Version 1.6 — Last updated: August 12, 2026
This Privacy Policy describes how BAGHOLDER ("we," "us," or "our") collects, uses, and protects your information when you use our mobile application.
BAGHOLDER stores the following data locally on your device using encrypted storage (iOS Keychain / Android Keystore for secrets, an encrypted local database for structured data):
Other than the blocked-attempt mirror noted above, this data is NOT transmitted to our servers and remains exclusively on your device.
To protect against data loss (device replacement, app reinstallation, or accidental storage clearing), BAGHOLDER automatically creates an encrypted backup of your on-device data. This backup is encrypted on your device using a key derived from your wallet before transmission. We store the encrypted data on our server but cannot decrypt, read, or access its contents. Only your wallet can unlock the backup.
The backup includes: purchase history, bag configurations, app settings, and portfolio snapshots. On reinstall or device change, signing in recovers your wallet, which automatically decrypts and restores your data.
You can delete your backup at any time by deleting your account in Settings.
Our server stores the following data in a secured database:
During signup, before you have a wallet, the App records the pass/fail outcome at each eligibility gate (age verification, state selection, and legal-document review) so we can maintain a compliance audit trail and apply anti-abuse and rate-limiting safeguards against automated or repeated evasion. These records are keyed to a device identifier rather than your wallet, name, or email, and are retained for about one year. On a failed age check we record only an age band — never your date of birth. We also record the request IP at the moment of state attestation as a secondary cross-reference for the audit trail; your self-attested state of residence is the primary record. These records are never linked to your wallet, payment, or order records, and do not include your name, email, or any other personally identifiable information (PII).
Important: your email address may pass through our server when you make a buy — it is forwarded to our payment provider as required by their payment API. The transit is encrypted (HTTPS) and the value is discarded immediately after it's sent. No row of any database on our server contains your email at rest.
BAGHOLDER does not store on any server:
BAGHOLDER integrates with third-party services that process your data under their own privacy policies:
Our licensed payment provider processes your fiat payment and delivers a USD stablecoin (currently USDC) directly to your wallet, and performs any identity checks under its own privacy policy. You can pay as a guest with Apple Pay, Google Pay, card, and more depending on your provider — no account needed to get started. On every buy we pass your wallet address, the amount, and the destination chain to the provider; the provider collects any payment or identity details directly from you on its own payment screen. We receive only confirmation of successful delivery of the stablecoin.
Tax reporting: BAGHOLDER is a non-custodial software tool and does not prepare or file tax forms on your behalf. Buying cryptocurrency through our integrated onramp is generally not itself a taxable event under current US tax law, but each subsequent token swap or sale can be a taxable event for which you are responsible. Any tax forms you receive related to your crypto activity will come from a third party (such as an exchange where you eventually sell), not from BAGHOLDER. Use the Activity CSV export in the app's Settings to keep a copy of your purchase history for your own records. Tax rules vary by jurisdiction and change over time — always consult a qualified tax advisor for your specific situation.
Privy creates and manages your non-custodial embedded wallet using
advanced cryptographic techniques. Privy may collect your email
address or social login credentials for authentication. We do not
receive or store these credentials.
See: privy.io/privacy
We use Google's Firebase Crashlytics for crash reporting. When
the app crashes, Crashlytics sends Google a crash report that
includes a Crashlytics Installation UUID (an anonymous identifier
Google generates per app install — not linked to any account
or wallet on our side), your IP address (used by Google for
geographic crash distribution and discarded afterward), the stack
trace and exception details, device model, and OS version. We
strip wallet addresses and Solana addresses from error messages
before sending. Crash reports do NOT contain your name, email,
phone, or wallet address.
See: firebase.google.com/support/privacy
Third-party providers relay blockchain data between your wallet and the network. They may see your wallet address in transaction requests. No personal data is shared beyond the wallet address.
For purchases on Solana, our server sends your swap parameters
(input token, output token, amount, your wallet address) to
Jupiter's public aggregator API so it can return a routed swap
transaction your wallet then signs. Jupiter sees only the wallet
address and swap parameters.
See: jup.ag/legal/terms-of-use
We fetch public cryptocurrency market data from CoinGecko. No user data is shared with CoinGecko.
We fetch public near-live token prices from DefiLlama, keyed only by the token identifier. No user data is shared with DefiLlama.
You have the right to:
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:
To exercise these rights, contact us at [email protected].
BAGHOLDER is available in 43 U.S. states. BAGHOLDER is not available in New York, Connecticut, Louisiana, Vermont, Minnesota, New Mexico, the District of Columbia, or Pennsylvania.
BAGHOLDER is not intended for anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal information, we will take steps to delete such information.
We use industry-standard security measures to protect your data, including:
No system is 100% secure. You are responsible for securing access to your device.
We may update this privacy policy from time to time. The current version is always available in the app under Settings. If we make material changes, you will be asked to review and accept the updated policy.
If you have questions about this privacy policy, contact us at:
[email protected]
getbagholder.com