Privacy Policy
Last updated: June 30, 2026
Passkallet is a non-custodial smart-wallet service operated by Known Distance. This policy explains what data we process, why, and the choices you have. Passkallet is designed to be privacy-first: we do not perform identity verification (KYC) for individual users, we never hold your private keys, and your biometric data never leaves your device.
1. Who we are
Known Distance is the data controller for Passkallet. References to “we”, “us”, or “Passkallet” mean Known Distance. If you use Passkallet through a business that integrates our technology (a “BaaS” integrator), that business is a separate controller for the data it collects from you, and its own privacy policy also applies.
2. The short version
In plain terms:
- We do not ask you for identity documents. There is no KYC for individual users.
- We never store your private keys. Your wallet is non-custodial — only your device can authorize transactions.
- Your fingerprint or face never reaches us. Biometrics stay in your device's secure hardware; we only receive a public cryptographic key.
- Wallet addresses and on-chain activity are public by nature of the blockchain and are pseudonymous — not tied to your identity unless you reveal it.
- We use Firebase for sign-in and notifications, and we keep limited security logs.
3. Information we collect
Account & identity. When you create an account we process the information from your chosen sign-in method (email and password, or Google sign-in via Firebase Authentication): your email address, and, where available, your name and profile photo. You may set a preferred display currency and interface language.
Wallet & blockchain data. For each smart wallet we store its public on-chain address, an optional label you choose, cached balances, the tokens and NFTs held, and a record of your transactions (hashes, status, type, and the recipient/amount that are, in any case, public on the blockchain). This data is pseudonymous: an address is not, by itself, your identity.
Passkeys (security keys). To secure your wallet we use passkeys (WebAuthn / P-256). We store the passkey's public key, its credential identifier, a signature counter, the transport types, and the domain it was registered for. We do not store, and never receive, your private key or your biometric data.
Notifications. If you enable push notifications, we store the push token issued by Firebase Cloud Messaging for your device, so we can notify you about your transactions and approvals.
Contacts (your address book). If you add contacts, we store the alias, address, and network you enter. This is your personal address book — we do not build a directory of users, and we do not let you search for other people's accounts.
Business accounts (BaaS). If you create or join an organization, we store the organization name and description, members and their roles, and API keys (we store only a hash of each key — the key itself is shown once and never stored). Organizations may configure a webhook URL to receive event notifications.
Technical & security logs. Our servers keep audit logs of requests for security and troubleshooting, which include your IP address, browser/user-agent, the endpoint accessed, and timing. We use a lightweight session cookie (a simple flag) to keep you signed in, and store your profile and language preference in your browser's local storage.
4. What we deliberately do NOT collect
By design, Passkallet does not collect or store:
- Identity documents, government IDs, or KYC information for individual users.
- Private keys, seed phrases, or recovery secrets that could move your funds.
- Biometric data — fingerprints or facial data never leave your device's secure enclave.
- A searchable directory of users — there is no way to look up other people by email.
5. How we use your information
We process the data above to:
- Create and operate your wallet, and prepare and submit the transactions you authorize.
- Authenticate you and register/verify your passkeys.
- Show balances, tokens, NFTs, and history, and display values in your preferred currency.
- Send you notifications about transactions and approvals (if enabled).
- Keep the service secure, prevent abuse, and meet legal obligations.
- Provide and bill the Banking-as-a-Service features to organizations that integrate Passkallet.
6. Legal bases (EEA/UK)
Where the GDPR applies, we rely on: performance of our contract with you (to provide the wallet and execute your instructions); our legitimate interests (to keep the service secure and prevent fraud); your consent (for push notifications, which you can withdraw at any time); and compliance with legal obligations.
7. Service providers and recipients
We share data only with providers that help us run Passkallet, and only as needed:
- Google Firebase — authentication (sign-in) and push notifications (Cloud Messaging).
- Our blockchain infrastructure — a Web3 API and RPC node provider that broadcast your signed transactions and read on-chain state. These receive wallet addresses, passkey public keys, and transaction parameters.
- A message broker and price service used internally to process on-chain events and display fiat values.
- A secrets manager used to protect our own credentials.
- For business integrations, transaction events are delivered to the webhook URL the organization configures, signed with a shared secret.
- The public blockchain — transactions you authorize are, by nature, recorded publicly and permanently on-chain, outside our control.
8. International transfers
Some of our providers (such as Google) process data outside your country, including in the United States. Where required, such transfers are covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
9. Data retention
We keep account and wallet data for as long as your account is active. When you delete your account we mark it deleted and stop using it for the service; we may retain limited records where necessary for security, dispute resolution, or legal compliance. Security logs are kept for a limited period. Note that data already written to the public blockchain cannot be deleted by us or by anyone.
10. Your rights
Depending on where you live (for example under the GDPR or the CCPA), you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. You can manage your passkeys, contacts, and notifications in the app, and you can request account deletion. To exercise any right, contact us at the address below. We do not sell your personal data.
11. Children
Passkallet is not directed to children under 16 (or the age required by your local law), and we do not knowingly collect their data.
12. Security
Security is the core of the product: your wallet is non-custodial and protected by passkeys bound to your device, so transactions cannot be authorized without you. We use encryption in transit, store only hashes of sensitive secrets such as API keys, and keep audit logs. No system is perfectly secure, but we work to protect your data and keep the threat surface minimal.
13. Changes to this policy
We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, provide a more prominent notice.
Questions about this policy or your data? Contact our privacy team:
privacy@knowndistance.com