cannot be deleted)

Portability

Download your account data in machine-readable format

Object

Opt out of analytics and marketing communications

Withdraw Consent

Withdraw consent for non-essential data processing at any time

5. Data Requests

Email privacy@cashmereum.com to exercise any of the above rights. We respond within 30 days. For GDPR erasure requests, we will delete all off-chain data. On-chain data is permanent and cannot be erased — this is disclosed at registration.

6. Cookies

Essential cookies (cannot be disabled): Authentication session, CSRF protection.

Analytics cookies (optional): Pseudonymised usage analytics to improve the app.

7. Security

We use AES-256-GCM encryption, TLS 1.3, and quantum-resistant cryptography for all data at rest and in transit. An independent third-party security audit is planned ahead of mainnet; none has been completed yet. See our Security page for details.

8. Contact

Data Protection Officer: dpo@cashmereum.com