Legal

Privacy Policy

Effective date: August 11, 2026  ·  Choco / usechoco.app

Short version: Choco is a non-custodial app. We never see your private keys or seed phrases. Your wallet address and on-chain transactions are public by design (Celo Mainnet). We collect minimal off-chain data — only what is needed to run the service.

1. Who we are

Choco ("we", "us", "our") is a non-custodial remittance tool built on the Celo blockchain. It is operated by Choco, a company registered in Colombia. You can reach us at support@usechoco.app.

2. What data we collect and why

Email address — if you sign in with email using Privy (our wallet infrastructure provider), your email is stored and managed by Privy under their own privacy policy. Choco receives a user identifier from Privy but does not store your email on our servers.

Wallet address — your Celo wallet address is used to read your USDC balance, prepare transfer actions, and query your on-chain history. Wallet addresses on Celo are public by nature.

On-chain transaction data — all schedules, transfer runs, and receipts are recorded on Celo Mainnet in ChocoLedger and ChocoGateway contracts. This data is permanently public on the blockchain. Choco reads it to display your history inside the app.

Recipient contact labels — if you add a name or label to a recipient wallet address, that label is stored in Supabase (our database provider, listed in §4) linked to your user identifier. It is not shared with third parties. A future update may migrate this to device-local storage only.

Support messages — when you use the contact form, your message is composed into a mailto link and sent via your email client. Choco only receives what you include in the email. We store support correspondence for up to 12 months for service quality purposes.

3. What we do NOT collect

4. Withdrawals and identity verification

When you use the withdraw-to-bank feature, Choco helps you complete identity verification through Bridge (Stripe), Kotani Pay, or Orionx, depending on the corridor you choose (see §5). You provide your email — Choco relays it to the provider so they can start your KYC flow. The full verification (ID documents, liveness check) happens on the provider's own hosted pages. Choco's servers never receive your identity documents.

To complete a payout, you provide your bank account number, Bre-B llave, PIX key, CLABE, or mobile-money phone number. Choco forwards this to the provider to create a liquidation address assigned to your verified identity. The provider holds your KYC data per their own privacy policy and data processing agreements.

Choco also uses your wallet to produce a one-time signature for Supabase contact sign-in (see §5). This signature is verified by a server-side edge function and is not stored long-term; it proves that a live wallet is making the request, disassociated from any on-chain transaction.

5. Third-party services

6. Cookies and local storage

Choco uses browser localStorage to cache your wallet session (via Privy), the Supabase authentication token (choco-sb-auth), your recipient contact labels (choco-contacts-v1), and address label caches (choco-label-*). The Bridge customer identifier is stored in sessionStorage (cleared on tab close) for additional security. We do not use advertising cookies or cross-site tracking.

7. Your rights

Depending on where you are located, you may have the following rights:

To exercise any right, email support@usechoco.app. We will respond within 30 days.

8. Data retention

Off-chain data (support emails) is retained for up to 12 months. Recipient contact labels and synthetic Supabase auth identities are retained until you delete them or request deletion. Bridge-session identifiers are stored in your browser's sessionStorage and lost when you close the tab. Privy session data is retained per Privy's policy. On-chain data on Celo is permanent and outside Choco's control.

9. Colombian data protection (Ley 1581 de 2012)

Choco is operated by a company registered in Colombia. Under Colombia's habeas data law, you have the right to know, update, and request deletion of personal data we hold, and to revoke authorization for data processing. To exercise these rights, contact support@usechoco.app. We respond within 10 business days for consultation requests and 15 business days for claims, per Colombian regulation. Our database registrations with the Superintendencia de Industria y Comercio (SIC) are available upon request.

10. Security

Choco is non-custodial — funds and private keys remain in your wallet at all times. Our smart contracts are open-source and publicly verifiable on Celoscan. We do not operate servers that hold your funds or private keys.

11. Children

Choco is not directed to users under 18. We do not knowingly collect data from minors. If you believe a minor has used our service, contact us and we will delete any off-chain data promptly.

12. Changes to this policy

We may update this policy as the app evolves. Material changes will be noted with an updated effective date at the top of this page. Continued use of Choco after an update constitutes acceptance of the revised policy.

13. Contact

Questions about this policy? Email us at support@usechoco.app or use the contact page.