Privacy Policy
Last Updated: September 2, 2026
Introduction
Stealf is a privacy-first neobank on Solana operated by Stealf Corporation, a company incorporated in the State of Delaware, USA. This Privacy Policy explains what data we collect, how we use it, who we share it with, and the rights you have over it.
By using Stealf, you agree to the practices described below. If you don't agree, please don't use the app.
What We Collect
Depending on which features you use, we collect:
- Account info: email address and username.
- Wallet addresses: the public address of your wallet (created via Turnkey) and, if you use private features, your on-device stealth address.
- On-chain transactions: amounts, timestamps, counterparty addresses, and signatures. This data is already public on the Solana blockchain — we read it via Helius to display your history.
- Identity verification (KYC) data: if you use features that convert crypto to fiat (cash-out / off-ramp), you and our regulated partner collect the identity information required to verify you — see "Identity Verification" below.
- Financial data: for cash-out, the bank account details (e.g. IBAN or account number) you provide to receive fiat, and the associated payout records.
- Gift-card orders: the product, denomination, and amount when you purchase a gift card. We do not store the delivered gift-card codes.
- Technical data: IP address, device type, OS version, and app version.
- Diagnostics and product analytics: crash and error reports (via Sentry) and anonymized usage events (via PostHog), used to fix bugs and improve the product. Session replay is disabled.
Identity Verification (KYC / AML)
Converting crypto to fiat is a regulated activity. When you use our cash-out feature, identity verification is required by law (anti-money-laundering and know-your-customer regulations). This verification is handled through our licensed payments partner, Dakota, using identity-verification providers (Sumsub and/or Persona).
As part of this process you may be asked to provide your legal name, date of birth, residential address, a government-issued ID, and a selfie / liveness check. This information is collected and processed by our KYC providers and our payments partner to verify your identity and screen against sanctions lists.
Stealf does not store your government ID images or biometric (selfie / liveness) data — that data is processed by the specialized providers above. We retain only the verification status and the records we are legally required to keep.
Privacy by Design — What We Don't See
This is the part that matters:
- We never see or store the private key of your stealth wallet. It's generated on your device and stored in the secure enclave (iOS Keychain / Android Keystore). It never leaves the device.
- We never see your private (encrypted) balance in plaintext. Your private balance is encrypted through Umbra's confidential protocol (which runs on the Arcium MPC network). Even our backend cannot decrypt it.
- We never receive the private key of your Turnkey-secured wallet. It is held inside Turnkey's secure key-management infrastructure; only you can authorize it through your login.
- We do not sell your personal data, and we do not share it for advertising.
How We Use Your Information
- Provide the service: authenticate sign-ins, display balances and transaction history, process swaps, yield, gift-card purchases, and cash-outs.
- Verify identity: meet our know-your-customer and anti-money-laundering obligations for regulated features.
- Communicate: send one-time passcodes for email authentication, account and transaction notifications, and (only if you opt in) product updates.
- Security: detect abuse, rate-limit suspicious activity, and debug errors.
- Legal compliance: comply with applicable law and respond to lawful requests when required.
Authentication & Biometrics
Stealf authenticates access to your wallet via Turnkey using OAuth (Google, Apple) or one-time passcodes sent to your email. Any device biometric authentication (Face ID, Touch ID, fingerprint) is handled locally by iOS or Android — we never receive, store, or transmit your facial images, fingerprints, or any device biometric templates. We only receive the result of the local authentication (success or failure).
The selfie / liveness check used for identity verification (KYC) is separate and is processed by our KYC providers, not stored by Stealf (see "Identity Verification" above). One-time passcodes sent to your email expire after a short period and are invalidated after use.
Third-Party Services
We rely on the following service providers. Each has its own privacy policy:
| Provider | Purpose | Data shared |
|---|---|---|
| Turnkey | Wallet key management, OAuth authentication | Email, wallet address |
| Dakota | Crypto-to-fiat cash-out, identity verification (KYC/AML) | Name, date of birth, address, government ID, bank details, transactions |
| Sumsub / Persona | Identity verification on behalf of Dakota | Government ID, selfie / liveness, personal details |
| Bitrefill | Gift-card fulfillment | Order and amount details |
| Reflect | USDC+ yield (STLF) | Wallet address, on-chain transactions |
| Umbra | Confidential balance and private transfers | Encrypted data only |
| Jupiter | Token swap routing | Wallet address, transaction parameters |
| xStocks (Backed) | Tokenized stocks | Wallet address, on-chain transactions |
| Helius | Solana RPC and transaction data | Wallet addresses (already public on-chain) |
| Resend | Sending authentication emails | Email address |
| Sentry | Error monitoring | Crash logs, anonymized context |
| PostHog | Product analytics | Anonymized usage events (no keys or balances) |
| MongoDB Atlas / Railway | Database and application hosting | Account data (email encrypted at rest) |
| CoinGecko | SOL/USD price feed | No personal data |
Some of these providers are located outside the EU (mainly in the United States). When you use Stealf from the European Union, your data may be transferred to the US. We rely on Standard Contractual Clauses where applicable.
Your Rights
If you're in the European Economic Area, UK, or Switzerland (GDPR), you have the right to:
- access the personal data we hold about you
- correct inaccurate data
- request deletion of your data
- restrict or object to processing
- request portability of your data
- withdraw consent at any time
- lodge a complaint with your local supervisory authority (in France: the CNIL)
If you're a California resident (CCPA/CPRA), you have the right to:
- know what personal information we collect and how we use it
- request deletion of your personal information
- opt out of the sale of personal information (we do not sell personal information)
- non-discrimination for exercising your rights
Some rights are limited where we are legally required to keep certain records (for example, identity-verification and transaction records under anti-money-laundering law). To exercise any of these rights, email us at louis@stealf.xyz from the email address linked to your account. We'll respond within 30 days.
Data Retention
We keep your account data for as long as your account is active. If you delete your account, we delete your personal data within 90 days, except where we are legally required to retain it.
In particular, identity-verification (KYC) data and cash-out/transaction records tied to regulated features are retained for the period required by applicable anti-money-laundering and financial regulations (typically up to five years after the end of our relationship), even after account deletion.
On-chain transactions cannot be deleted — they are permanent records on the Solana blockchain, which we don't control.
Children
Stealf is not intended for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact us and we'll delete it.
Security
We use industry-standard measures to protect your data: encryption in transit (HTTPS/WSS), encryption at rest, restricted access, rate limiting, and monitoring. No system is 100% secure, and you are responsible for keeping your device, login, and recovery phrase safe.
Changes to This Policy
If we update this policy, we'll post the new version here and update the "Last Updated" date. For material changes, we'll notify you by email.