PRIVACY POLICY

Privacy, by data flow.

This policy covers the Lymo public website, the wallet’s current architecture and the separate Lymo Operations Alerts utility.

Pre-launch disclosure draft · 9 September 2026

This text describes the current implementation and planned production deployment. Professional legal review and a final release-specific update are still required. It is not legal certification.

Scope and status

Lymo Wallet is the product name used on this site. Contact the Lymo operator at lymo.app1@gmail.com. We will identify the accountable legal entity and any additional region-specific disclosures in the release policy before public launch.

The website is informational. The wallet and gateway are in development; the production gateway and permanent operations-email connection are not yet fully activated. The data flows below distinguish what the software is built to do from a claim that every service is currently live.

1. Wallet and device data

Customer seed phrases and private keys are not sent to or held by Lymo servers. Wallet setup, recovery and signing are device-side operations. Protected local storage contains wallet-related data and local transaction history, including addresses, balances, transaction identities and transaction-time fiat records.

Local preferences and cached blockchain metadata support the wallet interface. Locking or removing the app does not erase public blockchain records. Removing local data without a usable recovery backup may permanently remove access to a wallet.

Device authentication is handled through the platform’s authentication system. Lymo’s servers do not need your fingerprint or device-unlock secret to operate.

2. Blockchain and market requests

To display balances, histories and transaction state, the app requests public blockchain information. A gateway and its selected RPC/indexing providers can process requested public addresses, transaction hashes, token identifiers and related blockchain data. Public data can still be sensitive: requests may reveal that particular addresses belong together.

The configured production read providers are NOWNodes (Bitcoin and Dogecoin), SwiftNodes (Litecoin), Alchemy (Ethereum and Polygon) and Helius (Solana). They process network requests under their own policies and infrastructure controls. Provider credentials are company operational secrets, not customer wallet keys, and must not be embedded in the customer app.

The current development market-data source is CoinGecko. Market requests obtain prices, chart data and historical fiat information; these are distinct from wallet signing. Commercial licensing and attribution remain subject to pre-launch review.

A future enabled Send broadcasts signed transaction data to the selected blockchain. The destination, amounts, fees and other protocol data may become publicly and persistently accessible. We cannot delete or rewrite an independent blockchain.

3. Fly.io gateway and app integrity

The Fly.io gateway is the planned production boundary for provider access. It validates app requests, uses short-lived sessions and applies request-integrity and abuse protections. Google Play Integrity is used for app/device integrity verification; it does not require disclosure of customer seed phrases or private keys.

During processing, the gateway can see request content needed for the blockchain read, connection metadata and session context. The hosting/network infrastructure necessarily handles IP addresses and request timing. Application metrics are designed to exclude IP addresses, customer identifiers, wallet addresses, balances, transaction hashes, raw bodies, authentication headers and secrets.

Persistent operations state holds aggregate provider usage, security-stop flags and bounded alert delivery/retry state—not a centralized copy of customer wallets or transaction journals. Short-lived session processing can correlate requests within a session; “non-custodial” does not mean “anonymous.”

4. Google Cloud and company authorization

Google Cloud KMS processes signing requests for company fee-policy, Send-control and EVM quote authorization. The company keys serve defined authorization purposes and are separate from all customer keys. KMS receives the company signing input or digest required by its algorithm, not a customer seed phrase or private key.

Google Cloud audit and monitoring services record operational identities, key/resource activity, timing and status information. Security and uptime notifications may identify company infrastructure or key names. These company audit records are not a customer wallet backup.

5. Cloudflare public website

The intended public website is a static site on Cloudflare Pages at lymowallet.com. Cloudflare handles HTTPS delivery, caching and network/security metadata such as IP address, requested URL, browser information and timing. See Cloudflare’s Privacy Policy.

The authored website does not use analytics beacons, advertising pixels, browser storage, tracking cookies, external fonts, wallet connections or embedded forms. It makes no calls to the wallet API. Cloudflare or your browser may separately process network/security information; that is distinct from application tracking.

Opening an email link uses your chosen mail application. Following external links or using a blockchain explorer sends information to that service under its own policies. Copying an address to the system clipboard can make it available to other software with clipboard access.

6. Lymo Operations Alerts and Google data

Lymo Operations Alerts is for the company operator only. It is not a customer Google-login feature, wallet approval service or mailbox reader. The approved operator account and alert destination are lymo.app1@gmail.com.

The utility requests only Gmail’s gmail.send permission. It sends service-health, security and test notifications from the operator-authorized account. It does not request permission to read email, contacts, calendars or Drive files. Notification content is restricted to operational categories and references; customer wallet data and credentials must not be included.

The administrative OAuth grant is encrypted with Windows user-bound protection. The intended deployed mail transport uses Fly.io runtime secret storage. Authorized infrastructure administrators can manage these operational secrets; this is not a guarantee against a compromised administrator.

Google processes OAuth authentication and Gmail delivery. Generated mail may remain in the sending and receiving accounts. Queues and delivery results support retries and deduplication. Google Cloud’s separate monitoring emails are not evidence that the Gmail transport itself is continuously deployed.

Lymo Operations Alerts’ use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not used for advertising, sold to data brokers or used to train generalized AI models.

The operator can revoke this connection through Google Account third-party connections and request removal of retained operational credentials. Revocation stops future authorization; it does not automatically erase delivered emails or cloud audit records. See the Operations Alerts overview.

7. Retention, access and your choices

Device history is retained locally for wallet operation. Operational state, support correspondence, delivered alerts and cloud audit records have different purposes and storage locations. We do not promise a universal deletion period that has not been implemented and verified. Final production retention schedules and access controls require release-specific review.

We use service providers to deliver the functions described here. Processing may occur outside your country. Appropriate administrative access is separate from customer wallet ownership. Support may retain information you voluntarily email; do not send recovery material or unnecessary wallet details.

To ask about access, correction or deletion of personal information held by Lymo, or to exercise rights available under applicable law, contact lymo.app1@gmail.com. We may need proportionate verification but will not request your recovery phrase or private key. We cannot remove public blockchain data or control another provider’s records.

8. Updates and legal review

This draft must be reviewed before a public wallet release for legal-entity details, applicable privacy rights, international processing, retention and the exact services enabled in that release. Material changes will be reflected in the dated public policy. No legal or regulatory compliance certification is implied.