DigiByte Mobile — privacy policy
Effective 2026-10-07. Using the wallet to hold and move DigiByte requires no account. We do not know who you are. The app contains no analytics, no crash-reporting SDK, no advertising ID, and no third-party trackers of any kind. Your keys, recovery phrase and PIN never leave your device — there is no mechanism in the app that could send them. Sync never sends your addresses to anyone. The app sends your address list to a server only when you run “Scan for missing transactions” or Recover funds, or tap “Check other formats” while restoring a wallet. The app’s optional community features (Hub chat and forum, DigiRunner, tipping) DO create a pseudonymous DigiScope account — no name, email or phone, but keyed to your DigiByte address, and what you post there is public. They are opt-in and separate from the wallet. The app makes network requests, and this policy names every server it contacts and what each one can see.
Who publishes this app. DigiByte Mobile, formerly DigiByte Wallet, is published by Around The Block LLC, an Oklahoma limited liability company, which also operates the DigiScope service the app connects to. Where this policy says “we”, it means Around The Block LLC. Around The Block LLC is the party responsible for the data practices described here. This policy covers the app under both of its names: DigiByte Mobile (package app.aroundtheblock.wallet) and its predecessor, DigiByte Wallet (package io.digibyte). The company is at aroundtheblock.us, which hosts the authoritative copy of this policy. The version you are reading is published on digiscope.me for convenience, where the app is distributed. To reach us about anything in this policy, write to privacy@aroundtheblock.us, or use the support page linked at the bottom.
What we collect: nothing that identifies you. Holding and moving DigiByte requires no account. There is no sign-up, no email address, no password, and no profile — you can install the wallet, generate keys, receive and spend, and never identify yourself to anyone. If you never open the community features described below, we hold nothing about you beyond the short-lived server logs any web request produces. The app contains no analytics SDK, no crash-reporting SDK, no advertising or attribution SDK, and does not read the Android advertising ID. It does not use Google Play Services. There is no telemetry to disable, because none was written.
What never leaves your device. Your recovery phrase, private keys, PIN, and any biometric data stay on your device. Biometrics are handled by Android itself; the app receives only a yes-or-no unlock result and never sees your fingerprint or face data. Transactions are signed locally. Signing keys are never transmitted, in any form, to any server — ours or anyone else’s. Camera frames used for QR scanning are decoded on-device in real time. Images are neither stored nor uploaded. Your address book, transaction labels, and settings are stored in the app’s private storage on your device.
What the app connects to, and what each can see. Any device on the internet reveals its IP address to the servers it contacts. That is true of the wallet as it is of a browser. Here is every destination the app reaches, and what it can observe. Automatically, as part of normal use: The DigiByte peer-to-peer network — for blockchain sync. The wallet downloads BIP 157/158 compact block filters and matches them on your device, so peers are never told which addresses are yours. Peers see the IP address you connect from and receive the transactions you broadcast, as they must for any wallet. The wallet starts from a built-in list of well-known nodes and DNS seeds, some of which we operate (digiscope.me, seed.aroundtheblock.app). Optional Tor transport and optional Dandelion++ transaction relay reduce what the network can infer. api.digiscope.me, peer list — a certificate-pinned list of DigiByte nodes to connect to, fetched when sync starts and about every 15 minutes in the background, including when you have paired your own node. It sees your IP address and that a wallet asked for peers. It receives no wallet data. api.digiscope.me, confirmation checks — while any transaction in your wallet is unconfirmed, sent or received, the app asks for the status of those transaction IDs, at most every few minutes. The server can therefore associate your IP address with those transactions. DigiAsset data — for assets your wallet holds or receives, the app requests the asset’s details and the earlier transactions that prove its history, by asset ID and transaction ID. It asks assets.digistamp.co first (operated by DigiStamp, a third party), then api.digiscope.me, then api.digiassets.net. These requests carry no addresses, but asset IDs and transaction IDs are public records tied to your holdings, so whichever service answers can associate your IP address with the assets you hold. Asset images and files — fetched by content ID through our IPFS proxy on api.digiscope.me, falling back to the public gateways trustless-gateway.link, dweb.link and ipfs.io. Some assets point to an image on a web server chosen by the asset’s issuer; the app loads it when the asset is shown, so that server sees your IP address and which image was requested. api.coingecko.com, falling back to api.binance.com — public price tickers, polled every few minutes while the app is open, to display a fiat value. The request carries no wallet data and is the same for every user; those services see your IP address. api.github.com — on every launch the app checks GitHub for a newer release. The request carries no wallet data; GitHub sees your IP address. Only when you take an action: Sending a DigiAsset — before you confirm, the app asks api.digiscope.me what each coin it is about to spend carries, by transaction ID and output number. The server can associate your IP address with those coins. Scan for missing transactions, and Settings → Recover funds — these tools send the list of addresses they check to api.digiscope.me, so the server can report coins the wallet may have missed: your wallet’s addresses, or, when recovering, those of the recovery phrase you entered, including its DigiDollar address. The server can therefore associate your IP address with those addresses. Together with the restore check below, this is the only place the app discloses your addresses. Nothing sends them automatically, and the scan tool can be pointed at a server you run instead. Restoring a wallet from a recovery phrase (DigiByte Mobile) — the restore itself sends nothing: sync finds this app’s own address formats on your phone. Only if you tap “Check other formats” does the app derive the addresses your phrase would have in other wallet apps’ formats (Coinomi, Ledger, Trezor, older BreadWallet forks) and send them to api.digiscope.me, which reports any funds on them; the server can associate your IP address with those addresses. The screen says this before you tap. Optional community features — the Hub API and its websocket on api.digiscope.me, once you sign in. See “Optional community features” below for exactly what those carry. Digi-ID sign-in — the site you sign in to receives a signature from the wallet. See “Digi-ID sign-in” below. The DigiStamp Market tab — opens the marketplace at assets.digistamp.co, a site run by a third party, inside the app. It behaves like a web page in a browser: it sees your IP address, your device model and Android version, what you view and do there, and the asset you opened it from. Its cookies and site storage stay on your device until you wipe the wallet. The page cannot read your keys, addresses or balances; the most it can do is ask the app to open a screen that you then approve. DigiStamp’s own privacy policy governs what it does with what it sees. Links you tap — a block explorer (which receives the transaction ID), GitHub, the asset creator, or the bug-report page — open in your browser. Those sites see an ordinary web visit, governed by their own privacy policies, not this one. Tor is off by default. When you turn it on, the app’s connections go through Tor, except the DigiStamp Market tab and links opened in your browser. If Tor cannot start or cannot reach any peer, the app falls back to a direct connection and tells you so with a banner rather than stop working — so Tor reduces what servers and peers learn, but is not a guarantee.
Bug reports are voluntary, and here is exactly what they carry. Reporting a bug from inside the app opens the report page on digiscope.me in your browser, pre-filled with technical facts about the build so you do not have to transcribe them: device model and manufacturer, Android version and SDK level, app version and build number, memory page size, whether you are on mainnet or testnet, and the sync stage the wallet was in. That is the complete list. No addresses, no balances, no keys, no identifiers, and nothing that names you. You write the description yourself, you can see the pre-filled values before sending, and nothing is submitted unless you submit it.
Server logs. Requests to DigiScope-operated servers produce ordinary web-server access logs: IP address, timestamp, the path requested (which, for the requests described above, can include a transaction ID, an asset ID, a coin’s outpoint or a DigiDollar address), the user agent, and the browser or app language header. These exist to keep the service running and to diagnose faults. They are rotated daily and retained for roughly two weeks, then deleted. They are not used to build user profiles, are not combined with any other dataset to identify individuals, and are not sold or shared for advertising.
Android permissions, and why each one exists. Internet and network state — to sync with the DigiByte network. Camera — to scan QR codes for addresses, payment requests and Digi-ID sign-in. Frames are processed on-device; nothing is stored or sent. Biometric (and, on older Android versions, fingerprint) — to unlock the app with the credential Android already holds. The app never receives the biometric itself. Notifications — to show sync status locally while the wallet syncs. Notifications are generated on your device; there is no push service and no remote message. Foreground service (data sync) — so blockchain sync can continue while the app is in the background without Android killing it. Wake lock and start at boot — added by Android’s background-work library so scheduled sync can run. The app requests no location, contacts, storage, microphone, or phone permissions.
We do not sell or share your data. We have no personal data to sell, and we sell none. Nothing is shared with advertisers, data brokers, or analytics providers. There are no advertising or attribution partners. We may disclose the limited server-log information described above if legally compelled to. We cannot disclose keys, recovery phrases, or balances under any circumstances, because we do not hold them.
Digi-ID sign-in. Digi-ID lets you sign in to a supporting website by scanning its QR code. The wallet signs a challenge and sends the signature, with the address that made it, to that site. No password and no personal information are transmitted, and DigiScope is not an intermediary in that exchange. Each site gets its own key, so sites cannot link your sign-ins to each other or to your wallet. The exceptions are DigiScope’s own sites, and any site you signed in to before per-site keys were introduced: those keep the wallet address used before, so your existing account there still works. What the site you sign in to learns, and what it does with it, is governed by that site’s own privacy policy.
Optional community features create a pseudonymous account. The app includes optional community features served by DigiScope: the Hub (chat channels and forum threads), the DigiRunner game and its leaderboard, and tipping. They are opt-in — the wallet works fully without ever opening them — but if you do use them, they are a different privacy situation from the wallet itself, and this section is the honest description of it. Signing in uses Digi-ID: DigiScope issues a challenge, your wallet signs it with the key of its first receiving address (the legacy m/0’/0/0 address, which the wallet also watches for payments), and DigiScope returns a session token that the app stores encrypted on your device. That signature proves control of the address, and that address becomes your account identifier on DigiScope. What DigiScope then holds and can see: An account record keyed to your DigiByte address, with the public handle you choose. Everything you post — chat messages, forum threads, replies, and upvotes — together with the handle and address that posted it. Each message, thread and reply carries that address and its signature, and other users can see the address. This content is PUBLIC to other users by design. Chat messages are deleted automatically after 30 days; forum threads and replies persist until removed. DigiRunner scores you submit, and your position on the public leaderboard. Tips you send or receive through the site’s tip system, which is a custodial balance held by DigiScope and is separate from the funds in your wallet. Reports you file about other users’ content. The account is pseudonymous: no name, email address, or phone number is ever collected or requested, and the handle is whatever you choose. We do not know who you are, and nothing in the sign-in flow could tell us. What makes it more than a throwaway username is that the identifier is a DigiByte address — one of your own wallet’s addresses, a permanent, public key on a public ledger. Posting in the Hub therefore links that address to whatever you say, and anyone can look up what it has received. If you have ever used the same address with a service that knows your legal identity — an exchange withdrawal, for instance — that service can connect the two, and chain analysis can link it to the rest of your wallet. None of that involves DigiScope, and none of it can be undone afterwards. So: pseudonymous, not anonymous. If that distinction matters to you, use a separate wallet for the Hub, or do not sign in at all — nothing else in the app depends on it. Signing out removes the session token from your device; content you already posted remains until you ask us to delete the account (see “Deleting your community account” below).
The blockchain itself is public and permanent. DigiByte is a public blockchain. Every transaction — addresses, amounts, and timing — is visible to anyone, permanently, and neither the wallet nor DigiScope can delete, alter, or hide it. This is a property of the network, not a choice this app makes. The wallet is designed to avoid linking that public record to you: compact-filter sync means your addresses are not handed to a server during sync, and the Receive screen moves to a fresh address once the one it shows has been paid. Your DigiDollar receive address is the exception: it is fixed, so everyone you give it to can see the same history. Anything you publish yourself — posting an address, or sharing it with a service that knows your identity — connects that history to you, and no wallet can undo it.
Children. The wallet is intended for adults and is not directed to children, and we do not knowingly collect information from anyone. Using the wallet itself requires no account and produces no record here; if you used the optional community features and want that account and its posts removed, see the next section.
Deleting your community account. The wallet itself has no account to delete: uninstalling the app removes its data from your phone. Write down your recovery phrase first, because we cannot restore it. If you signed in to the optional community features, you can ask us to delete that DigiScope account. Email privacy@aroundtheblock.us with the subject “Delete my account” and include your Hub handle and the address shown on your profile. We may ask you to confirm the request from inside the Hub, so that we know it comes from whoever controls the account. If the account holds a tip balance, say so in the request and we will settle it with you before deleting. Deletion removes the account record, your handle, your chat messages, forum threads, replies and upvotes, your DigiRunner scores, and the reports you filed. We complete it within 30 days. Server access logs are not separately erased; they age out within about two weeks. Anything recorded on the DigiByte blockchain, including the address itself, cannot be deleted by anyone.
Your data, your control. Because everything meaningful lives on your device, you control it directly. Uninstalling the app removes its local data from your phone. Funds are not stored in the app — they exist on the blockchain, and your recovery phrase is what reaches them, which is why that phrase must be backed up before you uninstall anything. If you want access, correction, or deletion of anything you believe we hold, write to privacy@aroundtheblock.us and we will respond within 30 days. In practice the honest answer is usually that we hold nothing tied to you.
Changes and contact. If a future release adds a network request or changes what a request carries, this policy is updated in the same release rather than afterwards. The effective date above tracks the current version. If Around The Block LLC ever transfers ownership of the DigiScope service or of this app, this policy will say so before the transfer takes effect, and the authoritative copy at aroundtheblock.us is the one to check. A wallet holding your own keys is not affected by who owns a website — but who operates the servers it talks to is exactly the kind of thing this policy exists to tell you. Questions, corrections, or a claim here that does not match what you observe: write to privacy@aroundtheblock.us, or use the support page or the wallet feedback form linked below. If you find a discrepancy between this policy and what the app actually does, that is a bug, and we want the report. Around The Block LLC, 7122 S Sheridan Rd Ste 2 PMB 1022, Tulsa, OK 74133-2748, United States. privacy@aroundtheblock.us
Frequently asked questions
- Does the DigiByte wallet collect personal data?
- Holding and moving DigiByte requires no account and no personal data. The app contains no analytics, no crash-reporting SDK, no advertising ID and no third-party trackers. The optional community features (Hub, DigiRunner, tipping) do create a DigiScope account tied to your DigiByte address.
- Do my private keys or recovery phrase ever leave my device?
- No. Keys, recovery phrase and PIN are generated and stored on your device, and transactions are signed locally. There is no mechanism in the app that transmits them.
- Which servers does the wallet contact?
- The DigiByte peer-to-peer network; api.digiscope.me for peers, confirmation checks, asset data and asset media (and the Hub API if you opt in); assets.digistamp.co and api.digiassets.net for asset data; public IPFS gateways and issuer-chosen image hosts for asset media; api.coingecko.com and api.binance.com for prices; and api.github.com for update checks. Each sees your IP address.
- Does the wallet ever send my addresses to a server?
- Not automatically. Blockchain sync matches BIP 157/158 compact filters on your device, and asset lookups carry asset and transaction IDs, not addresses. Your address list goes to api.digiscope.me only when you run Scan for missing transactions or Recover funds, and the scan can be pointed at a server you run.
- What does an in-app bug report send?
- Device model and manufacturer, Android version and SDK level, app version and build, memory page size, mainnet or testnet, and the sync stage — no addresses, balances, keys, or identifiers. You write the description and choose whether to submit.