Privacy Policy
KŌINIsend is a self-custody, transfer-only wallet. There are no accounts. Your keys are generated and stored only on your device (Secure Enclave / Keychain on iOS, Keystore on Android) and never leave it. We cannot see, recover, or move your funds.
What stays on your device
Private keys, seed material, your Destination Book (saved recipients), your activity history, fee ledger, and settings. All of it is encrypted at rest on the device and is deleted when you delete the app, except the vault key, which the operating system keeps in its secure keystore even after the app is deleted so that a reinstall can restore access to your funds.
What our servers receive
- Send Live sessions. When you start a Send Live call, our relay receives a random device identifier (not tied to your name), which chain and asset you chose, the mode (Confirmed or Plain), and session state changes. The relay never receives destination addresses, amounts, keys, or video. Video and audio run directly between the two phones (peer-to-peer). For Send Live Anywhere subscribers, encrypted media may be relayed through Cloudflare when a direct connection is impossible; Cloudflare cannot decrypt it.
- Ringing a contact (optional). If you choose to be reachable by phone number, we store a one-way hash (SHA-256) of your number together with a push-notification token so a contact can ring you. We never store the number itself. You can remove this at any time on the Send Live → Rings screen ("Turn off rings"), which deletes the record from our directory.
- Abuse controls. Per-device counters (sessions started, calls abandoned, relayed minutes) and rate-limit counters keyed by device identifier and IP address, kept only as long as needed to enforce limits.
- Subscriptions. Send Live Anywhere is billed by Apple or Google. We use RevenueCat to check that a device holds an active subscription; we receive an anonymous app-user identifier and entitlement status, never your payment details.
Third parties your device talks to
To read balances and broadcast transactions, the app connects to public blockchain nodes (for example Ethereum, Bitcoin, Solana, XRP Ledger and Tron RPC providers). Those providers see your IP address and the transactions you broadcast, as any wallet's do. For the 10¢ minimum and 0 cap the app fetches reference prices from Coinbase and CoinGecko public price endpoints; no personal data is sent. Push notifications are delivered by Apple, Google, and Expo.
What we do not do
No analytics SDKs, no advertising, no tracking across apps, no sale or sharing of personal data, no email or phone collection except the optional hashed reachability record above. Our server logs contain event names, counters and session identifiers only.
Retention and deletion
Session records expire within minutes of a session ending. Reachability records persist until you turn rings off in the app. Abuse counters reset daily or monthly and are the only other per-device data we hold. For any other request, email support@koini.io.
Children
KŌINIsend is not directed to anyone under 18.
Changes and contact
We will post changes here with a new effective date. Questions: support@koini.io.
