Skip to content
everything
简体中文
  • Privacy
  • Terms
  • Support
  • Delete account

Privacy Policy

App · E for Everything Limited · Version 1.0 · Effective 29 September 2026

This Privacy Policy explains what personal data E for Everything Limited collects when you use the App, why we collect it, who we share it with, and what rights you have. Please read it alongside our Terms of Service.

  • 1. Who we are
  • 2. Our starting position: we do not hold your keys or your funds
  • 3. Personal data we collect
  • 4. Where the data comes from
  • 5. Why we use your data
  • 6. Automated decisions
  • 7. Who we share your data with
  • 8. Links to third-party services
  • 9. International transfers
  • 10. How long we keep data
  • 11. Security
  • 12. Your rights
  • 13. Age requirement
  • 14. Website, cookies and similar technologies
  • 15. Changes to this Policy
  • 16. Contact and complaints

1. Who we are

In this Policy, "we", "us" and "our" mean E for Everything Limited, a company incorporated in the British Virgin Islands (company number 2207801). "You" means a user of the App. "everything" (the "App") means our self-custodial cryptocurrency wallet application for iOS and Android, distributed through the Apple App Store and Google Play.

We are the data controller for the processing described in this Policy. Where a third party independently determines how and why it processes your data — for example Apple or Google when you use their sign-in, or an analytics provider acting for itself — that party is a controller for its own processing and its own privacy notice applies. We have not appointed a data protection officer, because we are not required to appoint one. Privacy questions and rights requests should be sent to privacy@everything.co.

2. Our starting position: we do not hold your keys or your funds

The App is a self-custodial wallet. This shapes everything in this Policy, so we state it plainly:

  • A private key for your wallet is generated inside a hardware-backed trusted execution environment (a secure enclave) operated by our wallet-infrastructure provider, Privy, and is held only as encrypted cryptographic shares under a threshold scheme — one sealed inside the enclave, the other released only against your valid authentication. It is reassembled inside the enclave only to sign a transaction you have authorised. You are not given a seed phrase or recovery phrase.
  • We never hold your private key, or any share of it, in a form we can read or use. No share held by us or by Privy can be decrypted or combined outside the enclave, and the enclave signs only after you have authenticated. Signing in on another device gives you the same wallet without any key material passing through us.
  • We cannot recover, reset, restore or reconstruct your key. Nobody at E for Everything Limited can, in any circumstances, including on your request.
  • We do not hold your crypto-assets, and we have no technical ability to move, freeze or seize assets in a wallet you control.

We will never ask you for your private key. Any message, email, call, social media account, advertisement or support agent asking for it is fraudulent, however convincing it appears and whoever it claims to be. Report it to support@everything.co.

3. Personal data we collect

3.1 Account and sign-in data

You access the App by signing in with a one-time code sent to your email address, or with Google or Apple. There is no password. Your account identity is shared with the account system of the everything trading platform: the same email address resolves to the same account across both products. This interconnection is identity-only — no balance, funds or custody information is shared through it, and nothing done at the trading-platform account level can reach or affect the wallet described in section 2.

  • Email sign-in: your email address, a record of the one-time code request and its outcome, and account creation and sign-in timestamps.
  • Google or Apple sign-in: the email address and basic account identifier that the provider returns to us to identify you. If you use Apple's "Hide My Email", we receive only the relay address Apple issues.
  • Session and security data: authentication tokens, device identifiers linked to a session, sign-in and sign-out events, and records of failed sign-in attempts and any resulting temporary lock.

3.2 Device and technical data

  • Device model, operating system and version, application version, device language and time zone.
  • IP address, from which approximate location (country or region level) is derived. We use this for security and for the geographic restrictions described in section 5.
  • Crash reports, error logs, diagnostic data and performance data.
  • Screens viewed, features used, session length and frequency of use, and aggregated or statistical data derived from these.

3.3 Blockchain and wallet data

  • The public wallet address provisioned to your account.
  • Balances, token holdings and transaction history associated with that address, which we retrieve from the public Ethereum blockchain and from third-party data providers in order to display them to you.
  • Preferences you set, such as your market watchlist and display language, synced to your account.

Blockchain data is public and permanent. Transactions you broadcast are recorded on a public ledger that we do not control and cannot alter or erase. Anyone can view them, and analytics firms can and do link addresses to identities. Deleting your App account does not remove anything from a blockchain. This is a property of the technology, not a choice we have made.

3.4 Support and communications data

  • The content of support requests, including any screenshots or information you choose to send us.
  • Your contact details and our correspondence with you, and any marketing preferences and consent records, where applicable.

3.5 Data we do not collect

We do not collect or store private keys or usable key material, seed or recovery phrases, biometric templates, government identity documents, payment card numbers or bank account credentials. The encrypted key shares described in section 2 are held by Privy as our processor and are of no use to us. The App does not carry out identity verification (KYC), and does not include any buy, sell, convert or fiat funding function that would require it. There is no password to store.

4. Where the data comes from

  • Directly from you, when you sign in, configure the App, contact support or submit a request.
  • Automatically from your device, when you use the App.
  • From the sign-in provider you choose (Google or Apple), limited to the identifiers described in section 3.1.
  • From the public Ethereum blockchain and third-party data and infrastructure providers, including market-data and node or indexing APIs.
  • From app store platforms, in the form of aggregated installation and performance reporting.

5. Why we use your data

The bases in the third column are those recognised under the EU and UK General Data Protection Regulation. They apply where that legislation applies to the processing in question. Where it does not, we still process personal data only where we have a lawful and proportionate reason to do so under the applicable law, including the British Virgin Islands Data Protection Act, 2021.

Purpose Data used Legal basis (GDPR)
Provide the App: display balances, build and present transactions for you to sign, sync your preferences Account, blockchain, device, usage Performance of our contract with you
Authenticate you and secure your account Account, device, security logs Contract; our legitimate interest in security
Prevent, detect and investigate fraud, abuse, unauthorised access and platform misuse Device, usage, security logs, IP Legitimate interest; legal obligation
Apply geographic restrictions and sanctions-related access controls IP and derived country, account data Legitimate interest in operating lawfully and managing sanctions risk; legal obligation
Confirm you meet the minimum age requirement Account data and app store age-rating controls Legitimate interest in restricting the Service to adults
Diagnose crashes and improve stability and usability Crash, diagnostic, usage Legitimate interest
Respond to your support requests Support, account Contract; legitimate interest
Send service and security notices Account, contact Contract; legal obligation
Send optional product updates and marketing Contact, preferences Consent, withdrawable at any time
Comply with law and respond to lawful requests from competent authorities Any relevant data Legal obligation

We do not sell your personal data. We do not share it with third parties for their own independent advertising purposes. We do not profile you to evaluate your personal characteristics, and we do not use your personal data to train artificial intelligence models or make it available to others for that purpose.

6. Automated decisions

We apply automated controls that can restrict access to the App or to particular features — for example, blocking access from a restricted jurisdiction, or applying rate limits and fraud controls. These decisions do not determine whether you can reach assets in a wallet you control, because your wallet exists independently of us and can be reached using a private key you have exported. If an automated control has affected you and you believe it is wrong, contact privacy@everything.co and a person will review it. Where the EU or UK GDPR applies and a decision based solely on automated processing produces legal effects concerning you or similarly significantly affects you, you have the right to obtain human intervention, to express your point of view and to contest the decision.

7. Who we share your data with

Recipient category What they receive and why
Sign-in providers (Google, Apple) You authenticate through them; they return a limited identifier to us. They process your use of their sign-in under their own privacy notices.
Blockchain infrastructure and market-data providers Your public wallet address and queries, so we can display balances, transaction history and prices. This includes node/indexing APIs and market-data sources.
Cloud hosting and infrastructure providers Data hosted or transmitted through their systems to run the service.
Analytics and crash-reporting providers Device, usage and diagnostic data, to keep the App working and improve it.
Customer support tooling providers Your support correspondence and account reference.
App store platforms Installation and platform-level data governed by their own policies.
Professional advisers, auditors and insurers Data strictly necessary for advice, audit or claims.
Courts, regulators, law enforcement Data we are lawfully required to disclose, or that is necessary to establish, exercise or defend legal claims.
A successor entity In connection with a merger, acquisition or reorganisation, subject to equivalent protection.

Account identifiers — your email address and account references — are unified with the account system of the everything trading platform, so that the same email address resolves to the same account across both products. This interconnection is identity-only and involves no balance, funds or custody data. Our embedded-wallet infrastructure provider is Privy (Privy Technologies, Inc.), which provisions wallets and performs signing inside a secure enclave as described in section 2. A current list of all specific processors we use is available on request from privacy@everything.co. We put a written contract in place with every processor we use, requiring it to act only on our documented instructions, keep the data confidential, apply appropriate security measures, engage a sub-processor only with our authorisation, assist us with rights requests and breach notification, and delete or return the data at the end of the engagement.

8. Links to third-party services

The App may show you information that links out to the public internet, and a token that arrives in your wallet may itself direct you to an external website. Once you leave the App you are dealing with that third party under its terms and its privacy notice. We do not control what it collects or how it uses it, and this Policy stops applying. Read the notice of any service before you use it, and treat links that arrive unsolicited with caution.

9. International transfers

We are incorporated in the British Virgin Islands and our providers operate in a number of countries. Your personal data will therefore be transferred to and processed in jurisdictions other than your own, and the privacy laws in those jurisdictions may differ from those where you live.

Where personal data protected by the EU or UK GDPR is transferred outside the EEA or the United Kingdom to a country without an adequacy decision, we rely on an appropriate safeguard, ordinarily the European Commission or UK standard contractual clauses, together with supplementary technical and organisational measures where required. You can request details of the safeguard applying to a particular transfer from privacy@everything.co.

10. How long we keep data

These are maximum periods. We delete or anonymise data sooner where it is no longer needed. Data recorded on a public blockchain is outside these periods and outside our control; we cannot delete it.

Data Retention
Account and sign-in data For the life of the account, then up to 24 months after closure
Security, access and fraud logs Up to 24 months from the event
Crash and diagnostic data Up to 12 months
Analytics and usage data Up to 24 months, and indefinitely once aggregated and no longer identifying
Support correspondence Up to 36 months from the close of the request
Records needed for a legal claim, investigation or authority request Until the matter is finally resolved and any limitation period has expired

11. Security

We apply technical and organisational measures proportionate to the data we hold, including encryption of data in transit and at rest, access control on a least-privilege and need-to-know basis, multi-factor authentication for administrative access, logging and monitoring, segregation of environments, vendor due diligence and an internal incident response process.

The most important security control, however, is not ours. Because your key can be used only with your authenticated sign-in, the security of your assets depends on the security of your device, your device passcode, the email, Google or Apple account you sign in with, and your handling of any private key you export. No measure we take can protect a wallet whose private key has been disclosed.

Where a personal data breach occurs and applicable law requires notification, we will notify the relevant supervisory authority without undue delay and, where the EU or UK GDPR applies, within 72 hours of becoming aware of the breach where feasible. Where the breach is likely to result in a high risk to you, we will also notify you without undue delay.

12. Your rights

Depending on where you live and which law applies, you may have the right to:

  • Ask what personal data we hold about you and obtain a copy of it.
  • Have inaccurate data corrected.
  • Have data deleted, where we no longer have a lawful reason to keep it.
  • Restrict or object to processing, including processing based on legitimate interests.
  • Receive certain data in a portable, machine-readable format.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Opt out of marketing, using the unsubscribe link or by contacting us.
  • Complain to a data protection authority in your country.

To exercise a right, contact privacy@everything.co. We will respond within the period required by the applicable law, and in any event within one month of a verified request unless the request is complex, in which case we will tell you and explain why. We may need to verify your identity before acting, and we will not use verification as a way of collecting more data than necessary.

Two practical limits. First, we cannot delete anything recorded on a public blockchain. Second, we cannot delete or provide your private key, because we have never held it in a form we can use.

12.1 If you are in the EEA or the United Kingdom

Where the EU or UK GDPR applies to our processing, you have the rights listed above as a matter of law, and you may lodge a complaint with your national supervisory authority. Where we are required under Article 27 of the EU GDPR or the UK GDPR to appoint a representative in the Union or the United Kingdom, we will appoint one and publish its name and contact details in this Policy before the App is made available in the European Union or the United Kingdom.

12.2 If you are in the United States

Where a state privacy law such as the California Consumer Privacy Act applies to us, you may request to know the categories and specific pieces of personal data we have collected, the purposes of collection and the categories of recipients; request deletion or correction; and exercise these rights without being discriminated against for doing so. We do not sell personal data and we do not share it for cross-context behavioural advertising. You may use an authorised agent to make a request, and we may ask for proof of that authority. Send requests to privacy@everything.co. We honour opt-out preference signals, including Global Privacy Control, where the applicable law requires us to. We do not knowingly sell or share the personal data of anyone under 16.

13. Age requirement

The App is for adults. You must be at least 18 years old, or the age of majority in your jurisdiction if that is higher, to use it. We do not knowingly collect personal data from anyone under that age. If we learn that we have, we will delete it and close the account. If you believe a minor has provided us with personal data, contact privacy@everything.co.

14. Website, cookies and similar technologies

The App itself does not use cookies. This Policy covers the App only. The everything.co website — including the pages where this Policy and related documents are published — is operated as part of the everything trading platform under its own terms and privacy notice, which apply to any use of that website beyond reading these documents.

15. Changes to this Policy

We may update this Policy to reflect changes to the App, our providers or the law. The version number and effective date at the top will change. Where a change materially affects your rights or how we use your data, we will give you reasonable advance notice in the App or by email before it takes effect. Continuing to use the App after the effective date means the updated Policy applies to you.

16. Contact and complaints

Privacy questions and rights requests: privacy@everything.co. General support: support@everything.co. Written correspondence: E for Everything Limited, Vistra Corporate Services Centre, Wickhams Cay II, Road Town, Tortola, VG1110, British Virgin Islands.

© 2026 E for Everything Limited

Support: support@everything.co