Privacy Policy
Last updated: [DATE]
VAC Digital Culture Technology Group Company Limited ("we", "us") operates the Mamago mobile wallet application ("Mamago").
1. Summary
Mamago is a non-custodial wallet. Your private keys and recovery phrase are generated on your device and never leave it. We have no account system, no login, and no way to access your funds. We do not collect your name, email address, phone number, or any other directly identifying information.
We do, however, operate a gateway server that Mamago uses to read blockchain data, and your device also connects directly to public blockchain nodes and, if you use WalletConnect, to the WalletConnect relay network. All of these are described below, because they involve data leaving your device.
2. What stays on your device and is never sent to us
- Your recovery phrase and private keys. Stored encrypted in the platform secure storage (Apple Keychain on iOS;
EncryptedSharedPreferenceswith AES-256 on Android). They are never transmitted to us or to any third party. - Your wallet password. Used locally to encrypt the stored key material. If you turn on biometric signing for a wallet, a protected copy of that wallet's password is also kept on this device (see "Biometric data" below).
- Camera images. When you scan a QR code, frames are decoded on the device and discarded. No image is stored or uploaded.
- Biometric data. Face ID / fingerprint checks are handled entirely by the operating system. We never receive or store biometric data. If you turn on biometric signing for a wallet (shown as "Sign with Face ID", "Sign with fingerprint" or "Sign with biometrics", depending on your device), a copy of that wallet's password is kept on this device so that transfers you make from the Send screen, energy rental payments and low-risk WalletConnect transactions on EVM networks can be confirmed with your face or fingerprint. On iOS the copy is an Apple Keychain item that can only be read after your device's Face ID / Touch ID check. On Android it is stored encrypted in the app's private storage, and the key that decrypts it is held in the Android Keystore and can only be used after a strong biometric check on your device. The copy is not synced to iCloud or any other cloud service and cannot be used on another device. Enrolling a new face or fingerprint makes the copy unusable; when Mamago detects this, it deletes the copy and asks for your password instead. Turning the feature off or deleting the wallet removes it. Uninstalling Mamago removes it on Android; on iOS it stays in the Apple Keychain after you uninstall (like the encrypted key material, see §6) and is deleted the next time Mamago starts after a reinstall.
3. What leaves your device
3.1 Requests to our gateway
To show your transaction history and token prices, Mamago sends requests to a gateway server we operate. Each request carries:
- the blockchain address you are viewing (public information on the blockchain itself), and
- a random device identifier — a UUID generated on first launch, used only to apply rate limits. It is not derived from your device hardware, is not linked to any identity, and is regenerated if you reinstall the app.
Requests to our gateway first pass through Cloudflare, which provides encrypted connections and network protection for our server. Cloudflare therefore sees your device's IP address and the full request, including the blockchain address being viewed, and processes them under its own privacy policy.
Our gateway does not maintain a database. Our server keeps an access log for up to 15 days. For each request it records only the time, the path requested (without the parameters that carry the blockchain address), the result, the response size and duration, and the user-agent string sent by the app (for example the app version and the operating-system version). It does not record your IP address or the blockchain address.
To avoid repeating identical lookups, transaction history is kept in the gateway's memory for up to one hour, indexed by network and blockchain address. It is not associated with your device identifier or IP address, and it is lost whenever the gateway restarts.
For abuse prevention our server applies two independent rate limits, and both keep only short-lived counters in memory:
- by random device identifier — the counter covers a rolling 60-second window. When this limit is hit, a warning is logged containing only the first 8 characters of that identifier;
- by the network address your device connects from (its IP address) — the counter is held in memory and is not written to disk. When this limit is hit, the IP address is not logged. We do not associate it with a wallet address, a device identifier, or any identity, and we do not use it for anything other than rate limiting.
Besides the access log, the gateway keeps its own log of errors and of the rate-limit warnings described above. It contains no IP address and no blockchain address, and it is deleted after at most 15 days.
The gateway forwards these requests to: Etherscan, Helius and TronGrid (transaction history) and CoinGecko (token prices). Etherscan, Helius and TronGrid receive the blockchain address being queried; CoinGecko receives only which tokens' prices are requested. All of them see our server's network address — not your device's.
3.2 Direct connections to public blockchain nodes
For balances and token information, and to broadcast transactions, Mamago connects directly from your device to public blockchain RPC endpoints (for example publicnode.com, drpc.org, tenderly.co, pocket.network, and the official endpoints of the networks we support). All of them are operated by third parties.
⚠ Because these connections come from your device, the operator of each endpoint can see your device's IP address together with the content of each request — the wallet addresses being looked up and any transaction you broadcast. It can therefore link the addresses looked up from the same device to one another and to that IP address. Some endpoints, including Pocket Network, forward requests to other independent node operators; those operators receive the content of the request, and we do not know whether they also receive your IP address.
Mamago does not send these endpoints your random device identifier, an API key, or any account information. We have no contract with these operators and do not control what they record, how long they keep it, or how they use it; they operate under their own terms and privacy policies. A transaction you broadcast becomes public on the blockchain in any case. If this matters to you, consider using a VPN.
3.3 WalletConnect
While you are pairing Mamago with an application over WalletConnect, and each time Mamago starts for as long as a pairing or session remains active, Mamago connects to the WalletConnect relay network operated by Reown so that it can receive requests from that application. If you have no active pairing or session, Mamago does not connect to the relay. This connection carries a random identifier that the WalletConnect library generates and keeps on your device, together with Mamago's WalletConnect project identifier and the library version; Reown also sees your device's IP address. Reown processes this data under its own privacy policy. We have switched off the WalletConnect library's built-in usage reporting.
When a paired application sends Mamago a connection, sign-in or signing request, the WalletConnect library may also contact Reown's Verify service (verify.walletconnect.org) to check which website the request came from. Mamago shows you that website, and when you are asked to connect it warns you if the site could not be verified or is known to be malicious. That lookup may include a hash of the request; Reown also sees your device's IP address.
If you pair with an external application over WalletConnect, that application receives the wallet address you choose to share and any transaction or message you approve. Those applications are operated by third parties under their own terms and privacy policies. Mamago does not embed a browser and does not run third-party code.
3.4 Energy rental on TRON (optional)
TRON charges "energy" for token transfers. Mamago has an optional Energy screen that lets you rent energy from TronSave, a third-party provider, instead of burning TRX. If you never open that screen, no data described in this section leaves your device.
When you open the screen, Mamago asks the provider, through our gateway, what the energy would cost. The app includes your TRON address in its request to our gateway, which checks that the address is well-formed and does not pass it on. The price request the provider receives carries the rental parameters only — how much energy and for how long. It does not carry your address. Prices do not depend on who is renting, so there is no reason to send it.
When you confirm a rental, our gateway sends the provider:
- the TRON address the energy is rented for — this is your own address. It is sent at this point because the provider has to delegate the energy to it on-chain;
- the rental parameters — how much energy and for how long;
- the payment transaction you signed. It is an ordinary TRX transfer from your address to the provider's address. The provider submits it to the TRON network; we never hold your funds and we cannot submit or reverse it for you.
What our gateway does not send the provider:
- not your random device identifier, and
- not your device's network (IP) address — the provider sees our server's address, not yours.
We do not store the address in a database and we do not write it to our logs. Like every request to our gateway, these requests pass through Cloudflare (§3.1). Price lookups are cached for 60 seconds so that repeated lookups do not become repeated upstream requests; orders are never cached.
⚠ Note that a rental is public on the blockchain either way: the payment transaction, your address, and the amount are all visible on TRON once the provider submits it.
A rental lasts one hour. When it ends, the energy returns to the provider. Send the transfer you rented the energy for before then.
Mamago does not take a commission on energy rentals, does not set the price, and does not guarantee that the provider delivers. The screen says so above the button before you confirm.
4. What we do NOT do
We do not use analytics, telemetry, crash reporting, advertising, or tracking software of any kind. We do not build user profiles, and we do not sell or share data for advertising.
5. Third parties
Data leaves your device only to the recipients described in §3:
- Cloudflare, which provides network protection for our gateway (§3.1);
- Etherscan, Helius and TronGrid, which our gateway queries for transaction history, and CoinGecko, which it queries for token prices (§3.1). They see our server's network address, not your IP address or device identifier;
- the public blockchain RPC endpoints your device connects to directly (§3.2);
- Reown, for the WalletConnect relay and Verify service (§3.3), and any application you choose to pair with over WalletConnect;
- TronSave, only if you use energy rental (§3.4).
We share with each of them only the data described in §3, only so that they can provide the service described there, and we do not share your data with anyone else or for any other purpose. We do not sell your data and do not share it for advertising.
These recipients are independent of us and process data under their own terms and privacy policies — in particular the public RPC endpoints in §3.2, which anyone can use without an agreement. We cannot guarantee that they protect your data to the standard described in this policy. That is why we send each of them no more than its request needs and, except as stated in §3, never your device identifier.
6. Retention and deletion
- On your device: deleting a wallet in the app removes that wallet's encrypted key material from the platform secure storage. Uninstalling Mamago removes the app's settings and the random device identifier; on Android it also removes the encrypted key material. On iOS, the encrypted key material stays in the Apple Keychain after you uninstall Mamago. It remains encrypted, is not synced to iCloud, and cannot be restored onto another device; if you reinstall Mamago, you will be offered to restore it. To remove it, delete the wallet in the app before uninstalling. If you have not backed up your recovery phrase, your funds cannot be recovered by anyone, including us.
- On our gateway: we hold no user database. Cached blockchain and price data expires automatically within hours and is not associated with your device identifier or IP address. Our server's access log and the gateway's own log, neither of which contains an IP address or a blockchain address, are deleted after at most 15 days.
- How to withdraw consent: because Mamago requires no account and no personal information, you withdraw consent by deleting the wallet or uninstalling the app. There is no account to close.
- How to request deletion: email hello@vac.asia. Our gateway logs contain no IP address, no blockchain address and no full device identifier, so we cannot tell which entries relate to you; instead, we will delete all of our gateway logs for the period you name. In any case they are deleted automatically after at most 15 days. We cannot delete data held by the third parties named in §3 and §5; their own privacy policies explain how to ask them.
- Access and correction: you may ask us for access to, or correction of, any personal data we hold about you by emailing hello@vac.asia.
7. Children
Mamago is not directed to children under 18.
8. Changes
We will post any change to this policy at this URL and update the "Last updated" date.
This policy may be provided in other languages. If a translation differs from the English version, the English version prevails.
9. Contact
VAC Digital Culture Technology Group Company Limited, RM 1506, 15/F THE GATEWAY TOWER 1, 25 CANTON RD TSIM SHA TSUI, HONG KONG — hello@vac.asia