Coming soon
English (UK)

Privacy policy

This version applies from 7 October 2026 to this website and to the support email address. What it says about the app and the Lightning address service describes the version going to the app stores, still under legal review, and may change before the app reaches them. When it changes, this date changes with it.

This policy covers the Voltz Wallet app and this website. It says what each one keeps, who receives it and why, and how to have it deleted.

To have your data deleted, see Deleting your data from Voltz Wallet.

In short

  • The app asks for no name, email address, phone number or document, and there is no account to create.
  • Your recovery words and your private keys stay on your phone and are never sent to Voltz or to anyone else.
  • Voltz never holds your money and never sees your balance.
  • The one service Voltz runs answers for your Lightning address, and everything it keeps is listed below.
  • This website sets no cookies and tracks no one.

Who is responsible

The controller of the personal data this policy describes is Bitwright. For anything about your data, write to support@usevoltz.app.

What stays on your phone

Your recovery words, the optional passphrase and your PIN are kept encrypted on the phone, protected by the Keychain on iPhone and by the Keystore on Android, and are never sent to Voltz or to any server.

The Breez SDK Spark, the wallet engine inside the app, keeps the wallet's own data on the phone, such as its payment history, and keeps it in step through Breez's sync server.

Wallet names and photos, the contacts you save and your settings stay on the phone. Contacts also pass through Breez's sync server, encrypted with a key only your wallet holds. The camera only reads QR codes, and a photo you pick for a wallet is made smaller and kept on the phone.

Face ID and fingerprints are checked by the phone itself, and the app learns only whether the check passed.

On Android, the app keeps its data out of the phone's cloud backup. On iPhone, a backup of the phone can include the app's data, such as wallet names and payment history, but the recovery words and the PIN come back only on the same phone.

Removing a wallet in the app deletes its recovery words, its passphrase and its photo from the phone. Its name, its payment history and its contacts stay in the app's storage.

The Lightning address service

The app gives each wallet a generated Lightning address, made of two English words and two digits, the first time you open Receive or the Lightning address screen, and you can replace it with a chosen name, such as yourname@usevoltz.app, which is paid for. The one service Voltz runs answers for it. It is made of the Breez LNURL server, run unmodified, a gateway of Voltz's own and the wallet that collects what you pay Voltz, and it runs on servers Voltz rents from Hetzner, reached through Cloudflare.

It never receives your recovery words or your private keys, so it cannot spend, freeze or seize your balance. It knows your wallet by its public identity key and by the name on your address, and it sees the IP address each request comes from, which it uses to limit abuse. Of your payments it sees only those made to your address and those you make to Voltz for a name or a domain.

Your address

The service keeps the name, its domain and the public key of the wallet it belongs to. A name you remove or replace stays on record as reserved for your wallet, with the time you let it go, so nobody else can take it.

It keeps these with no set expiry.

Changes to your address

It keeps the first name each wallet received and every later change, with the new name and when it happened, so it can tell a first address from a change and limit how often an address changes.

It keeps these with no set expiry.

Payments to your address

For each payment made to your address, it keeps the amount, the time, the payment's reference and the comment the payer attached, if any, and uses them to tell your phone that a payment arrived.

The gateway erases the comment after 180 days and keeps the rest with no set expiry. The LNURL server keeps its own record of each payment request, comment included, with no set expiry.

Notifications

On Android, the app registers your phone with the service once notifications are allowed, which on Android 12 and earlier is from installation. It sends a Firebase token for the app on that phone, your wallet's public identity key, the platform, the app's language and the wording of its notifications in that language.

The service keeps these until Firebase reports, on a notification it tries to send, that the token no longer reaches the phone. If nothing is sent after the app is removed, they stay.

A domain of your own

If you connect a domain you own, the service keeps the domain, the wallet that owns it, the wallets you allow to use it, and the year paid for it with its end date. Cloudflare receives the domain's name to issue its certificate.

It keeps these with no set expiry.

Purchases

When you start buying a name or a year of your domain, the service keeps what is being bought, the wallet key it is for, the amount and the invoice, paid or not, and when it was paid. The invoice comes from Voltz's own wallet and names what it pays for, and that wallet's records keep it too.

It keeps these with no set expiry.

If you pay a Lightning address the service answers for, the service sees the amount, the time and any comment you attach, and Cloudflare sees the IP address your wallet connects from.

The service's databases are backed up. Data deleted from the service stays in the copies made before the deletion until those copies are discarded.

Requests to the service travel over HTTPS as far as Cloudflare, which carries them to Voltz's servers through a tunnel. There a request reaches only the gateway or the LNURL server, and the wallet that collects what you pay Voltz answers the gateway alone. When a request fails, the gateway logs the error and, for a refused purchase or a problem with a domain, the payment's reference or the domain too, so Voltz can find the case.

Who else receives data

These providers receive data from the app, from the Lightning address service or from this site, each for the reason given. Voltz asks those that process data on its behalf to protect that data at least as well as this policy does, while those you deal with directly, such as MoonPay when you buy bitcoin, the network that carries a payment and the server of an address you pay, follow their own policies. Voltz sells no data and shows no ads.

Breez

Makes the Breez SDK Spark, the wallet engine inside the app, and runs the services the SDK reaches, including the real-time sync server it uses by default.

What it receives
Requests from the SDK, identified by the app's API key for Breez's services, and the wallet data the SDK keeps in step through the sync server, encrypted on the phone.
Why
The SDK needs these services to send, receive and keep the wallet up to date.

Spark operators and the Spark service provider

Run the Spark network that holds the wallet's balance, and the service provider that carries its Lightning and on-chain Bitcoin payments.

What it receives
The wallet's public keys and the payments it sends and receives.
Why
Balance, sync and payments come from the Spark operators, and Lightning and on-chain payments go through the service provider.

Flashnet

Runs the pools that convert between bitcoin and tokens such as USDB, and pays the USDB rewards.

What it receives
Each conversion the person makes, and, to read the reward balance, the wallet's public identity key.
Why
A conversion is a swap in a Flashnet pool, signed on the phone, and the reward balance is read from Flashnet's rewards service.

Orchestra, run by Flashnet

Carries cross-chain payments, sending USDC or USDT to another network or receiving them from one.

What it receives
The destination address, the amount and the wallet's Spark address for each cross-chain payment it carries.
Why
The SDK asks it for a quote, and it delivers the payment on the other network.

MoonPay

Sells bitcoin to a person who chooses to buy it on MoonPay's page, and sends it to the wallet's own address.

What it receives
The wallet's bitcoin address, and what the person gives MoonPay on its own page to complete a purchase.
Why
The purchase happens on MoonPay's page, opened from the app, and neither the money nor the bitcoin passes through Voltz.

Kraken

Supplies the bitcoin price history behind the chart on the asset screen.

What it receives
A request for price history, made by the phone, which carries its IP address and no wallet data.
Why
The SDK gives only the current price, so the chart takes its shape from Kraken's public price data.

Google Firebase Cloud Messaging

Delivers the notifications that tell a person a payment reached their Lightning address.

What it receives
An installation identity, which the Firebase SDK in the app sets up with Firebase from the moment the app starts, on iPhone and Android, whether or not notifications are allowed. On Android, once they are, a token that identifies the app on the phone and the notifications the Lightning address service sends to it.
Why
Push notifications reach the phone through it, and its SDK starts with the app on both platforms.

The block explorer the person picks

Shows an on-chain transaction when the person asks to view it. The app comes with mempool.space and blockstream.info, and a person can add their own.

What it receives
The transaction's identifier and the browser's request, only when the person opens the link.
Why
Viewing a transaction opens the chosen site in the browser. The wallet reads nothing from it.

The server of an address or voucher

Answers for a Lightning address the person pays or a voucher they redeem, and belongs to whoever runs that address or voucher.

What it receives
The phone's request, with its IP address, the amount and any comment the person adds.
Why
To pay a Lightning address the app asks that server for an invoice, and to redeem a voucher it sends that server an invoice to pay, both straight from the phone.

Google Workspace

Holds the mailbox of support@usevoltz.app.

What it receives
The messages a person sends to support, with their email address.
Why
Support answers by email.

Cloudflare

Serves this website, and carries the requests to the Lightning address service, those for a domain a person connects included.

What it receives
The requests a browser makes to the site and the requests the app and payers' wallets make to the Lightning address service, each with its IP address, and the name of any domain a person connects.
Why
The site and the service are both reached through Cloudflare's network, which also issues the certificate for a connected domain.

Hetzner

Rents Voltz the servers the Lightning address service runs on, with its databases.

What it receives
Everything the Lightning address service keeps, as this page lists it, stored on its servers.
Why
The service needs servers to run on, and Voltz rents them from Hetzner.

This website

This site sets no cookies, stores nothing in your browser and loads nothing from any other address. It has no analytics, no advertising tags and no tracking of any kind.

Cloudflare serves the site and receives each request with your IP address, as any web host does. The site runs no code of its own there, so Voltz keeps no log of visits, and Cloudflare's dashboard shows totals, such as how many requests arrived and from which countries, and the details of any request its security rules block.

If you write to support@usevoltz.app, your message and your email address are kept in Voltz's mailbox, on Google Workspace, for up to 2 years after the last message of the conversation, or for 5 years when it concerns a purchase, and are then deleted.

When the app prepares an email to support about something you paid for and did not get, the email already carries your wallet's public key and the payment's reference, so Voltz can find the payment.

Your choices

You can ask, at any time and free of charge, for confirmation that Voltz processes data about you, for access to it, for correction of anything incomplete, inaccurate or out of date, for anonymisation, blocking or deletion of anything unnecessary, excessive or processed against the law, for portability, for deletion of data processed with your consent, to know whom Voltz has shared your data with, to know whether you may refuse consent and what follows if you do, and to take back your consent. You can also object to processing done without your consent when it breaks the law. Write to support@usevoltz.app and name the Lightning address or the domain your request is about.

In the app you can stop an address at once, without deleting anything. Open the menu, choose Lightning address and then Remove address, and that address stops receiving. The service keeps the name reserved for your wallet and keeps the records listed above, and the next time you open Receive the app gives the wallet a new address. To have those records deleted, see Deleting your data from Voltz Wallet.

You can also complain to the ANPD, Brazil's data protection authority, or to the data protection authority where you live.

Deleting your data from Voltz Wallet

You can ask for your data to be deleted at any time, without installing or opening the app.

Write to support@usevoltz.app with the subject ‘Delete my data’ and the Lightning address or the domain it concerns.

Voltz deletes your data within 15 days of your message and replies to confirm when it is done.

The service deletes some records on its own, such as the gateway's copy of a payer's comment, after 180 days, and a registered device, once Firebase reports that it no longer receives notifications. The LNURL server keeps its own copy of the comment with no set expiry.

Backup copies made before a deletion keep the data until they are discarded. Voltz cannot delete what a provider above keeps on its own account, such as the Spark operators' record of your payments, or a payment on the Bitcoin blockchain, which is public and permanent.