Stashi Wallet User guide

Pirate Chain Foundation

Stashi Wallet Privacy Policy

Effective date: 3 September 2026

Stashi Wallet is a self-custodial Pirate Chain wallet. Wallet keys and wallet records are kept on your device. No account registration is required, and the application does not contain advertising or analytics.

1. Who this policy covers

This policy applies to Stashi Wallet, published by the Pirate Chain Foundation. On Google Play, the application is identified by the package name com.pirate.wallet.

This policy describes information handled by the Stashi Wallet application. Websites, lightwalletd servers, market-data providers, GitHub, and swap services have their own privacy practices.

2. Information kept on your device

Stashi Wallet stores the information needed to operate your wallet locally. This may include:

  • Recovery phrases, spending keys, and viewing keys that you create or import
  • Wallet names, addresses, balances, transaction records, memos, contacts, and preferences
  • Downloaded compact blockchain data and synchronisation state
  • Swap records and locally generated swap credentials when the swap feature is used
  • Diagnostic logs when you choose to enable debug logging

Wallet secrets and wallet databases are protected by the local passphrase and supported platform security features. The Pirate Chain Foundation does not receive your recovery phrase, private keys, viewing keys, or plaintext local passphrase through an account, analytics, or telemetry service.

Debug logs are stored locally. They may contain technical information such as errors, timing, selected network mode, and endpoint status. A log leaves your device only if you choose to share it.

3. Information sent over the network

Stashi Wallet requires a network connection to synchronise and to submit transactions. A direct internet connection can reveal standard connection information, including your IP address and request timing, to the service you contact. The selected transport, such as Tor, SOCKS5, or I2P, may change what the destination service can observe.

Lightwalletd services

The application requests blockchain heights, compact blocks, and transaction status from the lightwalletd server that you select or that Auto mode selects. The server can observe connection metadata and the block ranges requested. Normal compact-block scanning does not send your recovery phrase, spending key, viewing key, or shielded address to the server.

When you send ARRR, the signed transaction is submitted to a selected lightwalletd server for broadcast. The transaction data required by the Pirate Chain network is then processed by network participants and recorded on the blockchain.

Optional external services

Non-lightwalletd internet features are controlled under Settings > Privacy and Network > Outbound API Calls. These controls are enabled by default and can be switched off. Depending on the features you use, Stashi Wallet may contact:

  • CoinGecko, CoinPaprika, and CoinMarketCap for ARRR market prices and fiat estimates
  • GitHub for release metadata, signed verification files, and desktop update checks
  • Komodo DeFi Framework services and peer networks for swap order books, quotes, balances, orders, and settlement

These services receive the request content and standard connection metadata needed to respond. Stashi Wallet does not send wallet recovery phrases or Pirate Chain spending keys to market-data or GitHub services.

4. Device permissions

  • Camera: Used only when you choose to scan a payment address or QR code. Scanning is performed on the device.
  • Biometrics: Used when you enable biometric approval. Authentication is performed by the operating system. Stashi Wallet receives the success or failure result, not your fingerprint or face template.
  • Notifications: Used for locally generated wallet and background synchronisation status where the operating system requires permission.
  • Network access: Used to synchronise, broadcast transactions, and access the optional services described above.
  • Background operation: Used to keep an active synchronisation task running where the operating system permits it.

5. Sharing and sale of information

The Pirate Chain Foundation does not sell personal information from Stashi Wallet. The application does not include advertising networks, behavioural tracking, or analytics SDKs.

Information is sent to a network service only when required for wallet operation or for a feature you use, as described in this policy. Each external service may process and retain connection data under its own terms and privacy policy.

6. Security

Stashi Wallet uses local encryption and platform security facilities to protect wallet material. Supported network connections use encrypted transport where the selected endpoint and mode provide it. No method of storage or transmission can be guaranteed to be completely secure.

Anyone with a recovery phrase or spending key can control the related funds. Keep these secrets offline and do not send them to support staff or enter them on a website.

7. Retention and deletion

The Pirate Chain Foundation does not operate a Stashi Wallet user-account database. Wallet information remains on your device until you delete the wallet, clear the application's storage, or uninstall the application. Back up the recovery phrase before deleting local wallet data if you may need to recover the wallet later.

Disabling debug logging clears the active local debug log. Information already submitted to an external service is subject to that service's retention policy. Confirmed transaction records form part of the Pirate Chain blockchain and cannot be deleted by Stashi Wallet or the Pirate Chain Foundation.

8. Your choices

  • Select Direct, Tor, SOCKS5, or I2P networking where supported.
  • Select a lightwalletd endpoint or use Auto endpoint selection.
  • Disable price, GitHub, update, or swap requests under Outbound API Calls.
  • Leave camera, biometric, and notification permissions disabled unless you want the related feature.
  • Enable debug logging only when you need diagnostic information.
  • Delete local wallet data using the wallet controls or the operating system.

9. Changes to this policy

We may update this policy when Stashi Wallet features or privacy practices change. The effective date at the top of this page identifies the current version.

10. Contact

For privacy questions about Stashi Wallet, contact the Pirate Chain Foundation at dev@piratechainfoundation.com.

Source code and issue reporting are available in the Stashi Wallet GitHub repository.