Privacy Policy
What information Tidal Wallet handles, and what leaves your device. This is the same account given on the app's Privacy & data screen, written out in more detail.
Who operates Tidal and how to reach us
Tidal Wallet is made and operated by T54 Labs Inc. ("T54"), a Delaware, U.S. corporation. Privacy questions and requests to access, correct, delete or stop processing your information go to privacy@t54.ai.
Tidal Wallet is a self-custody wallet. Your wallet moves only with this device's keys, and T54 does not receive, store or recover your seed or lock passphrase.
What lives only on your device
These stay in the device's secure storage and are designed not to be sent to a server.
- Seed and lock passphrase — the seed is encrypted with your lock passphrase and kept in this device's secure storage. The passphrase itself is not stored; it stays in memory only long enough to unlock the vault.
- Agent records — only the authorization ID and the label you chose.
- Settings and guide marks — your language choice, guide completion marks and the like.
What goes out
Information leaves the device in the cases below. In none of them is your seed or lock passphrase sent.
Mainnet and Testnet use separate service and session contexts. The encrypted vault on the device is shared between the two network selections, while enrollment and session records are kept per network.
- To the XRPL ledger — balance and activity reads, and transactions you signed. The ledger is a public record, so an address and its history are visible to anyone.
- To the Tidal gateway — only once this device is registered: its device public key, your wallet address and wallet public key, your approve and revoke requests, and session upkeep.
- To websites you sign in to — one signed proof: your wallet address, a public key and a signature, plus routine fields like a nonce, origin and expiry.
- When you request Testnet XRP — your public wallet address and xrpl.js client information are sent to Ripple's Testnet faucet (faucet.altnet.rippletest.net). This feature is not available on Mainnet.
What it is used for
Information that leaves your device is used only for the purposes below. It is not used for advertising or profiling, and it is not sold.
- XRPL ledger — to show your balances and activity, and to submit the transactions you sign.
- Tidal gateway — to register your device, process agent approvals and revocations, keep sessions alive, and protect the service.
- Websites you sign in to — to prove to that site that you control this wallet.
- Testnet faucet — to send test XRP to a Testnet wallet when you ask for it.
- Support — to answer the support and privacy requests you send us.
Camera
The camera is used only to read QR codes. Images are not stored or sent.
First release scope
The first production release does not include the Girin integration or the Mini App discovery and launch surfaces.
Processing outside your country
The Tidal gateway runs on infrastructure located in the United States. Once you register a device, its device public key, your wallet address and wallet public key, your approve and revoke records and session data may be processed in the United States.
How long information is kept
Retention differs by category. The settings currently in force are:
- Ordinary application and error logs — kept under a 30-day retention setting.
- Platform-required security and audit logs — kept longer under the cloud platform's own policy (currently 400 days). That retention is locked by the platform and cannot be shortened or deleted at will.
- Enrollment, device and session data — kept while needed to provide the service; eligible records are removed through the deletion request process.
- Support correspondence — kept for as long as handling the case requires.
- Database backups — expire on their own rolling schedule. If a backup is restored, deletions recorded after that snapshot are reapplied before service resumes.
- Public ledger records — cannot be erased by T54.
Your rights
You can ask to access, correct or delete your information, or to stop its processing, at privacy@t54.ai.
How to request deletion of service records, and what happens afterwards, is set out on the service data deletion page.
Ending a session blocks access through that session, and revoking a device removes that device's approval access. These actions do not erase all server registration, session or audit records.
Before a request is carried out we need to confirm control of the wallet. That check never requires your seed, private key or lock passphrase. Never send them.
Changes to this policy
If the policy changes, the app tells you and shows the effective date. This page shows the date it was last updated.
Contact
Privacy: privacy@t54.ai. Other support: support@t54.ai.