Salmon Wallet Privacy Policy with Power-ups
Effective date: October 6, 2026
This policy explains what information is used in Salmon Wallet and its Payments and Swap Power-ups, who receives it, and what choices you can make.
Power-ups version 1.4.
1 Controller and scope
GeekOcean Labs Ltd, a company incorporated in the British Virgin Islands (“Salmon,” “we,” “us,” or “our”), is the controller for the information processing it carries out for the purposes described in this Policy.
The Policy covers the Salmon Wallet mobile applications and browser extension (the “Wallet”), their features, and the institutional website salmonwallet.io (the “Site”). The Site provides information; it is not a web wallet.
The core features covered by this version include Solana and viewing balances and history, sending, and receiving BTC on the Bitcoin network. Payments and Swap operate only on Solana; Bitcoin is not part of those Power-ups. Ethereum connections and transactions are not enabled. Payments covers payment requests through Solana Pay; it does not include x402 or encrypted messaging.
The Power-ups Terms and Conditions describe the service. This Policy is a data notice: reading it or accepting the Terms does not by itself constitute consent to analytics or other optional processing.
For privacy questions or to exercise your rights, write to help@salmonwallet.io.
2 Self-custody and privacy limitations
Salmon is a self-custodial wallet: you control the keys that authorize movements of your assets. The Wallet stores your private keys and recovery phrase encrypted on your device. Salmon's servers do not receive or store those secrets or the local password protecting the Wallet and cannot reconstruct them.
Creating or importing a wallet does not require a Salmon account, email address, name, or identity documents. Activating a Power-up does not transfer control of those keys to Salmon.
Self-custody does not mean anonymity or absence of data processing. Wallet addresses, queries, IP addresses—identifiers of internet connections—and transactions may allow a person to be identified or linked to information. We treat information as personal data where it qualifies under the law, even if it comes from a public record.
The blockchain maintains an independent public record. Salmon cannot erase your transactions or prevent third parties from viewing, copying, or analyzing them.
3 Information that remains on your device
Keys, preferences, and authorizations
In addition to keys, the Wallet retains local preferences, including Power-up activation and analytics choices. Selecting a feature may require checking its availability with Salmon; it does not mean that all local data is sent to the server.
Transactions are signed on the device. A signed transaction contains instructions and cryptographic proof of authorization, but does not contain the private key or recovery phrase.
Biometrics and camera
If you enable biometric authentication, the operating system performs the check and communicates the result to the Wallet. Salmon does not receive your fingerprint, face, or biometric template.
With your permission, the camera is used to read QR codes. Image analysis takes place on the device; the image is not sent to Salmon as part of scanning. Data extracted from the code, such as an address or amount, may subsequently be used to query the network or prepare a transaction, as explained in this Policy.
Payments requests
Requests created through Payments are stored locally by wallet and network. They include the recipient, USDC amount—a token whose issuer seeks to maintain a value equivalent to the US dollar—order identifier, reference, any note you add, and expiry. The shared payment code also includes the account name. The request list and notes are not sent to Salmon's servers or synchronized between devices through this Power-up.
Deleting a request erases that local record. Deleting application data or resetting the device may cause requests and notes to be lost. Keeping the recovery phrase allows keys to be restored, but not necessarily those local records.
4 Data we receive or query
Support and communications
When you contact us, we receive your email address, message, and any files or data you choose to send. If you include a wallet address or transaction, we may associate it with that communication to handle it. We do not automatically obtain your email address when you create the Wallet.
We use Migadu to host and manage support emails, including messages and attachments. Salmon's team manually deletes those emails according to the period in section 9.
Do not send private keys or recovery phrases. If you need to demonstrate control of a wallet for a request, we will not ask you to reveal those secrets or make a payment.
Public network information
The Wallet and supporting infrastructure query public addresses, balances, transactions, public signatures, asset identifiers, and collectible data to display contents and activity. An address is a wallet's public identifier, not a secret credential.
Data associated with an NFT, an individually identifiable token, may include images, descriptions, and links hosted outside the blockchain. Retrieving that content may reveal the requested identifier and the querying party's IP address to its hosting server.
Requests and technical logs
Communicating with our infrastructure involves processing information needed to respond and protect the service: IP address, date and time, request type, platform, result, errors, and data included in the request. Depending on the feature, this may include a wallet address, assets, an amount, or unsigned instructions.
Operational logs may allow an IP address to be linked to the address or information queried. The absence of a user account does not prevent this technical association. We do not promise anonymity or a complete absence of logs.
Request logs in Amazon CloudWatch are retained for 30 days, except for limited preservation needed to investigate an incident, meet a legal obligation, or address a claim. We do not use those logs for targeted advertising.
To prevent abuse, we use a temporary request counter per IP address that expires automatically after 60 seconds. To avoid repeating certain Swap risk checks, we retain the queried public address and result for 24 hours. This temporary data is hosted by Upstash, Inc. through an encrypted connection. Its expiry does not delete independent CloudWatch request logs.
5 Information by feature
5.1 Balances, Activity, and Collectibles
To query Solana balances, activity, and collectibles, Salmon's infrastructure uses Triton One. It receives the public address whose data is requested and the Salmon server connection, not the user's IP address through that forwarding. Direct device connections to Triton One to broadcast transactions or check payments are described separately.
To query a Bitcoin address's balance, history, and spendable funds, Salmon's servers query mempool.space and, if that service does not respond, blockstream.info. The queried provider receives the public address and Salmon server IP address, not the user's IP address through that forwarding. These queries do not require sending private keys or creating an account with those providers.
Services supplying images and other metadata receive the identifiers needed to deliver that content. Independent providers keep their own records under applicable conditions.
5.2 Market information
CoinGecko supplies general price and asset information. Salmon's queries identify assets, currencies, or periods; they do not include the wallet address, its balances, or a transfer amount, and do not forward the user's IP address.
5.3 Transfers and transaction broadcasting
For Solana transfers, payments, and swaps covered by this Policy, the device broadcasts the signed transaction directly to Triton One, the network connection provider. Triton receives the signed transaction and device IP address. Salmon's servers do not receive that signed transaction for rebroadcasting. A signature does not reveal the private key or allow other transactions to be signed.
For Bitcoin transfers, the device broadcasts the signed transaction directly to mempool.space and, if that fails, to blockstream.info. Each provider to which broadcasting is attempted receives the signed transaction and device IP address, even if the transaction is not confirmed on the network. Salmon's servers do not receive the signed transaction for rebroadcasting. No private keys or recovery phrases are sent.
When the transaction is recorded on the blockchain, sender, recipient, asset, amount, reference, and other included instruction data may become public. Requesting support or checking status may cause Salmon to process identifiers and public information about that transaction again.
5.4 Payments and data shared through QR codes
Displaying or sharing a request communicates to its recipients the receiving address, amount, token, account name, note, and order identifier contained in the QR code or text. Anyone with access can read, copy, and share them. The note is not an end-to-end encrypted message, and the QR code does not guarantee confidentiality.
The Payments screen queries the balance through Salmon's infrastructure, which receives the public address as in ordinary Wallet queries. To check whether payment was received, the device queries Triton One directly. It may receive the request reference and recipient address along with the IP address, even before a confirmed payment exists. Neither query sends the request list or local note to Salmon's server.
In Salmon's Payments flow, the payment is recorded publicly along with the order identifier and a single-use reference. The note is not included in the transaction or published on the blockchain through this feature. Deleting the request, application, or local note does not erase public payment data or copies of the QR code or its contents retained by others. An external wallet reading the request may have its own practices; this description does not guarantee what a third party does with the received note.
Do not include sensitive data, keys, personal documents, or information about others without an appropriate basis for sharing it. This feature does not use x402 or an encrypted messaging service.
5.5 Swap quotes and preparation
When you request a Swap, Salmon processes the public address, network, input token, requested token, amount, tolerance for price changes, and fee data needed to obtain the quote and prepare unsigned instructions.
The request is sent from Salmon's infrastructure to the selected provider, 0x or Metis, the Jupiter routing software used by Salmon, according to territorial availability and applicable restrictions. The provider receives the public address, tokens, amount, and transaction parameters needed to calculate the route and prepare instructions, including applicable fee settings. Salmon does not forward the user's IP address to the routing provider; it receives the Salmon server connection.
Salmon prepares the unsigned transaction and simulates it through a Solana connection provider to check its expected processing. That provider receives the instructions and addresses needed for simulation even if you do not sign. Simulation does not move funds.
If you accept the transaction, your device signs it and broadcasts it directly to Triton One. Salmon's servers do not receive the signed transaction for rebroadcasting. The routing provider calculates options, Salmon facilitates preparation and presentation, and network protocols process the authorized transaction; none of these information exchanges requires disclosure of your private keys.
Requesting a quote already involves processing and sharing this data even if you do not sign afterwards. The provider may infer an interest in an exchange from the query, without that query proving that the transaction occurred.
If you sign and the transaction is confirmed, the blockchain records its public data, including incorporated fees. Technical logs may include rejected-request or error details to investigate a problem; they remain subject to the corresponding retention rules.
5.6 Approximate location and territorial availability
Salmon uses the connection's IP address to estimate the country and apply access restrictions or select a provider. This check does not require GPS access, precise location, or continuous device tracking.
Eligible requests from the United States are directed to 0x, not Metis. In other countries, selection follows the service restrictions. If no provider is enabled for the request, Swap is not offered. This availability check takes place when the feature is requested, not only when the application is downloaded.
The estimate uses an IP-range database from DB-IP hosted in Salmon's infrastructure. A user lookup does not require sending their IP address to DB-IP. Updating that database is different from querying a particular user.
Availability logic uses the estimated country, platform, and feature rules. It may log the decision to allow or deny access. Although that decision record does not deliberately include a wallet address, other infrastructure technical logs may contain IP addresses and request data; section 4 applies.
The inferred country may be incorrect and does not establish citizenship or residence. You may contact support if you believe a restriction is erroneous. Correcting a location does not guarantee access to a feature subject to other requirements.
5.7 Address and risk checks
Before requesting a quote from Metis, Salmon compares the public address with a local copy of the SDN sanctions list of OFAC, the US Treasury's sanctions office, and queries TRM Labs, which receives the public address to return an assessment result. The query does not send TRM the user's IP address, private keys, recovery phrases, Payments notes, or identity documents.
The result helps determine whether the integration can serve the request. Checking a public address does not establish its holder's civil identity. In the 0x flow, the provider performs its own controls using the data needed for the quote; Salmon does not send that request to TRM through the Metis flow.
Local checks against public sanctions lists do not, by themselves, send the queried address to the agency publishing the list. The copy of addresses published by OFAC is updated daily and retained between updates; it is not a list built from user queries. User-check results are stored temporarily to avoid repeated queries, as described in section 9.
These decisions may be automated and restrict access to Swap, but do not transfer control of funds to Salmon. You may request review of a possible error through the contact channel. We will honor applicable rights concerning automated decisions and explain relevant limitations without disclosing information whose disclosure is legally restricted.
5.8 Mobile application updates
On opening, the mobile application checks with Expo for an update. That direct connection sends Expo the device IP address and application version to deliver the corresponding update. It is an operational technical communication, separate from optional analytics: disabling analytics does not disable this check. No private keys or Payments notes are sent as part of it.
6 Optional analytics and cookies
6.1 Analytics within the Wallet
Usage analytics is disabled by default. It is enabled only through an affirmative choice and can be disabled in Settings. Activating a Power-up does not itself activate analytics.
With your consent, the Wallet uses a random installation identifier and events from a limited catalog to understand feature usage. Events must not include keys, recovery phrases, wallet addresses, balances, exact amounts, or Payments notes. Where an amount reference is used, it is expressed as a broad range.
Events are sent to Salmon, where they are validated before forwarding to Google Analytics 4. That forwarding does not include the user's IP address: Google receives the Salmon server IP address. Through this mechanism, the Wallet does not place an advertising identifier, cookie, or Google SDK on the device. Technical receipt by Salmon is distinct from the content sent to Google.
Withdrawing consent stops new events and deletes the local identifier and events awaiting delivery. It does not automatically erase events already received; retention is described in section 9, and you may exercise applicable rights.
6.2 Institutional website
Google Analytics loads on the Site only after analytics cookies are accepted. If you do not accept, you can use its essential features without that analytics. The Site choice is independent of the choice made within the Wallet.
The Site uses only Google Analytics 4 for analytics. With your consent, it may process cookie identifiers, connection and device data, visited and referring pages, scrolling to approximately 90% of a page, outbound link clicks, and press-kit downloads. The Site has no forms, videos, or search feature generating those event types. The browser connection to Google exposes technical information; it must not be confused with the server forwarding described for the Wallet.
You can withdraw consent through the Site's cookie settings or delete cookies through your browser. Technical data strictly necessary to serve and protect pages does not depend on analytics consent.
7 Purposes and grounds for processing
Where applicable laws require identification of a legal basis, we use the following according to the activity:
- Requested services: processing queries, requests, and transaction data needed to display information, obtain quotes, prepare instructions, or provide support; the basis is performance of the requested service or agreement with the user, where applicable.
- Security and operation: applying limits, detecting abuse, diagnosing errors, and protecting infrastructure; the basis is our legitimate interest, balanced against individuals' rights, or a specific legal obligation where one exists.
- Availability and controls: applying territorial restrictions and address checks; the basis may be an applicable legal obligation or a legitimate interest in preventing prohibited uses and meeting valid provider conditions. Not every provider commercial requirement is presented as the user's legal obligation.
- Optional analytics: understanding usage and performance with your consent; you may withdraw it without ceasing to use essential features.
- Claims and obligations: addressing rights, complying with valid requests, and retaining evidence needed for claims; the basis is the applicable legal obligation or legitimate interest.
We request consent only where it is the appropriate basis, without imposing it for optional purposes. If you do not provide data necessary for a feature, that feature may be unavailable; this does not authorize processing additional data for other purposes.
We do not sell personal data or share it for cross-context behavioral advertising. We do not use Wallet data for credit assessment or deliberately link optional analytics to addresses, keys, balances, or user identity.
8 Recipients and responsibilities
We share the data needed for each feature with the following recipients, without indiscriminately sending all information to all of them:
| Recipient | Information and purpose |
|---|---|
| Triton One | On direct device connections, signed transactions, status queries, and the user's IP address. On queries from Salmon, public addresses and necessary request data, without forwarding the user's IP address. |
| mempool.space and, as fallback, blockstream.info | For Bitcoin queries from Salmon, public addresses and the server IP address. For device broadcasting, the signed Bitcoin transaction and user's IP address. |
| Connection provider used to simulate Swap | Unsigned instructions and addresses needed to check the transaction, from Salmon's infrastructure. |
| CoinGecko | Asset identifiers and parameters of market queries made by Salmon; it does not receive the wallet address or user's IP address through these queries. |
| 0x or Jupiter's Metis | Public address and parameters needed to quote, prepare the swap, and apply the selected provider's controls, without forwarding the user's IP address. |
| TRM Labs | Public address queried for the Metis-flow risk assessment described in section 5.7, without forwarding the user's IP address. |
| Amazon Web Services | Data processed or logged in Salmon's infrastructure, including operational logs. |
| Upstash, Inc. | Temporary counters per IP address and public addresses with temporary risk-check results, to prevent abuse and repeated queries. |
| Expo | Device IP address and mobile application version when checking for updates. |
| Google Analytics 4 | Authorized analytics events, with the differences between the Site and Wallet explained in section 6. |
| Migadu | Email address, messages, attachments, and data you include when contacting support, to host and manage those communications. |
| Request recipients and public networks | Data you share through QR codes or text and data included in transactions recorded on the blockchain. |
Providers processing data on Salmon's instructions must use it for the contracted purposes and protect it according to their obligations. Those determining their own purposes and means are responsible for that independent processing. A direct connection does not by itself determine a provider's legal role or remove Salmon's responsibilities.
You can consult the 0x privacy notice, Jupiter policy published in its documentation, Upstash policy, and Expo policy. The specific service's identity and notices must be available when using it. A provider's description of certain data as public does not remove its potential personal-data status for Salmon.
For support, see Migadu's privacy and data-processing policy. For Bitcoin connections, see the mempool.space policy and privacy information published by Blockstream for its Explorer API.
We may also disclose information to authorities, courts, or advisers where necessary and supported by a valid basis, or to a business successor subject to appropriate protections and notices. We do not disclose private keys or recovery phrases we do not possess.
DB-IP supplies the database used locally to infer countries; it does not receive the individual queries described here. Image or content hosting services may receive technical data needed to deliver requested resources.
9 Retention and deletion
We retain information for the time needed for the stated purposes, using these periods and criteria:
| Information | Retention or deletion |
|---|---|
| Keys and local preferences | On the device until you delete them or erase the corresponding data. Salmon does not keep a recoverable copy of your secrets. |
| Payments requests and notes | On the device where created until deleted or Wallet data is erased. Request expiry does not automatically delete it. |
| CloudWatch request logs | 30 days; exceptional preservation must be limited to the information and period necessary for incidents, obligations, or claims. |
| Upstash request counter per IP address | Automatic expiry after 60 seconds. This does not delete the independent CloudWatch request log. |
| Public address and temporary TRM-check result in Upstash | Automatic expiry after 24 hours to avoid repeated checks. This period does not determine TRM retention or independent request, incident, or claim records. |
| Support emails and attachments in Migadu | During handling and for up to 12 months after the inquiry closes, to handle follow-ups or recurring problems. Salmon's team deletes them manually at the end of that period, except for limited retention of information needed for a pending claim or legal obligation. |
| Local analytics identifier and queue | Until consent is withdrawn or application data is deleted. |
| Wallet event data in Google Analytics 4 | Configured retention period of 2 months. |
| Data associated with the installation identifier in Google Analytics 4 | Configured period of 14 months from that installation's last activity; new activity resets the period. |
| Site event data in Google Analytics 4 | Configured retention period of 2 months. |
| Site user-level data in Google Analytics 4 | Configured period of 14 months, subject to the property's activity settings. |
| Records needed for claims or legal obligations | For the period applicable to the case, with use restricted to that need. |
Where data under our control must be deleted, we use service controls or instruct providers acting on our behalf. The Upstash database used for this data has no configured backups or replicas in other regions. Upstash also uses disk storage: “temporary” describes entry expiry, not that entries exist only in memory or are guaranteed to be physically erased immediately upon expiry. It also does not determine retention of the provider's own records.
The Google Analytics 4 periods stated apply to Wallet and Site event and user or installation data, not all Google's aggregated statistical reports. Withdrawing consent stops new events from the relevant service but does not immediately delete information already received.
Migadu keeps mailbox backups for recovery. Manual deletion of an email from the support mailbox does not guarantee its immediate deletion from those backups. The 12-month period describes Salmon's mailbox retention, not an additional guaranteed physical-erasure period by Migadu.
Network connection providers may retain their own logs to operate the service, address problems, and prevent abuse. Triton publishes a standard period of four weeks for its shared services and different logging options for dedicated services. That period is not a universal guarantee for all Triton connections; retention depends on the service and applicable conditions.
Under its privacy policy, mempool.space retains server logs containing IP addresses and requests for 10 days. That period does not describe all its own statistics or Bitcoin's public record. For blockstream.info, Salmon does not guarantee a specific deletion period or complete absence of logs.
Providers' independent logs are governed by their terms and purposes; Salmon's periods do not automatically apply to them. A provider's statement that it keeps no persistent logs does not mean its service does not receive the IP address needed for a connection. You can consult Triton's privacy information and Blockstream's policy.
The blockchain, copies of shared requests, and independent controllers' records cannot be erased through an action by Salmon. Disabling Swap or Payments stops future use of that feature through its interface; it does not automatically erase quotes already requested, queries already made, or public transactions.
10 Providers and international data processing
To provide its features, Salmon uses technology providers that may process information in countries other than the user's country of residence. Depending on the feature used, that information may include public wallet addresses, blockchain queries, transaction data, and technical connection data, as explained in this Policy.
GeekOcean Labs Ltd is incorporated in the British Virgin Islands. Salmon's Amazon Web Services servers and Upstash database for temporary data are located in Northern Virginia, United States. The Upstash database has no replicas in other regions. Blockchain networks are distributed among participants in multiple jurisdictions.
Salmon shares information needed to provide the requested feature, maintain security, and apply relevant restrictions. These communications do not include private keys, the recovery phrase, or the Wallet's local password.
Each provider's processing is governed by the terms applicable to its service and the relevant legislation. Salmon's retention periods do not automatically apply to those providers' own records. Their involvement does not remove Salmon's obligations for its own activities, including any legally required international-transfer safeguards.
You may request information about recipients, processing of your data, and applicable transfer safeguards, including a copy where appropriate, by writing to help@salmonwallet.io. Using the Wallet does not waive your privacy rights or constitute blanket consent to transfers requiring another basis or protection.
11 Security
We apply reasonable technical and organizational measures to protect information we control. No system guarantees absolute security. Risks include unauthorized access, device failures, errors, and third-party vulnerabilities.
The connection between Salmon's infrastructure and Upstash uses encryption in transit. This protection is distinct from encryption of keys on the device and does not mean that all data stored by each provider has the same protections. Nor does it make the Payments QR code confidential or hide data recorded on the blockchain.
Self-custody keeps keys off our servers but requires you to protect your device and recovery backups. Restricting an interface or handling a privacy request does not prevent someone who already possesses your keys from using other software to transact.
If we detect an incident requiring notice to users or authorities, we will act according to applicable requirements.
12 Rights and choices
Depending on your jurisdiction and applicable legal conditions, you may request access, a copy, correction, deletion, portability, restriction, or objection to processing. You may also withdraw consent, challenge automated decisions where applicable, and complain to a competent data-protection authority.
To exercise a right, write to help@salmonwallet.io. We may request proportionate information to verify the request and locate the data. We will not require private keys, recovery phrases, or payment to substantiate it. We will handle the request within legal deadlines and explain any refusal or limitation.
Where your law permits, you may act through an authorized representative or request review of a denial. You will not be discriminated against for exercising your rights. Features needing certain data may become unavailable if that data is deleted or not provided; optional uses do not thereby become mandatory.
You may withdraw analytics without disabling the Wallet, disable Power-ups, and revoke camera or biometric permissions through available controls. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
We cannot identify all of a person's data from their name if we have never received a link to their wallet. Nor can we erase information from a public blockchain. We will explain these limitations without using them to reject requests about information we do control.
13 Minors
The Services are intended for adults under the Terms. We do not knowingly collect minors' personal data. If you believe a minor provided us with information, contact the privacy channel so we can investigate and delete data under our control where appropriate.
14 External services and stores
Sites, applications, independent providers, and stores may process information under their own policies. Opening an external link may reveal technical visit information to its destination. Review their notices before providing additional data.
Apple, Google, and extension-store operators may process download, update, or platform-usage information. Salmon does not automatically receive all that data. Their policies do not replace this Policy for Salmon's activities.
15 Versions and changes
The applicable Policy identifies its version and effective date and must correspond to the processing performed by the service version used. Publishing a proposal does not start data processing or replace the notice in force.
We will notify you of material changes before applying them where required and request fresh consent where appropriate. We will not use a text amendment to retroactively legitimize a purpose incompatible with the purpose for which data was obtained.
If a feature is withdrawn, retention of the data it generated follows its applicable purpose and period; removing the feature does not erase its public history or allow indefinite retention of its private data.
16 Contact
Controller: GeekOcean Labs Ltd, British Virgin Islands. For privacy questions, requests, or complaints: help@salmonwallet.io. Do not include private keys or recovery phrases.