> For the complete documentation index, see [llms.txt](https://sovavault.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sovavault.gitbook.io/docs/legal-information/sova-wallet/privacy-policy.md).

# Privacy Policy

**Sova Wallet Privacy Policy**

**Sova Labs, Inc.**

**Last Modified: May 16, 2026**

This Privacy Policy describes how Sova Labs, Inc. ("Sova," "we," "us") collects, uses, and discloses information when you use the Sova Wallet mobile application (the "App") and the related services that support it (collectively, "Sova Wallet"). It applies only to Sova Wallet and is separate from the legal documents governing the Sova Interface at sova.io and app.sova.io (see the [Terms of Use](/docs/legal-information/terms-of-use.md) and [Legal Disclaimer](/docs/legal-information/legal-disclaimer.md) for the Interface).

You can reach us at **<privacy@sova.wallet>** with any privacy questions.

### 1. Self-Custody First

Sova Wallet is self-custodial. Your wallet's private keys are generated and stored on your device through the Dynamic Labs embedded wallet SDK. We never see your keys, your seed material, or any signing material. We cannot move your funds, recover your wallet, or sign transactions on your behalf.

If you lose your device and the authentication method you used to provision it (e.g. email or social identifier), you may lose access to the wallet. Sova cannot restore it for you. On-chain assets associated with your wallet address are public and outside our control.

### 2. Information We Collect

We collect only what we need to operate the strategy marketplace, evaluate trading-agent signals against your guardrails, and notify you about trades:

* **Wallet address.** Your public, on-chain Ethereum-compatible address. Used to identify your subscriptions, signal history, and notification tokens.
* **Authentication identifier.** When you sign in via Dynamic Labs (email, social, or another connector), Dynamic Labs collects and holds the underlying identifier per its own privacy policy. Sova receives a stable Dynamic user ID that we use to bind your wallet to your account.
* **Subscription state.** Which strategies (e.g. Copy Trade, DCA, Grid) you have enabled, their configuration, and your pause / restart history.
* **Signal and trade history.** Each trade signal evaluated by the local guardrail engine produces an audit-log row containing the signal payload, whether it was approved or blocked, and the resulting on-chain action (if any). This lets us show you the History tab.
* **Push notification tokens.** Apple or Google push tokens registered to your device, used to deliver fill and signal notifications.
* **Crash and performance telemetry.** We use Sentry to capture crashes, unhandled errors, and slow operations. Sentry events may include device metadata (OS version, app version, screen) and the address that triggered the error.

### 3. Information We Do Not Collect

We do not collect:

* Private keys, mnemonics, or seed phrases.
* Plaintext passwords.
* Off-device biometric data. Face ID and Touch ID prompts are handled by iOS or Android; the operating system never shares the biometric template with Sova.
* Detailed IP-level analytics or advertising identifiers.
* Contacts, photos, microphone audio, or location.

### 4. Third Parties

We rely on a small set of third-party services. Each handles only the slice of data needed for its function:

* **Dynamic Labs** — authentication and embedded wallet SDK. Receives your email or social identifier and a Dynamic user ID.
* **Hyperliquid** — trade execution venue. Receives your public wallet address and the trade actions you sign.
* **Relay Protocol** — cross-chain bridging. Receives the source and destination addresses and amounts you sign.
* **Sentry** — crash and error telemetry. Receives device metadata, error stacks, and the wallet address that triggered the event.
* **Railway** — backend hosting. Stores server-side logs and the database holding the items in Section 2.
* **Apple and Google** — app distribution and push delivery. Receive your device push tokens and App Store / Play Store account state.

We do not sell your personal information and we do not share it for cross-context behavioral advertising.

### 5. Where Data Lives

Server-side data is stored in PostgreSQL hosted on Railway in the United States. On-device data (your encrypted key material, biometric preferences, local trade history cache) lives in iOS Secure Enclave or Android Keystore through the Dynamic Labs SDK and Expo Secure Store. Push notification tokens are stored on both your device and our servers so we can route notifications.

### 6. Your Rights and Choices

* **Account deletion.** You can delete your Sova Wallet account directly in the App at **Settings → Delete Account**. Deletion removes your subscriptions, signal history, push tokens, and authentication session from our servers. Public on-chain history associated with your wallet address cannot be deleted by Sova — that is a property of public blockchains.
* **Notification opt-out.** You can turn off individual notification categories at **Settings → Notifications**.
* **Sign-out.** Signing out clears the local wallet session and authentication token from your device. It does not delete your account.
* **Privacy questions.** Email **<privacy@sova.wallet>**. We aim to respond within fourteen (14) days.

### 7. Retention

We retain server-side data for as long as your account is active. When you delete your account, we remove your records in the next maintenance window, typically within twenty-four (24) hours. Crash and error events in Sentry are retained for ninety (90) days and then aged out.

### 8. Children

Sova Wallet is not directed at people under the age of 18. If you believe a child has used Sova Wallet, please contact us at **<privacy@sova.wallet>** and we will delete the relevant records.

### 9. Sanctions and Prohibited Use

Sova Wallet is not available to persons or entities in jurisdictions subject to sanctions by the U.S. Office of Foreign Assets Control (OFAC) or other applicable lists. We may decline service to users on those lists.

### 10. Changes to This Policy

We will surface material changes to this Privacy Policy in the App on next launch and update the "Last Modified" date above. Your continued use of Sova Wallet after a material change constitutes acceptance of the revised policy.

### 11. Contact

**<privacy@sova.wallet>**

For legal notices related to Sova Wallet, see also the [Sova Wallet Terms of Service](/docs/legal-information/sova-wallet/terms-of-service.md).
