Privacy Policy
Last updated: July 2026
1. Data controller
The CryptoSeed app is developed and maintained by S2 Tech Services LTDA, registered under Brazilian company ID (CNPJ) 65.592.643/0001-17, headquartered in Brasília/DF, Brazil, acting as data controller under Brazilian Law No. 13.709/2018 (LGPD).
Contact for matters relating to this policy and for exercising the rights set out in Article 18 of the LGPD: contato@cryptoseed.com.br.
2. Core principle
CryptoSeed was built with privacy as a core requirement, not an optional feature. No seed phrase, password or usage metadata is collected, transmitted or stored on external servers — under any circumstance. S2 Tech Services does not operate any server that receives data from the app.
The only exception regarding data being read is described in section 6 (install affiliate identifier), which stays on the device and is never sent to servers of our own.
All encryption and decryption operations happen entirely on the user's device, with no internet communication during those operations.
3. Data the app does NOT collect
- Seed phrases, mnemonic words or any cryptocurrency wallet data
- Passwords or password derivations
- Biometric data
- Geographic location
- Device identifiers for tracking purposes
- Usage history, click events or behavioural telemetry
- Session logs sent to external servers
4. Google Play Billing
The Pro version of CryptoSeed uses Google Play Billing solely to process subscription payments. The app has no access to credit card data, banking data or any payment information — processing and storing payment data is entirely Google's responsibility.
To learn how Google handles your payment data, see the Google Privacy Policy.
5. Play Integrity API
On launch, the app requests a token from Google's Play Integrity API. The content of that token is encrypted by Google and is not read by the app — opening it would require a server, which CryptoSeed deliberately does not have. The token is discarded, and no decision about how the app works depends on it.
The only thing recorded is an entry in the session history — kept in memory only and erased when the app closes — when the token could not be obtained (for example, with no connection). No personal information is extracted from that response or transmitted to servers of our own.
6. Install Referrer API
On the first run after installation, the app may read the install URL referrer via Google's Install Referrer API. This data is used solely to identify the referral channel (affiliate programme) responsible for the install. The affiliate identifier (referrer_id) is stored locally on the device and included in the technical field of the Pro purchase for affiliate commission purposes — it is never transmitted to servers of our own.
7. Data stored locally
The app stores the following information locally, on the user's device only:
- Onboarding preference (whether the tutorial was completed)
- Pro licence information (purchase token and expiry date), stored encrypted via the Android Keystore
- Install affiliate identifier (where applicable)
None of this data is sent to external servers.
8. App permissions
- CAMERA — used solely to scan QR Codes during decryption. No image is saved or transmitted.
- ACCESS_NETWORK_STATE — used to detect connectivity and show security alerts to the user. The app makes no network requests during encryption/decryption operations.
- INTERNET — used only by Google Play Billing and the Play Integrity API. Never used during encryption/decryption operations.
9. Children
CryptoSeed is not directed at children under 13 and does not knowingly collect any data from minors.
10. Changes to this policy
Any change to this Privacy Policy will be published on this page with a revised update date. We recommend checking this page periodically.
11. Contact
For questions, clarification requests or to exercise rights relating to this policy, get in touch: