Privacy Policy for Dena
Effective Date: July 27, 2026 Last Updated: July 27, 2026
Dena Pay (“Dena,” “we,” “us,” or “our”) operates the Dena mobile application (the “App”), a self-custodial digital wallet. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
Dena is a self-custodial wallet: your funds are controlled by cryptographic keys generated and stored on your device, and we never have access to, or custody of, your assets. This shapes what data we collect — much less than a typical financial app, because we are not a bank, broker, or custodian.
By using Dena, you agree to the collection and use of information as described in this policy.
Current Scope of the App
As of the date of this policy, Dena provides self-custodial wallet functionality only — holding, sending, and receiving USDC on the Solana blockchain. Any features marked “Coming Soon” within the App (including, without limitation, fiat deposit/withdrawal via PIX, debit card issuance, or similar integrations) are not yet available, do not collect or process any personal data, and are not covered by this Privacy Policy. Before any such feature becomes available to you, we will publish an updated Privacy Policy describing the additional data collected and how it will be used, and you will have the opportunity to review it before using that feature.
1. Information We Collect
1.1 Information You Provide Directly
- Recovery email address — used solely to enable account recovery if you lose access to your device. This is the only personal identifier we require.
- Support communications — if you contact us for support, we retain the content of that correspondence.
We do not require government ID, proof of address, selfies, or other identity-verification documents to create or use a Dena wallet.
1.2 Information We Do NOT Collect
- Private keys or seed phrases. Your Device Key is generated and stored in your device’s secure hardware (e.g., Secure Enclave/StrongBox) and never leaves it. We have no technical ability to access, view, or reconstruct your private keys.
- Government-issued identification.
- Financial account details (bank accounts, cards). We do not currently offer any feature that collects this information. If we launch a feature that requires it (e.g., debit card issuance or PIX integration), we will publish an updated Privacy Policy before that feature is available to you — see “Current Scope of the App” above.
1.3 Information Collected Automatically
- Device information: device model, operating system version, app version, and unique device/installation identifiers, for compatibility and security purposes.
- Usage data: app interactions, feature usage, crash logs, and performance diagnostics, used to improve reliability and user experience.
- Approximate location (e.g., country/region, derived from IP address) where necessary for regulatory compliance (e.g., regional feature availability) or fraud prevention. We do not collect precise GPS location.
1.4 Blockchain (On-Chain) Data
Dena operates on the Solana blockchain. Your public wallet address and transaction history are, by the nature of public blockchains, permanently and publicly visible on the Solana ledger to anyone — this is not private information under our control, and it cannot be deleted by us or by you. We do not control, and are not responsible for, data visible on the public blockchain.
2. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the App
- Process and relay transactions you initiate (as a signing/gas-sponsorship service — see Section 5)
- Enable account recovery via your registered email
- Detect, prevent, and investigate fraud, abuse, or security incidents
- Diagnose technical issues and improve app performance
- Communicate with you about your account, security notices, or changes to our services
- Comply with applicable legal and regulatory obligations
We do not sell your personal information, and we do not use your data for third-party advertising.
3. How We Share Information
We share information only in the following limited circumstances:
- Service providers: We use third-party infrastructure providers to operate the App, including email delivery (for OTP codes and recovery notices), blockchain RPC/node providers (to broadcast transactions), and cloud/key-management infrastructure (to support the recovery service). These providers process data only as necessary to perform services for us and are bound by confidentiality obligations.
- Legal requirements: We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Dena, our users, or others.
- Business transfers: If Dena is involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to this policy’s protections.
We do not share your recovery email or usage data with data brokers or advertisers.
4. Our Role as a Non-Custodial Service
Because Dena is self-custodial:
- We never hold, control, or have signing authority over your funds in the ordinary course of use.
- Our backend relay acts only as a transaction signing facilitator and gas sponsor — it co-signs and forwards transactions you authorize but cannot move funds independently.
- Our recovery service can only assist in restoring wallet access under a time-delayed, verifiable process (including a mandatory waiting period and email/OTP verification) — it cannot unilaterally access or transfer your funds.
This means the personal information we hold is intentionally minimal, and most safeguards in this policy exist to protect your recovery email and account-recovery process, not financial account data (because we don’t hold any).
5. Data Retention
- Recovery email: retained for as long as your wallet account is active, plus a limited period thereafter for security and legal purposes.
- Support correspondence: retained per our internal retention schedule for a limited period, unless a longer period is required by law.
- Device/usage logs: retained in aggregated or anonymized form after a limited retention window for diagnostic purposes.
We delete or anonymize personal data once it is no longer needed for the purposes described in this policy, unless a longer retention period is required by law.
6. Data Security
We implement technical and organizational measures appropriate to the sensitivity of the (limited) data we hold, including:
- Encryption of data in transit and at rest
- Hardware-backed key storage on your device (Secure Enclave / Android Keystore)
- Multi-key (threshold) architecture so no single compromised key or party can access your funds
- Access controls and monitoring on our backend infrastructure
No method of transmission or storage is 100% secure. While we work to protect your information, we cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have rights including the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your recovery email and associated account data (note: this does not, and cannot, delete on-chain transaction history, which is public and immutable)
- Withdraw consent to data processing where consent is the legal basis
- Data portability, where applicable
- Lodge a complaint with your local data protection authority
For users in Brazil: These rights are provided in accordance with the Lei Geral de Proteção de Dados (LGPD, Law No. 13.709/2018). You may exercise these rights, or contact our Data Protection contact, using the details in Section 11.
To exercise any rights, contact us at [email protected].
8. International Data Transfers
Our service providers may process data outside your country of residence. Where we transfer personal data internationally, we take steps intended to ensure an adequate level of protection consistent with applicable law (e.g., LGPD, and where relevant, other regional frameworks).
9. Children’s Privacy
Dena is not directed to, and we do not knowingly collect personal information from, individuals under the age of 18. If we become aware that we have collected personal data from a minor without appropriate consent, we will take steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the App or by other reasonable means, and will update the “Last Updated” date above. Continued use of the App after changes take effect constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Dena Pay Email: [email protected]