Privacy Policy — Mate Wallet
Short version
Mate Wallet has no servers of its own. We do not collect, receive or store any personal data about you. There is no account, no registration, no analytics, no crash reporting, no advertising identifier and no tracking of any kind. Your recovery phrase and private keys never leave your device except into your own iCloud Keychain, if you choose to enable backup.
The app does talk to one third party — TonAPI — because a wallet cannot read a blockchain without a node. What that involves is set out below in full.
1. We collect nothing
Mate App LLC operates no backend. There is no server that receives data from the app. We therefore do not collect, store, process, sell or share:
- your name, e-mail address, phone number or any identity information;
- your recovery phrase, private keys or passwords;
- your wallet address;
- your balance, transactions or contacts;
- your device identifier, advertising identifier or IP address;
- usage analytics, behavioural events or crash reports.
There is no analytics SDK and no crash-reporting SDK in the application. There is no advertising framework. We do not use cookies or any similar technology, because there is no web property involved in the app's operation.
2. What stays on your device
| Data | Where it is kept | Protection |
|---|---|---|
| Your 24-word recovery phrase (working copy) | Device Keychain, marked device-only (it is not transferred to a new device by backup or restore) | Requires Face ID / Touch ID, or your device passcode, on every read. Invalidated if the device's biometric enrolment is changed |
| Your wallet's public address and public key | Device Keychain | Not secret; used to read the blockchain |
| Your settings (auto-lock delay, backup status, whether you have verified your phrase, lock-screen counter) | Standard app preferences on the device | Removed when you delete the app |
None of the above is transmitted to us. We have no technical means to read any of it.
3. If you turn on iCloud backup
Backup is optional and off by default. If you turn it on, a copy of your recovery phrase is written to your own iCloud Keychain, operated by Apple under your Apple ID.
- It goes to Apple, not to us. We never receive it and have no access to it. Apple's handling of it is governed by Apple's own privacy policy.
- It syncs to the other devices signed in to the same Apple ID.
- It is not protected by Face ID or Touch ID. A synchronized iCloud Keychain item cannot carry a biometric access control list — this is a limitation imposed by Apple's Keychain, not a choice we made. While your device is unlocked, the copy is readable. The local working copy on your device is biometrically protected; the iCloud copy is not.
- Turning backup off removes the copy from iCloud across your devices.
4. What the app sends to TonAPI, and why
A wallet cannot see a blockchain without asking a node. Mate Wallet asks one provider: TonAPI (tonapi.io), operated by TON Apps Group. This is a third party; we do not control it, and its handling of the requests it receives is governed by its own privacy policy and terms, not by this one.
The application makes requests to TonAPI only — no other host is contacted by the app's own code.
| When | What is sent | Why |
|---|---|---|
| Opening the app / refreshing | Your wallet address | To read your USDT balance and account state |
| Opening the app / refreshing | Your wallet address | To read your transaction history |
| Before every signature | Your wallet address | To read the current transaction counter (seqno) |
| Balance display | The USDT token identifier | To fetch exchange rates. Your address is not part of this request |
Typing a .ton domain as recipient | The domain you typed | To resolve it to an address |
| Preparing a transfer | Your address, the recipient address, the amount, your comment if you wrote one | To obtain a fee quote for the gasless transfer |
| Sending a transfer | The signed transaction (which contains the recipient, amount and comment) | To broadcast it to the network |
As with any internet request, the provider also necessarily sees your IP address and the fact and timing of the request. Taken together, this allows the provider — and anyone with lawful access to its records — to associate your IP address with your wallet address and your activity. We have no insight into what they retain.
Requests carry an API key identifying the application, not you. Your recovery phrase and private keys are never sent to TonAPI or anywhere else. Signing happens entirely on your device; only the already-signed result is transmitted.
If you prefer not to expose your IP address to the provider, use a VPN or a similar measure at the device level. The app has no setting for this.
5. The blockchain is public and permanent
Every transfer you make is written permanently to the public TON blockchain. Your address, the counterparty address, the amount, the time and any comment you attach are visible to anyone, forever. Neither you nor we can delete or alter them. Anyone who learns that an address belongs to you can see its entire history.
This is a property of the blockchain itself, not of this application.
6. Children
Mate Wallet is not directed to children. The Terms of Use require you to be at least 18, or the age of majority where you live if that is higher. We do not knowingly collect personal information from anyone of any age, because we collect nothing at all — there is no server to collect it to. For the same reason there is nothing for a parent or guardian to ask us to delete; anything on the device is removed by deleting the app.
7. Your rights
Data-protection rights such as access, correction, portability and erasure apply to personal data held by a controller. We hold none, so there is nothing for us to produce, correct or erase:
- data on your device is removed by deleting the app;
- data in your iCloud Keychain is managed by you, through Apple, under your Apple ID;
- data on the blockchain cannot be removed by anyone, including us — that is a property of a blockchain, not a policy choice;
- the provider that serves blockchain data to the app is a separate company with its own policy; requests about what it retains go to it, not to us.
If you believe we nevertheless hold personal information about you, write to us at the address in §9 and we will tell you what we find. We expect the answer to be "nothing", and we would rather say so to you directly than have you wonder.
On the GDPR specifically. Mate Wallet is not offered in the European Union or the European Economic Area — see the Terms of Use, §11. This policy therefore does not set out a GDPR lawful basis, a representative or a supervisory authority. If that territory decision changes, this section has to be rewritten before the app ships there, not afterwards.
8. Changes to this policy
The current version is the one published at https://mateapp.org/privacy/. Material changes will be reflected in the version date above.