privacy

Privacy Policy

Last updated September 28, 2026

Fhenix Pay (“the app”) is a self-custodial wallet for confidential payments, published by FHE Labs (“we”, “us”). This policy explains what the app keeps on your device, what it sends to which services, and why. It also covers this website.

Summary

  • There are no accounts. We don't ask for your name, email, or phone number.
  • Your private key and recovery phrase are created on your device and never leave it. We can't see them, and neither can anyone else we work with.
  • The app has no analytics, advertising, or crash-reporting tools, and it doesn't track your location.
  • To work, the app talks to blockchain networks and to Fhenix services. Those services see your IP address and your public wallet address, as described below.
  • Anything recorded on a blockchain is public and permanent. For confidential tokens the amounts are encrypted, but addresses and the fact that a transaction happened are not.
  • If you post a shared permit on-chain, the permit itself becomes public: who you share with, what it covers, and until when.
  • We don't sell or rent personal data.

What stays on your device

The app stores the following only on your phone. We have no copy and no access to it.

  • Private key and recovery phrase, in the operating system's secure storage (iOS Keychain, Android Keystore). They are kept on this device only and are excluded from backups and from phone-to-phone transfers. With a Ledger, no key is stored on the phone at all.
  • Permits and their keys: the permits that let the app decrypt your own balances, the permits you have shared with others (kept so you can check and revoke them), and permits others have shared with you. Stored in secure storage. The private decryption keys that go with them never leave your device; see shared access for what leaves it when you share a permit.
  • Activity history, including the amounts of payments you sent, and your friends list. Stored in secure storage.
  • App data: tokens you added, recipients you have paid before, dApps you saved, and settings such as network, theme, and device name. Excluded from backups and phone-to-phone transfers.
  • Website data (cookies and site storage) from dApps you open in the Browser tab.

What the app sends, and to whom

The app contacts the services below only to provide its features. Each one can see your IP address and whatever the request contains. They are operated by us or by third parties with their own privacy policies.

ServiceWhyWhat it receives
Blockchain RPC providers (the public Arbitrum Sepolia endpoint run by Offchain Labs; PublicNode by Allnodes for Ethereum Sepolia)Read balances and send transactionsYour wallet address, token and contract addresses, signed transactions, and requests from dApps you use
Fhenix CoFHE network (fhenix.zone, operated by Fhenix)Encrypt payment amounts, decrypt your own balances, and settle unshield claimsYour wallet address, encrypted values and their proofs, and permits (your address, a public sealing key, and a signature). Amounts are encrypted on your phone before they are sent, and your balances are decrypted on your phone.
Fhenix token list (Google Cloud Storage)Load the list of Fhenix tokensOnly a standard download request
Token logo hosts named in the token listShow token logosOnly a standard image request
CoinGeckoShow USD pricesWhich tokens to price. Not your wallet address.
Fhenix Confidential Explorer (hosted on Vercel)The Explorer tabYour wallet address. Any amounts it shows you are decrypted on your phone.
Websites you open in the Browser tabUsing dAppsWhatever you do on the site. Your wallet address only after you approve connecting, and signatures only after you approve them.
Web link pairing server (Google Cloud, Belgium) and Google's connection-setup (STUN) serverPair the app with a dApp in your desktop browserA random pairing code and encrypted pairing messages the server cannot read. The paired dApp receives your address and the results of requests you approve.
Block explorers (Arbiscan, Etherscan, Fhenix Explorer)When you tap to view a transactionThe transaction hash, opened in your browser

Nearby devices. When you share a payment request over Bluetooth, nearby devices can see your device name (set in Settings) and the request. NFC payment requests are read from or written to tags you choose. A Ledger talks to the app directly over Bluetooth; nothing about it is sent to us.

Blockchain data and shared access

Transactions are recorded on public blockchains that no one, including us, can edit or delete. Wallet addresses, the timing of transactions, public token balances, and unshield claim amounts are public. For confidential tokens, balances and transfer amounts are stored encrypted.

With shared access you can let someone else read chosen confidential data. A shared permit is a signed, read-only grant. It contains your wallet address, the recipient's address, what it covers (token contracts, or the specific transactions you picked), when it expires, how it can be revoked, and your signature. It contains no private key: only the recipient's own wallet can use it.

  • Shared as a QR code or file, the permit goes only to the person you give it to, and to any app you use to send the file.
  • Posted on-chain, the whole permit is written to a public registry contract. Anyone can read it, permanently: that you share with that recipient, which tokens or transactions it covers, and until when. Removing it from the recipient's inbox later doesn't erase that record and doesn't revoke access.
  • Revoking a permit is an on-chain transaction, so the revocation is public too.
  • When the recipient reads the shared data, their wallet sends the permit to the Fhenix CoFHE network, which checks it and returns the data encrypted to the recipient's own key.

In every case your balances and amounts themselves stay encrypted; only someone holding a valid permit can decrypt what it covers.

Device permissions

  • Camera: to scan QR codes.
  • NFC: to read and write payment tags.
  • Bluetooth: for phone-to-phone payments and for connecting a Ledger. On Android the system also requires location permission to scan for a Ledger; the app never reads your location.
  • Face ID, fingerprint, or passcode: checked by the operating system to unlock the app and approve signatures. The app never receives your biometric data.
  • Network access: to reach the services above.

You can turn each of these off in your phone's settings; the matching feature then stops working.

Keeping and deleting data

  • Data on your device stays until you use Settings → Delete Wallet, which erases everything the app keeps (keys, history, friends, tokens, saved dApps and their data, and permits), or until you uninstall the app. On iPhone, a reinstalled app starts empty.
  • Blockchain records are permanent.
  • Third-party services keep request data according to their own policies.
  • We don't keep a profile of you. The pairing server keeps pairing sessions in memory only while they are active; its hosting provider records standard request logs, such as IP addresses.

This website

pay.fhenix.io is hosted on Vercel, which processes standard request data such as your IP address to serve the pages. Fonts load from Google Fonts and Fontshare, which also see your IP address. The site sets no cookies of its own and uses no analytics. The download page checks your browser's user agent, in your browser, to send you to the right app store.

Security

We protect the app with measures such as device-only key storage, biometric approval of every signature, encrypted pairing, and pinned connections to our own servers. No system is perfectly secure: keep your phone locked and your recovery phrase offline and private.

Children

The app is not intended for anyone under 18, and we don't knowingly collect information from children.

International use

The services the app uses run in several countries, including the United States and the European Union. By using the app you understand that requests may be processed there.

Your rights

Depending on where you live (for example under the GDPR or the CCPA), you may have rights to access, correct, or delete personal data about you. Because we don't run accounts or collect data about you on our servers, most of your data is already under your control on your device. For anything else, contact us below.

Changes to this policy

We may update this policy as the app changes. We'll change the date at the top, and point out significant changes on this site or in the app.

Contact

Questions about privacy: tovi@fhenix.io. See also our Terms of Use.