DigiByte Wallet — privacy policy
Effective 2026-08-27. Using the wallet to hold and move DigiByte requires no account. We do not know who you are. The app contains no analytics, no crash-reporting SDK, no advertising ID, and no third-party trackers of any kind. Your keys, recovery phrase and PIN never leave your device — there is no mechanism in the app that could send them. The app’s optional community features (Hub chat and forum, DigiRunner, tipping) DO create a DigiScope account tied to your DigiByte address, and what you post there is public. They are opt-in and separate from the wallet. The app makes network requests, and this policy names every server it contacts and what each one can see.
What we collect: nothing that identifies you. Holding and moving DigiByte requires no account. There is no sign-up, no email address, no password, and no profile — you can install the wallet, generate keys, receive and spend, and never identify yourself to anyone. If you never open the community features described below, we hold nothing about you beyond the short-lived server logs any web request produces. The app contains no analytics SDK, no crash-reporting SDK, no advertising or attribution SDK, and does not read the Android advertising ID. It does not use Google Play Services. There is no telemetry to disable, because none was written.
What never leaves your device. Your recovery phrase, private keys, PIN, and any biometric data stay on your device. Biometrics are handled by Android itself; the app receives only a yes-or-no unlock result and never sees your fingerprint or face data. Transactions are signed locally. Signing keys are never transmitted, in any form, to any server — ours or anyone else’s. Camera frames used for QR scanning are decoded on-device in real time. Images are neither stored nor uploaded. Your address book, transaction labels, and settings are stored in the app’s private storage on your device.
What the app connects to, and what each can see. Any device on the internet reveals its IP address to the servers it contacts. That is true of the wallet as it is of a browser. Here is every destination the app reaches, and what it can observe: The DigiByte peer-to-peer network — for blockchain sync. The wallet downloads BIP 157/158 compact block filters and matches them on your device, so peers are never told which addresses are yours. Peers do see the IP address you connect from. Optional Tor transport and optional Dandelion++ transaction relay reduce what the network can infer. api.digiscope.me — a peer-seeder endpoint (certificate-pinned) that returns a list of DigiByte nodes to connect to. It sees your IP address and the fact that a wallet asked for peers. It receives no wallet data. api.digiscope.me — additionally, if and only if you use the optional community features, the Hub API and its websocket (authenticated with a session token). See “Optional community features” below for exactly what those carry. DigiAsset lookups — api.digiscope.me, api.digiassets.net, or a node you configure. These requests DO include your public DigiByte addresses, because that is what an asset-balance query is. The endpoint can therefore associate your IP with the addresses you hold assets for. This is the one place the app discloses addresses, and you can point it at your own node in Settings so nobody else sees them. api.coingecko.com and api.binance.com — public price tickers used to display a fiat value. The request carries no wallet data; those services see your IP and that a price was requested. IPFS gateways (ipfs.io, dweb.link, trustless-gateway.link) — used to fetch DigiAsset images and files by content ID. A gateway sees your IP and which content you requested. Links you tap — a block explorer, a marketplace, GitHub, or the bug-report page — open in your browser. Those sites see an ordinary web visit, governed by their own privacy policies, not this one.
Bug reports are voluntary, and here is exactly what they carry. Reporting a bug from inside the app opens the report page on digiscope.me in your browser, pre-filled with technical facts about the build so you do not have to transcribe them: device model and manufacturer, Android version and SDK level, app version and build number, memory page size, whether you are on mainnet or testnet, and the sync stage the wallet was in. That is the complete list. No addresses, no balances, no keys, no identifiers, and nothing that names you. You write the description yourself, you can see the pre-filled values before sending, and nothing is submitted unless you submit it.
Server logs. Requests to DigiScope-operated servers produce ordinary web-server access logs: IP address, timestamp, the path requested, the user agent, and the browser or app language header. These exist to keep the service running and to diagnose faults. They are rotated daily and retained for roughly two weeks, then deleted. They are not used to build user profiles, are not combined with any other dataset to identify individuals, and are not sold or shared for advertising.
Android permissions, and why each one exists. Internet and network state — to sync with the DigiByte network. Camera — to scan QR codes for addresses, payment requests and Digi-ID sign-in. Frames are processed on-device; nothing is stored or sent. Biometric — to unlock the app with the fingerprint or face credential Android already holds. The app never receives the biometric itself. Notifications — to tell you locally about sync progress and incoming transactions. Notifications are generated on your device; there is no push service and no remote message. Foreground service (data sync) — so blockchain sync can continue while the app is in the background without Android killing it. The app requests no location, contacts, storage, microphone, or phone permissions.
We do not sell or share your data. We have no personal data to sell, and we sell none. Nothing is shared with advertisers, data brokers, or analytics providers. There are no advertising or attribution partners. We may disclose the limited server-log information described above if legally compelled to. We cannot disclose keys, recovery phrases, or balances under any circumstances, because we do not hold them.
Digi-ID sign-in. Digi-ID lets you sign in to a supporting website by scanning its QR code. The wallet signs a challenge with a key derived for that site and sends the signature to that site. No password and no personal information are transmitted, and DigiScope is not an intermediary in that exchange. What the site you sign in to learns, and what it does with it, is governed by that site’s own privacy policy.
Optional community features create a real account. The app includes optional community features served by DigiScope: the Hub (chat channels and forum threads), the DigiRunner game and its leaderboard, and tipping. They are opt-in — the wallet works fully without ever opening them — but if you do use them, they are a different privacy situation from the wallet itself, and this section is the honest description of it. Signing in uses Digi-ID: DigiScope issues a challenge, your wallet signs it with a key derived from your seed, and DigiScope returns a session token that the app stores in its private storage on your device. That signature proves control of a DigiByte address, and that address becomes your account identifier on DigiScope. What DigiScope then holds and can see: An account record keyed to your DigiByte address, with the public handle you choose. Everything you post — chat messages, forum threads, replies, and upvotes — together with the handle and address that posted it. This content is PUBLIC to other users by design. Chat messages are deleted automatically after 30 days; forum threads and replies persist until removed. DigiRunner scores you submit, and your position on the public leaderboard. Tips you send or receive through the site’s tip system, which is a custodial balance held by DigiScope and is separate from the funds in your wallet. Reports you file about other users’ content. The practical consequence is worth stating plainly: posting in the Hub links your DigiByte address to whatever you say. That is inherent to a signature-based identity, not an accident. If you want the wallet’s privacy properties, do not sign in — nothing else in the app depends on it. Signing out removes the session token from your device; content you already posted remains, as it would on any forum.
The blockchain itself is public and permanent. DigiByte is a public blockchain. Every transaction — addresses, amounts, and timing — is visible to anyone, permanently, and neither the wallet nor DigiScope can delete, alter, or hide it. This is a property of the network, not a choice this app makes. The wallet is designed to avoid linking that public record to you: compact-filter sync means your addresses are not handed to a server during sync. Be aware, though, that the Receive screen shows a stable address rather than a fresh one for each payment — so everyone you give it to can see the same history. Anything you publish yourself — posting an address, or sharing it with a service that knows your identity — connects that history to you, and no wallet can undo it.
Children. The wallet is not directed to children, and we do not knowingly collect information from anyone. Since the app has no accounts and collects no personal data, there is nothing to delete on request — but if you believe otherwise, contact us.
Your data, your control. Because everything meaningful lives on your device, you control it directly. Uninstalling the app removes its local data from your phone. Funds are not stored in the app — they exist on the blockchain, and your recovery phrase is what reaches them, which is why that phrase must be backed up before you uninstall anything. If you want access, correction, or deletion of anything you believe we hold, contact us at the support link below. In practice the honest answer is usually that we hold nothing tied to you.
Changes and contact. If a future release adds a network request or changes what a request carries, this policy is updated in the same release rather than afterwards. The effective date above tracks the current version. Questions, corrections, or a claim here that does not match what you observe: use the support page or the wallet feedback form linked below. If you find a discrepancy between this policy and what the app actually does, that is a bug, and we want the report.
Frequently asked questions
- Does the DigiByte wallet collect personal data?
- Holding and moving DigiByte requires no account and no personal data. The app contains no analytics, no crash-reporting SDK, no advertising ID and no third-party trackers. The optional community features (Hub, DigiRunner, tipping) do create a DigiScope account tied to your DigiByte address.
- Do my private keys or recovery phrase ever leave my device?
- No. Keys, recovery phrase and PIN are generated and stored on your device, and transactions are signed locally. There is no mechanism in the app that transmits them.
- Which servers does the wallet contact?
- The DigiByte peer-to-peer network, api.digiscope.me for peer seeding (and the Hub API if you opt in), DigiAsset lookups via api.digiscope.me or api.digiassets.net, price data from api.coingecko.com and api.binance.com, and IPFS gateways for asset media. Each sees your IP address.
- Does the wallet ever send my addresses to a server?
- Blockchain sync never does — BIP 157/158 compact filters are matched on your device. DigiAsset balance lookups do include your public addresses, because that is what such a query is; you can point them at your own node instead.
- What does an in-app bug report send?
- Device model and manufacturer, Android version and SDK level, app version and build, memory page size, mainnet or testnet, and the sync stage — no addresses, balances, keys, or identifiers. You write the description and choose whether to submit.