← alcove

Privacy Policy

Applies to: aleolabs.io, alcovewallet.com, and the Alcove Wallet application (the "Services"), and, as described in Section 6, Aleo Labs' public source-code repositories.

Provider / controller: Aleo Labs Operations LLC, 1604 Philadelphia Pike, Suite 302, Wilmington, DE 19809, USA ("Aleo Labs").

Effective date: August 1, 2026

1. Introduction

This Policy explains how Aleo Labs ("we," "us," "our") handles information for our websites (aleolabs.io, alcovewallet.com), the Alcove Wallet app, and our public source-code repositories. We aim to collect as little personal information as possible and to be transparent about the limited data involved. By using the Services, you acknowledge these practices.

2. Who we are and how to contact us

Aleo Labs Operations LLC is the controller. Contact: privacy@aleolabs.io.

3. Our approach to data

We design to minimize personal information. Where a feature can work without collecting it, we build it that way. Where third parties are involved, we prefer configurations that reduce or avoid personal-information collection.

4. Our websites

The only cookies are Cloudflare strictly-necessary and functional cookies, used for bot detection, security challenges, rate limiting, and load balancing. Examples: __cf_bm, cf_clearance, __cfruid, _cfuvid, __cflb. They are not used to track you or build a profile.

Mailing-list signup is processed server-side. Your email is relayed to Mailchimp from our server, so no Mailchimp scripts or cookies load in your browser.

Because only strictly-necessary cookies are used, a consent banner is generally not required. This notice is for transparency.

Each provider maintains its own terms and privacy policy. Contact the provider to review those documents.

5. The Alcove Wallet application

5.1 Non-custodial by design

Only you can access your wallet. If you lose your private key and have not backed it up, it is lost forever. You are responsible for safeguarding your key, and for keeping your own exported copy of it before moving to a new device. Aleo Labs cannot access, transfer, freeze, or recover your key or funds.

Alcove cannot currently import a private key. An exported key lets you reach your Digital Assets in another compatible Aleo wallet; it is not a way to restore your Alcove installation. Note also that Aleo Labs' inability to freeze does not mean that no one can. See Section 8 and Terms Sections 6 and 7.

5.2 Analytics (TelemetryDeck GmbH)

A privacy-focused service. It may collect:

TelemetryDeck stores no IP addresses, uses no cookies or tracking, and is designed so that signals cannot be traced back to an individual. We do not attempt to identify anyone from it, we do not believe we could do so if we tried, and we do not place personal information in the metadata we define.

TelemetryDeck represents that its service does not collect or generate personal data under the GDPR. We apply a legal basis to this processing regardless, as a precaution (Section 9). Documentation of how the anonymization works is published by TelemetryDeck.

5.3 Backup server (convenience features)

Provides key backup, contact syncing, transaction-history syncing, and multi-device support. All are for convenience and should not be solely relied upon. You remain responsible for backing up your data.

We do not track "last login," and we cannot derive contents, contacts, or transactions from this metadata, because the backups are end-to-end encrypted.

Account and authentication. To secure and identify your backup, we hold a pseudonymous account identifier and your passkey credential, used to authenticate you. These are not linked to your identity or to your wallet key, and we cannot use them to determine who you are or your on-chain activity.

Your passkey is required to reach your backup, and the backup code is not an alternative to it. Using your backup on a new device requires that passkey to be available there.

Whether your passkey moves to a new device depends on how you store it. Passkeys held by a platform or a password manager are commonly synchronized across your devices. Passkeys held on a hardware security key, and some created by a platform authenticator, are device-bound and are not backed up or synchronized. Whether your passkey synchronizes is not something we provide or control.

If you lose both your passkey and your backup code, we cannot restore your backup. The backup is encrypted with a key only you hold, so we cannot read it, and your passkey is the only way to authenticate you to it. This is a consequence of the design: it is what allows the backup to exist without us being able to read what is in it.

5.4 USDCx

The wallet supports USDCx, a private stablecoin on Aleo backed 1:1 by USDC held in xReserve contracts. Aleo Labs does not issue, deploy, operate, or control USDCx. Privacy features apply only while an asset is on Aleo; bridging elsewhere removes them. USDCx accounts have view keys and USDCx addresses are subject to freezing, both held and exercised by third parties. See Section 8.

5.5 Third-party services

The wallet uses the third-party services below. We do not control them, and each handles information under its own terms and privacy policy. Contact the provider to review those documents. Use is at your own risk.

Provable Inc. The wallet uses two Provable services.

Provable has stated that both services run inside trusted execution environments, with the encrypted connection terminating inside the enclave, so that Provable itself cannot observe what is sent. Aleo Labs cannot verify this and does not guarantee it. Connection metadata, such as your IP address and the timing and size of requests, is visible to the operators of these endpoints regardless.

Aleo Network Foundation, Fee Master. A publicly accessible service that can sponsor or pay network fees. It receives an encrypted transaction and a fee amount. It receives no keys, and does not see the sender, the receiver, or the amount.

Circle. Circle Internet Group and subsidiaries, including Circle Internet Financial, Circle Technology Services, and Arc Network Services. Comprising xReserve, the non-custodial infrastructure holding the USDC that backs USDCx; CCTP, for cross-chain USDC transfers; and Arc, Circle's stablecoin network.

NEAR Intents ("Intents Technology"). A permissionless swap path.

Aleo Protocol. The public, open-source Aleo blockchain. Decentralized software, with no separate consumer terms or privacy policy. Data written to a public blockchain is outside our control and generally cannot be changed or deleted.

6. Public source-code repositories and contributors

This Section applies to public source-code repositories operated by Aleo Labs, for example on GitHub. It does not apply to the source code itself, which processes no personal information, and it does not make those repositories part of the Services.

What we receive. If you interact with a repository by filing an issue, opening or reviewing a pull request, commenting, or contributing code, we receive the information your code-hosting account transmits:

Legal basis. Legitimate interests (Art. 6(1)(f) GDPR / UK GDPR) in developing, maintaining, and supporting our software in public.

The hosting platform is an independent controller. GitHub, or any other platform we use, processes your information under its own privacy policy and terms, which we do not control. Your account, profile, and email-privacy settings are managed there, not with us.

Public and effectively permanent. Contributions and commit history are public and, once published, effectively permanent. Anyone may clone a repository, and an author name or email address in a published commit cannot be removed from copies already distributed. We therefore cannot guarantee deletion or correction of information contained in published commit history or public discussion threads, in the same way that data written to a public blockchain is outside our control (Section 5.5).

If you do not wish your email address to be public, configure a no-reply or dedicated address in your version-control settings before contributing.

Retention. Repository history is retained indefinitely as part of the project record.

7. Legitimate use, sanctions, and export compliance

The Services are for end users with a legitimate need for privacy or confidentiality, and any illegal or illicit use is strictly prohibited. Use of the Services is also restricted under U.S. sanctions and export-control law, including OFAC.

The restricted persons, restricted jurisdictions, and representations that apply are set out in Section 10 of the Terms of Service, which is the authoritative statement of those requirements. They are not restated here so that a single list governs. We may block or refuse access to our websites and to the backup and convenience features where use would violate them.

8. USDCx: view keys, freezing, and lawful process

About view keys. A USDCx account has a view key, a credential that lets whoever holds it see (decrypt and read) the records, balances, and activity associated with that account, but not move funds.

Aleo Labs does not hold or use a view key and does not read your activity on the servers it operates. Section 5.5 describes the one case in which the wallet shares your view key with a third-party service.

USDCx is private, but that privacy is not absolute:

Both capabilities are exercised under arrangements that Aleo Labs is not party to, has no visibility into, and cannot control, limit, or verify. Aleo Labs is not entitled to notice when either is exercised, and cannot prevent, reverse, or appeal a freeze. Terms Section 6 describes the resulting risk, and Terms Section 8.6 describes the capabilities.

Aleo Labs supports efforts to stop and identify those who abuse the Services, and will cooperate with regulators and law enforcement where we believe in good faith that it is legally required or necessary to prevent harm or unlawful activity.

9. Legal bases (EEA/UK)

Where the GDPR / UK GDPR applies:

Processing carried out by the third parties described in Sections 5.5 and 8 is not carried out by Aleo Labs and is not covered by these legal bases.

Withdraw consent or object to legitimate-interests processing as in Section 13.

10. Data retention

We keep personal information only as long as necessary or as required by law. In practice:

11. Where we process information

Aleo Labs is based in the United States and processes personal information there. Some providers we use process information elsewhere, including at locations outside the United States, under their own terms and transfer arrangements. Where we transfer personal information out of the EEA or the UK and a transfer mechanism is required, we will implement an appropriate one and update this Policy.

12. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing, and to withdraw consent. EEA and UK residents may complain to their supervisory authority. California and other U.S. state residents may have rights to know, access, delete, and correct, and to opt out of "sale" or "sharing." We do not sell your personal information. Because we minimize data, we may hold little or none about you, and where information is irreversibly anonymized or end-to-end encrypted we may be unable to identify it to you.

These rights operate against Aleo Labs. They do not reach information held or processed by the third parties described in Sections 5.5 and 8, over whom we have no control.

13. Exercising rights; account and data deletion

To request a copy of your information, delete your account and information, or exercise other rights, contact privacy@aleolabs.io. We may need information from you to locate your data, since we cannot identify it from your name or email address alone. Deletion is subject to the exceptions in Section 10. Requests concerning information published in our public source-code repositories are subject to the practical limits described in Section 6.

14. Children's privacy

The Services are not directed to, or intended for, children under 18. We do not knowingly collect their personal information. If you believe a child provided information, contact us and we will delete it.

15. Security

We use technical and organizational measures, including encryption in transit and end-to-end encryption of key backups. No method is completely secure. You are responsible for safeguarding your private key and device.

16. Changes

We may update this Policy. The current version is available on our websites, linked from within the app, and shows its effective date. For material changes we will revise the effective date, and your continued use after that date constitutes acceptance.

17. Contact

Questions: privacy@aleolabs.io.