KlipbitNeoPrivacy

KlipbitNeo — Privacy Policy

Last updated: August 10, 2026

1. Who we are

KlipbitNeo is a self-custodial digital wallet application, published by KLIPBIT LTDA, a company registered in Brazil under CNPJ 68.234.941/0001-23, São Paulo/SP. KLIPBIT LTDA is a software company — not a financial institution or financial services provider. We do not collect personal data for commercial purposes.

This Policy describes how KlipbitNeo software handles information when you use it. KLIPBIT LTDA (CNPJ 68.234.941/0001-23) is the entity responsible for this software and acts as data controller for the limited information it handles, in accordance with the Brazilian Lei Geral de Proteção de Dados (LGPD) and other applicable data protection laws.

2. Core principle

KlipbitNeo is designed to operate with the minimum data possible. The architecture is self-custodial: your private keys, Recovery Phrase, and digital assets remain exclusively on your device. We do not have access to them and we do not want access.

If you opt into encrypted backup (optional), your email is collected for OTP verification. Your Recovery Phrase is encrypted on your device with a password only you know (AES-256-GCM), and the encrypted blob is stored on the server. KlipbitNeo cannot decrypt your backup — only you have the password.

3. What we do NOT collect

To be clear, KlipbitNeo never collects:

  • Private keys, Recovery Phrases, or wallet passwords (even with backup enabled — the backup is encrypted on your device before leaving);
  • Identity documents, government ID numbers, selfies, or any identity-verification data (Section 4.2);
  • Your wallet balances or transaction history;
  • Precise location (GPS);
  • Contacts, photos, files, or data from other apps;
  • Biometric data (fingerprint and Face ID are processed locally by your device — never transmitted).

4. What we collect

The software may collect or process the following data, depending on the features you use:

4.1 Encrypted backup (optional)

If you opt into encrypted backup, we collect your email address for OTP verification. Your Recovery Phrase is encrypted locally on your device (AES-256-GCM with a password you set) before being sent to the server. The stored blob is unreadable without your password — KlipbitNeo cannot access your keys.

4.2 Local currency access (licensed providers)

To access local currency rails you may optionally complete an identity verification with a licensed provider operating in your country. That data collection (identity, documents) is performed directly by that provider, under its own privacy policy, and the provider holds the applicable license in its market. KlipbitNeo does not collect, store, or have access to that data. Activating a provider is optional and at your own discretion.

4.3 Diagnostics and telemetry

The app sends technical diagnostic data to our servers so we can detect crashes, failed transactions and delivery problems. This includes: app version and build number, device platform (iOS or Android), error messages and technical stack traces, timing measurements, and step-by-step progress markers from payment and transfer flows. For events tied to a blockchain transaction, the diagnostic record can include your public wallet address and the transaction signature — both of which are already public on the blockchain. When the app contacts our servers, the server also records the request's IP address and browser/device identifier (user-agent) for security, abuse prevention and rate limiting.

Diagnostic data is used only to operate, secure and improve the service (legal basis: legitimate interest, LGPD Art. 7, IX). It is not used for advertising, not sold, and not shared with third-party analytics or advertising companies. We do not use third-party analytics SDKs.

Your seed phrase, private keys and password never leave your device and are never included in diagnostic data.

Diagnostic logs are retained for up to 6 months and then deleted automatically. To exercise your LGPD rights regarding diagnostic data, contact us at the address in the Contact section; include your public wallet address so we can locate records tied to it.

4.4 Web browsing data

The web interfaces (website and web app) are hosted on Vercel, which may automatically collect IP address, browser type, and access data per its own privacy policy. KlipbitNeo does not use tracking cookies, conversion pixels, or third-party analytics tools.

5. Blockchain data

Blockchain transactions are public and permanent. Wallet addresses, transferred amounts, and transaction signatures are recorded forever on decentralized networks — beyond the control of anyone, including KLIPBIT LTDA.

The software cannot erase, modify, or hide data already recorded on a blockchain. If you made a transaction, that transaction data is permanent. This is an inherent characteristic of blockchain networks, not a design choice.

6. Local storage (your device)

The software stores locally on your device:

  • Private keys and Recovery Phrase — in your device's secure storage (Keychain/SecureStore), encrypted by the device;
  • Preferences — language, selected network, interface settings;
  • Cache — temporary data to improve performance.

This data remains exclusively on your device. If you uninstall the app, all local data is erased. If you do not have a copy of your Recovery Phrase or an active encrypted backup, your assets will be permanently and irreversibly lost.

7. Data sharing

KlipbitNeo does not sell, rent, or trade user data. Data may be shared only in the following circumstances:

  • With infrastructure providers — database, hosting, and blockchain RPC providers process technical data necessary for operation;
  • With a licensed local provider — if you choose to activate local currency access, your identity-verification data is submitted directly to the licensed provider under its own privacy policy, and is never stored by KlipbitNeo;
  • On the blockchain — transactions are public by nature.

We do not use data for advertising, profiling, or any purpose beyond the operation of the software.

8. Your rights

KLIPBIT LTDA (CNPJ 68.234.941/0001-23) acts as data controller. You may exercise the rights provided by data protection laws (LGPD, GDPR) by contacting hello@klipbit.com. In practice:

  • Access and portability — your assets and keys are on your device. You already have full access;
  • Deletion — you can request removal of your backup email at hello@klipbit.com. Blockchain data cannot be erased;
  • Minimization — the software already collects the minimum necessary by design;
  • Uninstall — uninstalling the app erases all local data. If you do not have a copy of your Recovery Phrase or an active encrypted backup, your assets will be permanently and irreversibly lost.

9. Security

The project adopts reasonable security practices, including encryption in transit (HTTPS/TLS), secure storage of sensitive credentials, and code review. However, no system is infallible.

Security vulnerabilities can be reported at hello@klipbit.com.

10. Minors

The software is not intended for anyone under 18 years of age. We do not intentionally collect data from minors. If you believe a minor has provided data through the software, please contact us so we can remove it.

11. Changes to this Policy

This Policy may be updated at any time. The current version will always be available on this page with the date of the last update. Continued use of the software after changes indicates acceptance of the updated Policy.

12. Contact

For privacy questions, data removal requests, or vulnerability reports: hello@klipbit.com