During an authentication session, the app transmits the following data to the On-Chain-Unlock relay server:
| Data | Purpose | Retention |
|---|---|---|
| Wallet public address | Identity verification against NFT ownership on-chain | Volatile — deleted immediately after device retrieval |
| sr25519 cryptographic signature | Proof of private key ownership for the session nonce | Volatile — deleted immediately after device retrieval |
These values are held in volatile server memory exclusively for the duration of the authentication session and permanently deleted as soon as the access control device retrieves them. They are never written to disk, never logged, and never retained.
The app stores the following data exclusively on your device, encrypted with Argon2id key derivation and libsodium secretbox:
This data is never transmitted to any server. It can be deleted at any time by uninstalling the app or using the in-app reset function.
| Permission | Purpose | Data collected |
|---|---|---|
| Camera | QR code scanning for authentication | None — frames are processed locally and never stored |
| NFC | Tap-to-authenticate via NFC tag | None — tag content is processed locally |
| Biometric | Local vault unlock (fingerprint / face ID) | None — biometric data never leaves the device OS |
NFT ownership queries are made against the public Enjin Matrixchain RPC. Your wallet address may appear in public blockchain records as a result of NFT ownership. This is inherent to public blockchain infrastructure and is not controlled by On-Chain-Unlock.
OCU KeyStore is not directed at children under 13. We do not knowingly collect any data from minors.
We may update this Privacy Policy at any time. The latest version is always available at this URL. Continued use of the app after changes constitutes acceptance.
On-Chain-Unlock
[email protected]