Legal
Privacy Policy
Last updated
mallow labs LLC ("mallow," "we," "us," or "our") values your privacy. This Privacy Policy describes what information we collect when you use the mallow wallet mobile application (the "App") or visit wallet.mallow.art (the "Site," and together with the App, the "Services"), how we use it, with whom we share it, and the choices and rights you have. By using the Services, you agree to the practices described in this Privacy Policy.
This document is a wallet-specific policy. It is not the privacy policy for the mallow marketplace at mallow.art, which is governed separately. Some features in the App open mallow.art in your browser; once you leave the App, the marketplace's own policy applies.
1. Who we are
The data controller is:
- mallow labs LLC
- 30 N Gould St Ste R, Sheridan, WY 82801, USA
- Privacy contact: legal@mallow.art
2. App privacy at a glance (Apple App Store nutrition)
The categories below mirror Apple's App Privacy disclosures — and the Google Play Data Safety form, which carries the same answers — so you can see at a glance what the App does and does not collect.
| Category | What we collect | Linked? | |---|---|---| | Data Used to Track You | None | — | | Contact Info — Name | Display name, username, and handle on your profile, if you set them | Linked | | Contact Info — Email Address | An email address, only if you choose to add one to your profile and verify it with a one-time code. The wallet works fully without one. | Linked | | Contact Info — other (phone, physical address) | None | — | | Identifiers — User ID | Your public wallet address. Used for authentication, push notification routing, scrubbed diagnostics keying, and standard server logs. | Linked | | Identifiers — Device ID | A random identifier the App creates for itself the first time you open it and keeps in your device's secure storage. It lets us count how many people use a feature without knowing who they are. It is not the IDFA, IDFV, or any advertising identifier — we never read those. | Linked | | Identifiers — Advertising ID | None | — | | User Content — Photos or Videos | Avatar and banner images you upload to your profile, and any image you choose to mint as an NFT. NFT mint images are stored publicly on IPFS and are permanent. | Linked | | User Content — other | Bio, social links, curations you assemble, NFT mint metadata (title, description, royalty settings), and the optional note you can attach when reporting content | Linked | | User Content — emails, audio, customer support, gameplay | None | — | | Purchases | Whether a purchase, sale, bid, or offer completed or failed, together with the collection involved and the approximate USD value, recorded in product analytics. These are on-chain transactions — there are no in-app purchases, and we never see a card, bank account, or payment method. | Linked | | Financial Info — Other Financial Info | The approximate USD value and the token symbols of transactions you complete, recorded in product analytics. We never receive your seed phrase, private keys, payment cards, or account credentials, and we do not collect or retain your balances or holdings. | Linked | | Financial Info — Payment Info, Credit Info | None | — | | Usage Data — Product Interaction | Which actions you start, complete, or fail — creating or importing a wallet, sending, swapping, transferring or burning an NFT, minting, listing, buying, bidding, making an offer, staking — plus when you open the App, and changes to your network, display currency, and analytics settings. | Linked | | Usage Data — Advertising Data, other | None | — | | Diagnostics — Crash Data | Stack traces from caught and uncaught exceptions, with seed phrases, private keys, PINs, bearer tokens, and raw wallet addresses scrubbed before transmission. Sent to mallow's self-hosted error-tracking service — no third-party processor. | Linked | | Diagnostics — Performance Data | A 10% sample of transaction timings and span data, scrubbed on the same rules as crash data | Linked | | Diagnostics — other | Breadcrumbs the App records around an error to give it context, scrubbed on the same rules | Linked | | Browsing History | None — we do not record which artworks, collections, or profiles you view | — | | Search History | None — marketplace search is not retained against your wallet | — | | Health & Fitness | None | — | | Location | None — see "On the Android location permission" below | — | | Sensitive Info | None — we do not solicit sensitive categories; please do not put them in your bio | — | | Contacts (OS address book) | None | — | | Surveys, Environment Scanning, Other Data | None | — |
On product analytics. The App records the actions listed above so we can see which parts of the App work and which break. They go to our own systems first, and from there to Mixpanel, the analytics provider that processes them for us. The record of an action does not carry your wallet address — but you are signed in when you take it, so we could connect the two. That is why these rows are marked Linked. You can turn this off at any time in Settings → Security & Privacy → "Share usage analytics". The same switch also stops diagnostics. Anything still waiting on your device when you switch it off is thrown away rather than sent.
On "Linked". The wallet address is the de-facto account identifier across mallow infrastructure. Even when individual data points (a redacted identifier in a crash report, a push token paired with a session) are themselves anonymized, they remain Linked because the same authenticated wallet session ties them to your wallet address. We chose to disclose this plainly rather than fragment the row.
On Purchases and Financial Info. Your trades happen on public blockchains, not through us — we are not a broker, and no money passes through mallow. We disclose these two categories anyway because our analytics record that a purchase or swap happened and roughly what it was worth. We would rather tell you about that than publish a label that looks tidier than the truth.
On diagnostics destination. Crash, performance, and breadcrumb data are sent to mallow's self-hosted error-tracking service running on mallow infrastructure. They are not shared with Sentry, Firebase Crashlytics, or any other third-party processor.
On the Android location permission. Android 11 and older will not let an app search for nearby Bluetooth devices unless it also asks for location permission. The App asks for it on those versions for one reason: to find your Ledger hardware wallet. On Android 12 and newer it does not ask at all, because those versions let us declare that the Bluetooth search is not being used to work out where you are. The App never requests, reads, works out, or sends your location.
On Reown social sign-in. If you create a wallet via Google or Apple sign-in, the third-party identity provider receives your authentication signals. Your social-account email and password do not reach mallow. See Section 3.4 and Section 4 for what Reown itself handles.
3. Information we collect
3.1 Information stored only on your device
The following is created and stored locally on your device. It is never transmitted to mallow:
- Your recovery phrase (12 or 24 words) and derived private keys, held in iOS Keychain or Android Keystore
- Your PIN and biometric-unlock preferences
- Your address book entries — nicknames you assign to wallet addresses for sending
- Your wallet labels and account nicknames
- Your watchlist and favorites (artworks, tokens, artists)
- Your app preferences, including theme, currency, chain toggles, push toggle, analytics opt-out, and biometric preference
These never sync to mallow servers and are not included in any remote backup. On iOS, your seed phrase and private keys are stored so that they can only be read on the device that created them, while it is unlocked. They are not copied to iCloud.
3.2 Information generated automatically when you use the App
- Public wallet addresses for the chains you use (Solana, Ethereum, Tezos)
- On-chain activity initiated by you (transactions, balance reads, swap quotes). On-chain activity is by nature public and visible on the underlying blockchain
- Push notification token, if you grant push permission, registered with our notification service so we can deliver app notifications
- Product analytics — a record of the actions listed in Section 2. Each record carries the random device identifier described above, your operating system and its version, the App's version, your device model, the network you are using, and an identifier for the current sitting that resets after 30 minutes of inactivity. If you are offline, records wait on your device; if you opt out before they are sent, they are discarded rather than sent. The App does not record which screens, artworks, collections, or profiles you view.
- Diagnostic data — crash reports, a 10% sample of performance traces, and breadcrumbs recorded around an error — scrubbed of seed phrases, private keys, PINs, bearer tokens, and raw wallet addresses before transmission. This data is sent to a mallow-operated, self-hosted error-tracking service running on mallow infrastructure. It does not reach Sentry, Firebase Crashlytics, or any other third-party processor.
Product analytics and diagnostics are both governed by the single "Share usage analytics" switch in Settings → Security & Privacy.
3.3 Information collected on this Site
wallet.mallow.art does not use cookies, run analytics, or load any third-party scripts. Your browser may transmit standard HTTP request metadata (IP address, user agent, referer) to Cloudflare, our hosting provider, for the purpose of delivering the Site. See our Cookie Policy.
3.4 Information from third-party sign-in (optional)
If you create a wallet using social sign-in (Google or Apple) via Reown AppKit, the third-party identity provider will share authentication signals necessary to create your embedded wallet. mallow does not receive your social-account email, identifier, or password. The sign-in provider's privacy policy and Reown's privacy policy each apply to the data they handle.
3.5 Your profile (optional)
Creating a mallow profile is optional; the wallet works without one. Some social and marketplace features require one, and the App will tell you when that is the case. If you create a profile, we store on our servers whatever you choose to provide:
- Username and handle, display name, and bio
- Avatar and banner images you upload
- Social links (X/Twitter, Instagram, YouTube, website)
- Additional wallet addresses you link to the profile
- Curations you assemble, and the accounts you follow
- An email address, only if you add one and verify it with a one-time code we send to it. We use it to contact you about your account; it is not shown on your public profile
Your profile is public by default. Your username, display name, bio, images, social links, linked addresses, curations, follower counts, and the artworks held by your linked addresses are visible to anyone in the App and on mallow.art. Do not put anything in a profile field that you would not want published.
3.6 Reports and blocks
If you report an artwork, curation, or account, we receive the item you reported, the reason you selected, any note you write, and the part of the App you reported it from. If you block an account, we store that block against your profile so we can filter that account out of your view. See our Acceptable Use Policy for how reports are handled.
3.7 Device permissions the App asks for
The App asks your operating system for the permissions below. In every case the data stays on your device or goes only where the feature obviously requires — none of it is collected by mallow.
| Permission | Why | Where the data goes | |---|---|---| | Camera | Scanning QR codes (recipient addresses, hardware-wallet payloads) | Decoded on-device; nothing is uploaded | | Photo library (read) | Choosing an avatar, banner, or an image to mint | The image you pick — and only that image — is uploaded when you confirm | | Photo library (add) | Saving artworks you own to a "mallow" album | Written to your device only | | Bluetooth | Connecting to a Ledger hardware wallet | Direct device-to-device; nothing reaches mallow | | Local network + Bonjour | Discovering Chromecast and Android TV devices to cast artwork to | Discovery stays on your network; the cast device fetches the artwork itself | | Notifications | Delivering push notifications you opt into | See Section 4 (Firebase Cloud Messaging) | | Face ID / biometrics | Unlocking the wallet and authorizing transactions | Handled entirely by iOS/Android; mallow never sees biometric data |
4. Third-party services
The App relies on the third-party services listed below. Each has its own privacy practices, which apply to data they receive. We have configured the App to share only what is necessary to provide the feature.
mallow operates its own diagnostics service on its own infrastructure; no third-party error-tracking processor is used.
| Service | Used for | What it receives | |---|---|---| | api.mallow.art | Marketplace listings, profiles, and preparing transactions for you to sign. First-party — operated by mallow | Public wallet address; profile data you provide; what you asked to see | | rpc.mallow.art | Our own relay for blockchain requests. The App talks to it, and it passes requests on to the providers below. First-party — operated by mallow | Your public addresses and the blockchain requests the App makes | | Helius | Reading Solana balances and assets, and submitting your Solana transactions. Reached through rpc.mallow.art | Your wallet's public addresses, the tokens you look up, transactions you submit | | Alchemy | Checking what an Ethereum transaction would do before you sign it, so the App can stop one that would move the wrong asset. Reached through rpc.mallow.art | The unsigned transaction, including sender and recipient addresses | | Infura | Estimating Ethereum network fees. Reached through rpc.mallow.art | Fee queries; no address | | publicnode.com (Allnodes) | Default public Ethereum node for balance reads and tracking pending transactions | Your Ethereum address and your IP address | | TzKT | Public Tezos node and indexer — balances, fee simulation, and broadcast | Your Tezos address, transactions you broadcast, and your IP address | | Jupiter | Token swap quotes and routing on Solana | Wallet address, input/output token mints, amounts | | Mixpanel | Processing product analytics for us. Records reach Mixpanel through our own systems, never straight from the App. Nothing is sent at all if you opt out | The actions in Section 2, identified only by the random device identifier | | Firebase Cloud Messaging (Google) | Push notification delivery | Device push token; the content of notifications | | Reown AppKit | Optional social sign-in (Google/Apple) for embedded wallet | Your social-account identifier as needed to provision an embedded wallet | | IPFS (pin.mallow.art) | NFT metadata and image pinning when you mint | Public NFT metadata and images you submit — permanent and public | | Public IPFS and Arweave gateways | Fetching NFT media that is not served from our CDN | Your IP address and the content identifier requested | | Mux | Video playback for artworks published as video | Your IP address and the video requested | | Google Cast | Discovering and casting artwork to Chromecast / Android TV | Device discovery on your local network; the cast device fetches the artwork directly | | Cloudflare | Hosting and CDN for wallet.mallow.art, our APIs, and images | Standard request metadata (IP, user agent) | | Apple / Google | App distribution, push transport, and the in-app "rate this app" prompt | Whatever the platform collects under its own policy |
Block explorer links (Solscan, Solana Explorer, Solana Beach, Etherscan, TzKT, Orb) open in your browser rather than in the App. Once you follow one, that site sees your IP address and the address or transaction you looked up, under its own privacy policy.
We do not sell, rent, or trade your information.
5. How we use information
We use the limited information we collect to:
- Operate, maintain, and secure the Services
- Display your profile and the content you publish
- Deliver push notifications you have opted into
- Diagnose crashes and improve reliability via scrubbed diagnostic reports sent to mallow's self-hosted error-tracking service
- Understand which features are used and which fail, via the product analytics described in Sections 2 and 3.2, so we can prioritise fixes
- Review reports and enforce our Acceptable Use Policy
- Communicate with you when you contact us, or about your account if you have verified an email address
- Comply with legal obligations and enforce our Terms of Service
We do not perform behavioral advertising, do not build advertising profiles, and do not use your information to train AI models.
6. How long we keep data
- On-device data (seed phrase, keys, PIN, preferences): retained on your device until you uninstall the App or wipe the device
- Profile data (username, display name, bio, images, social links, curations, follows, verified email): retained until you delete your account, then removed from our systems
- Push tokens: retained while the App is installed; revoked when you uninstall or disable push
- Product analytics: retained by Mixpanel for up to 24 months, then deleted. The random device identifier lives on your device and is gone when you uninstall the App
- Diagnostics (crash reports, performance traces, breadcrumbs): retained on mallow's self-hosted error-tracking service for up to 90 days, accessible only to authorized mallow engineers, and pruned on a rolling basis
- Reports and blocks: retained while your account exists, and after account deletion where we need them to enforce our policies or meet a legal obligation
- Site request logs: retained by Cloudflare per its standard logging retention
7. How we share information
We share information only as described in this Policy. Specifically:
- Service providers listed in Section 4, only to provide the Services
- Legal disclosures when required by law, lawful process, or to protect the rights, property, or safety of mallow or others
- Business transfers in the event of a merger, acquisition, or sale of assets, in which case we will notify you and provide reasonable notice before your information becomes subject to a different policy
8. Your choices and rights
You can:
- Turn off analytics and diagnostics at Settings → Security & Privacy → "Share usage analytics". One switch stops both pipelines immediately, and discards anything still queued on your device
- Decline push notifications in your device settings
- Block accounts you do not want to see, and manage the list at Settings → Security & Privacy → Blocked accounts
- Edit or clear your profile at any time, including removing a verified email address
- Delete your mallow account at Settings → Security & Privacy → Delete account. See below for exactly what this does and does not remove
- Disable optional social sign-in by creating a wallet from a seed phrase instead
- Delete the App to remove all on-device data; this is irreversible — we cannot recover your wallet for you
- Contact us at legal@mallow.art for any request not handled by the controls above
What account deletion removes
Deleting your account removes your profile and the data attached to it from our systems: username, display name, bio, avatar and banner images, social links, verified email address, curations, follows, and linked addresses. Your local session is torn down at the same time.
Some things cannot be removed by us, and you should understand this before you rely on deletion:
- On-chain data is permanent. Every transaction you have made, and every asset you hold, remains on the public blockchain forever. Deleting your account does not and cannot erase it
- Minted NFT images and metadata are permanent. Anything you have minted is pinned to IPFS and is public and immutable by design
- Your wallet is unaffected. Deleting your mallow account does not delete your wallet, keys, or funds — it removes your profile, nothing more
- Backups, diagnostics, and analytics age out on the schedules in Section 6 rather than being deleted on the spot
- Reports and blocks may be retained where we need them to enforce our policies or meet a legal obligation
9. EEA and UK users (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights with respect to personal data we hold about you, subject to applicable law:
- Access — confirm whether we process your personal data and request a copy
- Rectification — correct inaccurate data
- Erasure — request deletion in certain circumstances
- Restriction — limit how we use your data
- Objection — object to processing based on legitimate interests
- Portability — receive your data in a portable format
- Withdraw consent at any time where consent was the basis for processing
- Lodge a complaint with your local data protection authority
Lawful bases. Where we rely on a legal basis under Article 6(1) GDPR, it is one of the following:
| Processing | Basis | |---|---| | Operating the wallet and the profile you asked for | Performance of a contract | | Security, abuse prevention, and handling reports | Legitimate interests | | Crash and performance diagnostics | Legitimate interests — you may opt out at any time in Settings | | Product analytics | Legitimate interests in understanding which features work and which fail — you may opt out at any time in Settings | | Push notifications | Consent (the OS permission prompt) | | Retaining records to meet a legal obligation | Legal obligation |
Analytics and diagnostics are on by default and controlled by a single opt-out switch in Settings → Security & Privacy. We do not use them to profile you, to advertise to you, or to make any decision about you.
International transfers. Some of our service providers are based in the United States. We rely on appropriate transfer mechanisms (Standard Contractual Clauses or equivalent) where required.
EU representative. If you require an EU representative under Article 27 GDPR, please contact us at legal@mallow.art and we will provide current designation information.
To exercise any right, email legal@mallow.art. We will respond within the timeframes required by applicable law.
10. California residents (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what categories of personal information we collect, the purposes, and the categories of recipients
- Access the specific pieces of personal information we hold about you
- Delete personal information, subject to legal exceptions
- Correct inaccurate personal information
- Opt out of sale or sharing of personal information for cross-context behavioral advertising
- Limit use of sensitive personal information
- Non-discrimination for exercising your rights
We do not sell personal information and we do not share personal information for cross-context behavioral advertising. Because the Site uses no cookies and no analytics, there is nothing to opt out of with respect to this Site. The App's product analytics are not a sale or a share — the data goes to a processor acting on our instructions, not to an advertiser — and you can switch them off in Settings regardless.
To exercise California rights, email legal@mallow.art with the subject "California Privacy Request." We will verify your request using the wallet address you provide and respond within the statutory timeframe.
11. Children's privacy
The Services are intended for users 18 years of age or older, or the age of majority in their jurisdiction, whichever is greater. We do not knowingly collect personal information from anyone under 13 (or under the equivalent age in jurisdictions outside the United States). If you believe a child has provided us with personal information, contact us at legal@mallow.art and we will delete it promptly.
12. Security
We design the App to minimize data exposure: your seed phrase is encrypted at rest using your device's secure enclave, never transmitted to mallow, and not visible to any cloud backup. Network requests use TLS. We follow industry-standard practices to protect the limited data we do receive.
No system is perfectly secure. You are responsible for protecting your device, your seed phrase, and the access methods you use to unlock the App. See our Security guide for recommended practices.
13. Changes to this Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects when changes took effect. Material changes will be surfaced in the App or on the Site. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.
14. Contact
Questions about this Privacy Policy or our handling of your information?
- mallow labs LLC
- 30 N Gould St Ste R, Sheridan, WY 82801, USA
- legal@mallow.art