Privacy Policy

Privacy Policy

Last updated: 3 October 2026

Overview

Duality does not collect personal data for analytics, advertising, profiling, or sale. Duality is a self-custodial Bitcoin Lightning wallet: your recovery phrase and wallet keys are generated and stored on your device. Duality does not custody your funds and does not have access to your recovery phrase.

Some optional features require limited operational data to work, such as payment notifications and @dualitywallet.money Lightning addresses. Those uses are described below.

Data Stored On Your Device

Your recovery phrase is stored using operating-system secure storage, such as iOS Keychain or Android Keystore through Expo SecureStore.

Your favourites, your Lightning address, and extra details about your payments are also backed up through Breez’s sync service, so they come back when you restore your wallet. They are encrypted on your device, with a key derived from your wallet, before they leave it.

Otherwise, local data leaves your device only when needed to operate the features described below, or when you export it yourself, such as by sharing debug logs.

Duality Address And Notifications

If you claim a @dualitywallet.money Lightning address or enable payment notifications, Duality uses a Duality-operated worker to route address records, webhook registration, and push notifications.

The worker may process your chosen address username, the linked Breez Lightning address username, a wallet-signed public key used to protect updates, a push token, preferred currency, webhook delivery metadata, payment amount, payment hash, and limited operational diagnostics needed to deliver and debug notifications.

Duality does not use this worker to store your recovery phrase, private keys, full wallet balance, or full transaction history.

Third-Party Services

Duality connects to Breez Spark infrastructure to provide Lightning payments, Spark wallet functionality, Lightning addresses, webhooks, passkey recovery support, stable balance features, and the encrypted sync described above. Breez may process network-level payment data, IP addresses, and service telemetry under its own policies.

Duality also uses Firebase Cloud Messaging or Expo push services for notifications, mempool.space for Bitcoin price data and on-chain lookups, open.er-api.com for exchange rates between currencies, public market data from Binance, or from Kraken where Binance is unavailable, for charts, and device services such as camera, NFC, biometrics, and secure storage. Price and rate requests are made periodically while the app is open and send your IP address to those services.

The on-chain lookups are how Bitcoin sent to your wallet’s Bitcoin address is found and claimed. When a deposit arrives, Duality asks mempool.space about its transaction to follow its confirmations. For a day after you show your Bitcoin address in Receive, and for longer if a deposit to it is still confirming, Duality also checks the address itself with mempool.space, so a deposit can appear before it has confirmed. These lookups send the address or the transaction, with your IP address, to mempool.space, which processes them under its own policies.

If you add money with a card inside Duality, a Duality-operated worker talks to Coinbase on your behalf. This happens in three steps, and they send different things.

When you open the deposit screen, the worker asks Coinbase which currencies and card limits apply in your country. That request sends only your country, taken from your phone’s SIM card or region setting, or from your currency if neither gives one. The answer is kept on your device for a day, so it is not asked again each time you open the screen.

While you are typing an amount, the worker asks Coinbase to price it. That request sends the amount and currency you entered and your country. It does not send your IP address, and it does not send any wallet address. Coinbase creates nothing at this stage.

When you press the deposit button, the worker asks Coinbase to open a purchase session. That request sends your IP address, the amount and currency, your country, and the address the purchase will be delivered to — an address that credits your own wallet. You are then handed to Coinbase’s own checkout. Coinbase processes that data, and anything you enter during its checkout, under its own policies. Your card details go to Coinbase directly and are never seen by Duality. Nothing is sent to Coinbase at any other time.

The worker itself receives your IP address with each of these requests, as any web server does. It uses the address only to limit how often requests can be made, and passes it on only at the purchase step. Requests are also signed by your wallet, so the worker sees your wallet’s public key, which it uses only to check the signature. Apart from a request count kept for one minute to enforce that limit, Duality does not log or store either.

A deposit buys USDC delivered on the Base network. Your wallet has no Base address of its own, so the delivery address belongs to a cross-chain provider, Flashnet, which receives the USDC and credits the equivalent to your Cash balance. Flashnet processes the deposit address, the amount, and the on-chain transaction under its own policies. The same provider handles receiving and sending stablecoins on other chains.

Passkeys

If you create or recover a wallet with passkeys, Duality uses the Breez Spark passkey flow associated with dualitywallet.com. Your device or platform account may sync passkey credentials through services such as iCloud Keychain or Google Password Manager, depending on your device settings.

Camera, NFC, And Biometrics

The camera is used to scan payment QR codes. NFC is used to read payment requests from tags and payment terminals. Biometric APIs are used to lock and unlock the app. Duality does not store camera frames or NFC scans after processing them.

Debug Logs

Debug logs can include operational wallet metadata, payment states, amounts, device events, and error messages. They stay on your device unless you share them, and are intended for support and troubleshooting. Review logs before sharing them.

No Analytics, Advertising, Or Sale

Duality does not include analytics SDKs or advertising SDKs. Duality does not sell personal data. Duality does not collect your recovery phrase, private keys, full wallet balance, or full transaction history.

Retention

Local wallet data stays on your device until you use Reset wallet in Settings or delete the app. On iPhone, the Keychain keeps your recovery phrase and other securely stored data even after the app is deleted, so use Reset wallet first if you want them erased.

Duality address and notification records are kept while the address or notification feature is active, and may be deleted or replaced when you turn the feature off, change address, or reinstall. The encrypted copies held by Breez’s sync service are kept under Breez’s policies.

Children

Duality is not directed at children under 18. We do not knowingly collect information from minors.

Changes

We may update this policy as Duality evolves. Material changes will be communicated through an app update.

Contact

Questions about this policy can be sent to admin@dualitywallet.com. The current version is always at dualitywallet.com/privacy.