This is a courtesy translation. The Portuguese version is the authoritative text and prevails in the event of any divergence.
XIP is a non-custodial wallet: your private keys are generated and remain on your device, and we have no access to them or to your funds. We process only the data necessary to maintain your account, carry out conversion operations between Brazilian reais (BRL) and crypto-assets, and comply with the legal obligations that apply to those operations.
Purpose and scope
This Data Protection and Privacy Policy describes how XIP collects, uses, stores, shares, protects and deletes personal data, and how the data subject may exercise the rights afforded to them by law.
It applies to all processing of personal data carried out by XIP in the context of:
- the XIP mobile app, including account creation, authentication and the crypto-asset wallet;
- the application programming interface (API) that supports the app;
- the identity verification process that enables inbound (on-ramp) and outbound (off-ramp) operations in BRL;
- the institutional website xip.cash;
- the user service and support channels.
This policy observes Law No. 13,709/2018 (the Brazilian General Personal Data Protection Law — LGPD), Law No. 12,965/2014 (the Brazilian Civil Rights Framework for the Internet), Law No. 8,078/1990 (the Brazilian Consumer Protection Code) and Law No. 9,613/1998 (the Brazilian anti-money laundering law), as regards the record retention required by anti-money laundering legislation.
Definitions
| Term | Meaning adopted in this document |
|---|---|
| Personal data | Information relating to an identified or identifiable natural person. |
| Sensitive personal data | Data on racial or ethnic origin, religious belief, political opinion, trade union membership, health, sex life, or genetic or biometric data. In XIP's context, the relevant category is biometric data, present in the facial image (selfie) required for identity verification. |
| Data subject | The natural person to whom the personal data relates. |
| Controller | The party that makes the decisions regarding the processing of personal data. |
| Processor | The party that carries out the processing on behalf of the controller and in accordance with its instructions. |
| Payment services provider | The authorized institution, contracted by XIP, responsible for settling operations in BRL and for verifying users' identity. Referred to throughout this document as the contracted provider. |
| Non-custodial wallet | A crypto-asset wallet in which the cryptographic keys are generated and kept exclusively under the user's control, with the software provider holding no power to move the assets. |
| Inbound operation (on-ramp) | Conversion of BRL into a crypto-asset, credited to the user's wallet. |
| Outbound operation (off-ramp) | Conversion of a crypto-asset into BRL, credited to a payment account or bank account indicated by the user. |
Our role in the processing
XIP acts as controller of the personal data it collects directly from the user in order to create and maintain the user's account, authenticate the user and record the user's operations.
In identity verification, XIP collects the data and documents in the app and forwards them to the contracted provider, which is the authorized institution responsible for analysing them, deciding on approval and complying with the corresponding regulatory obligations. At this stage:
- XIP is controller as regards the decision to require verification and as regards recording the outcome (approved, refused, under review) that conditions use of the platform;
- the contracted provider is an independent controller as regards the analysis of the documents, the verification decision and compliance with the obligations that the law imposes directly on it, including the retention of the identity documents;
- XIP does not decide the verification outcome and does not re-examine the contracted provider's decision.
Providers of cloud infrastructure, hosting, transactional messaging and observability act as processors, processing personal data exclusively under XIP's contractual instructions.
Non-custodial architecture: what we never have access to
XIP's architecture deliberately restricts what we are able to process. The elements below never reach our servers and cannot be accessed, exported or recovered by us, by design:
| Element | Where it resides | Consequence |
|---|---|---|
| Recovery phrase (seed) and private keys | Exclusively on the user's device, in an area protected by the operating system | We cannot move, block or freeze the user's crypto-assets, nor restore their wallet if the recovery phrase is lost. |
| App access password, PIN and device biometrics | Features of the device's own operating system | We neither receive nor store these local unlock factors. |
| XIP account password | Our servers, only in the form of a cryptographic hash (bcrypt, cost factor 12) | The plaintext password is neither stored nor recoverable; a leak of the database does not expose usable passwords. |
As a direct consequence of the non-custodial model, the loss of the recovery phrase entails the permanent loss of access to the crypto-assets. No support procedure, identity verification or court decision enables us to recreate that information, because it has never been in our custody.
Personal data processed
We process the categories of data set out below. The "source" column indicates whether the data is provided by the data subject, generated by the system or received from a third party.
Account and authentication data
| Data | Source | Note |
|---|---|---|
| E-mail address | Data subject | Primary account identifier and channel for transactional communication. |
| Username (handle) | Data subject | Public identifier chosen by the user, of up to 20 characters. |
| Password | Data subject | Stored exclusively as a bcrypt hash; never in plaintext. |
| Date of e-mail confirmation | System | Records the validation of the address provided. |
| Single-use verification codes | System | Used in e-mail confirmation, code-based sign-in and password reset. They are short-lived and are discarded after use or expiry. |
| Two-step authentication secret and recovery codes | System | Generated when the user activates two-step authentication. The recovery codes are stored in protected form and are individually invalidated after use. |
Identification and verification data
| Data | Source | Persisted by XIP |
|---|---|---|
| Full name | Data subject | Yes |
| CPF number (CPF, Brazil's individual taxpayer registry number) | Data subject | Yes |
| Telephone number | Data subject | No — forwarded to the contracted provider, with no persistence in our database. |
| Type of document presented (RG, the Brazilian identity card, or CNH, the Brazilian driver's license) | Data subject | No — reported to the contracted provider upon submission. |
| Images of the identity document | Data subject | No — see the following section. |
| Facial image (selfie) — biometric data | Data subject | No — see the following section. |
| Status of the verification and of the verification record | Contracted provider | Yes — verification states and enablement states of the verification record. |
| Reason for refusal, where applicable | Contracted provider | Yes — shown to the user so that they can correct and resubmit. |
| Date of analysis | Contracted provider | Yes |
| Identifier of the verification record with the contracted provider | Contracted provider | Yes — allows the verification record to be correlated without replicating its content. |
Operation data
| Data | Source | Note |
|---|---|---|
| Type of operation (inbound or outbound) | System | — |
| Amount in BRL and quantity of crypto-asset | System | Includes the quote applied and the destination asset. |
| Operation status and time markers | System and contracted provider | Creation, expiry of the quote and completion. |
| Destination wallet address | Data subject | Public blockchain address, indicated by the user. |
| Operation identifiers | System and contracted provider | Internal identifier and order and quote identifiers with the contracted provider, for reconciliation and traceability. |
| Instant payment code and payee details in outbound operations | Data subject and contracted provider | Payment key, key type, and the payee's name and identification document, where applicable to the outbound operation. |
| Event records received from the contracted provider | Contracted provider | Audit trail of the notifications of changes in the status of operations, with the dates of receipt and of processing. |
Operations recorded on a blockchain are public, permanent and irreversible by nature. Wallet addresses, amounts and transaction times are visible to anyone and cannot be altered, hidden or erased by us or by any other party — including in response to a deletion request. This characteristic is inherent to the technology, and not a choice made by XIP.
Technical and security data
- IP address, date and time of access and basic identification of the access agent, recorded for security, fraud prevention and compliance with the Civil Rights Framework for the Internet;
- Application event records (logs) of errors and relevant events, kept with minimization of personal identifiers — sensitive data such as the full CPF is recorded in masked form or omitted;
- Records of blocks for excess requests, produced by the traffic-limiting controls.
Data we do not persist
The images required for identity verification — the photograph of the document (front and back in the case of the RG; a single image in the case of the CNH) and the facial image — are not stored by XIP at any time.
Technically, the flow is as follows: the images are captured or selected in the app, compressed on the device and transmitted over an encrypted channel to our API; the API keeps them in memory only for the duration of the request, long enough to reassemble the submission, and forwards them immediately to the contracted provider. Once the request ends, the data is discarded. There is no writing to disk, to a file system, to an object storage service, to a database or to a cache.
The retention of the identity documents, for the periods required by applicable legislation, is the responsibility of the contracted provider, in its capacity as an authorized institution.
Likewise, the telephone number provided during verification is transmitted to the contracted provider but is not persisted in our database.
Deliberately reducing what we store reduces the potential harm of any security incident. A compromise of our database would not expose document images or facial images, because they are not there.
Purposes and legal bases
All processing carried out by XIP relies on a legal basis under Art. 7 of the LGPD and, where it involves sensitive personal data, also on a ground under Art. 11.
| Purpose | Data involved | Legal basis |
|---|---|---|
| Create and maintain the account; authenticate the user; recover access | Account and authentication | Performance of a contract — Art. 7, V |
| Verify the user's identity as a condition for enabling operations in BRL | Identification, documents and facial image | Compliance with a legal and regulatory obligation — Art. 7, II; and, as regards biometric data, Art. 11, II, "a" and "g" (compliance with a legal obligation and prevention of fraud and security of the data subject) |
| Execute, settle, reconcile and evidence the contracted operations | Operations and identification | Performance of a contract — Art. 7, V |
| Prevent, detect and suppress money laundering, terrorist financing and fraud; retain operation records | Identification, operations and technical data | Compliance with a legal obligation — Art. 7, II; prevention of fraud and security of the data subject — Art. 11, II, "g", where applicable |
| Ensure the security of the platform: limit abuse, block attacks, investigate incidents | Technical and security data | Legitimate interest — Art. 7, IX |
| Provide support and respond to user requests | Account and data provided during the support interaction | Performance of a contract — Art. 7, V |
| Comply with requests from competent authorities and exercise rights in proceedings | As per the subject matter of the request | Compliance with a legal obligation — Art. 7, II; regular exercise of rights — Art. 7, VI |
| Maintain application access logs | IP address, date and time | Compliance with a legal obligation — Art. 7, II (Civil Rights Framework for the Internet, Art. 15) |
We do not use personal data for behavioral advertising, we do not sell it and we do not transfer it to third parties for marketing purposes. We do not make automated profiling decisions with legal effects on the data subject beyond the identity verification described above, the decision on which is communicated together with its reason and admits resubmission.
Sharing with third parties
We share personal data only to the extent necessary and with the following categories of recipients:
| Recipient | What is shared | Why |
|---|---|---|
| Contracted payment services provider | Name, CPF, e-mail, telephone number, wallet address, document images and facial image, operation data | Identity verification and settlement of operations in BRL. Legal obligation and performance of the contract. |
| Cloud infrastructure and hosting providers | Data stored and processed on the platform | Technical operation of the systems, under a processor agreement with security and confidentiality obligations. |
| Transactional messaging provider | E-mail address and message content | Sending of confirmations, access codes and security notices. |
| Competent public authorities | As per the subject matter and the limits of the request | Compliance with a legal, regulatory or judicial determination. |
| Legal advisers and independent auditors | The minimum necessary for the contracted work | Regular exercise of rights and compliance verification, under a duty of confidentiality. |
| Successors, in a corporate reorganization | The database, to the extent of the transaction | Continuity of the provision of the service, with the purposes and safeguards of this policy preserved. |
International transfer
Part of the infrastructure that supports the platform may be located outside Brazil. Where there is an international transfer of personal data, it takes place under the terms of Art. 33 of the LGPD, by means of:
- transfer to a country or international organization that provides an adequate level of protection, where so recognized; or
- specific contractual clauses ensuring compliance with the principles, the data subject rights and the data protection regime provided for in the LGPD; and
- contractual obligations of confidentiality, information security, purpose limitation and assistance in responding to data subject requests.
Retention periods and deletion
We retain personal data only for as long as necessary for the purposes that justify it, subject to the statutory retention periods. Once the period has ended, the data is deleted or irreversibly anonymized.
| Category | Retention period | Basis |
|---|---|---|
| Account and authentication data | While the account is active and for 5 years after its closure | Performance of a contract and limitation period for the exercise of rights |
| Identification data and verification outcome | 5 years from the end of the relationship with the user | Anti-money laundering legislation |
| Operation records | A minimum of 5 years from the completion of each operation, extendable by determination of a competent authority | Anti-money laundering legislation and tax obligations |
| Trail of events received from the contracted provider | The same period as the record of the operation to which it relates | Integrity and auditability of the operation record |
| Application access logs | 6 months, extendable upon request by an authority | Civil Rights Framework for the Internet, Art. 15 |
| Application and security logs | Up to 12 months | Legitimate interest in security and in the investigation of incidents |
| Single-use verification codes | Minutes — discarded after use or expiry | Data minimization |
| Service and support records | 5 years from the closure of the support interaction | Consumer Protection Code and regular exercise of rights |
Operation records are treated as financial records: the system prevents their cascading deletion when an account is closed, precisely in order to preserve the integrity of the bookkeeping and to allow compliance with the retention obligations.
Security measures
We adopt technical and administrative measures to protect personal data against unauthorized access, loss, alteration and improper disclosure. The principal measures, in operation today:
Protection of user access
- Passwords stored only as a bcrypt hash with cost factor 12;
- Two-step authentication via an authenticator app, with single-use recovery codes;
- E-mail confirmation and sign-in by short-lived single-use code;
- Session tokens that are signed, with expiry, and invalidation of the session when the server detects an invalid credential;
- Brute-force controls on the credential endpoints, with limits per source address and per account.
Protection of the platform
- Encryption in transit by TLS across all communication between the app, the API and the contracted provider;
- Traffic limiting at multiple layers: a global cap per source for the entire API, caps per authenticated account and specific caps on the verification and operation endpoints;
- Request filters against header anomalies, SQL injection attempts and malicious content;
- Verification of the authenticity of the notifications received from the contracted provider by HMAC-SHA256 signature over the raw message body — notifications without a valid signature are rejected, with no exception or bypass mode;
- Concurrency control by database locks and idempotency by unique identifiers, avoiding duplicate verification records and duplicate operations;
- Minimization in application logs: sensitive identifiers are masked before being recorded.
Administrative controls
- Access profiles and granular permissions in the administrative panel, with assignment by role and the least-privilege principle;
- Segregation of environments between development, staging and production;
- Contractual obligations of confidentiality and information security imposed on processors and providers;
- Confidentiality undertaking applicable to all personnel with access to personal data, maintained after the end of the relationship.
No security measure is absolute. We undertake to maintain controls proportionate to the risk and to report relevant incidents as described below, but it is not possible to guarantee the inviolability of the transmission of data over the internet.
Data subject rights
Under the terms of Art. 18 of the LGPD, the data subject may, at any time and free of charge, request:
| Right | What it means in practice |
|---|---|
| Confirmation and access | To know whether we process your data and to obtain a copy of it in a legible format. |
| Correction | To correct incomplete, inaccurate or out-of-date data. The name, the e-mail address and the telephone number may be updated by the user in the app before verification is approved; the CPF, once verified, is immutable and changing it requires assistance through the channel indicated below. |
| Anonymization, blocking or deletion | To request the anonymization, blocking or erasure of data that is unnecessary or excessive, or that has been processed in breach of the law. |
| Portability | To request the transfer of the data to another provider, subject to ANPD (ANPD, Brazil's National Data Protection Authority) regulations and to trade and industrial secrecy. |
| Information on sharing | To know with which public and private entities we share your data. |
| Information on the refusal of consent | To be informed of the possibility of not providing consent and of the consequences of that refusal. |
| Withdrawal of consent | To withdraw consent, where this is the legal basis used. |
| Review of an automated decision | To request a review of a decision taken solely on the basis of automated processing that affects your interests. |
| Petition to the authority | To petition the National Data Protection Authority (ANPD) directly. |
How to exercise them
Send your request to privacy@xip.cash, identifying yourself and describing the request. We may ask for additional information to confirm your identity — a measure necessary to avoid disclosing personal data to someone who is not the data subject. We will respond:
- immediately, in simplified format, where the request is for confirmation of existence or for simplified access; or
- within 15 (fifteen) days of the request, in all other cases, by means of a clear and complete statement, in accordance with Art. 19 of the LGPD.
Limits on the deletion request
Some data cannot be deleted upon request, because a legal or regulatory retention obligation prevails, or because it is necessary for the regular exercise of rights (Art. 16 of the LGPD). This is notably the case for the identification and operation records, which are subject to a minimum retention period under anti-money laundering legislation. In such cases, we will inform the data subject of the partial refusal and of its basis, and will restrict the processing to the retention purpose.
Records already published on a blockchain cannot be deleted by us or by any third party, as explained above.
Data Protection Officer and contact channel
| Channel | Address | Subject |
|---|---|---|
| Data Protection Officer (DPO) | Raphael Mirante — privacy@xip.cash | Data subject rights, questions and complaints about privacy; liaison with the ANPD. |
| Compliance and prevention of money laundering | compliance@xip.cash | AML/CFT matters, requests from authorities and institutional cooperation. |
| Information security | security@xip.cash | Responsible disclosure of vulnerabilities and suspected incidents. |
| User support | support@xip.cash | Questions about the account, verification and operations. |
| Postal address | Rua dos Goitacazes, 375, Sala 1404, Centro, Belo Horizonte/MG, CEP 30190-050 | Formal correspondence. |
Cookies and technologies on the website
The institutional website xip.cash consists of static pages and does not use tracking, advertising or audience-analytics cookies, nor does it generate browsing profiles.
For the sake of transparency, we record that the pages load typefaces hosted by the Google Fonts service. That loading causes the visitor's browser to establish a connection with the provider's servers, which exposes to that third party the IP address and basic information about the request. No other information is transmitted by us, and the visitor is not identified.
The mobile app does not use cookies. Local usage preferences remain in the device's own storage.
Security incidents
We maintain an incident response procedure comprising detection, containment, eradication, recovery, assessment of the risk to data subjects and recording of the measures adopted.
Where the occurrence of a security incident that may entail relevant risk or harm to data subjects is confirmed, we will notify:
- the ANPD, within 3 (three) business days from becoming aware of the incident, in accordance with the regulations in force; and
- the affected data subjects, within the same period, informing them of the nature of the data involved, the risks, the measures taken and the protective recommendations.
Suspected vulnerabilities may be reported to security@xip.cash. We undertake to review good-faith reports and not to adopt retaliatory measures against anyone who reports responsibly, without exploiting third-party data and without degrading the service.
Children and adolescents
XIP is intended exclusively for persons aged 18 or over, with full legal capacity. We do not intentionally collect data from children or adolescents. One of the functions of identity verification is to confirm that the user is of legal age. Where an account held by a minor is identified, it is closed and the associated data is deleted, except for the retention required by law.
Amendments to this policy
This policy may be revised to reflect legal, regulatory, technical or operational changes. The version in force is always the one published on this page, with the version and revision date indicated in the header.
Amendments that restrict data subject rights or significantly expand the purposes of processing will be communicated in advance, by e-mail or by notice in the app, a reasonable time before they take effect.
Version history
| Version | Date | Changes |
|---|---|---|
| 1.0 | July 29, 2026 | Initial publication. |