Privacy Policy
Last updated: February 23, 2026
1. Our Commitment to Privacy
Protocol 01 ("P-01", "we", "us", or "our") is a privacy-first Solana wallet and protocol. Privacy is not a feature we added — it is the foundation upon which every component of Protocol 01 is built. This Privacy Policy explains what data we collect, what we do not collect, and how we protect your information.
By using our mobile application, browser extension, SDK, or any Protocol 01 service (collectively, the "Services"), you agree to the practices described in this policy.
2. Information We Do NOT Collect
We have designed Protocol 01 to minimize data collection. We do not collect, store, or have access to:
- Private keys or seed phrases — your wallet keys are generated and encrypted locally on your device. We never transmit or store them on any server.
- Transaction history — we do not maintain logs of your transactions. On-chain data is publicly available on the Solana blockchain, but we do not aggregate, index, or link it to your identity.
- Personal identity information — we do not require your name, email address, phone number, or any government-issued identification to use the wallet.
- IP addresses or geolocation — Protocol 01 does not log IP addresses or track your physical location.
- Browsing activity — our browser extension does not monitor, record, or transmit your browsing history.
3. Information We Collect
3.1 Authentication Data (Optional)
If you choose to authenticate via Privy (Google, Apple, email, or SMS), Privy Inc. processes your authentication credentials. We receive a pseudonymous user identifier and, if applicable, an embedded wallet address. We do not receive or store your OAuth tokens, passwords, or full email/phone number.
3.2 On-Chain Data
When you perform transactions, they are recorded on the Solana blockchain. While Protocol 01 employs zero-knowledge proofs, shielded pools, stealth addresses, and decoy mechanisms to obscure transaction details, certain metadata (e.g., transaction signatures, timestamps) is inherently public on the blockchain.
3.3 Relayer Data
Our relayer service processes shielded transactions and zero-knowledge proofs. The relayer temporarily handles proof data required to submit transactions on-chain. This data is:
- Processed in memory only — never persisted to disk or database.
- Discarded immediately after the transaction is confirmed.
- Not linked to any personal identifier — the relayer processes cryptographic proofs, not identity data.
3.4 Crash Reports & Diagnostics (Optional)
If you opt in to crash reporting, anonymized diagnostic data may be sent to help us improve the application. This data does not include wallet addresses, balances, transaction details, or any personally identifiable information.
4. Zero-Knowledge Privacy Architecture
Protocol 01 uses advanced cryptographic techniques to protect your financial privacy:
- Shielded Pools — funds are deposited into on-chain pools using quantum-resistant STARK zero-knowledge proofs (Goldilocks field, hash-based, no trusted setup). The link between depositor and withdrawer is cryptographically broken.
- Stealth Addresses — recipients can generate one-time addresses, preventing observers from linking payments to a single wallet.
- Merkle Tree Commitments — deposits are stored as hashed commitments in an on-chain Merkle tree, making it computationally infeasible to determine which commitment belongs to which user.
- Client-Side Proof Generation — zero-knowledge proofs are generated on your device or via our Rust-native prover service. In both cases, your secret data (nullifiers, note secrets) never leaves your control unencrypted.
5. Third-Party Services
Protocol 01 integrates with the following third-party services:
- Privy — authentication provider. Subject to Privy's Privacy Policy.
- Helius / Solana RPC Providers — blockchain data access. RPC requests contain your wallet address when querying balances or submitting transactions.
- Jupiter — token price data and swap aggregation. Price queries do not include personal data.
We encourage you to review the privacy policies of these third-party services.
6. Data Storage & Security
- All sensitive data (private keys, seed phrases) is encrypted using device-level secure storage (Android Keystore / iOS Keychain) and never transmitted externally.
- Cached data (balances, transaction history) is stored locally on your device and can be cleared at any time.
- We do not operate user databases. There are no accounts to breach because we do not store account data.
7. Your Rights
Because we collect minimal data, your rights are straightforward:
- Right to deletion — uninstalling the application removes all locally stored data. If you authenticated via Privy, you may request account deletion through Privy's interface.
- Right to portability — you can export your seed phrase at any time and import it into any compatible Solana wallet.
- Right to transparency — our smart contract source code is publicly verifiable on-chain and on GitHub during the open-source phase of the project.
8. Children's Privacy
Protocol 01 is not directed at individuals under the age of 18. We do not knowingly collect data from minors. If you believe a minor has used our Services, please contact us so we can take appropriate action.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the application or on our website. Continued use of the Services after changes constitutes acceptance of the revised policy.
10. Contact
For privacy-related inquiries, contact us at: privacy@protocol-01.com