UTXOSUITE — home
PRIVACY / COOKIES / LOCAL-FIRST

Collect less. Explain what remains.

This notice describes the public UTXO Suite website and the transaction-security product boundary. It does not claim that every sibling product, payment processor or future hosted service uses the same data flow.

Last updated: 29 August 2026

1. Data-minimizing architecture

UTXO Suite is designed around local-first transaction analysis where practical. SafeSign and Security Core do not require server-side custody of seed phrases or private keys. A self-custody wallet such as Vigi Wallet handles its own encrypted key material inside its separate wallet boundary.

2. Essential browser storage

The website may store essential local values required for functionality, such as language preference, cookie-consent choice, Academy progress or other user-requested local state. These values are not advertising identifiers and should not be used for cross-site profiling.

3. Optional analytics

Optional analytics storage is disabled by default. If analytics are introduced, they must not activate before opt-in where consent is required, and this policy must identify the actual provider, purpose, retention and data categories before collection begins.

4. Marketing technologies

Marketing or advertising trackers are disabled by default. UTXO Suite must not silently add cross-site advertising identifiers. Any future marketing integration requires explicit consent where legally required and must be listed here before activation.

5. Security and diagnostic data

Security tooling should minimize retained payloads. Full wallet history, seed phrases, private keys and raw secret material are outside the intended UTXO Suite service boundary. Diagnostic exports should disclose what they contain before the user shares them.

6. Wallet and blockchain data

Public blockchain addresses and transactions may be public on their networks, but UTXO Suite should not treat that as permission to build unnecessary cross-service identity profiles. Vigi Wallet remains a separate self-custody product and its own runtime data flows must be documented by that product.

7. Third-party services

If a page uses a payment processor, store, RPC provider, hosted API or other external service, that service may process data under its own terms. UTXO Suite must identify material production subprocessors before relying on them for personal-data processing.

8. Your controls

The cookie panel lets you keep only essential storage or opt into optional categories when available. You can reopen preferences from the Privacy page. Local browser data can also be cleared through browser controls, subject to the consequences of removing local progress or settings.

9. Retention and deletion

Local-only data remains on the device until the user clears it or the application removes it under its documented retention policy. Hosted personal data, if introduced, requires a stated retention period and deletion process before collection.

10. Security claims

Privacy and security controls reduce exposure but do not create absolute security. Missing evidence, unavailable simulation or incomplete third-party context must not be represented as proof that a transaction or service is safe.