Privacy policy

Short version: we do not collect your data. There is no account, no analytics, no advertising, and no server of ours that stores anything about you. The detail below is mostly about the one place that gets complicated.

Effective 1 August 2026. Applies to dankest.llc and to the software Dankest, LLC publishes, including XChain Wallet.

What we do not do

No accounts. No analytics or telemetry SDK in any app or on this site. No crash reporting. No advertising, no advertising identifiers, no third-party trackers, and no cookies set by us. We do not sell, rent, or share personal information, because we do not collect it in the first place.

This website

dankest.llc is a static site. It sets no cookies and runs no analytics.

Like nearly every web server, ours writes an access log. Each request records your IP address, the time, the page requested, the response status, the referring page, and your browser's user-agent string. Those logs exist to keep the site running and to spot abuse. They are rotated daily and kept for 14 days, then deleted. We do not link them to any identity, build profiles from them, or feed them to anyone else.

This site is served directly from our own server. It is not behind a content delivery network, so no third party sees your visit.

XChain Wallet

XChain Wallet is a self-custody wallet: it holds your keys on your device and we never hold them.

What stays on your device, always

Your recovery phrase, every key derived from it, any private key you import, your password, and your labels, address book and settings. These are encrypted on your device with a key derived from your password. We never receive them, in any form, at any time. There is no backup of them on our servers, because there is no server of ours that holds user data.

That has a consequence we would rather state plainly than bury: if you lose your recovery phrase, we cannot recover your funds. Nobody can. That is the trade self-custody makes.

What leaves your device, and where it goes

This is the part most wallets are quiet about. To show you a balance, a wallet has to ask a server about your addresses, and that tells the server which addresses you are interested in.

  • Your addresses go to our indexer. To display balances and history, the wallet asks explorer.xchain.io about the addresses in your wallet. To prepare a transaction, it sends the addresses and amounts involved to encoder.xchain.io. Both see your IP address, as any server you contact does.
  • Chain settings come from hub.xchain.io. Nothing about you is sent; the wallet is fetching a signed configuration file.
  • Prices come from CoinGecko (api.coingecko.com), a third party, if you have fiat values switched on. They see your IP address. They are not told your addresses, your balances, or anything else about you.
  • Update checks, only if you installed the Android APK directly. Play and other stores handle their own updates. A direct install asks downloads.xchain.io, at most once a day, whether a newer version exists. The request carries nothing but the request itself, and you can switch it off.

All of these endpoints are configurable in the wallet. If you run your own indexer, point the wallet at it and we see nothing at all.

What our servers keep

The same answer as this website, because it is the same kind of server: an access log per request, containing your IP address, the request, and your user-agent. Rotated daily, kept 14 days, then deleted. No account is attached, because there are no accounts. We do not correlate those logs across services or use them to build a picture of a person.

One thing to be clear about, since we cannot control it: xchain.io and its subdomains sit behind Cloudflare, which absorbs attacks for us. Cloudflare therefore sees requests to those services and keeps its own logs under its own policy. dankest.llc does not go through them.

On Android

  • Camera. Asked for the first time you scan a QR code, and only then. Frames are decoded on your phone; nothing is photographed, stored, or transmitted. Decline it and the rest of the wallet works.
  • Biometric unlock. If you turn it on, your phone's secure hardware holds an encrypted copy of your wallet password and releases it only after your fingerprint or face is checked, once, for that unlock. The wallet never sees your biometrics: Android checks them and answers yes or no. Adding a new fingerprint to the phone destroys the stored copy deliberately, and you go back to typing your password.
  • No cloud backup. The app tells Android not to include it in cloud backup and not to transfer during device-to-device setup. The wallet file is encrypted with a key that cannot leave your phone, so a copy elsewhere would be unreadable anyway, and your settings and address book are not something we want in anyone's cloud. Moving to a new phone means importing your recovery phrase.
  • Screenshots. Blocked on the screens that show your recovery phrase or a private key, and on the unlock screen. That also keeps them out of the app-switcher thumbnail your phone writes to storage. Everywhere else screenshots work normally, because sharing your own receive code is an ordinary thing to do.

Our other software

Dankest publishes and maintains other open-source projects. Where any of them collects something this policy does not describe, that project says so in its own documentation. If the two ever disagree, treat the stricter one as binding and tell us, because it means we made a mistake.

Children

Our software is not directed at children, and we do not knowingly collect information from anyone. There is no account system through which a child could give us anything.

Your choices

There is no account to close and no data export to request, because we hold nothing tied to you. If you want to be sure nothing of yours reaches us at all: point the wallet at your own indexer, turn off fiat prices, turn off update checks, and use the wallet over Tor if your platform supports it. Uninstalling removes everything the app stored, and the wallet can erase its own storage from its settings first.

Changes

If this policy changes in a way that affects what we collect, we will change the effective date at the top and describe the change in our news feed. We will not quietly broaden it.

Contact

Questions about this policy, or anything in it that reads as untrue: info@dankest.llc

Dankest, LLC · Sheridan, Wyoming · USA