Volver

Privacy Policy

Version 2.0 · Effective September 29, 2026

Summary. Nodo One is a non-custodial wallet: private keys are used exclusively on the User's device, and of the recovery phrase Nodo keeps only an encrypted copy that it cannot decrypt. Nodo processes the personal data necessary to provide the Services and to comply with the law, and does not sell it or use it for advertising purposes. This summary does not replace the full text. 1. PURPOSE AND SCOPE 1.1. This Privacy Policy (the "Policy") describes how Nodo LLC ("Nodo") collects, uses, discloses, retains and protects the personal data of the persons who use its services (the "User"). 1.2. The Policy applies to Nodo One in all its forms: the iOS and Android applications, the web application available at app.nodo.llc —including its OTC module for institutional clients— and the websites one.nodo.llc and nodo.llc (together, the "Services"). 1.3. The Policy forms part of the Terms of Service and must be read together with them. 2. DATA CONTROLLER The controller of the personal data described in this Policy is Nodo LLC, a limited liability company organized in the State of Wyoming, United States, with its address at 30 N Gould St Ste N, Sheridan, WY 82801. Contact: legal@nodo.llc. 3. NON-CUSTODIAL NATURE AND DATA NODO CANNOT ACCESS 3.1. Private keys. They are generated and used exclusively on the User's device and are not transmitted to Nodo. 3.2. Recovery phrase. Before it is stored, it is encrypted on the User's device using the AES-256-GCM algorithm, with a key derived from the wallet password, which is not transmitted to Nodo. Nodo keeps only the encrypted content, for the sole purpose of allowing the User to access their wallet from another device, and cannot decrypt it. 3.3. Biometric data. Authentication through Face ID, fingerprint or the device passcode is handled by the operating system. Nodo does not receive or store biometric data; it only receives the result of the verification. 4. PERSONAL DATA PROCESSED AND ITS SOURCES 4.1. Data provided by the User: a) Account data: email address, name and access credentials. The password is stored only as a hash value; for passkeys, only their public keys are stored. b) Wallet data: the encrypted copy of the recovery phrase, the public addresses and the labels assigned by the User. c) Communications: the content of the inquiries the User sends to Nodo and, where applicable, the email address provided for a waitlist. 4.2. Data generated through the use of the Services: a) Notification subscriptions and the notifications sent, and the link with Telegram, when the User enables it. b) The identity verification status and the records of fiat currency transactions, when the User uses a ramp. c) Technical data: the IP address, the type of browser or device and the date and time of each request, recorded by Nodo's servers. The applications do not include analytics tools and do not collect device identifiers. d) On the one.nodo.llc website, browsing data collected through Google Analytics (section 10). 4.3. Data obtained from third parties: a) From Google or Apple, when the User signs in with them: the account identifier, the email address and the name. b) From identity verification and regulatory compliance providers: the result of those verifications. 4.4. OTC module. With respect to institutional clients and the beneficiaries they designate, Nodo processes identification data (name or company name, type and number of identity document, date of birth, tax identification number and verification documentation), bank details or destination addresses, the results of regulatory compliance checks —including sanctions list screening— and the record of each transaction. Beneficiary data is provided by the institutional client, who is responsible for having the necessary legal basis to disclose it to Nodo. 4.5. Mandatory data. Account data is necessary to provide the Services. If the User does not provide it, Nodo will not be able to create the account or provide the corresponding feature. 5. PURPOSES AND LEGAL BASES FOR PROCESSING — Providing the Services and managing the account. Basis: performance of the contract (Terms of Service). — Authenticating the User, protecting the Services and preventing fraud and abuse. Basis: the legitimate interest of Nodo and of Users in the security of the Services. — Complying with legal obligations, including those on the prevention of money laundering and terrorist financing in the OTC module and in ramps. Basis: legal obligation. — Responding to the User's inquiries. Basis: performance of the contract and legitimate interest. — Sending notifications and linking Telegram. Basis: consent, which may be withdrawn at any time. — Measuring visits to one.nodo.llc. Basis: consent or legitimate interest, depending on the applicable law. Nodo does not sell or rent personal data, does not use it for personalized advertising and does not track the User across third-party apps or websites. 6. AUTOMATED DECISIONS Before each transfer, Nodo One automatically analyzes the risk of the destination address, and may warn the User or prevent transfers to addresses considered high-risk or subject to sanctions. The analysis is based on the destination address, not on the User's personal profile. 7. RECIPIENTS OF THE DATA 7.1. Nodo discloses personal data only to the extent necessary for each purpose, to the following categories of recipients: a) Infrastructure providers: hosting and database (Google Cloud and Supabase) and transactional email delivery. b) Sign-in providers: Google and Apple, when the User uses them. c) Security providers: an automated-program detection service on the sign-in screen, which analyzes technical browser signals, and address risk analysis providers, which receive the destination address of each transfer. d) Blockchain networks and providers of access to them (nodes and explorers), which receive the public addresses necessary to query balances and history and to broadcast transactions. Information recorded on a blockchain is public, and Nodo cannot modify or delete it. e) ChangeNOW, when the User exchanges assets: the addresses and amounts of that transaction, in its capacity as counterparty. f) Regulated providers of fiat currency ramps, payments and identity or sanctions verification. g) Competent authorities, when required by law or by a valid request. 7.2. Nodo requires the third parties with which it shares personal data to provide a level of protection equal or equivalent to that established in this Policy. Third parties acting as independent controllers —the sign-in providers, ChangeNOW and the regulated providers— additionally process the data in accordance with their own privacy policies. 8. INTERNATIONAL TRANSFERS Nodo is based in the United States and processes personal data on servers located in that country. When the User uses the Services from another jurisdiction, their data is transferred to the United States, whose data protection laws may differ from those of their country. Nodo applies to such data the protection measures described in this Policy. 9. RETENTION AND DELETION 9.1. Nodo retains personal data for as long as the User's account remains active and for the time necessary to fulfill the purposes described. 9.2. The User may delete their account from the application (Settings → Security → Delete account) or through the procedure described at nodo.llc/eliminar-cuenta. Upon deletion, Nodo erases the encrypted copy of the recovery phrase, the addresses and labels, the passkeys, the notifications and the linked services, and anonymizes the account data. 9.3. After deletion, Nodo retains the data that the applicable law requires it to retain —in particular, transaction records subject to anti-money laundering regulations— for the period established by that law. 9.4. Server technical logs are kept for a limited period and are deleted automatically. 10. COOKIES AND SIMILAR TECHNOLOGIES 10.1. app.nodo.llc uses only the cookies and local storage necessary for its operation: the session, the selected language and theme, and the identification of the active wallet. It does not use analytics or advertising cookies. 10.2. one.nodo.llc additionally uses Google Analytics, which assigns an identifier to the browser to measure visits. The User can block these cookies from their browser settings without affecting the operation of the site. 11. USER RIGHTS 11.1. In accordance with the law of their jurisdiction, the User may request access to their personal data, its rectification or erasure, the restriction of its processing, object to it and obtain its portability. 11.2. The User may withdraw any consent given at any time, without affecting the lawfulness of prior processing. Notifications can be disabled from the application or device settings. 11.3. To exercise these rights, the User may write to legal@nodo.llc. Nodo may request the information necessary to verify their identity. The User can delete their account directly from the application. 11.4. The User may lodge a complaint with the competent data protection authority in their jurisdiction. 12. SECURITY Nodo applies appropriate technical and organizational measures to protect personal data, including the encryption of communications through TLS, the encryption of the recovery phrase on the User's device and restricted access to personal data. No system is completely invulnerable. In the event of a security breach affecting the User's personal data, Nodo will notify the User in accordance with the applicable law. 13. MINORS The Services are intended for persons over 18 years of age, in accordance with the Terms of Service. Nodo does not knowingly collect personal data from minors and, if it becomes aware of it, will delete it. 14. CHANGES Nodo may amend this Policy. Each version is published with its effective date. When a change is material, Nodo will inform the User through the application or by email before it takes effect. 15. CONTACT Nodo LLC · 30 N Gould St Ste N, Sheridan, WY 82801, United States · legal@nodo.llc