Privacy Policy
Last updated: 2026-09-22 · v2026-09-22 · 51558da5c787
1. Introduction
Ondex Labs LLC (“Ondex,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Ondex mobile application, browser extension, and website (collectively, the “Service”).
This policy describes how Ondex processes data. Where consent is required, Ondex asks for it separately and you may withdraw it through the applicable control.
2. Information We Collect
Information You Provide
- Profile information: Display name, avatar, bio, and Ondex Name (if registered)
- Support communications: Messages and information you provide when contacting our support team
- Social content: Posts, comments, and messages you create through the social features
Information Collected Automatically
- Device information: Device type, operating system version, app version, and device identifiers for compatibility and crash reporting
- Operational analytics and campaign attribution: After you accept this Privacy Policy, Ondex collects pseudonymous product telemetry and uses AppsFlyer to measure app installs, campaign attribution, and a limited allowlist of business events. Ondex telemetry may include a public wallet address, installation identifier, app version, platform, language, feature interactions, device model, operating-system version, latest network IP, and coarse network location. AppsFlyer processes SDK-generated app-install, device/network, and campaign-attribution metadata plus privacy-reviewed business-event fields. Ondex does not send AppsFlyer wallet addresses, transaction hashes, counterparties, user-entered content, or transaction amounts; advertising identifiers are disabled in the SDK configuration. Collection remains active while you use the App. Use Delete Ondex Profile and Controlled Data to delete linked Ondex analytics and suspend collection on that installation.
- Push notification tokens: If you opt in to notifications, we store a device token to deliver push notifications
- Crash reports: Diagnostic information to identify and fix bugs
- Log data: IP address, access times, and referring URLs when you visit our website
- Public XRPL data: To operate the wallet and related services, Ondex processes public information such as addresses, transaction hashes, assets, amounts, public memos, and validation status.
3. Information We Do NOT Collect
We do not collect or store:
- Seed or private key
- Recovery phrase
- Wallet PIN
- Biometric template
- KYC documents sent directly to a third-party provider
- Precise location data
4. How We Use Information
We use collected information to:
- Provide, maintain, and improve the Service
- Deliver push notifications (if opted in)
- Respond to support inquiries
- Detect and prevent fraud, abuse, and security incidents
- Measure product use, reliability, app installs, and campaign attribution after current Privacy Policy acceptance
- Comply with legal obligations
- Communicate important updates about the Service
5. Data Sharing & Third-Party Services
We do not sell your personal data. We may share information with the following categories of third parties:
- Push and platform providers: Firebase, Apple APNs/FCM, and Google Sign-In where you use those functions
- Analytics and attribution: AppsFlyer for app-install and campaign attribution plus allowlisted business-event measurement after current Privacy Policy acceptance
- Diagnostics and operations: Sentry and Better Stack for crash, security, and operational records
- Wallet and dApp connectivity: Reown/WalletConnect when you connect an external dApp
- Fiat ramps: MELD and the ramp provider you select, under that provider's policy
- Bridges, protocols, and data: Squid, SwapKit, Flare and other protocol providers, IPFS/gateways, and market/data providers used by the feature you request
- x402 parties: The merchant, resource server, or facilitator involved in an x402 request
- Law enforcement: When required by law, subpoena, or court order
Each third-party service operates under its own privacy policy. We encourage you to review their policies before using their services.
6. Blockchain Transparency
The XRP Ledger is a public, decentralized blockchain. Transactions conducted through the App are recorded on the public ledger and are visible to anyone. This includes wallet addresses, transaction amounts, and any data included in transaction memos.
Ondex Names are public identifiers linked to your wallet address and are visible on-chain. Profile information associated with Ondex Names is stored on-chain and is publicly accessible.
Ondex has no ability to delete, modify, or hide blockchain data. You should not include sensitive personal information in transaction memos, public profile fields, or on-chain social posts.
6A. x402 Payments
Depending on the x402 mode used, Ondex processes the merchant or dApp origin, resource URL and displayed metadata, public wallet address, payment requirement, asset, amount, destination, fee, prepared transaction, operation and payment identifiers, signed payment authorization, expected transaction hash, and relay, delivery, settlement, and resource status.
The optional companion relay encrypts request and response payloads in transit between the extension and mobile app. After explicit approval, the exact signed authorization is returned to the requester or merchant. A merchant or facilitator may submit it to XRPL before its LastLedgerSequence expires; if submitted, the transaction becomes public. Ondex never receives the seed or private key.
7. Data Retention
We retain your information for the following periods:
- Account and profile data: Retained until you delete your account or request deletion
- Analytics data: Raw events, sessions, and the linked user profile are deleted after 24 months of inactivity. Legacy signed preference receipts and installation credentials may be retained for audit and compatibility until deletion; they do not suppress current operational analytics or AppsFlyer attribution. AppsFlyer retains attribution data under its own policy; deleting Ondex-controlled data suspends future SDK collection on that installation but does not itself erase records held by AppsFlyer.
- Support communications: 36 months from the date of resolution
- Crash reports: 12 months
- Push notification tokens: Until you opt out or uninstall the App
- x402 relay terminal payloads: Redacted after 24 hours
- x402 relay and request rows: Deleted after 7 days
- Terminal x402 operational records and tombstones: Retained for up to 90 days
- Local encrypted x402 history: Bounded and deleted by age or when app data is erased
- Legal holds: As required by applicable law
On-chain data (transactions, Ondex Names, social posts) cannot be deleted as it is stored on the public XRP Ledger.
8. Data Security
Wallet seeds are encrypted with the user's PIN and stored using device secure storage; sensitive local stores use encryption; Ondex services use TLS; and end-to-end encryption is used where the feature specifies it. Public or operationally necessary metadata may be stored separately from encrypted secrets.
However, no method of electronic storage or transmission is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
General Rights
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Use Settings → Privacy → Delete Ondex Profile and Controlled Data, or the equivalent web route, to revoke push devices and extension pairings, delete linked analytics and profile data, anonymize support records, and hide indexed social content Ondex controls. This does not remove the wallet from your device and cannot erase XRPL records.
- Choices: Current legal acceptance is required before operational analytics and AppsFlyer attribution start. Push permission remains separate. You may use Delete Ondex Profile and Controlled Data to delete linked Ondex analytics and suspend future collection on that installation
- Portability: Request your data in a portable format
For EEA/UK Residents (GDPR)
- Right to restrict processing of your personal data
- Right to object to processing based on legitimate interests
- Right to withdraw consent at any time
- Right to lodge a complaint with your local data protection authority
For California Residents (CCPA/CPRA)
- Right to know what personal information is collected, used, and shared
- Right to delete personal information
- Right to opt out of the sale of personal information (we do not sell personal data)
- Right to non-discrimination for exercising your rights
Blockchain exception: Please note that data recorded on the XRP Ledger (transactions, Ondex Names, social posts) cannot be modified or deleted due to the immutable nature of blockchain technology.
To exercise any of these rights, contact us at [email protected].
10. Children’s Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete such information promptly. If you believe a child under 18 has provided us with personal data, please contact us at [email protected].
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from the laws of your country.
When we transfer data internationally, we implement appropriate safeguards, including standard contractual clauses approved by relevant data protection authorities, to ensure that your information receives an adequate level of protection.
12. Updates to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date shows when it was revised. Material changes will be presented in the App. Where acceptance or consent is required, Ondex will ask you to review and expressly accept the new version before continuing to use the affected Service.
13. Contact
For privacy inquiries, data requests, or questions about this policy, contact us at [email protected].
Ondex Labs LLC
30 N Gould St Ste R
Sheridan, Wyoming 82801
United States
14. Browser Extension Data
If you use the Ondex browser extension, the extension may run as a standalone encrypted browser vault or as an optional companion to Ondex mobile approvals. Browser-extension storage has different risk boundaries than mobile secure storage, and you are responsible for maintaining your wallet backup.
- Standalone browser vault secrets are encrypted locally in extension storage. Ondex does not receive recovery phrases, private keys, vault passwords, backup passwords, or decrypted vault payloads.
- Companion mode may process extension install metadata, pairing status, request identifiers, public wallet addresses, selected accounts, dApp origins, and approval status so requests can be routed to Ondex mobile.
- Companion terminal payloads are redacted after 24 hours, relay and request rows are deleted after 7 days, and terminal operational records may be retained for up to 90 days. Using reset, forget, or self-service profile deletion revokes applicable installs, pairings, and relay sessions.
- Extension features may process public wallet addresses, transaction hashes, ramp or bridge session identifiers, Social or Messages metadata needed for supported reads/writes/decrypt/send flows, diagnostics, and privacy-scrubbed operational analytics.
- Browser notifications should use generic approval copy and should not include recovery secrets, private keys, raw transaction JSON, decrypted message text, or payment-provider identity documents.
- Removing the extension, clearing browser data, deleting a browser profile, or losing every backup copy can make a self-custodial browser vault unrecoverable.
Ondex uses browser-extension data only to provide, secure, support, and measure the disclosed wallet functionality. We do not sell this data, use it for personalized advertising or credit decisions, or allow human access except with your specific consent for support, for security or abuse investigation, when required by law, or in aggregated and anonymized internal operations. These practices follow the Chrome Web Store User Data Policy, including its Limited Use requirements.
15. Compliance, Geolocation & Provider Data
To maintain sanctions compliance and country-based product availability, we may process limited location and risk-related data. This does not give us access to your private keys or assets.
- We may process IP address, network-derived country or region, device locale, app version, public wallet addresses, transaction identifiers, and on-chain protocol interactions.
- We may use this data to apply geofencing, prevent fraud and abuse, assess sanctions risk, comply with lawful requests, and determine whether a feature or provider is available to you.
- We may share limited data with infrastructure providers, analytics and crash providers, fiat/KYC/bridge providers, compliance tools, advisers, and authorities when required by law or needed to protect the Service.
- Ondex does not collect recovery phrases, private keys, or wallet PINs. Identity documents and payment information you submit to third-party providers are handled under those providers' privacy policies.
- IP-based geolocation is approximate. Access may be restricted even if a location estimate is imperfect, especially where a legal, provider, or risk-control requirement applies.
Moderation and voluntarily shared evidence
Reports and block notices are private, off-chain records. We process the reporting and reported addresses, content reference, reason, optional comments and review history to prevent abuse. For an encrypted message, only text you explicitly choose to share is sent to moderation; encryption keys, other messages and decrypted attachments are not sent. Evidence is supplied by the reporter and is not independently verified message content. Only moderators and superadministrators can read this evidence. It is encrypted at rest and deleted 90 days after case resolution, unless legally held. Active cases retain their evidence until resolution. Block relationships and periods are retained while needed to enforce your preferences; account-data deletion removes them. Public blockchain data cannot be erased by Ondex.