Operator, contact and scope

Orrerie LLC is responsible for the personal information described in this policy when operating the public websites wallet.orrerie.com and recover.orrerie.com, the iOS app and connected services. Our principal office is 30 N Gould St, #58667, Sheridan, Wyoming 82801, United States. This policy is effective September 30, 2026.

Send questions and privacy requests to hello@orrerie.com. Do not send wallet secrets. Providers and recipients may separately control information they receive under their own terms; the provider directory identifies their roles and notices.

Website delivery and enquiries

Website delivery: Bunny CDN and the Hetzner-hosted origin process connection and delivery data such as IP address, request time, requested path, browser or protocol details and security signals. recover.orrerie.com has no Orrerie server: Bunny stores and delivers it and processes the same kinds of request data when you open the page or download the Recovery tool. Orrerie uses this to deliver, secure and troubleshoot the sites. Operational logs are kept according to their delivery, security and incident-investigation purpose and applicable rotation settings; relevant evidence may be preserved to investigate abuse or meet a legal obligation. Browser controls can limit caching, but normal request data is required to deliver the site.

Enquiries: the form processes name, email, topic or request type, message, privacy-notice version, receipt reference and state for access review and support. Active form records expire after 90 days. Encrypted rollback copies are normally removed within eight additional days; deployment or maintenance safety gates can postpone that cleanup until maintenance resumes. The current tab stores an opaque receipt token for reconciliation. You can use email instead, but mail systems keep their own copies and schedules.

Recipients are the operator’s authorised reviewers, website hosting and delivery providers, and mail providers when email is used. Neither site has third-party advertising or analytics scripts in the current build.

Account, email, device and session data

Account setup and sign-in process a normalised email address, invitation and verification state, device name, account and device identifiers, session records, timestamps and security or rate-limit events. Email addresses and device names are encrypted in server storage; lookup, code and session values are hashed where the implementation permits. Titan SMTP necessarily receives the destination address and bounded authentication, invitation, welcome or deletion message.

Verification codes expire after 10 minutes and app sessions after 90 days. Identity, account, device, acceptance and security records otherwise remain for the account lifecycle or until the applicable revocation or deletion process. There is not one retention period for every security record. You can revoke device sessions and request account deletion; an email address does not recover wallet keys.

Waitlist and early access

While requests are open, anyone can ask to join Orrerie in the app. Nothing is queued until you verify your email with a six-digit code; an address that already has an Orrerie account simply signs in, and any other verified address is placed on a waitlist. A request stores your verified email address (encrypted in server storage), a masked form of it, keyed hashes used to find the request and to spot repeated addresses, your place in line, the request’s state and dates, the Privacy Policy version shown to you, whether an invite code or fast pass you entered was applied or refused, and the status of your admission and its notice. The encrypted record of your email verification, including the device name you used, is kept with a waiting or admitted request so that creating your account can confirm the same device; a declined request keeps none.

To prevent abuse and protect capacity, Orrerie also keeps a keyed hash of your connection’s network prefix (not your full IP address), counts of failed code attempts under keyed hashes, and simple flags such as a throwaway email domain, a repeated address pattern or many requests from one network. Flags never remove a request or its place; they stop automatic admission and help the operator review it. Codes you enter are checked against keyed hashes, and codes grant a place or access only, never paid features.

Referrals are optional and nothing depends on sharing. Each waiting request has a friend code, and an account can show one too. When a friend verifies their email and enters your code, Orrerie links the two requests to move you up a limited number of places or, where the operator has enabled it, to admit your friend. Neither person is shown the other’s address or place, and there is no public list. Links are deleted when the referring request ends, the referring account is deleted or either request is removed; only counts can remain.

We use this information to run the waitlist and your place in it, admit you, send one “You’re in” email to your verified address, prevent fraud and abuse, and protect service capacity, relying on steps you ask us to take before an account contract and on our legitimate interest in security. Waitlist information is not used for marketing, is not sold and is not used for advertising or cross-app tracking. Titan SMTP receives your address and the fixed admission email. Operator review in Orrerie’s private workspace shows a masked form of your address, not the full address. This release collects no notification token for a waiting request; if that option is added, the app will ask first and this policy will describe it before any token is collected.

A waiting or admitted request remains until you join, leave the waitlist, the operator declines or removes it, or the address is linked to an Orrerie account another way. The app’s access to your request lasts 90 days and renews when the app checks your place; a request is deleted 30 days after that access lapses. A declined request’s address is erased when it is declined; its masked form and keyed hashes are kept for 90 days so the same request is not placed again, then deleted. Declining also withdraws any invitation that admitted the request. When you join, the request’s address, network hash, access and friend code are erased, and the minimal remaining record is deleted with your account. Network hashes are cleared after 30 days, failed-attempt counts within a day, and operator action records, which contain no address, within 180 days. Encrypted backups of Orrerie’s server catalogue can keep deleted waitlist information for about 30 days.

You can leave the waitlist at any time in the app with Leave the waitlist or Use a different email. This deletes the request, your place, your friend code and its links, and any pending admission. If your request was declined, Delete my request removes its masked form and the app’s access, but the keyed hashes stay until those 90 days end, so the decline still applies if you ask again. You can also use the Privacy Requests page or hello@orrerie.com. Taking the tour or viewing the market preview before verifying an email sends no email address or account identifier; the preview is Orrerie’s own cached copy of public exchange prices.

Wallet addresses, transactions and custody boundaries

Orrerie processes public wallet addresses and owner descriptors, balances, assets and networks, transaction hashes, amounts, recipient or refund details, quotes, fees, provider orders, status evidence and security-policy decisions to display accounts, validate requests, co-sign approved transactions and reconcile uncertain outcomes. RPC, indexing, screening, swap, bridge and purchase providers receive the public transaction information needed for the route shown to you. Orrerie’s server reads TRON balances, blocks, transactions, fee receipts and resources from the TRON nodes of PublicNode, Nodies over Pocket Network, Dwellir, Alchemy, TronGrid and dRPC, asking them in turn until one answers; the nodes it asks receive the public TRON addresses and transaction references in the read and Orrerie’s server connection metadata, as the Third-party Providers page describes. Personal Gas reads and broadcasts go directly from the phone to fixed public endpoints (PublicNode, dRPC, Nodies over Pocket Network, QuickNode’s public endpoint and network-operated endpoints, as the Third-party Providers page lists them for each network), several at once for one read, which exposes the device IP address and request timing to each of them; no Personal Gas private key is sent. Each EVM Personal Gas broadcast also passes the same signed transaction bytes through Orrerie’s server, which forwards them once to its RPC provider and does not keep them.

Chain notifications use Orrerie-operated Bitcoin, Litecoin and Dogecoin nodes and a local bridge, together with configured public or authenticated RPC providers for the other networks. The listener processes watched public addresses, token-account or contract filters, transaction references, block positions and recovery checkpoints. Upstreams receive the public query or subscription information and server connection metadata needed to detect activity, not phone or offline signing secrets. A notification is a prompt to reconcile chain state, not a guarantee of final settlement.

Personal Gas uses a separate recovery phrase generated and kept on your phone. That phrase controls the EVM gas EOA and separate fee-only Solana and TRON addresses. Each gas address is controlled by your own key; none is an asset-wallet owner. Orrerie does not hold your Personal Gas funds, keys or recovery phrase. Orrerie still holds one server signing share for each two-of-three asset wallet, which cannot authorise an asset transaction alone. Phone-held phrases, offline-card phrases and PINs are excluded from ordinary server processing. Device credentials are sent through the encrypted native transport for authentication; the server hashes the received credential and matches it to the stored hash.

Personal Gas setup registers public fee addresses and wallet associations, never their private keys. Solana operations and TRON Energy purchases can pass reviewed public transaction details, signed transaction bytes, invoice or order identifiers and receipt evidence through Orrerie and the relevant RPC or Energy provider. These records let the app attribute fees and reconcile uncertain outcomes; a gas address can therefore be linked to the asset-wallet activity it pays for.

Public blockchain records are maintained by decentralised networks and cannot be erased by deleting an Orrerie account. Provider and recipient records can also remain under their own terms.

Device, sync, contacts, notifications and backups

The app and server process device and session identifiers, app version, timestamps, request and error metadata, notification tokens, preferences and bounded diagnostics to authenticate, synchronise, deliver notifications and protect the service. Apple receives APNs or PushKit tokens, topic, alert or call-delivery data and short-lived call information required for the notification.

Account sync can include display and visibility preferences, public contact names and wallet addresses, profile image, hidden-wallet choices, watchlists, Mail preferences and drafts, recent commands and bounded assistant display history. It excludes phone or offline private owners, PINs, biometric policy and executable financial queues. Removed uncommitted blobs receive a seven-day cleanup grace; referenced sync data remains until removal or account deletion.

Price alerts. If you create price, market-move or network-fee alerts, your account stores each alert (asset, condition, level and currency, timing, repeat and optional name), your alert time zone and up to 90 days or 500 entries of alert history. A shared alert service on Orrerie’s server keeps only what it needs to check and deliver them: an account identifier, a random alert identifier, the asset, condition, level, currency and timing, your quiet hours and time zone, and a record of each triggered alert (asset, observed price and time) until your account has received its outcome, at most 90 days. Market-data sources and the network endpoints used to read price-feed contracts receive shared requests with no account data. Deleting an alert removes it from the service; deleting your account deletes alerts, history and the service’s copy.

Encrypted whole-account backups are stored with Backblaze B2. Archives become eligible to hide 29 days after upload and for deletion one day after hiding. This lifecycle is measured from each archive’s upload, not the account-deletion request. Object locks, holds, maintenance and provider lifecycle processing can delay physical expiry; deletion at an exact hour is not promised.

Recovery kit and Recovery tool

Recovery kit: after you confirm on your phone with Face ID or your passcode, the app can export a Recovery kit to a place you choose. To build it, the app first refreshes your wallet records and Orrerie’s public co-signer keys from Orrerie. The file is created on your phone and contains public information only: the addresses of the Funding and Spot wallets you have set up, including earlier owner versions; the public keys or addresses of the phone, offline-card and server owners and the wallet setup data needed to rebuild those addresses; the fixed derivation paths; your Personal Gas addresses; a one-way hash of your account identifier; the app version, creation time and a checksum. It contains no recovery words, private keys, passphrases, PINs or email address. Orrerie does not receive the file. Anyone who obtains it can see your addresses and look up their balances and history. If you save it to iCloud Drive or another service, that service stores it under its own terms.

Recovery tool download: recover.orrerie.com offers the Orrerie Recovery tool, a single HTML file, for download and verification only. The hosted page does not accept recovery words, sets no cookies and has no advertising or analytics scripts.

Using the tool: you run a saved copy in a browser on your own computer. Your recovery words, the keys derived from them and any Recovery kit you open stay in that browser. The tool sends nothing to Orrerie, never contacts Orrerie’s servers and uses no cookies or browser storage. Words are cleared when you finish, when the tab is hidden or closed, after two minutes without input and if its signing process fails.

To show balances and submit transactions, the tool connects from your browser directly to the public blockchain endpoints listed in the provider directory, or to endpoints you add. Each operator receives your IP address, browser and protocol details such as the user agent and language, request timing, the public addresses and transaction references requested and, for a transfer, the signed transaction, and can link those addresses to your connection. Two lookups run only when you turn them on: CoinGecko receives coin identifiers for USD values, and the Safe Transaction Service receives an owner address you enter to find EVM Safes without a Recovery kit. An explorer website opens only when you choose one of its links. These connections are between you and those operators under their own policies; Orrerie does not receive or control that information.

Mail and Phone

Mail processes sender and recipient addresses, cc or bcc, subject, text or sanitised HTML, attachment names, types and bytes, reply headers, thread, delivery and outbox state. Resend receives this information to send and receive personal Mail. Delivered or cancelled outbox bodies and attachments are erased locally; unresolved failed rows can remain for recovery. Local deletion cannot promise deletion from Resend or recipients. Remote images are blocked by default; loading one contacts its host. Logo.dev receives a business domain only when a business avatar is requested.

Phone uses Bird for line, calling, SMS and voicemail services and LiveKit for real-time rooms and audio. They can receive line and call identifiers, E.164 caller or recipient numbers, caller name, timestamps, status, duration, price, SMS text, voicemail audio or transcript, delivery and webhook data; LiveKit receives per-call room and participant metadata and live audio. Ordinary telephone calls are not end-to-end encrypted through the public phone network. Emergency-calling capability is not claimed.

Provider copies and retention follow the service and provider policies identified in the directory; deleting a local message cannot erase a recipient’s copy. Controls include Mail deletion and remote-image choices, notification settings, and choosing whether to use optional Mail or Phone features. New Phone-line purchases and outbound SMS are unavailable in this release; existing enabled line and call services can continue.

Public artwork: when a screen contains an allowlisted remote coin, route, product or business image, the app can fetch that image directly from Relay, CoinGecko, Bitrefill, CryptoRefills, GitHub raw content, 1inch, jsDelivr or Logo.dev. The host receives the device IP address, request time, protocol or user-agent data and the requested asset or product path, which can reveal which asset or product was displayed. Orrerie does not intentionally add an account identifier, wallet address or cookie. These requests use a cookie-free, credential-free session and image bytes are kept only in a bounded on-device cache, but provider-side logs follow the host’s policy. Message-body remote images remain blocked until you choose to load them; coin and product artwork can load when its screen appears. There is no separate artwork toggle in this release.

Intelligence and optional AI sharing

Ask Orrerie can send OpenAI the question, bounded recent visible conversation, current app location, a pseudonymous safety identifier and results from user-authorised read-only tools. Tool results can include wallet values and recent activity, fees, non-secret security settings, provider health, notification settings, Mail metadata or plain text, editable draft content, and attachment filenames, content types and sizes. It excludes wallet secrets, credentials, raw email HTML, remote image URLs and attachment bytes.

Notification Intelligence can send OpenAI its channel, caller name and bounded SMS or voicemail text for classification. It omits the separate sender-number field, but names or message content may themselves contain telephone numbers or other personal information. Orrerie stores the resulting category, action, confidence, reason and model, not the classified message body in that decision ledger. Classification can affect notification priority or suppression; it does not authorise a transaction.

Both features default off and require separate, explicit permission for the relevant sharing. Refusing permission prevents the associated OpenAI request. Permission can be withdrawn in Privacy & Legal for future sharing without blocking recovery, privacy requests or deletion. API requests set provider response storage to false; this does not promise zero provider retention. Applicable OpenAI service and data-processing terms govern provider handling. Local and synced conversation history is bounded by size and count, rather than a fixed age.

Spend, swaps, bridges and other providers

Bitrefill or CryptoRefills can receive selected product, value and quantity, payment asset and network, delivery phone or email where required, recipient or beneficiary details, refund address, webhook and order identifiers and transaction status. CryptoRefills can also receive IP address, user agent and country. Marketing permission is not enabled by Orrerie.

Swap, bridge and RPC providers receive the route’s public source, payout or refund address, asset, network, amount, transaction or order identifier and status query. Scorechain receives a public address for sanctions screening. Which transaction provider applies is shown in the review; an integration does not mean that provider receives every user’s data. Market and foreign-exchange sources receive requested asset symbols or the USD reference-rate request plus Orrerie’s server connection data, not an account identifier or wallet address by design.

SideShift receives the end user’s public connection IP forwarded by Orrerie with permission, quote and order requests, in addition to the selected route’s addresses, assets and amounts. This is used for service eligibility and regional restrictions. A positive permission decision may be cached in server memory for up to ten minutes for that IP; this does not limit SideShift’s own retention. Orrerie also processes the App Store storefront country reported by supported app versions for additional route restrictions. This is a country setting, not GPS or proof of residency. Missing or malformed storefront information does not bypass a provider’s own checks.

Provider records and public-chain data follow their own retention and legal obligations. You can decline a route before approval; completed public transactions cannot be withdrawn or erased.

ChangeNOW and RocketX are retired integrations. Orrerie retains existing account records for receipts, support and reconciliation history but makes no new requests or status queries to those providers. Their existing records can remain under their own policies.

Retention, deletion and choices

Retention is purpose-specific as described above. Orrerie keeps information while needed for an enabled service, account security, reconciliation, support, deletion processing or an applicable legal obligation. The period depends on the record’s purpose, whether an operation remains unresolved, account activity, security incidents and legal requirements. Minimal closure and handle-reservation records can remain after account deletion as explained on the Account Deletion page.

Use account settings to manage notifications, sessions, Mail images, AI sharing and account deletion. Use the Privacy Requests page or hello@orrerie.com for access, correction or deletion requests. Identity verification is required before disclosing or changing account-bound information.

After the 30-day cancellation window, Orrerie deletes the account and eligible server-held data. Having configured a wallet does not prevent account deletion. Final cleanup can wait while a submitted transaction, provider cancellation or other external operation has an unresolved outcome; the app shows that status and Orrerie checks it again. Public blockchain records remain on their networks.

Why we process information

Where a lawful basis is required, we process account, authentication, requested communications and transaction-service data to provide the contract or take requested steps before it. We rely on legitimate interests for proportionate security, fraud prevention, service reliability and support, subject to your rights, and on legal obligations when a law requires processing.

Separate consent supports the optional AI sharing described above. Withdrawal does not affect processing that was lawful before withdrawal. Device permissions and feature settings provide additional controls. Required account or transaction information is necessary to provide that service; declining optional AI sharing leaves the rest of the account available.

Information comes from you, your devices, public blockchains and the providers used for the selected feature. We do not sell personal information or share it for cross-context behavioural advertising. We do not use AI output to sign transactions or grant signing authority.

International processing and security

Orrerie LLC is established in the United States. Hosting, communications, blockchain and other providers can process information in other countries where their infrastructure operates. Laws and government-access rules can differ from those in your country. The provider directory links their notices; contact us for information about the destination and safeguards applicable to a particular service. Where a restricted international transfer requires a legal safeguard, that requirement applies to our use of the service.

We use account isolation, access controls, encrypted transport and protected storage where described above. No internet service, device or public blockchain is free from security risk. Public transaction data is visible beyond Orrerie, and ordinary email and telephone delivery are not a promise of end-to-end encryption.

Your rights, age and policy updates

Depending on applicable law, you may request access, correction, deletion, portability or restriction, object to certain processing, withdraw consent, and complain to a competent privacy authority. The Privacy Requests page explains how to contact us, verification and response handling. Exercising a privacy right does not itself justify discriminatory treatment.

The app is intended for adults who are at least 18 and have legal capacity where they live. We do not knowingly provide accounts to children. Contact hello@orrerie.com if you believe a child supplied personal information so we can investigate and take appropriate action.

We publish the effective date and version of each change and keep earlier versions on record; the legal directory says which earlier versions are available online. We give notice of material changes through the app or another appropriate channel. New optional AI purposes require their own permission; an updated policy is not a blanket consent.