Last updated: 2026-09-15
Privacy Policy
M5wallet is self-custodial software: the keys that control your assets are created and used on your devices. This policy explains what our services do receive when you use the wallet, why, who else is involved and how long it is kept. It covers the M5wallet browser extension, the desktop and mobile apps, the web app and this website.
M5wallet is published by M5dex DAO LLC, a limited liability company registered in the State of Wyoming, United States.
The English version of this document is the authoritative one. Translations are provided for convenience; if they conflict, the English text governs.
Who is responsible
M5dex DAO LLC, which publishes M5wallet, is the controller for the personal data described in this policy. Because the wallet is self-custodial, the personal data involved is deliberately limited, and the sections below describe all of it.
Key material
How your keys are protected depends on the kind of wallet you use. For a seed phrase or private key wallet, the recovery phrase or key is encrypted on your device with AES-256-GCM, using a key derived from your passcode, and is never sent to us. A hardware wallet keeps its keys on the device. For a wallet created with Google sign-in, the recovery phrase is encrypted on your device and the key that decrypts it is split into two parts: our servers store the encrypted phrase with one part, which is released only after you sign in with Google, and the other part is held on separate PIN-protected servers, also operated for M5wallet, which release it only for your PIN and allow a limited number of attempts. Neither part can decrypt the phrase on its own. In a Fast Vault, our co-signer service stores one key share, encrypted with AES-256-GCM under a vault password that you choose and we do not store; that share cannot sign on its own. In a Secure Vault, both shares are held on your own devices and we hold none, and ceremony traffic passing through our relay is encrypted end to end between the two parties. If you turn on M5wallet Cloud, the items you sync, such as wallet and account names, your address book, watchlist and custom tokens and networks, are encrypted on your device before they are uploaded.
What the services receive
To show balances and history and to send transactions, the wallet sends your blockchain addresses and extended public keys to our wallet service, which looks them up on public blockchain nodes and block explorers, and it sends transactions you have already signed on your device so that they can be broadcast. When you request a swap or bridge quote, the tokens, amounts and addresses involved are sent to our swap service and passed on to the providers that quote the trade. Market pages request prices, charts and token information from our market service. If notifications are registered for your device, our notification service stores your addresses, the networks they belong to, account names, your watchlist and your notification settings, linked to an identifier for your installation. Requests to our services carry that installation identifier together with your language, currency, platform, device name and app version, and, like all web traffic, your IP address, user agent and the time of the request.
Sign-in and M5wallet ID
Signing in is optional. If you sign in with Google, Google returns your email address, name, profile picture and account identifier; our authentication provider, Supabase, stores them, and our servers store your email address and link it to your M5wallet ID and to any wallet you create with Google sign-in. If you sign in with an email code instead, we store your email address and a hashed copy of the code, and send the code through our email provider, SendGrid. While you are signed in, requests to our services can include your sign-in token so that they can be linked to your account. We never receive your Google password.
Referral program
If you take part in the referral program, which the Referral Program Terms govern, we process the following. As an inviter: your referral codes and the notes you add to them, linked to your M5wallet ID, and the receiving address you set for payouts, which you confirm with a one-time code sent to your email address; SendGrid delivers the code, and we keep only a hashed copy of it. For a linked wallet: the wallet address linked to a code, and the message and signature that created the link; the inviter can see the linked address and the rewards it earned them. To apply the linking window, the app reports the address and creation date of each wallet you set up that can be linked, whether or not you use a code. To calculate rewards, our swap service records each swap and bridge it builds on an EVM network for a linked wallet: the network, the sender address, the tokens and amounts, the US dollar value and the fee. When a swap is sent, its transaction hash is checked on the blockchain; a hash that does not belong to a linked wallet's swap is deleted within 7 days, and the tokens and amounts are deleted after 7 days. To detect self-referral and abuse, we keep hashed IP addresses and app installation identifiers for each link and for signed-in visits to the referral pages; they are hashed with a secret salt and never stored in the clear. Payouts are public transactions on BNB Chain. We rely on performance of a contract to run the program for its participants, and on our legitimate interests to apply its rules to wallets and swaps and to prevent abuse.
Websites and decentralised applications
The browser extension runs on the websites you visit so that decentralised applications can detect it, but it does not read or send page content and it does not report the websites you visit. When you connect the wallet to a website, review a request from one, or open a site in the in-app browser, that site's address can be sent to our market service to look up information about the site. Sessions you start through WalletConnect pass through the WalletConnect relay operated by Reown, which carries encrypted messages between the wallet and the application.
Service providers
We rely on other companies to run parts of the service, and each receives only what its part needs: DigitalOcean hosts our servers; Supabase and Google handle sign-in; SendGrid delivers email codes; 0x, 1inch, LI.FI, Jupiter, deBridge and CoW Protocol quote and route swaps, bridges and limit orders; Hyperliquid runs perpetual futures trading, which the wallet connects to directly; Breez provides the infrastructure for Lightning payments; Reown operates the WalletConnect relay; and public blockchain nodes and block explorers answer balance, history and broadcast requests. Staking and lending take place in the Lido and Aave protocols on their blockchains. This website uses ipapi.co, as described below.
This website
To choose an initial language, this site checks for a country header from any content delivery network in front of it, and otherwise performs a geolocation lookup of your IP address using the third-party service ipapi.co. The result is cached by network prefix rather than by full address, and the lookup is skipped entirely once you have chosen a language, because your choice is stored in a NEXT_LOCALE cookie and always takes precedence. That cookie and your light or dark theme preference are the only things this site stores in your browser. There is no advertising or cross-site tracking on this site. Our documentation site, docs.m5wallet.com, sets no cookies and has no analytics; it only remembers your light or dark theme in your browser.
Legal bases for processing
Where the GDPR or UK GDPR applies, we rely on: performance of a contract, for the data required to operate the wallet you asked us to run (blockchain queries, transaction broadcasts, swap quotes, sign-in, notifications and cloud sync); legitimate interests, for keeping the services secure, preventing abuse and diagnosing faults from server logs; and consent, where you have given it, which you may withdraw at any time. We do not rely on consent for anything the wallet needs in order to function.
How long data is kept
Web server request logs, which include IP addresses, are kept for 14 days and then deleted. Your email address, sign-in records and M5wallet ID are kept while your account exists. The encrypted backup of a Google sign-in wallet and its key parts are kept so that you can restore the wallet, until you ask us to delete them. A Fast Vault key share is stored for as long as the vault exists, because deleting it would destroy your ability to sign; it is removed when you delete the vault. Notification subscriptions and M5wallet Cloud data are kept until you remove them or ask us to delete them. Referral program records are kept while the program runs and afterwards for as long as they are needed for payouts, disputes and accounting. We do not build long-term behavioural profiles.
International transfers
Our servers and several of the providers listed above, including Supabase, Google, SendGrid and Reown, may process data outside your country, including in the United States, and the geolocation lookup on this website sends your IP address to a third-party provider that may process it elsewhere. Where such a transfer involves personal data of people in the EEA or UK, it is made on the basis of appropriate safeguards such as the Standard Contractual Clauses.
How data is protected
Traffic to our services is encrypted in transit with TLS. Recovery phrases and private keys stored on your device are encrypted with AES-256-GCM under a key derived from your passcode. The backup of a Google sign-in wallet is encrypted on your device before it is uploaded, and its decryption key is split between two services, one of which requires your PIN. Ceremony messages passing through our relay are encrypted end to end between the two parties, so the relay carries ciphertext it cannot read, and a Fast Vault share at rest is encrypted with AES-256-GCM under your password, which we do not store. Access to production systems is restricted. No system is perfectly secure, and we do not claim otherwise.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent. To exercise any of these, contact us as described below. You also have the right to complain to your local data protection supervisory authority. If you are a California resident, we do not sell or share personal information as those terms are defined by the CCPA and CPRA, and we do not discriminate against you for exercising your rights.
Your choices
Signing in is optional: a seed phrase wallet, a hardware wallet or a Secure Vault works without an account, and none of them places key material with us. You can turn off notifications and M5wallet Cloud, log out of a Google sign-in wallet, and clear this site's cookies at any time. To have data we hold deleted, contact us as described below.
Children
M5wallet is not directed at children and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.
What we do not do
We do not sell personal data or share it for advertising. The wallet contains no advertising networks or cross-site trackers, and the browser extension contains no analytics or crash-reporting service. We do not ask for your recovery phrase, private key, PIN, passcode, Fast Vault password or any share material, and no member of our team will ever request them.
Changes
If this policy changes materially, the date at the top of this page changes with it.
Contact
Questions about this document, or requests concerning your data, can be sent by email to info@m5dex.com. We aim to respond within 30 days.