Last updated: September 30, 2026
The controller responsible for data processing described in this policy is:
Hadamard Corporation
8206 Louisiana Blvd NE, Ste A #2316, Albuquerque, New Mexico 87113, USA (Entity ID 7388314)
German branch (Zweigniederlassung): c/o Matteo Ludwig, Rudolf-Hahn-Straße 67A, 53225 Bonn, Germany —
registered AG Bonn, HRB 29251, VAT ID DE449785620
Contact: info@hadamard.com
This policy covers bb84.com, the BB84 Wallet app (iOS, Android, and the web app at bb84.com/app), and the services described below. It does not cover hadamard.com, which has its own privacy policy.
BB84 Wallet is a self-custodial, non-custodial cryptocurrency wallet application. This policy explains what data the app and its supporting backend services collect, how it is used, and your rights.
BB84 Wallet does not collect, transmit, or store any of the following:
There is no mandatory account registration: you can use the wallet without giving us any personal data. Personal data is only processed by our servers if you use one of the optional features described in sections 8–15 (for example a public profile, notifications or a support ticket), and limited technical diagnostics are described in section 13.
The following data is stored exclusively on your device — in the iOS Keychain or the Android Keystore (hardware-backed secure storage where available):
This data never leaves your device except as described below, and is never transmitted to any server we operate in a form that would let us reconstruct your keys.
When you perform transactions, your wallet address and transaction data are submitted to the BB84 L2 blockchain network (Chain ID: 42069000) and, for deposits and withdrawals, the Ethereum mainnet. Blockchain transactions are public and permanent by nature — once broadcast, we cannot alter, hide, or reverse them.
The app connects to:
These connections log your IP address as part of standard server operation, for abuse prevention and rate limiting. We do not correlate these logs with your on-chain identity.
If you resolve or use a bb84.eth subdomain, the request is served by our self-hosted ENS gateway. Like any web server, it logs requesting IP addresses for operational and abuse-prevention purposes.
To read Ethereum data and broadcast your Ethereum transactions (deposits, withdrawal proofs and finalization), the app connects to the public RPC service PublicNode, operated by an independent third party. PublicNode receives your IP address and the requests and signed transactions your app sends to it, and processes them under its own privacy policy. Transactions you broadcast become public on the Ethereum blockchain.
On the web app, Ethereum transactions are signed by the browser wallet you connect (e.g. MetaMask), which is independent software subject to its own privacy policy.
You can attach an optional profile to a one-time address (OTA) in Settings → Profile. It may contain a display name, date of birth, email address, phone number, postal address (street, postal code, city, country) and a profile picture — only the fields you choose to fill in. Saving a profile requires an on-chain ownership proof from the OTA, so only the holder of that OTA can create or change it.
Profiles are public by default: anyone who knows the OTA address or its bb84.eth name can retrieve the profile through our gateway, and other BB84 users may see your name and picture in their app. If you switch the profile to private, all profile fields including the picture are hidden from every requester. You can change or delete your profile at any time in the app or by contacting us. Profiles are stored until you delete them.
The profile screen offers "Sign in with Apple" and "Sign in with Google" solely to pre-fill your name and email address. The sign-in happens between your device and Apple or Google under their privacy policies; we do not create an account for you and do not receive any access tokens. The pre-filled data only reaches our servers if you then save it as your profile (section 8).
If you used Sign in with Apple, Apple may send us server-to-server notifications (for example when you change your email-forwarding preference or delete your Apple ID link). We verify and log these events (up to the last 500 events) to be able to honour them.
If you enable push notifications, the app sends us your device's push token (an Expo push token), the OTA addresses you want to be notified about and your notification preferences (incoming/outgoing). We use this to notify you about incoming and outgoing transactions on those OTAs. Notifications are delivered through Expo (650 Industries, Inc., USA) and Apple Push Notification service or Google Firebase Cloud Messaging. We store the token until you disable push notifications or it becomes invalid. We also keep the last known balance of registered OTAs to detect changes.
If you add a notification email address, we store it together with the OTA addresses it is linked to, its verification status, the number of verification attempts, your notification preferences and the last known balance of those OTAs. We send a verification email and, after verification, transaction notifications through Resend (Resend, Inc., USA). You can remove the email address at any time in the app; it is then deleted.
If you open a support ticket (in the app or on bb84.com), we store the name and email address you enter, your messages and our replies, the ticket source, timestamps and the IP address the ticket was sent from. The app keeps a random access token on your device so that you can read replies. We use this data only to handle your request and keep it for as long as necessary for that purpose and for documentation of the request, unless you ask us to delete it earlier.
To detect and fix errors, the app sends technical event and error logs to our server. A log entry contains a random installation ID (not linked to your identity), the app version and platform, the screen and a short message, and — where relevant to the error — a shortened OTA address, a transaction hash or an amount. Logs are stored on our server and rotated once they reach a fixed size (older entries are then deleted).
If you request a developer API key on bb84.com/developers, we store the company name, contact name, email address, website and business address you provide, together with a hash of your key (the key itself is shown to you only once) and usage counters. We use this to operate the API, contact you about it and prevent abuse. You can revoke your key at any time.
Authorised Hadamard staff can view the data described in sections 8–14 for a given OTA (profile, linked OTAs, notification settings, support tickets, current on-chain balance) in our protected admin interface, solely to provide support and to operate and secure the service. Access to that interface requires authentication and is logged.
The app requests camera access solely to scan payment QR codes (e.g. bb84.com payment requests) in the Send screen. No images are stored or transmitted.
| Processing | Legal basis |
|---|---|
| Sending notification emails via Resend | Art. 6(1)(b) GDPR — performance of the contract you request by opting in |
| Server logs (RPC, ENS gateway) | Art. 6(1)(f) GDPR — legitimate interest in operating, securing, and rate-limiting the service |
| Ethereum RPC requests via PublicNode | Art. 6(1)(b) GDPR — necessary to carry out the Ethereum transactions and balance queries you request |
| Optional profile, push and email notifications | Art. 6(1)(b) GDPR — providing the optional feature you enable; for voluntarily published profile data also Art. 6(1)(a) GDPR (consent, revocable by deleting or hiding the profile) |
| Support tickets | Art. 6(1)(b) GDPR — handling your request |
| App diagnostics logs | Art. 6(1)(f) GDPR — legitimate interest in detecting and fixing errors |
| Developer API keys | Art. 6(1)(b) GDPR — providing the API you requested |
| Internal support access, Apple sign-in notifications | Art. 6(1)(f) GDPR — legitimate interest in support, security and honouring account-link changes |
Resend, Expo, Apple, Google and PublicNode are used as described above and may process data outside the EU/EEA (including in the United States). Where this occurs, transfers rely on the providers' own compliance mechanisms (e.g. Standard Contractual Clauses); please refer to their respective privacy policies for details.
Server access logs and app diagnostics logs are rotated on a routine schedule for operational purposes. Profiles, notification settings and developer API data are kept until you delete them or disable the feature; support tickets are kept as described in section 12. Blockchain data cannot be deleted by anyone (section 5).
Subject to applicable law, you have the right to request access to, rectification of, or erasure of personal data we hold about you, to restrict or object to processing, and to data portability. To exercise these rights, contact us at info@hadamard.com. You also have the right to lodge a complaint with a supervisory authority — for our German branch, the competent authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).
Private keys are stored in the iOS Keychain / Android Keystore, which provide hardware-backed encryption on supported devices. We recommend keeping a secure backup of your wallet export file and storing it in a safe location offline. Because BB84 Wallet is non-custodial, we have no ability to recover lost wallets or reverse transactions.
BB84 Wallet is not intended for users under the age of 18. We do not knowingly collect information from minors.
We may update this policy as the app evolves. Material changes will be reflected by updating the "Last updated" date above. Continued use of the app after changes constitutes acceptance of the updated policy.
For questions about this privacy policy or to exercise your rights, contact: info@hadamard.com