GaneshaWalletGaneshaWallet

Legal

Privacy Policy

Last Updated: June 18, 2026

This Privacy Policy explains how GaneshaWallet, managed by GaneshaDCERT, collects, uses, stores, and protects your information when you use the GaneshaWallet mobile application. GaneshaWallet is a self-custody digital wallet for holding your Decentralized Identifier (DID) and Verifiable Credentials. By using the app, you agree to the practices described here.

01Information We Collect

We collect: (a) Account data β€” your Decentralized Identifier (DID) and public key; (b) Credential data β€” the Verifiable Credentials and Verifiable Presentations you store, request, or share; (c) Identity verification (eKYC) data β€” your name, ID number, and ID document image, submitted in encrypted form when a credential requires it; (d) Device and usage data β€” app version, device model, push-notification token, and basic diagnostics. We do not collect your seed phrase, PIN, or biometric data.

02Data Stored on Your Device

Your seed phrase, PIN, and biometric settings are generated and stored locally on your device using its secure storage. They are never transmitted to us and we cannot access them. You are solely responsible for safeguarding your seed phrase β€” anyone who has it can access your wallet, and we cannot recover it for you.

03How We Use Your Information

We use your information to: create and manage your DID; deliver, verify, and manage Verifiable Credentials and Presentations; process identity verification (eKYC) when an issuer requires it; send notifications about credential requests and updates; and maintain the security, integrity, and reliability of the service.

04Identity Verification (eKYC)

When a credential issuer requires identity verification, you submit eKYC data β€” your name, ID number, and an ID document image. This data is encrypted on your device (ECIES, P-256) before it is sent and is stored encrypted at rest. The most sensitive items, your ID number and document image, are automatically deleted 24 hours after submission. You can delete your eKYC data at any time from Settings β†’ Identity Verification (eKYC).

05Blockchain Data

GaneshaDCERT records certain data β€” such as DID documents and the issuance or revocation status of Verifiable Credentials β€” on a blockchain to ensure authenticity and tamper-resistance. Blockchain records are immutable by design and cannot be edited or deleted. Personal data is never written to the blockchain in plaintext; on-chain records contain identifiers and cryptographic references only.

06Data Sharing and Disclosure

You control when your credentials are shared: a Verifiable Presentation is created and shared only when you choose to. We do not sell or rent your personal information. We may share data with the credential issuers and verifiers you interact with, with service providers who help operate the service under confidentiality obligations, or when required by law.

07Data Retention

We retain server-side data only as long as necessary to provide the service or as required by law. eKYC sensitive data is purged within 24 hours; other account data is removed when you delete your account, typically within several days. Immutable blockchain records remain permanently but are deactivated when no longer valid.

08Security

We protect your data using encryption in transit and at rest, ECDSA and ECIES (P-256) cryptography, and DID-signature-based authentication. The app also performs device-integrity checks. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

09Your Rights and Choices

Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data, to object to or restrict its processing, and to request data portability. You can manage your credentials and eKYC data in the app at any time.

10Account Deletion

You can delete your account and associated data from within the app or by contacting us. For full instructions and details on what is deleted or retained, see our Account Deletion page.

11Children's Privacy

GaneshaWallet is not intended for use by children under the age required by your jurisdiction. We do not knowingly collect personal data from children.

12Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the app or our website. Your continued use of the service after an update constitutes acceptance of the revised policy.

Contact Us

Questions about this Privacy Policy or your data? info@ganeshait.com

RelatedRead our Account Deletion policy