The information in this document is subject to change periodically.
This Privacy Policy (this “Policy”) describes how Cache Technologies Inc., a Delaware corporation ("Cache", "we", "us", or "our"), may access, collect, store, use and/or share (“process”) personal information when you use the Cache mobile application, the website located at cachewallet.com and all of its subdomains, and any related software, smart contracts, and services we provide through or to which this Agreement is linked (collectively, the "Services"), as well as when you engage with us in other ways, including through sales, marketing, or other events.
We encourage you to read this Policy to understand your privacy rights and how we process your personal information. If you do not agree with this Policy, please do not use the Services. If you still have any questions or concerns, please ask in our Telegram group, or write to us at the address at the end of this Policy.
1. Information We Collect
The information we collect depends on your interactions with us and the Services, the choices you make, and the products and features you use. The information we collect may include the following:
1.1 Information you provide
- A user identifier and authentication credential (a hashed password) created during sign-up.
- Where you choose to sign in with Google or Apple instead of a password, we record which provider you used and the stable account identifier that provider issues for you. If the provider also returns an email address, we store it. Signing in this way is optional, and the identifier is what links you to your account, not the email.
- An optional display name or first/last name where you choose to provide one.
- Information you submit when contacting support, such as the email address you write from and any details you include in your message.
- Wallet labels and other metadata you choose to save inside the app.
- Address book entries (contacts) you save in the app, including the contact name, the public blockchain address you save against that contact, and any optional note you choose to associate with the entry.
- A referral code entered during sign-up where you joined Cache through someone else's referral link.
1.2 Information collected automatically
We automatically collect certain information when you visit, use, or navigate the Services which does not reveal your specific identity (like your name or contact information) but may include device and usage information and other technical information. This information is needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes. The information we collect includes:
- Device information. Device identifier, device model and manufacturer, operating system and version, app version, app build number, locale, and time zone offset. We register a record of your device each time you sign in so that we can deliver notifications you have enabled.
- Push notification token. If you grant notification permission, we collect a push notification token issued by your device’s operating system and store it against your device record so we can deliver the alerts you enable (such as Recovery check-in reminders, scheduled transfer reminders and confirmations, incoming-funds alerts, and security alerts). We do not collect a token, and cannot send you push notifications, unless your operating system reports that you have granted permission. If a token is rejected as permanently invalid when we try to send to it, for example because you uninstalled the app, we delete it. Revoking notification permission stops us collecting a new token and stops the notifications reaching you, but does not by itself remove a token we already hold; deleting your account removes it. You can turn individual notification categories on or off in the app’s settings, or disable all push notifications in your device settings.
- Network and request metadata. Server access logs maintained by our hosting and runtime-security providers may include IP address, user agent, request timestamp, endpoint path, and HTTP response status. These logs are kept by those providers at the infrastructure layer for security, operational, and abuse-detection purposes; Cache does not separately store IP addresses or user agents in its application database. Our own database does keep two kinds of request record: a short-lived record of certain requests you make, used so that a repeated request is not carried out twice, and a log of the requests we make to third-party providers on your behalf, which can include your wallet address. Both are deleted on a rolling schedule.
- Server-side error events and performance metrics. When an API request fails or an unexpected error occurs, the error message, stack trace, and contextual metadata may be captured by our hosting provider’s log system, our runtime-security firewall, and by error-monitoring and performance tools we use to diagnose issues, detect abuse, and improve the Services. That context can include the content of the request that failed, from which passwords, tokens and similar credentials are removed before the report is sent. The Cache app also reports crashes and errors to an error-monitoring provider. These are operational logs, not user-tied analytics.
- App integrity checks. The app may ask Google’s Play Integrity service on Android, or Apple’s App Attest service on iOS, to confirm that it is a genuine, unmodified copy of Cache running on a genuine device. This protects sensitive actions against tampered builds and automated abuse. The check returns a verdict about the app and device, not information about you.
1.3 On-chain and wallet information
- The public addresses of wallets and smart wallets (Safe contracts) you create or import within Cache, including additional accounts and additional wallets you create within a single Cache installation.
- Public addresses derived from a recovery phrase or private key you choose to import into Cache. The recovery phrase or private key itself is not transmitted to our servers; only the resulting public address is recorded. The one exception is encrypted backup, described below, which you turn on deliberately.
- Smart wallet configuration metadata, including module enablement state, beneficiary public addresses you configure for the Recovery and Scheduled Transfer features, configured time intervals, and the public addresses of any guardians you nominate.
- Cached balance and transaction summaries fetched from public blockchains. This information is public data; Cache does not generate or own it.
- Reward NFT eligibility records indicating which qualifying activities you have completed (for example, whether you have deployed a smart wallet, enabled the Recovery feature, enabled the Scheduled Transfer feature) and the resulting tier eligibility.
- Referral data, including the public referral code we issue to you, and (where applicable) the identifier of the user who referred you, the timestamp at which you completed the actions that count you as a successful referral for them, and the identifiers of users who have used your referral code together with whether each has completed the qualifying actions.
- The public address that receives any commemorative reward NFT issued to you, the on-chain NFT contract address, the token identifier, and the transaction hash of the mint.
1.4 Encrypted backup
If you turn on encrypted backup, a copy of your recovery material is encrypted on your device and stored on our servers so that you can restore your wallet on a new device. It is encrypted before it leaves your device, and it is unlocked by a passkey that your device creates and that syncs through your Apple or Google account. We never hold that passkey. Cache cannot read the contents of your backup, and cannot restore your wallet on your behalf.
If you delete that passkey, or lose access to the Apple or Google account it syncs with, nobody can open the backup, including us. Your recovery phrase is then the only remaining copy of your wallet. Backups created by earlier versions of the app may be held in your Apple or Google account rather than on our servers. You can turn encrypted backup off, which deletes the stored copy.
1.5 Information you provide to fiat on/off ramp partners
When you buy or sell cryptocurrency through the in-app fiat ramp, you transact directly with a third-party fiat aggregator and the underlying licensed money services businesses. Identity verification (“KYC”), payment information, and bank or card data are submitted directly to those parties through their own interfaces, subject to their own privacy practices. Cache does not collect, view, or store your KYC documents, payment instruments, or bank details.
2. Information We Do Not Collect
Cache is a non-custodial, self-custody wallet. This means you, and only you, hold the keys to your funds. We want to be explicit about what this means for your privacy and security:
- We cannot read your seed phrase (recovery phrase). Your seed phrase is generated on your device and stored locally in your device’s secure enclave (iOS Keychain or Android Keystore). Unless you turn on encrypted backup, it is never transmitted to our servers at all. If you do turn on encrypted backup, what we hold is an encrypted copy that we have no way to decrypt, because unlocking it requires a passkey we do not hold.
- We do not have access to your private keys. Private keys are derived on your device and never leave it.
- We do not store your account password in plaintext. Your password is used locally to unlock the app and to encrypt sensitive data on your device. Where a password is used to authenticate against our servers, only a one-way cryptographic hash (with a per-user salt) is stored.
- We do not require an email address, phone number, or government ID in order to create a wallet or use core wallet features. If you choose to sign in with Google or Apple, that provider may give us an email address. If you ask for help in our Telegram group, your Telegram name and anything you post there are visible to the other members of the group, and Telegram’s own privacy policy applies to your use of Telegram. Neither signing in with Google or Apple nor using Telegram is needed to create or use a wallet.
If you lose your device and your seed phrase, Cache cannot recover your funds. The Recovery feature (described in our documentation available at https://cachewallet.com/docs) is an on-chain mechanism you configure in advance and is not a server-side recovery service.
3. How We Process Information
We process your information for a variety of reasons, depending on how you interact with our Services, including:
- To operate, maintain, and provide the Services and the features you request.
- To authenticate sessions, prevent unauthorized access, and detect abuse.
- To comply with our legal and regulatory obligations, including obligations applicable to our third-party service providers (for example, providers of swap routing and liquidity, fiat ramp aggregators, and address screening providers).
- To screen wallet addresses involved in your transactions against sanctions, malicious-actor, and high-risk lists in order to protect users and meet our compliance commitments.
- To determine your eligibility for, and to distribute, commemorative reward NFTs.
- To operate the referral program, including issuing referral codes, tracking which users joined through your code, and applying anti-abuse measures.
- To respond to your support requests and to send you service-related notifications.
- To send you the optional push notifications you enable, such as Recovery check-in reminders, scheduled transfer reminders and execution confirmations, incoming-funds alerts, and security alerts. Each category can be turned on or off in the app, and all push notifications can be disabled in your device settings.
- To analyse aggregated, non-identifying usage information in order to improve the Services.
- To enforce our Terms of Service and to protect the rights, property, and safety of Cache, our users, and third parties.
4. Legal Bases We Rely on to Process Your Information
We may rely on the following legal bases to process your information:
- Performance of a contract in order to provide the Services you have requested.
- Legitimate interests in operating, securing, and improving the Services, preventing fraud and abuse, and meeting our compliance commitments.
- Compliance with legal obligations, including sanctions screening and responses to lawful requests as well as to exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
- Consent, where you have given us permission to use your information for a specific purpose, for example for optional push notifications.
- Protection of vital interests, such as situations involving potential threats to the safety of any person.
5. How and With Whom We Share Information
We do not sell your personal information. We share information only in the limited circumstances described below.
5.1 Service providers and processors
We use a small number of third-party service providers to operate the Services. We share with them only what they need to perform their function. Categories include:
- Cloud hosting and database providers. To run our application servers, store account metadata, and deliver the application.
- Blockchain data and Remote Procedure Call (RPC) providers. To read public blockchain data such as balances, token metadata, and transaction status. We send these providers public wallet addresses, chain identifiers, and similar query parameters; we do not send personal identifiers.
- Decentralized exchange and cross-chain swap aggregators. To obtain quotes, route orders, and settle gasless on-chain swaps that you initiate. We share the public addresses, token addresses, chain identifiers, and amounts required to execute your swap.
- Fiat on/off ramp aggregators and the licensed money services businesses they integrate. When you buy or sell crypto, we share the wallet address, the amount, the currencies involved, your country, the type of payment method, the provider you selected, and an identifier for your Cache account. KYC and payment information is submitted by you directly to those parties, and we do not receive your identity documents, card numbers or bank details. We keep our own record of each purchase or sale, including its status, the amounts and currencies, and the wallet address involved.
- Wallet screening and blockchain analytics providers. To assess whether a sending or receiving wallet address is associated with sanctions, illicit activity, or other heightened risk. We share the wallet address and chain identifier; we do not share your name, IP address, or contact details with these providers.
- Push notification provider. To deliver push notifications to your device, where you have enabled them. We share the device push notification token and the contents of the notification needed to route and display the message.
- NFT minting infrastructure providers. To generate the signed minting authorizations needed for the on-chain reward NFT contract that you mint to. We share your public wallet address, the requested NFT tier, and the signing context required by the provider.
- On-chain automation and keeper providers. To execute Recovery and Scheduled Transfer triggers on-chain when the conditions you configured are met. We do not transmit personal identifiers to these providers; they read state from the public blockchain.
- Identity providers. Where you choose to sign in with Google or Apple, we exchange sign-in tokens with that provider to confirm the account is yours. The provider learns that you signed in to Cache; we receive the stable account identifier they issue and, where they supply it, an email address.
- Key management providers. To protect the material that guards encrypted backups. These providers hold key material on our behalf under our control; they do not receive your recovery phrase, and they cannot decrypt your backup.
- App integrity providers. To confirm that the app is a genuine, unmodified copy of Cache running on a genuine device. These providers return a verdict about the app and device rather than information about you.
- Error and crash reporting providers. To record errors and crashes in the app and on our servers so we can diagnose them. Reports contain technical context such as the error, where in the code it happened, the app version and the device model, and can include the content of the request that failed, with passwords, tokens and similar credentials removed. They are not used to build a profile of you.
- Operational alerting and monitoring providers. To deliver internal operational alerts about the health of the Services to our engineering team. These alerts describe system events, and some of them include a wallet address and details of an on-chain transaction so that our engineers can investigate a specific failure.
- Security and runtime protection providers. To detect and respond to attacks against the Services.
- Customer support tooling. To respond to your support enquiries.
- Privacy-friendly web analytics. To understand aggregate traffic patterns on our public marketing website (cachewallet.com) without identifying individual visitors. The provider we currently use (Plausible Analytics) is cookieless, does not track visitors across sites, does not set or read browser cookies, and does not store any personal identifiers. IP addresses are processed by the provider only to derive country-level geography and are immediately anonymized (no full IP is stored). The Cache mobile application does not use this service.
The identities of specific third-party providers may change from time to time as we maintain the Services. The categories above describe the kinds of providers we use and the data they receive.
5.2 Public blockchains
Transactions you submit through Cache are recorded on public blockchains. By design, this information is public, permanent, and outside Cache's control. Anyone can view balances and transaction histories of public addresses.
5.3 Legal, safety, and corporate transactions
We may disclose information when we reasonably believe disclosure is necessary to comply with a law, regulation, court order, or other lawful request; to enforce our Terms of Service; to protect the rights, property, or safety of Cache, our users, or third parties; or in connection with a merger, acquisition, financing, or sale of assets, in which case the recipient will be bound by privacy commitments at least as protective as this Policy.
5.4 Affiliates
We may share your information with our affiliates, in which case we will require those affiliates to honor this Policy. Affiliates include our parent company and any subsidiaries, joint venture partners, or other companies that we control or that are under common control with us.
6. Data Retention
We keep personal information only as long as we need it for the purposes described in this Policy.
Server access logs maintained by our hosting and runtime-security providers (which may include IP address and user agent for each API request) are retained by those providers under their own retention policies, typically for periods of up to ninety (90) days, for security, fraud, and abuse investigations. Cache does not extract this information into its primary application database. We may retain extracts longer where required by law or where reasonably necessary to investigate a specific incident.
Account metadata (user identifier, hashed password, device records, wallet addresses, smart-wallet configuration) is retained for as long as your account is active. After you delete your account, we retain account metadata for a limited period to comply with legal obligations, resolve disputes, and prevent abuse, after which it is deleted or anonymized.
Support correspondence is retained for as long as reasonably necessary to provide support and to maintain a record of significant interactions.
On-chain data recorded on public blockchains is permanent and cannot be deleted by Cache.
Deleting your account
You can permanently delete your Cache account and its encrypted cloud backups from inside the app (Settings → Delete account), or by request if you no longer have the app installed. To stop you deleting a wallet you would then be unable to restore, in-app deletion is not offered in every situation, for example when the device holds an imported private key or more than one wallet; the app tells you what to do first. Records of completed purchases, sales and swaps are kept afterwards for legal and accounting reasons with the link to your account removed, and those records still contain the wallet address involved. Full instructions, including exactly what is deleted and what cannot be, are on our account deletion page.
7. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including transport-layer encryption (HTTPS/TLS) for data in transit, encryption at rest for our managed database, hashed and salted credentials, scoped access controls for personnel, and runtime application security monitoring. No system is perfectly secure, and we cannot guarantee the security of information transmitted over the internet. You are responsible for safeguarding your device, your seed phrase, and your password; if these are compromised, your funds may be at risk and Cache cannot reverse on-chain transactions.
8. International Transfers
Cache is based in the United States. The Services are operated using cloud infrastructure located primarily in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States and other jurisdictions where our service providers operate. These jurisdictions may have data protection laws different from those in your country. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers of personal information from the European Economic Area, the United Kingdom, and Switzerland.
9. Your Rights
Depending on where you live, you may have the following rights regarding personal information we hold about you:
- The right to access a copy of the personal information we hold about you.
- The right to correct inaccurate or incomplete information.
- The right to request deletion of personal information, subject to legal exceptions. You can delete your Cache account and the personal information associated with it from inside the app, under Settings, or by following the instructions at cachewallet.com/delete-account. Deleting your account does not affect assets held on a blockchain, or any Recovery or Scheduled Transfer you have configured on-chain, because those exist independently of Cache.
- The right to restrict or object to certain processing.
- The right to data portability.
- The right to withdraw consent where processing is based on consent.
- The right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
- The right to lodge a complaint with a supervisory authority in your jurisdiction.
To exercise any of these rights, write to us at the address at the end of this Policy, or say in our Telegram group that you want to make a privacy request, without posting any personal details there, and an admin will reply in the group to arrange a private way to take it. We will respond within the timeframes required by applicable law (generally within thirty (30) days, extendable as permitted by law). We may need to verify your identity before fulfilling certain requests.
9.1 California Residents (CCPA / CPRA)
California residents have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including the right to know what categories of personal information we collect, use, and disclose; the right to request deletion; the right to correct inaccurate information; the right to opt out of the sale or sharing of personal information; and the right to limit the use of sensitive personal information. Cache does not sell personal information and does not share personal information for cross-context behavioural advertising. You may exercise California rights in the same ways, by writing to us at the address at the end of this Policy or through our Telegram group as described above. You may also designate an authorized agent to make a request on your behalf, subject to verification.
9.2 European Economic Area, United Kingdom, and Switzerland
If you are located in the EEA, the United Kingdom, or Switzerland, the controller of your personal information is Cache Technologies Inc. You may contact us at the address at the end of this Policy or through our Telegram group. You also have the right to lodge a complaint with your local data protection authority.
10. Children
The Services are not directed to and are not intended for children under the age of eighteen (18). We do not knowingly collect personal information from children under eighteen. If you believe a child has provided us with personal information, write to us at the address at the end of this Policy or tell us in our Telegram group, without posting the child’s details there, and we will take appropriate steps to delete it.
11. Cookies and Similar Technologies
Our marketing website (cachewallet.com) uses only those cookies and similar technologies strictly necessary to deliver the website. Aggregate website analytics are provided by Plausible Analytics, which is cookieless by design: it does not set or read browser cookies, does not track visitors across sites, and does not store personal identifiers. Because no non-essential cookies or trackers are used, no cookie-consent banner is displayed. Where we introduce any non-essential cookies or analytics in the future, we will provide appropriate notice and, where required, obtain consent. The Cache mobile application does not use browser cookies for its own features; it uses on-device storage to remember your settings and to securely store the data needed to operate the wallet on your device. The exception is the in-app browser you use to buy and sell crypto, which allows the payment provider’s own cookies because those providers require them to complete a purchase.
12. Third-Party Links and Decentralized Applications
The Services may contain links to, or interact with, third-party websites, smart contracts, decentralized applications, and include embedded content that are hosted by such third parties. We are not responsible for the privacy practices or the content of these other websites or third parties. These third parties may use web measurement and customization technologies (such as cookies) in conjunction with the provision of this content or functionality. We have no control over the information that is submitted to, or collected by, other websites and we are not responsible for the content of any linked site, or any link contained in a linked site, or any changes or updates to such websites or third-party services. Review the policies of any third party before providing them with information.
13. Controls for Do-Not-Track Features
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (“DNT”) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Policy.
California law requires us to let you know how we respond to web browser DNT signals. Because there currently is not an industry or legal standard for recognizing or honoring DNT signals, we do not respond to them at this time.
14. Changes to this Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page indicates when it was last revised. If we make material changes, we will provide additional notice through the Services or by other reasonable means. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.
15. Governing Language
This Privacy Policy is written in the English language, which is the sole authoritative and legally binding version. Any translation into another language is provided for your convenience only and has no legal effect. In the event of any conflict, inconsistency, or ambiguity between the English-language version and any translated version, the English-language version shall prevail and govern.
16. Contact
For privacy questions or to exercise your rights, ask in our Telegram group, without posting personal details there, or write to us at:
Cache Technologies Inc.
Attn: Legal
8 The Green, Suite B
Dover, Delaware 19901
United States