Privacy Policy
Last Updated: October 1, 2026
1. Introduction
Stealf Corporation, a Delaware corporation ("Stealf", "we", "us"), runs the Stealf mobile app and the website at stealf.xyz (the "Service"). This policy explains what personal data we collect, why, who receives it, how long we keep it and what you can do about it. For the purposes of the EU and UK General Data Protection Regulation (GDPR), Stealf Corporation is the controller of the data described here.
We built Stealf around keeping your financial activity yours, so we try to collect as little as we can. We'd rather be precise about what we do keep than make broad promises. This policy goes with our Terms of Use; where they mention privacy features, section 7 of the Terms explains what those features hide and what stays visible.
2. What We Collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Email address (stored encrypted, plus a one-way hash used to look up your account), pseudonym, sign-in method, Turnkey account identifier, account status, sign-up and last sign-in dates | You, and Turnkey when you sign in |
| Wallet | Your public Solana wallet address | Created through Turnkey when you sign up |
| Public on-chain activity | Public balances and transaction history of your wallet, kept in a short-lived server cache so the app updates in real time | Read from the Solana blockchain through Helius |
| Points | Your points balance | Our records of your activity in the app |
| Gift-card orders | Product, country and currency, amount, order and invoice identifiers, payment address, amount paid, any Umbra fee, order status and dates | You, Bitrefill and the Solana blockchain |
| Diagnostics and usage | IP address, device model, operating system, app version, crash reports and error logs, in-app usage events; all linked to your account identifier so we can fix problems on your account | Your device, through Sentry and PostHog |
| Messages | Anything you send us by email | You |
We don't collect your name, phone number, postal address, government ID or bank details.
3. What We Don't Collect, and What We Can't See
- Private keys. Your wallet's private key is generated and held inside Turnkey's secure hardware environments. We never receive it, and we can't use it to sign anything.
- Your private balance. Amounts in your private balance are encrypted by the Umbra protocol. Our servers never store or cache them.
- Biometrics. Face ID, Touch ID or fingerprint unlock runs entirely on your phone. We only learn whether it succeeded.
- Gift-card codes. Bitrefill delivers the code to you; we don't keep it.
- Identity documents. We don't run identity checks today, so we hold no ID scans, selfies or similar data.
One thing we do keep, and you should know about: when you pay for a gift card from your private balance, our order record shows the amount, the time and the Bitrefill payment address, tied to your account. The payment stays private on-chain, but our database knows it was you. We keep these records to track orders and recover failed ones.
4. How We Use Your Data, and on What Legal Basis
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Create your account and sign you in | Account, wallet | Performance of our contract with you |
| Show your balances and history in real time | Wallet, public on-chain activity | Performance of our contract with you |
| Process and recover gift-card orders | Gift-card orders, account | Performance of our contract with you |
| Run points programs and check eligibility for any future rewards | Points, wallet, account | Performance of our contract with you (the program's rules) |
| Find and fix bugs, keep the Service secure, prevent abuse | Diagnostics and usage, account | Our legitimate interest in a working, secure app |
| Understand how features are used so we can improve them | Diagnostics and usage | Your consent where the law requires it (including in the EU); otherwise our legitimate interest |
| Send sign-in codes and important service notices | Performance of our contract with you | |
| Send product news | Your consent; you can opt out at any time | |
| Meet legal obligations and answer lawful requests | Any of the above, only as needed | Legal obligation |
We don't sell your data, share it for advertising or use it to build advertising profiles. We don't make automated decisions about you that have legal or similar effects. Using the Service isn't the same as consenting to everything here; where we rely on consent, we'll ask for it separately.
5. Who Receives Your Data
Service providers that work for us only process data on our instructions:
| Provider | What they do for us | What they receive |
|---|---|---|
| Turnkey | Wallet keys and sign-in (OAuth, email codes) | Email, sign-in details, wallet address |
| MongoDB Atlas | Database | Account data, points, gift-card orders |
| Railway | Hosting our backend | Everything our backend processes, including the real-time cache |
| Helius | Solana data access | Wallet addresses (public on-chain) |
| Resend | Sending sign-in and service emails | Email address |
| Sentry | Error and crash monitoring | Diagnostics linked to your account identifier |
| PostHog | Product analytics | Usage events linked to your account identifier |
When you use a feature, the third party behind it also receives what it needs to run it, under its own privacy policy:
| Third party | Feature | What they receive |
|---|---|---|
| Umbra and Arcium | Private balance and transfers | Wallet address and transaction data; amounts in encrypted form |
| Jupiter | Swaps and xStocks | Wallet address and swap details |
| Jito | Liquid staking | Wallet address and staking transactions |
| Backed Assets | xStocks issuer | On-chain transactions involving xStocks |
| Bitrefill | Gift cards | Product, amount and payment details; not your email |
| CoinGecko | Price data | No personal data |
If the app calls one of these services directly from your phone, that service may also see your IP address. We may also disclose data where the law requires it, to protect people's safety or our rights, or to a buyer if Stealf is acquired; the buyer would then be bound by this policy.
6. Blockchain Data and Umbra
Everything on your public balance is recorded on Solana, where anyone can read it and nobody, including us, can change or delete it. Your rights under section 9 apply to the data we hold, not to the blockchain.
Private features run on the Umbra protocol, operated by Phoenix DAO LLC, which handles data under its own Privacy Policy. Umbra's SDK, which we use, doesn't send personal data or telemetry to Phoenix DAO by default, and Umbra doesn't ask for your identity.
Privacy features reduce what others can see on-chain; they don't make you anonymous. Timing, amounts and other metadata can still link activity together, and authorities can legally require you to disclose viewing keys. Section 7 of our Terms of Use explains what stays visible.
7. International Transfers
Stealf is a US company, and most of our providers store data in the United States. If you use Stealf from the European Economic Area, the UK or Switzerland, your data is transferred there. We rely on the EU-US Data Privacy Framework where a provider is certified under it, and on the European Commission's Standard Contractual Clauses otherwise. You can ask us for a copy of the safeguards that apply.
8. How Long We Keep Data
| Data | How long |
|---|---|
| Account, wallet address, points | While your account is open, then deleted within 90 days of closing it |
| Gift-card orders | While your account is open, then deleted within 90 days of closing it |
| Real-time balance and history cache | Refreshed continuously; not kept as a lasting record |
| Crash reports and error logs (Sentry) | 30 days |
| Usage events (PostHog) | 12 months |
| Emails you send us | As long as needed to handle your request, then up to 2 years |
We may keep some data longer where the law requires it or to settle a dispute. On-chain data stays on Solana permanently.
9. Your Rights
If you're in the EEA, the UK or Switzerland, you can ask us to:
- give you a copy of your data, or send it to you in a portable format;
- correct it if it's wrong;
- delete it;
- stop or limit certain processing, including anything based on our legitimate interests;
- withdraw a consent you gave, without affecting what we did before.
You can also complain to your local data protection authority; in France, that's the CNIL (cnil.fr).
If you're a California resident, you can ask what personal information we collect and how we use it, and ask us to delete it. We don't sell or share personal information for cross-context advertising, and we won't treat you differently for using these rights.
To use any of these rights, email louis@stealf.xyz from the address linked to your account, so we can confirm it's you. We'll reply within one month. Deleting your account deletes the data we hold, but it can't touch your wallet or anything on-chain; your funds stay yours, reachable with your keys.
10. Security
We encrypt data in transit (HTTPS and secure WebSockets) and at rest, encrypt your email in our database, limit who on our team can access production data, rate-limit our APIs and monitor for abuse. No system is fully secure, though. If a breach puts your data at risk, we'll tell you and the relevant authorities as the law requires. Keeping your phone and your Turnkey login safe is up to you.
11. Children
Stealf is for people aged 18 and over. We don't knowingly collect data from anyone younger; if you think a minor has an account, tell us and we'll delete it.
12. Changes to This Policy
When we change this policy, we'll post the new version here with a new "Last Updated" date. For material changes, such as collecting a new kind of data or using it for a new purpose, we'll tell you in the app or by email before the change takes effect.