Important: C&W does not receive any Recovery Phrase, private keys, Wallet PIN or biometric reference data. However, IP addresses, public wallet addresses, transaction data and technical device data may be transmitted to independent services for network, market-data, configuration and security functions.
1. Controller and Contact
The controller under the Swiss Federal Act on Data Protection ("FADP") and - where applicable - the General Data Protection Regulation of the European Union ("GDPR") is:
C&W Software Labs AG
Bundesplatz 4
6300 Zug
Switzerland
Represented by: Dennis Poschner, Managing Director, with sole signatory authority UID: CHE-101.808.011
Commercial Register No.: CH-170.3.016.428-8
Email: info@cundw.io
Product website: https://wallet.omegastack.io
Corporate website: https://www.cundw.ch
Privacy enquiries and requests to exercise data protection rights should be sent to this email address.
2. Scope and Principles
This Policy describes the processing of personal data when the Omega Wallet app is used, when users contact support and when users access C&W-controlled pages opened from the app. Independent app stores, blockchains, RPC, market-data, protocol and explorer services are also subject to their own privacy policies.
C&W processes data in accordance with the principles of lawfulness, good faith, transparency, proportionality, purpose limitation, accuracy, data minimisation and limited retention. Data protection by design and by default is taken into account from the product-design stage.
The GDPR also applies to the extent that C&W specifically offers the app to individuals in the European Economic Area or monitors their behaviour there within the meaning of Article 3 GDPR. Mandatory local data protection law remains unaffected in all cases.
3. Data Sources and Mandatory or Voluntary Data
C&W obtains data directly from the User, from the end device and, where technically required, from public blockchains and the infrastructure, market-data, app-store, security and protocol services listed below. Public addresses and transaction data may also be processed where another person has published them on a blockchain or provided them to support.
A Recovery Phrase, private keys, Wallet PIN and biometric templates are neither required by nor to be provided to C&W. Network, public-wallet and transaction data are required when the User requests the relevant blockchain function; without them, that function cannot be performed. Support information is generally voluntary, although a request may not be handled properly without an adequate description. Optional consent is voluntary and may be withdrawn without losing the core wallet functionality.
4. Full Self-Custody and Locally Stored Secrets
The Recovery Phrase and private keys are generated on, or imported to, the end device, stored in the device's protected environment and not transmitted to C&W or to analytics, support or infrastructure providers. Transactions are signed locally. C&W cannot view, recover or reset these secrets. The Wallet PIN and its local verification record remain on the device. Biometric characteristics are processed by the operating system; Omega Wallet receives only information about the availability and success of device authentication, not a fingerprint, facial image or biometric template. C&W does not store the Recovery Phrase or private keys in general app storage, diagnostic events, telemetry or server-side logs. Exporting or backing them up occurs only at the user's express direction and is the user's responsibility. A full app reset also deletes the Secure Vault.
5. Data Generally Stored Only Locally
• account labels, symbols, public wallet addresses, enabled networks and imported token metadata;
• local transaction history, amounts, senders, recipients, transaction identifiers and conversion rates;
• a local address book containing labels, public addresses and blockchain assignments;
• language, currency, theme, notification, explorer, testnet and other app settings;
• a local record of the accepted version of the legal documents and the time of acceptance;
• encrypted vault data, local security counters and app session data.
As a general rule, this data remains on the device until it is deleted by the user, a full app reset is performed, the app is effectively uninstalled or the operating system deletes it. Whether individual keychain data survives uninstallation depends on the platform; the app reset must therefore expressly delete the Secure Vault.
6. Technically Necessary Network Data
When retrieving balances, token information, NFTs, transaction histories, fees, market prices or quotes, or when broadcasting a signed transaction, the device connects directly to external services. For technical reasons, these services may process, in particular, the source IP address, time, device or client information and the content of the request.
• Blockchain/RPC: public wallet address, network, contract or mint address, token accounts, transaction identifier, signed transaction data, and the recipient, amount and other transaction parameters that will become public;
• Market and token information: symbol, coin ID, fiat currency, contract or mint address, and the requested image or metadata URL;
• Swaps: public wallet and token-account addresses, input and output assets, amount, slippage, quote, route, transaction version and signed transaction;
• Explorers and external websites: transaction identifier or public address in the requested URL, together with browser, cookie and usage data under the destination provider's rules;
• Configuration and integrity: Firebase installation identifier, app instance, platform and version data and, on Android, a device and app integrity request sent to Google Play Integrity.
7. Support and Communications Data
If a user contacts C&W, C&W processes the email address, name or alias, content, attachments, timestamps and necessary technical information provided in order to answer the enquiry, prevent misuse or handle legal claims. Users must not send any Recovery Phrase, private key, complete PIN or unnecessary personal blockchain data to support.
QR images generated by the app are created locally on a temporary basis and shared through the operating system's sharing function. Local notifications may display the amount, asset, abbreviated recipient and transaction identifier on the device; the user may disable notifications in the app and the operating system.
8. No Advertising or Behavioural Analytics in the Current Version
The current app version contains no advertising SDK, cross-app tracking, Firebase Analytics, Firebase Crashlytics, Sentry or push-token registration. Firebase Remote Config is used solely for configuration and security parameters; local Notifee notifications are not server-side push notifications. If optional analytics, crash uploads, advertising or push services are introduced in future, C&W will update this Policy and the app-store disclosures before activation. Non-essential access will be disabled by default and activated only with separate, informed and revocable consent where consent is required.
9. Purposes, Data and Legal Bases
Processing
| Data activity | Purpose Legal basis / retention |
|---|
| Core wallet | public addresses, network, app balances, history, fees, sending performance of a contract, Article |
|---|
| functionality | and request data and receiving 6(1)(b) GDPR; provider retention periods |
|---|
| Blockchain | signed transaction, sender, execution of the user's performance of a contract; blockchain |
|---|
| broadcast | recipient, amount, token, instruction data is generally permanent metadata |
|---|
| Remote Config | Firebase installation ID, app secure configuration, performance of a contract / |
|---|
| instance and technical metadata | maintenance, prevention of legitimate interest in security; until |
|---|
| misuse | deletion is initiated, followed by up to 180 days in Google backups |
|---|
| Play Integrity | nonce, app, device and account protection against manipulation legitimate interests, Article 6(1)(f) |
|---|
| signals, integrity token | and misuse GDPR; no storage on a C&W backend in the current app version |
|---|
| Market/token data | symbol, coin ID, contract/mint, prices, metadata, token display performance of a contract; provider |
|---|
| fiat currency, IP address | retention periods |
|---|
| Support | contact details, message, enquiries, troubleshooting, contract / legitimate interests; |
|---|
| attachments, necessary | defence against claims normally 24 months after closure technical information |
|---|
| Legal obligations | necessary communications and legal obligations and Article 6(1)(c) and (f) GDPR; for the |
|---|
| evidence | enforcement of legal rights statutory period |
|---|
Under Swiss law, the processing principles of the FADP apply in particular. To the extent that processing could constitute an infringement of personality, C&W relies on consent, an overriding private or public interest, or a legal basis. Under the GDPR, the legal bases stated in the table apply.
10. Recipients and Independent Services
The specific selection may vary by network, region and app version. Before production approval, C&W must document and approve the endpoints actually used. In production, only approved endpoints may be used, and this list will be updated before any material change.
| Service / function | Typical data Role / countries Details |
|---|
| Google Firebase | installation ID, app instance, service provider; Ireland/USA configuration and security |
|---|
| Remote Config | technical metadata and other Google locations values; no analytics |
|---|
| Google Play Integrity | nonce, app, device and account independent controller / service Android only; integrity check |
|---|
| signals | provider; Ireland/USA |
|---|
| Apple App Store / | store account, download, device and each an independent controller; distribution, updates, app-store |
|---|
| Google Play | payment where applicable EEA/USA and regional locations billing |
|---|
| Alchemy / public | IP address, public addresses, predominantly independent balances, history, NFTs, prices, |
|---|
| Ethereum and Solana | contracts/mints, requests, signed controllers; USA, EEA and global broadcast |
|---|
| RPCs | transactions infrastructure |
|---|
| BlockCypher / | IP address, BTC address, UTXO, independent controllers; Bitcoin requests and broadcast |
|---|
| Blockstream / | transaction data or fee request only USA/Canada/EEA and global |
|---|
| mempool.space | infrastructure |
|---|
| XRPL Cluster, XRPL | IP address, XRP address, history, independent controller / XRP requests and broadcast |
|---|
| Labs, Ripple test | signed transaction blob network; EEA/USA and global |
|---|
| nodes | nodes |
|---|
| Tatum (fallback) | IP address, public XRP address and independent controller / service only if the fallback is enabled |
|---|
| history request | provider; Czechia, USA, United Kingdom |
|---|
| CoinGecko | IP address, coin ID, symbol, fiat independent controller; market and token information |
|---|
| currency, contract/mint address | Singapore and international infrastructure |
|---|
| Raydium / Uniswap / | IP address, public address, independent swaps, token metadata and |
|---|
| Jupiter / | token/mint, amount, quote, route, protocols/providers; global trending data |
|---|
| DexScreener | transaction data |
|---|
| Service / function | Typical data Role / countries Details |
|---|
| Etherscan, Solscan, | IP address, transaction identifier, independent controllers; only when a user intentionally |
|---|
| Blockstream and | browser/cookie data EEA/USA/Asia and global opens an explorer |
|---|
| XRPL explorers | infrastructure |
|---|
| GitHub/Trust Wallet, | IP address, contract/mint/asset- independent controllers; global token logos and off-chain |
|---|
| image and NFT metadata hosts | specific URL metadata |
|---|
| Public blockchains | public addresses, amount, token, independent validators/nodes public and generally permanent |
|---|
| time, signature and smart-contract | worldwide data |
|---|
Provider information: Google/Firebase https://firebase.google.com/support/privacy/; Alchemy https://www.alchemy.com/terms-conditions/privacy-policy; CoinGecko https://www.coingecko.com/en/privacy; Tatum https://tatum.io/privacy-policy; BlockCypher https://www.blockcypher.com/privacy-policy.html. For any protocol or explorer accessed by the user, the current privacy policy linked there applies.
11. Disclosure Abroad
Recipients may be located in Switzerland; in the EEA - particularly Ireland, Germany and Czechia; in the USA, the United Kingdom, Singapore and Canada; and, in the case of public blockchain networks, in other countries worldwide. The level of protection may differ from that in Switzerland or Europe. Transfers that C&W can control may be activated in production only after the recipient, countries and specific transfer mechanism have been documented. Depending on the recipient country and provider, C&W relies on an applicable adequacy decision or - after a documented assessment - recognised standard contractual clauses with Swiss adaptations or EU standard contractual clauses, together with necessary supplementary technical and organisational measures. Data subjects may request information about the applicable safeguards and, where permissible, a copy by emailing info@cundw.io. Permissionless blockchains replicate transactions among unknown participants worldwide. It is not possible to bind all of these participants contractually. Data is transmitted only at the user's express instruction to execute a transaction; C&W minimises additional on-chain data and conducts a documented transfer assessment and data protection impact assessment before expanding into new countries.
12. Public Blockchains and Immutability
Public disclosure: When a transaction is made, public wallet addresses, the amount, token, transaction identifier, time and, where applicable, smart-contract data are published worldwide and generally replicated permanently. C&W does not control the networks and, as a rule, cannot delete, alter or retrieve confirmed entries.
Public wallet addresses and transaction data may constitute personal data if they can be linked to an individual. Users must therefore not write any additional personal, confidential or unlawful content into memo, reference or smart-contract data.
Statutory rights in relation to off-chain data controlled by C&W remain fully intact. The technical immutability of an independent blockchain is not a waiver of rights; it merely limits what C&W can in fact delete or rectify.
13. Device Permissions
• Camera: solely, and only after permission has been granted, for local scanning of QR codes;
• Photos/files: after permission has been granted, to save or share self-generated QR images;
• Biometrics: authentication by the operating system; no biometric template is provided to C&W;
• Notifications: local transaction notices; no FCM or APNs push token in the current version;
• Network status and internet: access to the necessary blockchain and information services.
Permissions can be withdrawn in the system settings. The affected functions may then cease to work, but other functions that do not depend on those permissions will not automatically be disabled.
14. Retention and Deletion
| Data category | Standard period / criterion Special consideration |
|---|
| Local app data | until app reset, effective uninstallation or deletion by the no C&W server account operating system |
|---|
| Secure Vault | until a verified app reset or express deletion of the wallet the app reset also covers platform keychain data |
|---|
| Firebase installation ID | until C&W/the client initiates deletion; according to provider retention period Google, backups may then be retained for up to 180 days |
|---|
| Play Integrity token | no central storage by C&W in the current app version Google processes it under its own rules |
|---|
| Support | generally 24 months after closure longer where legal claims or a statutory obligation apply |
|---|
| Contractual/legal records | in accordance with applicable retention and limitation necessary data only periods, potentially up to 10 years |
|---|
| Provider logs | in accordance with the relevant provider configuration C&W requires data minimisation and |
|---|
| and policy | appropriate retention periods |
|---|
| Blockchain data | generally permanent or for the lifetime of the network outside C&W's control |
|---|
15. Data Subject Rights
Subject to applicable law, data subjects may request access, rectification, erasure, restriction or cessation of processing, the release or transfer of data, and may object to processing. Consent may be withdrawn at any time with effect for the future.
Requests should be sent to info@cundw.io. C&W may require appropriate proof of identity. Because C&W does not maintain a central wallet account, C&W may be unable to identify an individual reliably from a public address alone.
Under Swiss law, a complaint or report may be submitted to the Federal Data Protection and Information Commissioner (FDPIC), https://www.edoeb.admin.ch. Where the GDPR applies, data subjects also have the right to lodge a complaint with a competent EU/EEA supervisory authority. Rights relating to data held by independent providers may need to be exercised directly with those providers.
16. App Reset, Uninstallation and Provider Data
A full app reset deletes the local data controlled by Omega Wallet, the Secure Vault, session data, local history, address book, settings and local record of contractual acceptance. Before resetting the app, the user must have securely and independently verified their recovery information.
Uninstallation alone may leave keychain data behind on some platforms. The full reset offered in the app should therefore be used to delete data securely. C&W cannot use a local reset to delete data held on public blockchains or by independent providers.
17. Data Security
C&W implements technical and organisational measures appropriate to the risk. These include, in particular, Secure Vault storage, local signing, encrypted transmission, data minimisation, fixed and verified network endpoints, access restrictions, privacy-friendly default settings, secure update processes, security reviews and an incident-response procedure.
No system is completely secure. Users must protect their device, recovery information and communication channels. This duty of cooperation does not reduce C&W's responsibility for the systems and data controlled by C&W.
Breaches of data security that require notification are reported to the FDPIC as soon as possible under Article 24 FADP if they are likely to result in a high risk. Where the GDPR applies, a notification under Article 33 GDPR will generally be made within 72 hours; data subjects will be informed under Article 34 GDPR where there is a high risk.
18. Automated Decision-Making
In the current version, C&W does not make any decision based solely on automated processing that produces legal effects concerning users or similarly significantly affects them. Local integrity checks are used to protect the app. If a future check leads to a significant automated restriction, C&W will provide clear information and a route to human review where required by law.
19. Minors
Omega Wallet is intended exclusively for persons aged 18 or over. C&W does not knowingly collect minors' data for wallet use. If C&W becomes aware that a minor's data has been processed unlawfully, C&W will delete the data under its control unless a statutory obligation prevents deletion. C&W cannot delete entries on public blockchains.
20. Data Protection Impact Assessment and Provider Governance
In the event of material changes and before expanding into new countries, C&W assesses, in particular, the linkability of public wallet addresses, IP addresses and installation identifiers, global blockchain replication, integrity checks and new telemetry. Where a high risk may arise, C&W conducts a data protection impact assessment under Article 22 FADP and, where applicable, Article 35 GDPR. Before production approval, C&W will complete its record of processing activities and the matrix covering providers, countries, roles, contracts, transfers and retention periods; these records will be kept current in production. A provider acting as a processor may be used only after a binding processing agreement is in place. Independent controllers and public networks are identified as such.
21. European Union
Intended EU data protection representation: C&W intends to appoint C&W Code und Consulting GbR, Waltersweierweg 5a, 77652 Offenburg, Germany, email: info@cundw.io (subject: EU Data Protection Representative), as its representative under Article 27 GDPR. The representative role takes effect only upon the final required contractual signature. This Policy must not be published for production use before that effectiveness has been documented.
Intended EU Representative under Article 27 GDPR: C&W Code und Consulting GbR, Waltersweierweg 5a, 77652 Offenburg, Germany; email: info@cundw.io. After the final required signature, the EU Representative can be contacted at this postal address or by email. The mandate is limited to data- protection representation under Article 27 GDPR and does not establish a C&W branch or other establishment in the EU, nor does it confer authority to represent C&W for contracts, transactions, MiCA, DSA or CRA obligations.
No Data Protection Officer is currently appointed. The formal assessment of the statutory appointment criteria must be completed before production approval. If a Data Protection Officer becomes mandatory or is appointed voluntarily, C&W will publish the contact details and update this Policy.
22. Changes and Contact
C&W will update this Policy if there are material changes to data flows, providers, countries, legal bases or functions. Material changes will be communicated in the app or through an appropriate channel before they take effect. The current and previous versions will remain available for saving. Questions and requests to exercise rights: C&W Software Labs AG, Bundesplatz 4, 6300 Zug, Switzerland; info@cundw.io; https://wallet.omegastack.io.
23. Bug bounty report form on this website
Sections 1 to 22 describe the Omega Wallet app. This section describes only
the bug bounty report form on
wallet.omegastack.io.
Anyone who does not use the form is unaffected by this section: merely visiting
the website sets no cookies and creates no report.
What data is processed. When submitting a report the user transmits:
name, email address, the product concerned, severity, platform, title and
description of the fault, and optionally an attachment (screenshot, video, log
or PDF) and a payout address for USDC (ERC-20). In addition the server records
the IP address, the browser identification (user agent) and the time of
receipt. The description is a free text field; what is written there is
decided by the user alone.
Purpose. The data is used to receive and assess the report, to fix
the reported fault, to raise questions with the reporter and to pay any
reward. IP address and time are additionally used to prevent abuse of the
form; the server limits the number of reports per address and hour.
Legal bases. Processing of name, email address, report content and
attachment rests on the explicit consent given before sending (Art. 6(1)(a)
GDPR; Art. 31 FADP). Consent may be withdrawn at any time with effect for the
future, without affecting the lawfulness of processing carried out until then.
Processing of IP address and browser identification for abuse prevention rests
on the overriding legitimate interest in secure operation (Art. 6(1)(f) GDPR;
Art. 31(1) FADP). Processing of the payout address rests on the initiation and
performance of the payout (Art. 6(1)(b) GDPR).
Where reports are held. Reports and attachments are stored in a
dedicated database belonging to the Omega Stack bug bounty programme, separate
from the application data of the individual products. The programme covers all
products; reports about Omega Wallet and about the other tools of the Omega
Stack therefore sit in the same store, distinguished by the “product”
field. The database is operated as a managed service at DigitalOcean; sections
10 and 11 apply accordingly to hosting, processing on our behalf and disclosure
abroad. No further third parties receive the data. There is no tracking, no
cookies are set and no content is loaded from third-party servers.
Record of consent. Before sending, three points are confirmed
separately: terms of participation, processing of the data, and contact by
email. Which of the three were given, when, and against which version of this
policy is stored together with the report. Without all three no report is
accepted.
Publication. The title and description of a report may appear in a
public list of processed findings. This does not happen automatically:
it requires a report to be expressly released for publication. Without that
release it stays internal, regardless of how it was processed. Name, email
address, IP address, attachment and payout address are never published. Anyone
who wants to rule out publication says so in the report or writes to the
address given below.
Retention. Reports are kept until two years after the case is closed,
so that duplicates can be recognised and the course of a fix remains traceable.
Attachments are deleted no later than twelve months after closure. The abuse
prevention entries (IP address and time) are deleted automatically after one
hour. Information belonging to a payout is subject to the statutory accounting
retention periods (Art. 958f CO, ten years).
Voluntary nature. Participation in the bug bounty programme is
voluntary. Without name, email address, product, severity, title and
description a report cannot be processed; attachment and payout address are
optional. There is no automated decision-making within the meaning of
Art. 22 GDPR — every report is read by a person.
What does not belong in a report. Recovery phrase, private keys, the
full PIN and personal data of third parties must not be transmitted.
Screenshots should be anonymised before uploading.
Rights. The rights under section 15 of this policy apply —
access, rectification, erasure, restriction, portability, objection and
withdrawal of consent. Questions about the report form go to
info@cundw.io.