Legal

Privacy policy

Last updated: September 6, 2026

1. Who we are

This privacy policy explains how Sube Technologies Ltd ("Sube", "we", "us") handles information in connection with the Sube mobile wallet application and the sube.online website (together, the "Service").

  • Legal entity: Sube Technologies Ltd, a private limited liability company
  • Registered under the Companies Law, Cap. 113, Republic of Cyprus
  • Registration number: HE 497682
  • Date of incorporation: 1 September 2026, Nicosia, Cyprus
  • Contact: Hello@Sube.online

For the purposes of the EU General Data Protection Regulation (GDPR) and the Cyprus Law 125(I)/2018, Sube Technologies Ltd acts as the data controller for the limited data described below.

2. Zero-knowledge by design

Sube is a non-custodial wallet with no KYC and no user accounts. We do not ask for your name, email, phone number, government ID, address or date of birth in order to use the app. There is no account to create, no profile to fill in, and no identity file for us to hold, lose or hand over.

3. What stays on your device

Your private keys, recovery phrase, device passcode or biometric unlock, wallet addresses, local transaction history and app preferences are generated and stored on your device only. They are never transmitted to our servers. We have no technical means to view, export, freeze or recover them.

If you lose your device and your recovery phrase, we cannot restore access to your funds. This is a deliberate consequence of the non-custodial design.

4. What we do collect

We process a narrow set of data, none of which identifies you by name:

  • Technical and diagnostic data — app version, operating system version, device model, crash reports and error traces, used to keep the app stable and secure.
  • Aggregated usage analytics — anonymous, event-level counts such as screen views or feature usage, used to understand which parts of the app are useful.
  • Network data — IP address and request metadata processed transiently by our infrastructure and security providers to deliver the Service and prevent abuse.
  • Voluntary correspondence — if you email us or use a contact or partnership form, we process whatever you choose to send, including your email address.

5. Legal bases for processing

  • Legitimate interests (Art. 6(1)(f) GDPR) — keeping the Service secure, stable and free from abuse, and improving it through aggregated analytics.
  • Performance of a contract (Art. 6(1)(b)) — providing the app functionality you request under our Terms of Use.
  • Consent (Art. 6(1)(a)) — optional analytics or marketing communications, where consent is required. You may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)) — where we must respond to a lawful order from a competent authority.

6. Service providers

We rely on a small number of processors acting on our instructions: app distribution platforms (Apple App Store, Google Play), cloud hosting and content delivery, crash reporting and analytics, blockchain node and market-data providers, and email delivery. Each is bound by a data processing agreement and may only use the data to provide the service to us.

7. Third parties, casinos and blockchains

Casinos and other services reachable from inside Sube are independent third parties. Once you interact with them, their own privacy policies and any KYC requirements apply — not ours. We do not receive your casino account details.

Public blockchain transactions are, by nature, public and permanent. Anything you broadcast on-chain is visible to anyone and cannot be deleted by us or by you.

8. International transfers

Some of our providers operate outside the European Economic Area. Where data is transferred outside the EEA, we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses, together with additional technical safeguards where appropriate.

9. Retention

Crash and diagnostic records are kept for up to 12 months. Aggregated analytics are retained in non-identifiable form. Email correspondence is kept for up to 24 months after the last message, or longer where needed to establish, exercise or defend legal claims. Data held on your device is retained until you delete the app or wipe the wallet.

10. Security

Keys never leave your device and are protected by your device's secure storage and biometric or passcode lock. Our infrastructure uses encryption in transit, least-privilege access and regular dependency review. No system is perfectly secure, and you remain responsible for safeguarding your recovery phrase and device.

11. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent. Because we hold no identity data, we usually cannot link anonymous technical records to you — in that case we may be unable to act on a request without additional information that we are not required to collect (Art. 11 GDPR).

Send requests to Hello@Sube.online. You may also lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, or with your local supervisory authority.

12. Children

The Service is not directed at anyone under 18. We do not knowingly process data relating to minors. If you believe a minor is using Sube, contact us and we will act accordingly.

13. Cookies and the website

The sube.online website uses only what is strictly necessary to serve pages and measure aggregate traffic. We do not use advertising cookies or cross-site tracking. Where non-essential cookies are used, they are set only with your consent and can be refused without losing access to the site.

14. Changes to this policy

We may update this policy as the Service evolves. The "last updated" date above always reflects the current version, and material changes will be announced in the app or on this page.

15. Contact

Privacy questions or requests? Email Hello@Sube.online — Sube Technologies Ltd, HE 497682, Nicosia, Cyprus.