AIVIVE Wallet — Privacy Policy
This Privacy Policy explains how TMGlobal Co., Ltd. (“we”, “us”, “our”) collects, uses, and shares personal information when you use the AIVIVE Wallet mobile application (the “Service”). We are the controller of the personal information described here.
We never collect your recovery phrase, private keys, or PIN. They are generated and encrypted on your device and never leave it. We cannot read them, recover them, or use them to access your wallet.
1. Information We Collect
1.1 Information you provide
| Category | Examples | Why |
|---|---|---|
| Account | Email address, name or nickname, and the account identifier supplied by Google or Apple when you sign in | To create and authenticate your account |
| Support | Subject, message body, and any attachments you send when you contact support | To answer your inquiry and keep a record of the exchange |
| Consents | Records of what you have accepted, and when | To evidence consent as required by law |
1.2 Information collected automatically
| Category | Examples | Why |
|---|---|---|
| Wallet identifiers | Your public blockchain addresses | To display balances and to process on-chain reward withdrawals |
| Device & app | Operating system and version, app version, device model, language, and a push notification token | Compatibility, notification delivery, and troubleshooting |
| Diagnostics | Crash reports, error traces, and technical logs | To detect and fix defects and to keep the Service secure |
| Service usage | Reward accrual and withdrawal records, event participation | To operate the rewards programme and prevent abuse |
1.3 Information stored only on your device
The following never reaches our servers: your recovery phrase and derived private keys (encrypted in the device secure store), your PIN, your biometric authentication (handled entirely by iOS or Android — we receive only a success or failure result, never fingerprint or face data), and your address book entries.
2. How We Use Your Information
- To provide, maintain, and secure the Service.
- To authenticate you and to protect against unauthorised access.
- To calculate, display, and pay out rewards, and to detect abuse of the programme.
- To send transactional and service notices.
- To respond to inquiries and provide support.
- To diagnose faults, analyse aggregate usage, and improve the Service.
- To comply with legal obligations and to establish or defend legal claims.
3. Legal Bases
Where data protection law requires a legal basis, we rely on:
- Performance of a contract — account creation, authentication, rewards, and support.
- Legitimate interests — security, fraud and abuse prevention, and product improvement, balanced against your rights.
- Consent — where you have given it for a specific purpose. You may withdraw consent at any time without affecting processing carried out beforehand.
- Legal obligation — record-keeping and responses to lawful requests.
4. Blockchain Data
Transactions you sign are broadcast to public blockchain networks. Blockchain records are public, permanent, and outside our control: we cannot modify, hide, or delete them, and third parties may be able to associate an address with an individual. Deleting your account with us does not and cannot remove on-chain data.
5. Sharing and Processors
We do not sell personal information. We share it only as follows:
| Recipient | Purpose | Data |
|---|---|---|
| Google, Apple | Social sign-in | Account identifier, email, name |
| Firebase Cloud Messaging (Google) | Push notification delivery | Push token, device identifiers |
| Sentry | Crash and error reporting | Diagnostics, app and OS version, error traces |
| Cloud hosting and CDN provider | Running our servers and serving static content | All server-side data, as processor |
| RPC node and market data providers | Reading balances, broadcasting transactions, price quotes | Public addresses, transaction data, network requests |
We may also disclose information where required by law, court order, or a valid request from a public authority, or where necessary to protect our rights, safety, or property, or those of our users.
6. International Transfers
Our providers may process data in countries other than your own. Where such transfers occur, we rely on appropriate safeguards such as standard contractual clauses or an adequacy decision, as applicable.
7. Retention
- Account data — for as long as your account exists, then deleted or anonymised within 30 days of account deletion, unless a longer period is required by law.
- Support records — up to 3 years after the inquiry is closed, to handle follow-up and disputes.
- Reward and withdrawal records — for the period required by applicable accounting and tax law.
- Diagnostics — typically up to 90 days.
8. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption of key material at rest on your device using the platform secure store (iOS Keychain / Android Keystore), access control on our systems, and logging. No method of transmission or storage is completely secure, and you remain responsible for the security of your device, PIN, and recovery phrase.
9. Device Permissions
- Camera — used only to scan QR codes for addresses. Images are processed on-device and are not stored or transmitted.
- Biometrics — used only to unlock the app. Biometric data stays in the device's secure hardware.
- Notifications — used to deliver service and reward notices.
You can revoke any of these permissions at any time in your device settings.
10. Your Rights
Subject to your local law, you may request access to your personal information, rectification, erasure, restriction of processing, portability, or objection to processing, and you may withdraw consent at any time. To exercise these rights, contact us at the address in Section 13. We will respond within the period required by applicable law. You also have the right to lodge a complaint with your local data protection authority.
Deleting your account
You can request account deletion by contacting us at the address in Section 13. Deletion removes your account data from our systems as described in Section 7. It does not affect your wallet or your on-chain assets, which remain under your sole control and recoverable with your recovery phrase.
11. Children
The Service is not directed to children and is restricted to users aged 19 or older (or the age of majority in your jurisdiction, if higher). We do not knowingly collect personal information from children. If we learn that we have, we will delete it promptly.
12. Changes to This Policy
We may update this Policy. Material changes will be announced in the Service before they take effect, and the “Last updated” date above will be revised. Where required, we will ask for your consent again.
13. Contact
TMGlobal Co., Ltd.
Privacy contact: Min Jeong Lee
Address: 25, Beopjo-ro, Yeongtong-gu, Suwon-si, Gyeonggi-do, Republic of Korea
Email: contact@tmglobal.co.kr