1. About this policy
This Privacy Policy explains how LifeHash ("we," "us," or "our") handles information when you visit our website or use our wallet, identity, verification, and related services (the "Services"). For privacy questions or requests, contact support@xyo.network.
LifeHash lets you manage identity evidence using a browser wallet and the XYO Layer 1 blockchain. Some information stays on your device, some is processed by services you choose to use, and some becomes a permanent public record. This policy explains those differences. Independent wallets, identity providers, blockchain participants, and other third-party services have their own privacy practices.
2. Information used by the Services
- Information on your device. The browser wallet stores encrypted wallet and private identity data in your browser's database, together with a device-held encryption key. Browser storage also remembers preferences, such as your theme, and non-secret wallet state. Wallet secrets are processed locally; the Services are designed so that our servers do not receive your recovery phrase or private signing keys.
- Verification information. If you use an enabled email, phone, or account verification feature, the relevant connector and delivery or identity provider process information needed to perform it. This may include your email address, phone number, provider account identifier, authorization response, and verification result. A connector needs the destination address or number to deliver a code.
- Public blockchain information. Transactions may publish wallet addresses, signatures, salted commitments, object hashes, claim types, relationships between addresses, timestamps, and transaction metadata. Public storage and indexes may also hold public proof objects and encrypted data.
- Information you choose to share. A disclosure can reveal selected identifiers, proofs, and the information needed to verify them to its recipient. When you contact support, we receive your message, contact details, and any attachments you provide.
- Technical information. Website hosts, gateways, storage providers, and other endpoints you contact receive network information such as your IP address and request details. Depending on the service, operational logs may also include browser information, access times, errors, and security events.
Do not send recovery phrases, private keys, backup passwords, or unnecessary identity documents to support.
3. How information is used
Information is used to provide and maintain the Services, display and verify identity evidence, complete verification requests, submit and read transactions, respond to support inquiries, prevent abuse, investigate errors, protect the Services, and meet applicable legal obligations.
Where data protection law requires a legal basis, we process information as necessary to provide services you request, pursue legitimate interests in operating and securing the Services, comply with legal obligations, or act on your consent where required. You may withdraw consent for consent-based processing without affecting processing that was lawful before withdrawal.
4. Public records and selective disclosure
Blockchain records can be read, copied, indexed, and retained by people and organizations worldwide. LifeHash uses salted commitments and encrypted objects to keep raw identifiers out of its public identity records. These protections do not make all activity anonymous: addresses, transaction patterns, and information you disclose can allow records to be linked to you.
Withdrawing a claim changes its active status; it does not erase the original transaction or copies of it. We cannot remove records from independently operated blockchains or guarantee deletion by other participants. Deleting local wallet data also does not delete public records.
Review a disclosure before sharing it. A recipient can retain or redistribute information you reveal, and a later withdrawal cannot make the recipient forget it.
5. When information is shared
Information may be disclosed to:
- Service providers that support hosting, storage, security, support, and enabled verification or message delivery features, as needed to perform those functions.
- Identity providers, wallets, gateways, and recipients you choose to interact with.
- Blockchain participants and the public when you submit public transactions or publish information.
- Authorities or other parties when required by law, or where necessary to protect legal rights, address fraud or security threats, or protect people from harm.
- A successor operator in connection with a merger, acquisition, or transfer of the Services, subject to applicable law and required notice.
The LifeHash application does not include advertising trackers or functionality for selling personal information or sharing it for cross-context behavioral advertising. Independent services you use may have different practices.
6. Cookies and browser storage
The application uses local storage and IndexedDB to support the wallet, remember preferences, and maintain verification state. These technologies store information on your device. The application does not include advertising or analytics cookies; hosting and third-party services may use cookies or similar technologies under their own policies.
You can manage cookies and site storage through your browser settings. Clearing wallet storage can permanently remove your access to locally held keys and private data unless you have a usable backup. Keep a secure backup before clearing site data. Browser tracking preferences do not prevent network endpoints from receiving requests or remove information already published to a blockchain.
7. Retention and security
Local wallet data remains on your device until removed by you, the application, or your browser. Copies you export remain wherever you store or share them. Public blockchain history may remain available indefinitely.
For information under our control, retention depends on the purpose of collection, the time needed to provide support or operate a feature, security and abuse-prevention needs, and applicable legal requirements. Verification expiration does not necessarily mean deletion of related operational records. Independent providers set their own retention periods.
LifeHash uses encryption and local key custody to protect sensitive wallet information. No storage or transmission method is completely secure. Protect your device, browser, recovery phrase, and backups, and share information only with recipients you trust.
8. Your choices and privacy rights
You can choose whether to create a wallet, use optional verification services, publish transactions, or share disclosures. You can manage local data through the wallet and browser, and manage connected-account permissions with the relevant identity provider.
Depending on where you live and which laws apply, you may have rights to access, correct, delete, or obtain a portable copy of personal information; restrict or object to processing; withdraw consent; or opt out of certain uses or disclosures. You may also complain to your local data protection authority. We will not discriminate against you for exercising applicable privacy rights.
Send requests to support@xyo.network. We may need enough information to verify your identity and understand the request, but will not ask for your recovery phrase or private keys. Authorized agents may submit requests where permitted by law. We respond within applicable legal deadlines. Some requests are subject to legal exceptions, and our ability to act is limited to information we control; we cannot retrieve device-only secrets or erase independent blockchain records.
9. International processing
The Services and their providers may process information in countries other than your own, where privacy laws may differ. Any international transfers we arrange must meet applicable data protection requirements. Contact us for information about applicable transfer safeguards. Public blockchain publication makes information accessible worldwide and cannot be restricted to a particular country.
10. Children
The Services are intended for adults and are not directed to children under 18. We do not knowingly collect personal information from children through our support or verification services. If you believe a child has provided personal information to us, contact us so we can investigate and take appropriate action for information under our control.
11. Changes and contact
We may update this policy as the Services or our practices change. We will post the updated policy here, revise the date above, and provide additional notice or obtain consent when required by law.
Contact LifeHash at support@xyo.network for questions about this policy. Use of the Services is also addressed in our Terms and Conditions.
12. SMS verification and mobile information
When LifeHash SMS Verification is enabled and you choose to use it, we use your phone number, verification requests, and SMS consent and opt-out information only to provide, secure, and support the requested verification service and honor your messaging preferences.
We do not sell, rent, or share mobile information or SMS opt-in consent with third parties or affiliates for marketing or promotional purposes. Information necessary to deliver and support the requested service may be processed by Twilio, mobile carriers, and other service providers solely for that service, not for their independent marketing. These restrictions control over any broader sharing provisions elsewhere in this policy.
Message frequency varies with your verification requests, including requests for replacement codes. Service replies may confirm preference changes or provide help. Message and data rates may apply. Reply STOP to opt out or HELP for help. You may also contact support@xyo.network.
See the LifeHash SMS Verification terms for the program description, consent process, and opt-out details.