Privacy Policy
Effective October 6, 2026
Unhex is a security app for self-custody crypto wallets, published by Anton Mitrafanau, IE (“we”). This policy explains what data the app handles and why. In short: your keys never leave your device, there are no accounts, we do not track you, and our server does not log your wallet addresses.
What stays on your device
- Recovery phrases and private keys you create or import. They are encrypted with a key held by the Secure Enclave and unlocked with Face ID, Touch ID or your passcode. They are never sent anywhere, including to us.
- The wallets you watch, cached approvals, your activity history, alerts and settings.
- Explanations written by Apple’s on-device language model, when your device supports it.
What the app sends to the Unhex server
To check a request or a wallet, the app needs blockchain data. It gets that data through our server at unhex.app, which forwards each request to the data sources listed below and returns the answer. The server receives:
- wallet addresses you watch or scan, to look up approvals, balances and history;
- the transaction or message you are reviewing and the contract and token addresses it involves, to simulate it and check those contracts;
- signed transactions you choose to send, to broadcast them to the network.
We use this data only to answer these requests. To answer repeated questions faster, the server keeps short-lived copies in memory: contract and address details for up to 15 minutes, balances for up to one minute. It does not write them to disk and does not build profiles of users.
The server’s logs record which kind of request was made, for which network, how long it took and whether it succeeded. They do not contain IP addresses, wallet addresses, transaction contents or messages. Your IP address is visible to the server while it handles a request and is kept in memory for a short time to protect the service from abuse. It is not stored.
Data sources our server contacts
- Public blockchain nodes for Ethereum, Base, Arbitrum, OP Mainnet and Polygon, operated by PublicNode, dRPC, LlamaRPC and the networks themselves.
- Blockscout block explorers, for contract details, token balances and history.
- Public scam databases, MetaMask eth-phishing-detect and ScamSniffer, which the server downloads to build its lists of scam sites and addresses. No user data is sent to them.
These providers see requests coming from our server, not from your device. If our server is unreachable, the app may contact them directly so that checks keep working. In that case they see your IP address and the request, under their own privacy policies.
Connections to apps and websites
- WalletConnect. When you connect to a dApp, the app talks to it through the WalletConnect network operated by Reown. Messages are end-to-end encrypted. Reown processes connection metadata such as your IP address under its own privacy policy.
- Built-in browser. Websites you open load directly from those websites. They see your IP address and what you do on them.
Purchases
Subscriptions are processed by Apple. The app checks your subscription status with Apple on your device. We do not receive your payment details or your Apple ID.
Notifications
Alerts about your wallets are created on your device during background checks and shown as local notifications. We do not run a push notification service.
What we do not do
We do not sell or share personal data, show ads, use analytics or tracking SDKs, or require an account.
Children
Unhex is not directed to children under 13.
Your choices
You can remove watched wallets and clear your history in the app at any time. Deleting the app removes its data from your device, with one exception: iOS keeps Keychain items, including encrypted wallet keys, after an app is deleted. To erase keys, remove those wallets in the app before deleting it. Because the server does not store personal data, there is nothing on our side to export or delete.
Changes
We will post any changes to this policy on this page and update the effective date.