How the protection is built
Short and without platitudes: what exactly protects the account, where the money sits and what we do not promise.
Sign-in without a password
Sign-in goes through Telegram or Google. The account has no password to lose or guess. The signature on the reply is checked bythe server, not the browser: anything that reached the device could have been forged by anyone.
Both methods can be attached to one account — it is one account with one balance. The last sign-in method cannot be detached: otherwise a person loses access to their own money with nothing left to restore it with.
A passcode
Four digits when the app opens — for the case where the phone ends up unlocked in someone else’s hands. Set and removed in settings.
Where the money is
Most of the crypto is kept in wallets with no permanent network connection. Traffic to the server runs over TLS; a session is time-limited and revoked on sign-out.
What we do not promise
Absolute protection does not exist, and promising it would be dishonest. A blockchain transfer is irreversible: nobody can recover what was sent to a wrong address. If a leak does happen, we will tell the people affected and the supervisory authority within 72 hours of learning about it.
What is up to you
- Protecting the Telegram and Google accounts themselves: whoever gets into them gets into the account too.
- Checking the address and the network before confirming a transfer.
- A second sign-in method attached — so you are never left outside.
What we do with your data — in theprivacy policy.