How to read this directory
Core providers support the website or account infrastructure. Optional providers receive information when you enable or use that feature. Route-specific providers apply to the selected transaction. Configurable chain endpoints can change or be used for fallback; an integration does not mean that provider receives every user’s data. Recovery tool endpoints are contacted directly by your browser when you run the Recovery tool, not by Orrerie.
The descriptions identify the data needed for each role. Provider terms and policies govern their separate handling and can change. Linked project or service pages are labelled as such when they are not a privacy notice; a public endpoint is not a promise of a particular retention period or service guarantee.
Website, hosting and backup
Bunny CDN — core website and API edge delivery, and storage and delivery of the Recovery tool download at recover.orrerie.com. Receives connection, request, browser or protocol and security data needed to route and protect traffic.
Hetzner — core origin and isolated account-server hosting. Stores and processes encrypted account, service and operational data handled by the server.
Backblaze B2 — core encrypted whole-account backups. Receives encrypted archive bytes and object metadata; archive lifecycle is described in the Privacy Policy.
Email, push and calls
Titan SMTP — core account verification, invitation, welcome and deletion email. Receives the destination email and bounded message.
Resend — optional Orrerie Mail transport. Receives message envelope, content, attachments and delivery identifiers.
Apple APNs and PushKit — optional notifications and incoming-call delivery. Receives device token, topic, bounded alert or call payload and delivery metadata.
Bird — optional Phone numbers, calls, SMS and voicemail. Receives the telephone and message data described in the Privacy Policy.
LiveKit — optional real-time call rooms and audio. Receives call-room, participant and realtime-media data.
Artificial intelligence
OpenAI — optional Ask Orrerie and Notification Intelligence processing, only after the separate account permission for the relevant sharing. Receives the bounded prompts, context and tool results described in the Privacy Policy. Requests set response storage to false; actual contractual handling remains subject to the operator’s OpenAI agreement.
Transactions, Spend, chain data and market data
Relay, SideShift, KyberSwap, Rubic, Across and THORChain are route-specific swap or bridge integrations; supported direct pool routes include Uniswap and PancakeSwap. The selected route can receive public addresses, network and asset identifiers, amounts, order or transaction identifiers and status queries. Availability depends on the network, pair, amount, region and provider. Not every integration is used for every account.
SideShift is an accountless, deposit-based exchange and can control deposited funds until payout or refund. Orrerie forwards the end user’s public connection IP for SideShift permission, quote and order requests, and requires a successful permission decision, which can be cached briefly. SideShift’s terms and country restrictions apply independently of Orrerie’s App Store country backstop. A permission response does not guarantee settlement or establish eligibility under every applicable term.
ChangeNOW and RocketX are retired. Orrerie sends them no new requests and does not poll saved orders. Earlier account records and public transaction references remain available for support; prior provider processing and retention are not undone by removal.
Bitrefill and CryptoRefills are optional Spend providers and receive product, order, payment and delivery data when you choose that provider. Scorechain receives public addresses for sanctions screening. TronRental receives the public TRON Energy recipient, requested Energy amount, reviewed TRX price, invoice or order identifiers and status queries for its Energy route. The user’s Personal Gas
TRON address pays the invoice directly; its public payment transaction can link that gas address to the Energy recipient. TronRental and RPC providers never receive the Personal Gas private key.
Alchemy, dRPC, Ankr, BlockPI, Dwellir, Infura, NodeReal and Chainnodes are configurable authenticated RPC or index providers. TronGrid supports additional chain reads. PublicNode, LlamaRPC and network-operated endpoints can provide public RPC or fallback checks. For TRON, Orrerie’s server reads balances, the latest block, transactions, fee receipts, Energy and account resources from PublicNode first, then Nodies over Pocket Network (POKT), Dwellir, Alchemy, TronGrid and dRPC in turn until one answers;
TRON account history comes only from TronGrid. The
TRON checks Orrerie’s co-signer makes before it signs, and its
TRON broadcasts, go only to TronGrid. These services receive the network, RPC method, public address, contract, transaction reference or signed transaction bytes needed for a read or broadcast, plus server connection metadata.
The Personal Gas client directly contacts PublicNode on every network and two more fixed public endpoints on each: dRPC and Nodies on Ethereum; Binance’s and BNB Chain’s own endpoints on
BNB Smart Chain; dRPC and QuickNode’s public endpoint on
Polygon; and the network’s own public endpoint and Nodies on
Arbitrum,
Optimism and
Base. Nodies serves these endpoints over Pocket Network (POKT). One read can go to several of them at once. Those endpoints receive the device IP address, RPC method, public address or transaction data and timing. A broadcast includes signed transaction bytes, never the Personal Gas private key. Each EVM Personal Gas broadcast also sends the same signed transaction bytes through Orrerie’s server, which forwards them once to its authenticated dRPC endpoint with Orrerie’s server connection metadata and does not keep them. Each endpoint’s policy governs its own logs and retention.
For Solana, Orrerie prepares and checks transactions with the public Personal Gas
Solana address as fee and rent payer. The phone verifies and signs the reviewed transaction locally. Orrerie and the selected
Solana RPC receive public addresses, the required signed transaction bytes and confirmation queries; the gas key is never supplied to them. The gas signer pays costs without replacing either required asset-owner approval.
THORChain status and quote checks can use public THORNode or Midgard operators including Liquify, Rorcual, Inter Blockchain Services and midgard.thorchain.network. They receive quote parameters, public addresses or transaction references and server connection metadata. Community node operators have independent practices; the THORChain project notice is not represented as a contract binding every independent node.
CoinGecko and Binance provide asset market data. ExchangeRate-API provides a daily USD foreign-exchange table; the fawazahmed0 currency-api dataset is delivered through jsDelivr as fallback. These market and rate requests run server-side and contain requested symbols or the USD dataset path and Orrerie’s server connection data, not an Orrerie account identifier or wallet address by design. Separate app artwork requests are described under Business and product artwork below.
Price alerts use one shared alert service on Orrerie’s server for every account: it reads Binance and CoinGecko market data, and Chainlink price-feed contracts (with the Arbitrum and
Optimism sequencer status feeds) through the keyless public endpoints of PublicNode, dRPC and NodeFlare. These requests name only public feeds and contracts and carry no account identifier, wallet address or alert.
Bitcoin fee alerts use Orrerie’s own
Bitcoin node, and
Ethereum base-fee alerts use block headers Orrerie already receives for notifications; ExchangeRate-API’s daily table, or the currency-api fallback through jsDelivr, converts alert levels set in another currency.
Orrerie’s own Bitcoin,
Litecoin and
Dogecoin nodes provide
Dogecoin balances and history, back up
Bitcoin and
Litecoin balance and history reads, check every coin used in a
Bitcoin,
Litecoin or
Dogecoin send, estimate network fees and are the first route for broadcasting signed transactions. mempool.space (
Bitcoin) and litecoinspace.org (
Litecoin) provide address balances, history and transaction details. They and dRPC’s keyless public
Dogecoin endpoint (dogecoin.drpc.org) are also secondary sources: when our node cannot return an older transaction, they receive only its transaction identifier; when our node has no fee estimate, mempool.space or litecoinspace.org supplies one; and when our node cannot confirm that a signed transaction was accepted, the identical signed transaction bytes are sent to that network’s service, which must return the same transaction identifier. These providers receive the public address, transaction identifier or signed transaction bytes required by the request and server connection metadata. Tatum, Blockchair and BlockCypher are retired: Orrerie’s servers send them no requests, and prior processing and retention are not undone by removal. The separate Recovery tool, which runs in your browser, can use BlockCypher’s public
Litecoin and
Dogecoin API; see Recovery tool endpoints below. Transaction links in the app can open a public block explorer page, such as mempool.space, litecoinspace.org or Blockchair, in your browser when you choose to open it. The linked service pages identify independent operators; public blockchain data cannot be made private by a website policy.
Orrerie operates its own Bitcoin,
Litecoin and
Dogecoin notification nodes and bridge. EVM,
Solana and
TRON notification subscriptions or recovery reads can use Blockmachine, PublicNode, dRPC, NodeFlare, OnFinality, Alchemy, TronGrid and official
Solana endpoints, according to network support and fallback availability. They receive public watch filters, addresses, token accounts, transaction references, block positions and server connection metadata. Orrerie’s notification bridge does not send them account email, phone or offline private keys. Notification processing is separate from other RPC, indexing and transaction-provider roles described above.
- Relay terms
- Relay privacy
- SideShift legal terms
- SideShift privacy
- KyberSwap terms
- KyberSwap privacy
- Rubic terms
- Rubic privacy
- Across terms
- Across privacy
- THORChain terms
- THORChain privacy
- Bitrefill privacy
- Bitrefill terms
- CryptoRefills privacy
- CryptoRefills terms
- Scorechain privacy
- Scorechain terms
- TronRental terms
- Alchemy terms
- Alchemy privacy
- Ankr terms
- Ankr privacy
- BlockPI terms
- BlockPI privacy
- Dwellir terms
- Dwellir privacy
- Infura / Consensys terms
- Infura / Consensys privacy
- NodeReal terms
- NodeReal privacy
- Chainnodes terms
- Chainnodes privacy
- dRPC terms
- dRPC privacy
- PublicNode terms
- PublicNode privacy
- Nodies privacy
- Nodies terms
- Pocket Network privacy
- Pocket Network terms
- QuickNode privacy
- QuickNode terms
- BNB Chain disclaimer
- BNB Chain privacy
- Polygon terms
- Polygon privacy
- Arbitrum developer terms
- Arbitrum privacy
- Optimism terms
- Optimism privacy
- Base terms
- Coinbase privacy for Base services
- CoinGecko terms
- CoinGecko privacy
- Binance terms
- Binance privacy
- ExchangeRate-API terms and privacy
- Currency API source and CC0 licence
- jsDelivr terms
- jsDelivr privacy
- TRON developer terms
- TRON privacy
- mempool.space project information
- litecoinspace.org service
- Blockchair terms
- Blockchair privacy
- Blockmachine service and documentation
- NodeFlare security and data handling
- OnFinality privacy
- OnFinality terms
- Solana public RPC documentation
- SideShift user permissions and IP handling
- SideShift current country availability
Business and product artwork
The app accepts public artwork only from an allowlist: assets.relay.link, coin-images.coingecko.com, assets.coingecko.com, cdn.bitrefill.com, cdn.cryptorefills.com, raw.githubusercontent.com, tokens.1inch.io, cdn.jsdelivr.net and img.logo.dev. When an allowlisted image is displayed, that host receives the device IP address, request timing, protocol or user-agent data and the requested asset or product path. The path can reveal which coin, route, product or business was displayed even though Orrerie does not intentionally add an account identifier, wallet address, credential or cookie.
Artwork requests use an ephemeral cookie-free and credential-free URL session. Successful image bytes may remain in Orrerie’s on-device cache, bounded to 512 files or 64 MB and subject to operating-system eviction or app deletion. Remote message-body images stay blocked until the user chooses to load them. Coin, route and product artwork can load when the related screen appears, and the current build has no separate artwork toggle.
Each image host controls its own logs and retention under its policies. The links below identify those providers. Direct artwork delivery exposes connection data even when the artwork is public; it is separate from the user-controlled loading of remote images within a message.
Recovery tool endpoints
The Orrerie Recovery tool runs from a saved file in your browser and contacts the public endpoints below directly; Orrerie’s servers are not involved and receive nothing. Each operator receives your IP address, browser and protocol details such as the user agent and language, request timing, the public addresses, contracts or transaction references requested and, for a transfer, the signed transaction. Requests carry no cookies, credentials or referrer. These are the defaults in version 0.1.0, checked on 27 September 2026.
Ethereum: PublicNode, bloXroute, thirdweb, dRPC and Alchemy, which now operates the Blast API public endpoint.
BNB Smart Chain: BNB Chain’s public endpoint, 48 Club, thirdweb, NodeReal and Blockmachine.
Polygon: PublicNode, QuickNode’s public endpoint, thirdweb, dRPC and Blockmachine.
Arbitrum: the network’s own public endpoint, fastnode, PublicNode, Pocket Network and dRPC.
Optimism: the network’s own public endpoint, fastnode, PublicNode, dRPC and BlockPI.
Base: the network’s own public endpoints, bloXroute, thirdweb and PublicNode.
Solana: PublicNode, Solana Tracker and Pocket Network.
TRON: TronGrid, PublicNode, TronStack and Pocket Network.
Bitcoin: mempool.space, Blockstream, mempool.emzy.de, mempool.ninja and BitPay’s Bitcore API.
Litecoin: litecoinspace.org, Bitcore and BlockCypher.
Dogecoin: Bitcore, dRPC and BlockCypher.
You can remove these endpoints or add your own in the tool; an endpoint you add receives the same information. CoinGecko receives coin identifiers only while you turn on USD values. The Safe Transaction Service run by Safe receives an owner address only when you use it to find EVM Safes without a Recovery kit. Explorer websites (Etherscan, BscScan, PolygonScan, Arbiscan, Optimistic Etherscan, BaseScan, Solscan, Tronscan, mempool.space, litecoinspace.org and Blockchair) open only when you choose a link. Operators named in the sections above keep the links listed there. A later release can change these defaults; this section is updated before such a release is offered.
- bloXroute privacy
- bloXroute terms
- thirdweb privacy
- thirdweb terms
- 48 Club service information
- fastnode service information
- Solana Tracker privacy
- Solana Tracker terms
- TronStack service information
- Blockstream privacy
- Blockstream terms
- mempool.emzy.de service information
- mempool.ninja service information
- BitPay privacy (Bitcore)
- Bitcore project information
- BlockCypher API documentation
- Safe privacy
- Safe terms
- Etherscan privacy
- BscScan privacy
- PolygonScan privacy
- Arbiscan privacy
- Optimistic Etherscan privacy
- BaseScan privacy
- Solscan service information
- Tronscan service information
Provider changes
A material provider or data-flow change requires the registry and privacy disclosures to be updated before use. Where personal data would be shared with a third-party AI for a new purpose, Orrerie requests new explicit permission. Provider changes do not silently expand an existing permission.