Privacy Policy
Effective October 6, 2026
Sendy ("Sendy", "we", "us") makes a mobile wallet for sending, receiving and holding stablecoins on Ethereum and other EVM networks, Solana and Tron. This policy explains what information we collect when you use the Sendy app and website, why we collect it, who we share it with and the choices you have.
The short version: Sendy is a self-custody wallet. We never hold your money and we cannot move it. We collect what we need to run the service and keep it safe, we do not sell your data, and we do not use it for advertising or to track you across other apps and websites.
How your wallet works
When you create an account, a wallet is created for you with Turnkey, a key-management provider. The private keys are generated and kept inside Turnkey's secure hardware, in a space that only your passkey can authorise. Sendy's servers hold no credential that can sign for your wallet, so we cannot spend, freeze or recover your funds.
Your passkey is created with Face ID or Touch ID on your device and is synced by Apple (iCloud Keychain) or Google (Google Password Manager). We never receive your biometric data — it stays on your device.
You can reveal your wallet's recovery phrase in the app (Manage wallet → Reveal recovery phrase) and move it to any other wallet at any time.
Information we collect
Information you give us or create in the app:
- Account details from Sign in with Apple or Google: your name, email address and the provider's account identifier. If you use Apple's "Hide My Email", we receive the relay address.
- Profile details you choose: your @handle, display name and profile photo.
- People features: the people you add, requests you send or accept, people you block or report, and the messages you send in chats.
- Money links and payment requests you create: the amount, asset, network, memo and expiry.
- Messages you send to support.
Information created when you use the wallet:
- Your public wallet addresses on each supported network, and their balances.
- Transaction details: amounts, assets, networks, recipient and sender addresses, fees, quotes, routes, status and timestamps. Transactions on a blockchain are public by nature.
Information collected automatically:
- Device and app information: device model, operating system and version, app version, language and a push-notification token if you turn notifications on.
- Session and security information: which devices are signed in, sign-in times and the IP address of requests to our servers.
- Usage and diagnostic information: the screens you open, the features you use and error and crash reports. We link it to your account identifier so we can fix problems you run into. Before it is sent, we strip fields that look like email addresses, wallet addresses and keys. We do not record your screen.
Device permissions, each asked for only when you use the feature:
- Camera — to scan QR codes. Images are read on your device and never stored or uploaded.
- Photos — only to pick a profile photo you choose to upload.
- Notifications — to tell you about payments and requests.
- Face ID / Touch ID — to unlock the app and approve payments. Handled entirely by your device.
We do not read your phone's address book, we do not collect precise location, and we do not use your device's advertising identifier.
How we use information
- To run the wallet: show your balances and activity, find a route for a payment, quote its fees, submit it and track it until it arrives.
- To run the people features: let others find you by @handle, deliver requests and messages, and show money links.
- To keep the service safe: detect fraud and abuse, protect accounts, enforce our Terms, and act on reports.
- To meet legal obligations, including sanctions screening (see below).
- To provide support and to send you service messages and notifications you turned on.
- To understand how the app is used and to fix bugs and improve it.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use it to track you across apps or websites owned by other companies.
Sanctions screening
Before a payment is sent, Sendy checks the destination address against public sanctions lists, including the U.S. Treasury OFAC Specially Designated Nationals list. We keep a record of each check (your account identifier, the address, the network, the result and the time). A payment to a listed address is refused.
Who we share information with
We share information only as needed to run the service, with:
- Turnkey — wallet key infrastructure and passkey authentication.
- Apple and Google — when you sign in with them.
- Blockchain networks and node providers (such as QuickNode, TronGrid and Etherscan) — to read balances and submit your transactions. Anything submitted to a public blockchain is visible to everyone and cannot be deleted.
- Payment routing providers — when a payment crosses networks or converts between assets, the route provider receives the details it needs to execute it (addresses, amounts, assets and networks). Depending on the route these include Circle (CCTP and Gateway), deBridge, Relay, LI.FI, Across, CoW Protocol and Uniswap.
- Fee sponsors — when you choose to pay network fees in a stablecoin, the transaction is submitted by a relayer operated by Sendy or a provider such as Kora or Circle, which sees the transaction.
- PostHog — product analytics and crash reporting.
- Railway — the cloud host for our servers and database.
- Expo — delivery of push notifications.
- Other users — your @handle, display name and profile photo are visible to people who find or add you. A money link shows the amount, asset, memo, status and your first name and last initial to anyone who has the link; it never shows your wallet address or full handle.
- Authorities — when the law requires it, or to protect the rights, property or safety of our users, the public or us.
- A successor — if we are involved in a merger, acquisition or sale of assets, subject to this policy.
Our service providers may use the information only to provide their service to us.
How long we keep information, and deleting your account
We keep your information while your account is open. You can delete your account at any time in the app: open Settings (tap your photo on Home) and tap Delete. When you delete your account:
- Your wallets and their keys are deleted from Turnkey straight away. Any money still in them can no longer be reached by you or by us, so move your funds out (or reveal and save your recovery phrase) first.
- You are signed out, and the data we can rebuild (your list of wallet addresses, preferences and linked payment accounts) is removed at once.
- For 3 days the closure can be undone: if you sign back in from a device that is still signed in, your account record is restored (deleted wallets cannot be restored).
- After 3 days your identity is permanently erased: your name, email, profile photo, @handle, contacts, push tokens, sessions and sign-in links are deleted, and your app history is detached from you.
We keep some records after deletion, without your name or contact details attached: payment and transaction records (needed for accounting, compliance and dispute handling), sanctions-screening records, reports of abuse, and a block on your old @handle so nobody can impersonate you with it. Conversations you took part in may remain visible to the other participants. Information already recorded on a public blockchain cannot be deleted by anyone.
Usage and diagnostic data is kept for a limited period and then deleted or aggregated.
Security
Your keys stay in Turnkey's secure hardware and every payment needs your passkey. Your session on the phone is kept in the iOS Keychain or Android Keystore, all traffic is encrypted in transit, and you can see and sign out your other devices in the app. No system is perfectly secure, so please keep your Apple or Google account and your devices protected.
Your choices and rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, and to object to or restrict how we use it. You can change your profile in the app, turn notifications off in your device settings, and delete your account in the app. For anything else, email support@sendybank.com — we will verify that the request comes from you and respond within the time the law requires. You also have the right to complain to your local data-protection authority.
We process your information to provide the service you asked for (our contract with you), to meet legal obligations, and for our legitimate interests in keeping the service secure and improving it.
International transfers
Our servers and several of our providers are located in the United States. When we transfer personal information across borders, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.
Children
Sendy is only for people aged 18 or older. We do not knowingly collect information from anyone under 18. If you believe a child has given us information, email support@sendybank.com and we will delete it.
Changes to this policy
We may update this policy. When we do, we will change the effective date above, and for material changes we will tell you in the app before they take effect.
Contact us
Questions about privacy? Email support@sendybank.com.