Privacy policy
Last updated: 29 August 2026
send21 is non-custodial software that prepares payment instructions. It never needs KYC data, government IDs, bank details, card numbers, or physical addresses — so it doesn't collect them. This notice explains the small amount of personal data we do process, why, and your rights under the GDPR.
What we store
- Email address — account identity, sign-in codes, and payment notifications. Stored encrypted (AES-256); lookups use a keyed hash so the database never needs to decrypt it.
- Display name (optional) — UI personalization. Stored encrypted.
- Credentials — password hashes (PBKDF2-SHA256), passkey public keys (encrypted), TOTP secrets (encrypted). Private keys for passkeys never exist on our servers.
- Payment metadata — addresses, amounts, memos, and order ids you create. Don't put other people's personal data in memos.
- IP addresses — in the security audit log and rotating server logs, for abuse prevention (legitimate interest). Application log files auto-delete after 30 days.
What we don't collect: names beyond the optional display name, physical addresses, phone numbers, government IDs, card or bank data, precise location, tracking cookies, or advertising identifiers. There are no third-party analytics or ad pixels; the only cookie is the session cookie used for signing you in.
How long we keep it
- Account data: for the life of the account.
- Confirmed payment records (incl. fee and valuation data): 7 years after the fiscal year, as required by Swedish accounting law (Bokföringslagen).
- Audit log entries incl. IPs: up to 12 months.
- Server log files: 30 days.
- Expired or cancelled drafts that were never paid: deletable on request.
Your rights
You can access and export everything you own through the API (JSON), and edit your email, display name, and address book in the app. For erasure, objection, or any other GDPR request, email [email protected] — deleting your account removes your credentials, API keys, address book, webhooks, and drafts. Where accounting law requires keeping confirmed-payment records, only the minimum bookkeeping data is retained; your encrypted email and display name are removed. We respond within 30 days. On-chain transactions are public by nature and cannot be erased by anyone; send21 only ever stored references to them.
Where it runs
Data is processed server-side within our hosting environment. Calls to price oracles and blockchain APIs are made from our servers and never carry your personal data or IP address. Sign-in code emails are delivered via our SMTP provider, which receives only the recipient address and the code.
Questions? [email protected] · Terms of service · Home