Privacy policy

Last updated: 29 August 2026

send21 is non-custodial software that prepares payment instructions. It never needs KYC data, government IDs, bank details, card numbers, or physical addresses — so it doesn't collect them. This notice explains the small amount of personal data we do process, why, and your rights under the GDPR.

What we store

What we don't collect: names beyond the optional display name, physical addresses, phone numbers, government IDs, card or bank data, precise location, tracking cookies, or advertising identifiers. There are no third-party analytics or ad pixels; the only cookie is the session cookie used for signing you in.

How long we keep it

Your rights

You can access and export everything you own through the API (JSON), and edit your email, display name, and address book in the app. For erasure, objection, or any other GDPR request, email [email protected] — deleting your account removes your credentials, API keys, address book, webhooks, and drafts. Where accounting law requires keeping confirmed-payment records, only the minimum bookkeeping data is retained; your encrypted email and display name are removed. We respond within 30 days. On-chain transactions are public by nature and cannot be erased by anyone; send21 only ever stored references to them.

Where it runs

Data is processed server-side within our hosting environment. Calls to price oracles and blockchain APIs are made from our servers and never carry your personal data or IP address. Sign-in code emails are delivered via our SMTP provider, which receives only the recipient address and the code.

Questions? [email protected] · Terms of service · Home