PRIVACY POLICY

Privacy at Mist Wallet

Last updated: June 2025

Keys stay on your device We never transmit private keys, seed phrases, or raw signing material to our servers.
Minimal data, clear purpose We collect only what’s necessary for the app, security, and support — no ads, no cross-site tracking.
Your choice, always Telemetry is optional. You can opt out anytime in the desktop app and docs-guided config.
Introduction

Who we are

Mist Wallet is a non-custodial, multi-chain Ethereum wallet for desktop (Windows, macOS, Linux) and a developer SDK. Our mission is to make self-custody and on-chain interactions safer and clearer.

Legal entities & correspondence:

  • Mist Labs — Bahnhofstrasse 18, 8001 Zürich, Switzerland
  • Mist Labs (MEA) — DIFC, Gate Village 7, Dubai, UAE

Support: support@mist.app • Media/partnerships: press@mist.app

Scope

What we collect (and don’t)

We design for data minimization. Here is a transparent view across our website, desktop app, and SDK:

Data category Examples Where Purpose Control
On-device secrets Private keys, seed phrases, derived keys Desktop app Wallet functionality Never leaves device
Wallet metadata Addresses, chain IDs, public asset balances (from RPC) Desktop app / SDK Show balances, build transactions User-controlled
Diagnostics (optional) App version, OS info, anonymized crash traces Desktop app Reliability, debugging Opt-in / Opt-out
Product analytics (minimal) Aggregated feature usage (no keys, no raw tx data) Desktop app / Website Improve UX, roadmap decisions Toggle in settings
Support interactions Emails, tickets, logs you choose to share Support Answer questions, resolve issues Your choice to submit
Web telemetry Basic visits, pages, referrers (cookie-lite) Website Site performance & security Consent where required

We do not sell your personal data. We don’t run ads. We do not build cross-site profiles. Blockchain interactions are public by design, but you decide which addresses to use and share.

Website

Cookies on our website

We use a small set of cookies/local storage entries to keep the site secure and useful. Categories:

TypeWhat it doesStorageExpiryRequired
Essential Load balancing, CSRF protection, fraud prevention Cookie Session → 24h Yes
Preferences Remember OS recommendation, language, reduced motion Local Storage Until cleared Optional
Analytics Aggregate page views, without cross-site tracking Cookie / Local Storage 6–13 months (jurisdiction-dependent) Consent where required

You can adjust browser settings to block or delete cookies. Some features may degrade if essential cookies are blocked.

Products

Desktop app & SDK specifics

Non-custodial by design. Keys are generated and stored on your device. Signing happens locally via OS-level cryptography APIs where applicable.

When you connect to chains (Ethereum mainnet, L2s), your client talks to RPC endpoints you configure or that we provide as defaults. These third-party endpoints may receive your IP address, wallet address, and request metadata. You can switch providers or run your own node.

Discovery and session protocols exchange public metadata (e.g., peer name, chain, capabilities). They are not used by us to build marketing profiles.

If enabled, the app may send anonymized crash traces, OS version, app version, and performance counters. No private keys or raw transaction payloads are included. You can disable diagnostics in app settings.

High-level data lifecycle On-device Keys & signing Network RPC / L2 endpoints Optional telemetry Aggregated diagnostics
Purpose

Why we process data

  • Provide the service — wallet functionality, SDK features, compatibility and updates.
  • Security — fraud/abuse prevention, rate-limiting, incident response.
  • Product improvement — fix crashes, measure aggregate adoption of features.
  • Support — respond to your requests when you contact us.
  • Legal — comply with obligations and enforce terms.
Retention & Security

How long we keep data & how we protect it

Retention. We keep personal data only for as long as needed for the purposes above, then delete or anonymize it. Typical windows:

  • Support tickets: 24 months after closure (unless law requires longer).
  • Diagnostics (opt-in): 12 months rolling.
  • Website analytics: 6–13 months (depending on region & vendor).

Security. We apply least-privilege access, encryption in transit, strict origin checks, request rate-limits, and audit logs for sensitive flows. Private keys never leave your device.

Your rights

Your privacy rights (GDPR/UK GDPR, Swiss nFADP, CCPA/CPRA)

Depending on where you live, you may have some or all of the following rights. We honor valid requests regardless of where you are when feasible.

  • Access — get a copy of your personal data.
  • Rectification — correct inaccurate or incomplete data.
  • Deletion — ask us to delete data we hold, subject to lawful exceptions.
  • Portability — receive data in a machine-readable format.
  • Restriction / Objection — limit or object to certain processing.
  • Consent withdrawal — turn off optional telemetry at any time.
  • Do Not Sell/Share (California) — we do not sell personal information.

To exercise rights, see Contact & requests.

Transfers

International data transfers

Our operations are in Switzerland and the UAE, with infrastructure that may be located in the EU and other regions. When transferring data internationally, we rely on appropriate safeguards, such as Standard Contractual Clauses where relevant.

EU/EEA & UK: GDPR/UK GDPR apply. Swiss nFADP applies in Switzerland. We implement contractual safeguards with processors outside these areas.

US (California): We do not sell or share personal information for cross-context behavioral advertising as defined by CPRA.

Requests

Contact & privacy requests

For privacy questions or to exercise rights, contact us at support@mist.app. We may ask you to verify your identity and ownership of relevant wallet addresses to protect your data.

  • Email: support@mist.app
  • Mail: Mist Labs, Bahnhofstrasse 18, 8001 Zürich, Switzerland

Response times vary by jurisdiction (typically within 30 days).

Updates

Changes to this policy

We may update this Privacy Policy to reflect product changes, legal requirements, or best practices. We’ll adjust the “Last updated” date and, when changes are material, we’ll provide a more prominent notice.

Last updated: June 2025

Appendix

Glossary

  • Personal data: Information that identifies or can reasonably be linked to an individual.
  • Telemetry: Diagnostic, performance, or usage data used to improve reliability and UX.
  • RPC provider: A service that relays your read/write requests to a blockchain network.
  • Non-custodial: You hold the private keys; we can’t access or recover them without your backups.