Skip to content

Legal

Privacy Policy

Last updated Morsel Labs LLC

Morsel is a self-custody wallet, built to need as little of your data as possible. You do not create an account or give us your name or email to use it. This policy explains the limited data that does reach us, and what happens to it.

On this page
  1. 1Who we are and what this policy covers
  2. 2What we never collect
  3. 3What we collect and why
  4. 4Legal bases (EEA and UK)
  5. 5How we share data
  6. 6International transfers
  7. 7How long we keep data
  8. 8Security
  9. 9Your choices
  10. 10Your rights
  11. 11United States privacy rights
  12. 12Children
  13. 13Changes to this policy
  14. 14Contact

1Who we are and what this policy covers#

Morsel Labs LLC ("Morsel", "we", "us" or "our"), 30 N Gould St, Ste R, Sheridan, WY 82801, United States, is responsible for the personal data described in this policy. Under the EU and UK General Data Protection Regulation ("GDPR") we are the controller of that data.

This policy covers Morsel Wallet for iOS, Android and Chrome (the "App"), our websites at morselwallet.app and its subdomains, the Morsel connect kit, and the infrastructure we operate for them, such as our API, RPC, relay and notification services at api.dumpsack.xyz, rpc.dumpsack.xyz and wss.dumpsack.xyz (together, the "Services"). It does not cover dApps, websites, protocols or other services run by others, even if you reach them through the App. They have their own privacy policies. Our Third-party services page lists the main ones.

Words like "Services" have the same meaning as in our Terms of Service.

2What we never collect#

  • Your recovery phrase, private keys and wallet password. They are created and stored on your device, encrypted, and are not sent to us. (If you created a cloud account in an earlier version of the App, an encrypted backup of your wallets is stored with us until that service is retired. We cannot decrypt it; see Section 3.14.)
  • The content of your chats. Messages are encrypted on your device before they are sent. We only ever handle the encrypted form. (The exception is when you report a wallet and choose to share its recent messages with us; see Section 3.6.)
  • Your voice. Voice search uses your device's or browser's speech recognition. Morsel never receives audio, and the words you say are matched to screens inside the App.
  • Your name, email address or phone number to use the App. There is no sign-up. You only give us contact details if you contact support.
  • Precise location, your contacts or your photos. The App does not ask for these permissions.
  • Advertising identifiers. The App contains no advertising or cross-app tracking software, and does not use your device's advertising ID.

3What we collect and why#

3.1Wallet addresses and blockchain data#

Wallet addresses and transactions on Cookie Chain and Solana are public. Anyone can see them, and nobody, including us, can delete them from a blockchain.

To show you your balances, tokens, positions, collectibles, prices and activity, the App sends the public addresses of the wallets in it, and of any wallet you choose to view, to Morsel Infrastructure and to the blockchain data providers listed on our Third-party services page. When you swap, bridge, stake, send, place a limit order or use another feature, the App also sends the details needed to quote and build that transaction, such as the tokens, amounts and network. Our servers relay the transactions you sign to the network.

We use this data to provide the features you ask for. We keep cached copies of public blockchain data, such as balances and transaction history, to make the App fast.

Some of these requests go to other services. To show your DeFi positions, our servers send your wallet address to the protocols involved, such as Raydium, Meteora and Kamino. To show prices, the App asks CoinGecko for the prices of the tokens you hold, which tells CoinGecko which tokens they are (but not your wallet address) and your IP address. Solana balances and transactions go through our Solana data provider, Helius.

We also keep some records tied to wallet addresses so the App works well: an index of activity for Cookie Chain wallets that use the App, and records of bridge transfers and stake accounts made through it. These describe public blockchain activity.

3.2Technical data and server logs#

When the App or our websites talk to our servers, our hosting provider's network and our servers receive your IP address. We use it to keep the Services secure and to prevent abuse, for example by limiting how many requests one IP address can make in a short time. Those counters expire within an hour.

Our servers also log each request they handle: the time, the address requested, the response and how long it took. The address requested can include details from the request itself, such as a wallet address or a search term. We use these logs to run the Services, investigate problems and keep them secure. Our hosting provider also keeps network logs for its own operation and security.

3.3Crash and error reports#

When the App hits an error, it sends a crash report to our error-monitoring provider, Sentry, so we can find and fix bugs. A report includes technical details such as the error, the screen you were on, your platform, device type, screen size and app version, and a short trail of recent app events. Before a report leaves your device, the App strips out anything that looks like a wallet address, key, recovery phrase, email address, IP address or access token, and it leaves out requests related to Private Route and transfer tracking. Sentry receives your IP address when a report is sent, and stores our reports in the European Union.

3.4Notifications#

If you allow notifications, the App registers your device with our notification service. It sends:

  • a push token from Apple or Google, which lets us address notifications to your device;
  • a random identifier the App creates for your device;
  • the wallet addresses you have used on that device;
  • your platform, app version, language, time zone, the networks you use and the currency you display;
  • the notification types you have turned on and their settings; and
  • a signature from your wallet proving you control the address.

We keep the push token linked to the wallets it was registered for, with your platform and the notification features your App supports, for 90 days after the App last registers it. We also keep your notification settings and any price alerts you create for each wallet. We use this data to send the notifications you choose, for example when you receive a payment, when a swap, bridge, limit order or recurring send completes, when a price alert triggers or when a chat message arrives; to send them in your language and currency; and to avoid sending market and promotional notifications at night in your time zone. We may also send service messages about the App. The App shows your recent notifications in an in-app list, which we keep for up to 90 days.

To notify you about incoming payments on Solana, we add your Solana wallet address to the list of addresses our Solana data provider, Helius, watches for us.

Promotional notifications, such as offers and news about new features, are sent only if you opt in. They are off until you do, and you can turn them off at any time in Settings, Notifications.

Notifications are delivered through Google's Firebase Cloud Messaging and, on iPhone, Apple Push Notification service. Chat notifications for conversations you have accepted carry the message in encrypted form: your device decrypts it to show a preview, and you can turn previews off with "Show message text" in Settings, Notifications. Notifications about new message requests show a shortened version of the sender's wallet address.

If you use Live Activities for a position on iOS, the App sends the wallet, network, token and entry amounts of that position, a code derived from your push token, and Live Activity tokens from Apple, so we can update it on your lock screen. We delete a Live Activity session an hour after it ends, and keep the token that lets us start one for up to 90 days.

3.5Swaps, limit orders, recurring sends, bridging and staking#

These features run on public blockchains and smart contracts, so most of the data involved becomes public when you use them. In addition:

  • Quotes and transactions. To quote a swap or bridge or build a transaction, the App sends your wallet address, the tokens and the amounts to Morsel Infrastructure, which passes them to the venues that provide quotes and build transactions, such as CookieBox and CookieScan on Cookie Chain, and Jupiter and Raptor (by Solana Tracker) on Solana. The App contacts Jupiter directly for token search and Solana limit orders. Signed Solana swaps may also be sent through Jito to reach validators faster.
  • Recurring sends. We keep a record of each recurring send you set up (your address, the recipient, the amount, the schedule and its payments) so our executor can carry it out and the App can show its history.
  • Tracking completion. When you place a limit order, bridge or send a private payment, the App may ask us to watch for its completion so we can notify you. We keep that request until the transfer completes or expires.

3.6Chats#

Chats are end-to-end encrypted between wallets, with keys derived from each wallet's own keys. To deliver them, our servers store:

  • the encrypted messages and reactions, with messages padded to standard sizes so their length reveals little;
  • metadata we can see: the wallet addresses in each conversation, when each message was sent, whether a conversation is a request, accepted or blocked, how far each side has read, unread counts, and markers for messages that were unsent; and
  • settings you choose, such as disappearing-message timers, where offered.

We keep chat history so it can follow your recovery phrase to a new device. It stays until it is deleted. Where offered in the App, you can delete messages for yourself, delete a chat, turn on disappearing messages and erase your chat data. Erasing your chat data deletes the messages you sent and received, your conversations and the reports you made or that were made about you. Deleting a chat for yourself does not delete the other person's copy.

Reports. If you report a wallet, we receive your wallet address, the reported wallet's address, the reason you choose and identifiers of its most recent messages to you. If you choose to, you can also include the text of those messages (up to its last five), which your device decrypts and sends to us with the report. Nothing else from the conversation leaves your device. Reporting also blocks the other wallet. We use reports to keep chats safe, for example by limiting a wallet's access to chats.

GIFs. When you search for a GIF, the App sends your search words to our servers, which fetch results from GIPHY. GIPHY receives the search words from our servers, not from your device, and our request logs record them. GIF images themselves load directly from GIPHY's servers, which see your IP address.

The App also keeps a copy of your chats on your device, encrypted with a key derived from your wallet, so they open quickly.

3.7Private Route#

To carry out a Private Route payment, we keep an order record with the recipient's address, the amount and fee, the refund address you chose, the one-time deposit address, the transactions involved and the order's status. We use it only to deliver, refund and account for your payment, and to meet our legal obligations. We delete the record once the payment has been delivered or refunded and the deposit address has been emptied, at least an hour after the order completes and normally within a few hours. An order that needs a person to resolve it is kept until it is resolved. We also keep a small integrity marker for each order so records cannot be tampered with; once the order is finished, the marker no longer identifies it. The deposits and payouts themselves are public on Cookie Chain.

3.8dApp browser, connect kit and WalletConnect#

  • Browsing history, bookmarks and connected sites stay on your device.
  • Phishing checks run on your device against a list the App downloads from us. We do not receive the sites you visit for this.
  • Site icons. To show the icon of a site you visit or that is listed in the App, the App may request it from Google's or DuckDuckGo's favicon services, or from the site itself, which tells that service the site's domain and your IP address.
  • Search. If you type something in the browser's address bar that is not a web address, the App sends it to Google Search.
  • Transaction previews. To simulate a transaction before you sign it, the App sends the transaction to Morsel Infrastructure. It does not send the address of the site that asked for it.
  • Reporting a site. If you report a site, we receive its domain, the reason and any message you add.
  • Connect kit. When you connect to a dApp by scanning a Morsel QR code, the dApp and the App exchange messages through our relay. The messages are end-to-end encrypted. The relay forwards them without reading them, keeps each session only in memory, drops it after 24 hours without activity, and does not store messages. Our request logs record the session's random identifier.
  • WalletConnect. If you connect to a dApp through WalletConnect, messages pass through WalletConnect's relay network, operated by Reown.

3.9Voice search#

When you use voice search, the App asks your device or browser to turn speech into text: Apple's speech recognition on iOS, Google's on Android, and your browser's (Google's, in Chrome) in the extension. These providers may process the audio on their servers under their own privacy policies. The App matches the text to screens on your device. Morsel does not receive the audio or the text, unless you then search for something, in which case the search works like typed search. Voice search needs your permission to use the microphone, and you can turn that off in your device settings.

3.10Images and media#

Token logos, collectible images and other media come from many sources, such as IPFS and Arweave gateways and project websites. To protect your privacy and speed things up, the App loads many of them through our image proxy, so the source sees our server instead of you. Some images, GIFs and logos load directly from their host or a content delivery network, which then sees your IP address.

3.11Support#

If you contact support, through the form on support.morselwallet.app or by email, we receive your name, email address, the subject and message, any images you attach, and your IP address, which we use to limit how many requests can be sent. Attachments are stored as you upload them, including any information embedded in the file, such as the location in a photo's metadata, so remove anything you do not want to share first. We use this to answer you and keep a record of the request. We send email through our email providers. Only Morsel team members who handle support can see tickets.

3.12Our websites#

Our websites do not use analytics, advertising or tracking tools, and they do not set cookies. Our hosting provider receives your IP address and request details to serve the pages. Some pages load fonts or images from other servers, which then see your IP address. If you vote on whether a help article was useful, we record only the article and your vote, and use your IP address briefly to limit repeat votes.

3.13Rewards#

If you claim a reward such as the Morsel Genesis Pass, we record the wallet address that claimed it and the IP address it was claimed from, to enforce limits such as one claim per person.

3.14Legacy cloud accounts#

Earlier versions of the App offered an optional cloud account and backup. We are retiring it. New accounts cannot be created, and updated versions of the App stop uploading backups and sign out of cloud accounts.

If you created a cloud account, we still hold, until the retirement is complete, your email address, the sign-in method you used (email and password, Google or Apple, with any password stored only as a secure hash), a list of your signed-in devices with when each was last seen, your token watchlist, and encrypted backups of your wallets and App preferences. The backups were encrypted on your device with your wallet password before upload, and we cannot decrypt them. We will delete these accounts and backups at the end of a notice period. To have yours deleted sooner, contact legal@morselwallet.app.

Your wallets do not depend on the cloud backup: your recovery phrase restores them in the App at any time.

If you are in the European Economic Area or the United Kingdom, we rely on these legal bases:

PurposeDataLegal basis
Providing the App's features (balances, activity, swaps, bridging, staking, recurring sends, Private Route, chats, connect relay)Wallet addresses, transaction details, encrypted messages and chat metadata, order recordsPerformance of a contract with you (Art. 6(1)(b))
Sending the notifications you turn onPush token, device identifier, wallet addresses, settings, time zone, languageYour consent, given through your device's notification permission and the App's settings (Art. 6(1)(a)), and performance of a contract (Art. 6(1)(b))
Promotional notificationsPush token, settingsYour consent (Art. 6(1)(a)), which you can withdraw at any time
Security, abuse prevention and keeping the Services runningIP addresses, server logs, rate-limit dataOur legitimate interests in operating safe and reliable services (Art. 6(1)(f))
Fixing bugsCrash and error reportsOur legitimate interests in a working App (Art. 6(1)(f))
Reviewing chat reportsReport details and, with your consent, recent messagesYour consent for the messages you share (Art. 6(1)(a)), and our legitimate interests in keeping chats safe (Art. 6(1)(f))
Answering support requestsName, email, message, attachmentsPerformance of a contract or steps you ask for (Art. 6(1)(b)), and our legitimate interests (Art. 6(1)(f))
Rewards and their limitsWallet address, IP addressOur legitimate interests in preventing abuse of free rewards (Art. 6(1)(f))
Legacy cloud accounts and backups, until they are deletedEmail, sign-in details, device list, encrypted backupsPerformance of a contract with you (Art. 6(1)(b))
Complying with sanctions and other laws, and responding to lawful requestsAny of the above, as neededLegal obligation (Art. 6(1)(c)) and our legitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, you can object, as described in Section 10.

5How we share data#

We do not sell personal data, and we do not share it with advertisers or data brokers. We share it only as follows:

  • Service providers that process data for us under contract, such as our hosting, error-monitoring, email and notification providers. They may use it only to provide their services to us.
  • Third parties you choose to interact with, such as blockchains, swap venues, bridges, validators, dApps and the other side of a chat or payment. They receive what is needed to carry out what you ask, and handle it under their own policies.
  • Data providers that the App or our servers query for blockchain data, prices, token information and media. They see the addresses, tokens or content requested and, when contacted directly by the App, your IP address.
  • Legal and safety. We may disclose data if we believe in good faith it is required by law, regulation or legal process, or needed to protect the rights, property or safety of Morsel, our users or others, including to prevent fraud or comply with sanctions.
  • Business transfers. If Morsel is involved in a merger, acquisition, financing or sale of assets, data may transfer to the new owner under this policy.

Our Third-party services page lists every provider involved, what it does and what data it handles.

6International transfers#

Morsel is based in the United States, and our providers process data in the United States, the European Union and other countries. These countries may have different data protection laws from yours. When we transfer personal data from the EEA, the UK or Switzerland to a country without an adequacy decision, we use safeguards recognized by law, such as the European Commission's Standard Contractual Clauses and the UK's International Data Transfer Addendum, or rely on a provider's certification under the EU-US Data Privacy Framework where it has one.

7How long we keep data#

We keep personal data only as long as we need it for the purposes in this policy, then delete or anonymize it.

DataHow long we keep it
Recovery phrase, private keys, wallet passwordNever received
Server request logsKept by our hosting provider for a limited period, up to 30 days
Rate-limit countersUp to one hour
Crash and error reportsUp to 90 days
Push token and the wallets it is registered for90 days after the App last registers it, or until you turn notifications off for that wallet or the token stops working, if sooner
Notification settings and price alertsWhile you use notifications for that wallet; delete an alert in the App at any time, or ask us to delete your settings
Notification list in the AppUp to 90 days (the most recent 50)
Completion watches for transfersUntil the transfer completes, and at most 3 hours (bridges and private payments) to 30 days (limit orders)
Live ActivitiesSession data until an hour after the Live Activity ends; the token that starts one, up to 90 days
Solana addresses on the payment watch listWhile the address is registered for notifications; addresses can remain on the list after that, and we remove them on request
Encrypted chat messages, reactions and chat metadataUntil they are deleted. Where offered in the App: messages set to disappear are deleted when their timer runs out, erasing your chat data deletes them at once, and the markers left by deleted or unsent messages are purged within 30 days
Chat reportsAs long as needed to review and act on them, unless erased with your chat data
Connect relay sessionsIn memory only: 5 minutes if the dApp and the App never pair, then until the session has been idle for 24 hours
Private Route order recordsDeleted at least an hour after the order completes and normally within a few hours; orders that need a person to resolve them are kept until resolved
Recurring send recordsWhile the order exists, and afterward as the record of its payments
Support requests and attachmentsAs long as needed to help you and keep a record of our support; we delete them on request unless we must keep them
Reward claims (wallet and IP address)As long as the reward's limits apply
Cached and indexed public blockchain dataRefreshed or discarded as the data changes
Legacy cloud account and backupsDeleted at the end of the retirement notice period, or sooner on request

We may keep data longer where the law requires it, or to establish or defend legal claims.

8Security#

We protect personal data with measures appropriate to the risk, including encryption in transit, encryption of your wallet data on your device, end-to-end encryption of chats and of the connect relay, access controls on our systems, and data minimization. No system is perfectly secure, and keeping your device and recovery phrase safe is up to you. If you find a vulnerability, please report it as described on our Security page.

9Your choices#

  • Notifications: choose which notifications you get, including promotional ones, in Settings, Notifications, or turn them off in your device settings.
  • Message previews: turn off "Show message text" to stop the App from keeping chat keys for notification previews.
  • Chats: where offered in the App, delete messages for yourself, delete chats, set disappearing messages, block wallets and erase your chat data.
  • Permissions: allow or revoke access to the camera, microphone, speech recognition, notifications and biometrics in your device settings.
  • Remove a wallet: removing a wallet deletes it from your device, but not from the blockchain. To stop its notifications straight away, turn them off before you remove it; otherwise its registration expires within 90 days. Removing every wallet from the App unregisters the device.

10Your rights#

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to our use of it, receive a copy in a portable format, and withdraw consent at any time (without affecting what we did before you withdrew it).

To exercise a right, email legal@morselwallet.app. Because we do not have accounts, we usually know you only by a wallet address, so we may ask you to prove you control that address, for example by signing a short message we give you. We never need your recovery phrase or private key to do this. We will respond within the time the law requires, normally within one month.

Some data cannot be changed or deleted: anything recorded on a public blockchain is permanent, and data held by third parties you used is governed by their policies.

If you are in the EEA or the UK and are not satisfied with our response, you can complain to your local data protection authority, such as the authority in your EU member state or the UK Information Commissioner's Office.

11United States privacy rights#

If you live in California or another US state with a consumer privacy law, you have additional rights.

Categories of personal information. In the last 12 months we have collected:

CategoryExamplesSourcePurposeDisclosed to
IdentifiersWallet addresses, IP address, push token, random device identifier; name and email if you contact supportYou and your deviceProviding the Services, notifications, security, supportService providers; third parties you interact with
Commercial informationRecords of transactions made through features we operate, such as Private Route and recurring sendsYou and public blockchainsProviding the ServicesService providers
Internet or network activityServer logs, crash reportsYour deviceSecurity, reliability, fixing bugsService providers
CommunicationsChat metadata; recent messages you choose to include in a reportYouDelivering chats; reviewing reportsService providers
Customer recordsName, email and messages in support requestsYouSupportService providers
Sensitive personal informationSign-in details of legacy cloud accounts; message text you choose to include in a chat reportYouLegacy accounts; reviewing reportsService providers

We do not collect precise geolocation, biometric information (Face ID and fingerprint checks happen on your device, and we never receive them), or audio. Your time zone and IP address may indicate your general location.

No sale or sharing. We do not sell personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined in the California Consumer Privacy Act. We have not done so in the last 12 months, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. We do not use or disclose sensitive personal information for purposes that would give you a right to limit it. Because we do not sell or share, there is nothing to opt out of, and we treat Global Privacy Control signals accordingly.

Your rights. You may ask to know what personal information we collect, use and disclose, and ask us to delete or correct it. Email legal@morselwallet.app. You may use an authorized agent, who must show us your written permission. We will verify requests as described in Section 10, and we will not discriminate against you for exercising your rights. If we decline your request, you may appeal by replying to our decision, and if you are still not satisfied, you may contact your state attorney general.

12Children#

The Services are not for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, contact legal@morselwallet.app and we will delete it.

13Changes to this policy#

We may update this policy from time to time. We will change the "Last updated" date at the top and, for material changes, tell you in the App or on our website before they take effect.

14Contact#

Morsel Labs LLC
30 N Gould St, Ste R
Sheridan, WY 82801
United States

Privacy questions and requests: legal@morselwallet.app
Help with the App: support@morselwallet.app