XIP

Institutional documents  /  Data Protection and Privacy Policy

Policy

Data Protection and Privacy Policy

How XIP collects, uses, shares, protects and erases personal data, and how data subjects exercise their rights under Brazil's General Data Protection Law.

Document POL-01
Version 1.0
In force since July 29, 2026
Last revised July 29, 2026
Classification Public

This is a courtesy translation. The Portuguese version is the authoritative text and prevails in the event of any divergence.

One-line summary

XIP is a non-custodial wallet: your private keys are generated and remain on your device, and we have no access to them or to your funds. We process only the data necessary to maintain your account, carry out conversion operations between Brazilian reais (BRL) and crypto-assets, and comply with the legal obligations that apply to those operations.

Purpose and scope

This Data Protection and Privacy Policy describes how XIP collects, uses, stores, shares, protects and deletes personal data, and how the data subject may exercise the rights afforded to them by law.

It applies to all processing of personal data carried out by XIP in the context of:

  • the XIP mobile app, including account creation, authentication and the crypto-asset wallet;
  • the application programming interface (API) that supports the app;
  • the identity verification process that enables inbound (on-ramp) and outbound (off-ramp) operations in BRL;
  • the institutional website xip.cash;
  • the user service and support channels.

This policy observes Law No. 13,709/2018 (the Brazilian General Personal Data Protection Law — LGPD), Law No. 12,965/2014 (the Brazilian Civil Rights Framework for the Internet), Law No. 8,078/1990 (the Brazilian Consumer Protection Code) and Law No. 9,613/1998 (the Brazilian anti-money laundering law), as regards the record retention required by anti-money laundering legislation.

Definitions

Term Meaning adopted in this document
Personal data Information relating to an identified or identifiable natural person.
Sensitive personal data Data on racial or ethnic origin, religious belief, political opinion, trade union membership, health, sex life, or genetic or biometric data. In XIP's context, the relevant category is biometric data, present in the facial image (selfie) required for identity verification.
Data subject The natural person to whom the personal data relates.
Controller The party that makes the decisions regarding the processing of personal data.
Processor The party that carries out the processing on behalf of the controller and in accordance with its instructions.
Payment services provider The authorized institution, contracted by XIP, responsible for settling operations in BRL and for verifying users' identity. Referred to throughout this document as the contracted provider.
Non-custodial wallet A crypto-asset wallet in which the cryptographic keys are generated and kept exclusively under the user's control, with the software provider holding no power to move the assets.
Inbound operation (on-ramp) Conversion of BRL into a crypto-asset, credited to the user's wallet.
Outbound operation (off-ramp) Conversion of a crypto-asset into BRL, credited to a payment account or bank account indicated by the user.

Our role in the processing

XIP acts as controller of the personal data it collects directly from the user in order to create and maintain the user's account, authenticate the user and record the user's operations.

In identity verification, XIP collects the data and documents in the app and forwards them to the contracted provider, which is the authorized institution responsible for analysing them, deciding on approval and complying with the corresponding regulatory obligations. At this stage:

  • XIP is controller as regards the decision to require verification and as regards recording the outcome (approved, refused, under review) that conditions use of the platform;
  • the contracted provider is an independent controller as regards the analysis of the documents, the verification decision and compliance with the obligations that the law imposes directly on it, including the retention of the identity documents;
  • XIP does not decide the verification outcome and does not re-examine the contracted provider's decision.

Providers of cloud infrastructure, hosting, transactional messaging and observability act as processors, processing personal data exclusively under XIP's contractual instructions.

Non-custodial architecture: what we never have access to

XIP's architecture deliberately restricts what we are able to process. The elements below never reach our servers and cannot be accessed, exported or recovered by us, by design:

Element Where it resides Consequence
Recovery phrase (seed) and private keys Exclusively on the user's device, in an area protected by the operating system We cannot move, block or freeze the user's crypto-assets, nor restore their wallet if the recovery phrase is lost.
App access password, PIN and device biometrics Features of the device's own operating system We neither receive nor store these local unlock factors.
XIP account password Our servers, only in the form of a cryptographic hash (bcrypt, cost factor 12) The plaintext password is neither stored nor recoverable; a leak of the database does not expose usable passwords.
Warning

As a direct consequence of the non-custodial model, the loss of the recovery phrase entails the permanent loss of access to the crypto-assets. No support procedure, identity verification or court decision enables us to recreate that information, because it has never been in our custody.

Personal data processed

We process the categories of data set out below. The "source" column indicates whether the data is provided by the data subject, generated by the system or received from a third party.

Account and authentication data

Data Source Note
E-mail address Data subject Primary account identifier and channel for transactional communication.
Username (handle) Data subject Public identifier chosen by the user, of up to 20 characters.
Password Data subject Stored exclusively as a bcrypt hash; never in plaintext.
Date of e-mail confirmation System Records the validation of the address provided.
Single-use verification codes System Used in e-mail confirmation, code-based sign-in and password reset. They are short-lived and are discarded after use or expiry.
Two-step authentication secret and recovery codes System Generated when the user activates two-step authentication. The recovery codes are stored in protected form and are individually invalidated after use.

Identification and verification data

Data Source Persisted by XIP
Full name Data subject Yes
CPF number (CPF, Brazil's individual taxpayer registry number) Data subject Yes
Telephone number Data subject No — forwarded to the contracted provider, with no persistence in our database.
Type of document presented (RG, the Brazilian identity card, or CNH, the Brazilian driver's license) Data subject No — reported to the contracted provider upon submission.
Images of the identity document Data subject No — see the following section.
Facial image (selfie) — biometric data Data subject No — see the following section.
Status of the verification and of the verification record Contracted provider Yes — verification states and enablement states of the verification record.
Reason for refusal, where applicable Contracted provider Yes — shown to the user so that they can correct and resubmit.
Date of analysis Contracted provider Yes
Identifier of the verification record with the contracted provider Contracted provider Yes — allows the verification record to be correlated without replicating its content.

Operation data

Data Source Note
Type of operation (inbound or outbound) System
Amount in BRL and quantity of crypto-asset System Includes the quote applied and the destination asset.
Operation status and time markers System and contracted provider Creation, expiry of the quote and completion.
Destination wallet address Data subject Public blockchain address, indicated by the user.
Operation identifiers System and contracted provider Internal identifier and order and quote identifiers with the contracted provider, for reconciliation and traceability.
Instant payment code and payee details in outbound operations Data subject and contracted provider Payment key, key type, and the payee's name and identification document, where applicable to the outbound operation.
Event records received from the contracted provider Contracted provider Audit trail of the notifications of changes in the status of operations, with the dates of receipt and of processing.
About the blockchain

Operations recorded on a blockchain are public, permanent and irreversible by nature. Wallet addresses, amounts and transaction times are visible to anyone and cannot be altered, hidden or erased by us or by any other party — including in response to a deletion request. This characteristic is inherent to the technology, and not a choice made by XIP.

Technical and security data

  • IP address, date and time of access and basic identification of the access agent, recorded for security, fraud prevention and compliance with the Civil Rights Framework for the Internet;
  • Application event records (logs) of errors and relevant events, kept with minimization of personal identifiers — sensitive data such as the full CPF is recorded in masked form or omitted;
  • Records of blocks for excess requests, produced by the traffic-limiting controls.

Data we do not persist

The images required for identity verification — the photograph of the document (front and back in the case of the RG; a single image in the case of the CNH) and the facial image — are not stored by XIP at any time.

Technically, the flow is as follows: the images are captured or selected in the app, compressed on the device and transmitted over an encrypted channel to our API; the API keeps them in memory only for the duration of the request, long enough to reassemble the submission, and forwards them immediately to the contracted provider. Once the request ends, the data is discarded. There is no writing to disk, to a file system, to an object storage service, to a database or to a cache.

The retention of the identity documents, for the periods required by applicable legislation, is the responsibility of the contracted provider, in its capacity as an authorized institution.

Likewise, the telephone number provided during verification is transmitted to the contracted provider but is not persisted in our database.

Why this matters to you

Deliberately reducing what we store reduces the potential harm of any security incident. A compromise of our database would not expose document images or facial images, because they are not there.

All processing carried out by XIP relies on a legal basis under Art. 7 of the LGPD and, where it involves sensitive personal data, also on a ground under Art. 11.

Purpose Data involved Legal basis
Create and maintain the account; authenticate the user; recover access Account and authentication Performance of a contract — Art. 7, V
Verify the user's identity as a condition for enabling operations in BRL Identification, documents and facial image Compliance with a legal and regulatory obligation — Art. 7, II; and, as regards biometric data, Art. 11, II, "a" and "g" (compliance with a legal obligation and prevention of fraud and security of the data subject)
Execute, settle, reconcile and evidence the contracted operations Operations and identification Performance of a contract — Art. 7, V
Prevent, detect and suppress money laundering, terrorist financing and fraud; retain operation records Identification, operations and technical data Compliance with a legal obligation — Art. 7, II; prevention of fraud and security of the data subject — Art. 11, II, "g", where applicable
Ensure the security of the platform: limit abuse, block attacks, investigate incidents Technical and security data Legitimate interest — Art. 7, IX
Provide support and respond to user requests Account and data provided during the support interaction Performance of a contract — Art. 7, V
Comply with requests from competent authorities and exercise rights in proceedings As per the subject matter of the request Compliance with a legal obligation — Art. 7, II; regular exercise of rights — Art. 7, VI
Maintain application access logs IP address, date and time Compliance with a legal obligation — Art. 7, II (Civil Rights Framework for the Internet, Art. 15)

We do not use personal data for behavioral advertising, we do not sell it and we do not transfer it to third parties for marketing purposes. We do not make automated profiling decisions with legal effects on the data subject beyond the identity verification described above, the decision on which is communicated together with its reason and admits resubmission.

Sharing with third parties

We share personal data only to the extent necessary and with the following categories of recipients:

Recipient What is shared Why
Contracted payment services provider Name, CPF, e-mail, telephone number, wallet address, document images and facial image, operation data Identity verification and settlement of operations in BRL. Legal obligation and performance of the contract.
Cloud infrastructure and hosting providers Data stored and processed on the platform Technical operation of the systems, under a processor agreement with security and confidentiality obligations.
Transactional messaging provider E-mail address and message content Sending of confirmations, access codes and security notices.
Competent public authorities As per the subject matter and the limits of the request Compliance with a legal, regulatory or judicial determination.
Legal advisers and independent auditors The minimum necessary for the contracted work Regular exercise of rights and compliance verification, under a duty of confidentiality.
Successors, in a corporate reorganization The database, to the extent of the transaction Continuity of the provision of the service, with the purposes and safeguards of this policy preserved.

International transfer

Part of the infrastructure that supports the platform may be located outside Brazil. Where there is an international transfer of personal data, it takes place under the terms of Art. 33 of the LGPD, by means of:

  • transfer to a country or international organization that provides an adequate level of protection, where so recognized; or
  • specific contractual clauses ensuring compliance with the principles, the data subject rights and the data protection regime provided for in the LGPD; and
  • contractual obligations of confidentiality, information security, purpose limitation and assistance in responding to data subject requests.

Retention periods and deletion

We retain personal data only for as long as necessary for the purposes that justify it, subject to the statutory retention periods. Once the period has ended, the data is deleted or irreversibly anonymized.

Category Retention period Basis
Account and authentication data While the account is active and for 5 years after its closure Performance of a contract and limitation period for the exercise of rights
Identification data and verification outcome 5 years from the end of the relationship with the user Anti-money laundering legislation
Operation records A minimum of 5 years from the completion of each operation, extendable by determination of a competent authority Anti-money laundering legislation and tax obligations
Trail of events received from the contracted provider The same period as the record of the operation to which it relates Integrity and auditability of the operation record
Application access logs 6 months, extendable upon request by an authority Civil Rights Framework for the Internet, Art. 15
Application and security logs Up to 12 months Legitimate interest in security and in the investigation of incidents
Single-use verification codes Minutes — discarded after use or expiry Data minimization
Service and support records 5 years from the closure of the support interaction Consumer Protection Code and regular exercise of rights

Operation records are treated as financial records: the system prevents their cascading deletion when an account is closed, precisely in order to preserve the integrity of the bookkeeping and to allow compliance with the retention obligations.

Security measures

We adopt technical and administrative measures to protect personal data against unauthorized access, loss, alteration and improper disclosure. The principal measures, in operation today:

Protection of user access

  • Passwords stored only as a bcrypt hash with cost factor 12;
  • Two-step authentication via an authenticator app, with single-use recovery codes;
  • E-mail confirmation and sign-in by short-lived single-use code;
  • Session tokens that are signed, with expiry, and invalidation of the session when the server detects an invalid credential;
  • Brute-force controls on the credential endpoints, with limits per source address and per account.

Protection of the platform

  • Encryption in transit by TLS across all communication between the app, the API and the contracted provider;
  • Traffic limiting at multiple layers: a global cap per source for the entire API, caps per authenticated account and specific caps on the verification and operation endpoints;
  • Request filters against header anomalies, SQL injection attempts and malicious content;
  • Verification of the authenticity of the notifications received from the contracted provider by HMAC-SHA256 signature over the raw message body — notifications without a valid signature are rejected, with no exception or bypass mode;
  • Concurrency control by database locks and idempotency by unique identifiers, avoiding duplicate verification records and duplicate operations;
  • Minimization in application logs: sensitive identifiers are masked before being recorded.

Administrative controls

  • Access profiles and granular permissions in the administrative panel, with assignment by role and the least-privilege principle;
  • Segregation of environments between development, staging and production;
  • Contractual obligations of confidentiality and information security imposed on processors and providers;
  • Confidentiality undertaking applicable to all personnel with access to personal data, maintained after the end of the relationship.
Limitation

No security measure is absolute. We undertake to maintain controls proportionate to the risk and to report relevant incidents as described below, but it is not possible to guarantee the inviolability of the transmission of data over the internet.

Data subject rights

Under the terms of Art. 18 of the LGPD, the data subject may, at any time and free of charge, request:

Right What it means in practice
Confirmation and access To know whether we process your data and to obtain a copy of it in a legible format.
Correction To correct incomplete, inaccurate or out-of-date data. The name, the e-mail address and the telephone number may be updated by the user in the app before verification is approved; the CPF, once verified, is immutable and changing it requires assistance through the channel indicated below.
Anonymization, blocking or deletion To request the anonymization, blocking or erasure of data that is unnecessary or excessive, or that has been processed in breach of the law.
Portability To request the transfer of the data to another provider, subject to ANPD (ANPD, Brazil's National Data Protection Authority) regulations and to trade and industrial secrecy.
Information on sharing To know with which public and private entities we share your data.
Information on the refusal of consent To be informed of the possibility of not providing consent and of the consequences of that refusal.
Withdrawal of consent To withdraw consent, where this is the legal basis used.
Review of an automated decision To request a review of a decision taken solely on the basis of automated processing that affects your interests.
Petition to the authority To petition the National Data Protection Authority (ANPD) directly.

How to exercise them

Send your request to privacy@xip.cash, identifying yourself and describing the request. We may ask for additional information to confirm your identity — a measure necessary to avoid disclosing personal data to someone who is not the data subject. We will respond:

  • immediately, in simplified format, where the request is for confirmation of existence or for simplified access; or
  • within 15 (fifteen) days of the request, in all other cases, by means of a clear and complete statement, in accordance with Art. 19 of the LGPD.

Limits on the deletion request

Some data cannot be deleted upon request, because a legal or regulatory retention obligation prevails, or because it is necessary for the regular exercise of rights (Art. 16 of the LGPD). This is notably the case for the identification and operation records, which are subject to a minimum retention period under anti-money laundering legislation. In such cases, we will inform the data subject of the partial refusal and of its basis, and will restrict the processing to the retention purpose.

Records already published on a blockchain cannot be deleted by us or by any third party, as explained above.

Data Protection Officer and contact channel

Channel Address Subject
Data Protection Officer (DPO) Raphael Mirante — privacy@xip.cash Data subject rights, questions and complaints about privacy; liaison with the ANPD.
Compliance and prevention of money laundering compliance@xip.cash AML/CFT matters, requests from authorities and institutional cooperation.
Information security security@xip.cash Responsible disclosure of vulnerabilities and suspected incidents.
User support support@xip.cash Questions about the account, verification and operations.
Postal address Rua dos Goitacazes, 375, Sala 1404, Centro, Belo Horizonte/MG, CEP 30190-050 Formal correspondence.

Cookies and technologies on the website

The institutional website xip.cash consists of static pages and does not use tracking, advertising or audience-analytics cookies, nor does it generate browsing profiles.

For the sake of transparency, we record that the pages load typefaces hosted by the Google Fonts service. That loading causes the visitor's browser to establish a connection with the provider's servers, which exposes to that third party the IP address and basic information about the request. No other information is transmitted by us, and the visitor is not identified.

The mobile app does not use cookies. Local usage preferences remain in the device's own storage.

Security incidents

We maintain an incident response procedure comprising detection, containment, eradication, recovery, assessment of the risk to data subjects and recording of the measures adopted.

Where the occurrence of a security incident that may entail relevant risk or harm to data subjects is confirmed, we will notify:

  • the ANPD, within 3 (three) business days from becoming aware of the incident, in accordance with the regulations in force; and
  • the affected data subjects, within the same period, informing them of the nature of the data involved, the risks, the measures taken and the protective recommendations.

Suspected vulnerabilities may be reported to security@xip.cash. We undertake to review good-faith reports and not to adopt retaliatory measures against anyone who reports responsibly, without exploiting third-party data and without degrading the service.

Children and adolescents

XIP is intended exclusively for persons aged 18 or over, with full legal capacity. We do not intentionally collect data from children or adolescents. One of the functions of identity verification is to confirm that the user is of legal age. Where an account held by a minor is identified, it is closed and the associated data is deleted, except for the retention required by law.

Amendments to this policy

This policy may be revised to reflect legal, regulatory, technical or operational changes. The version in force is always the one published on this page, with the version and revision date indicated in the header.

Amendments that restrict data subject rights or significantly expand the purposes of processing will be communicated in advance, by e-mail or by notice in the app, a reasonable time before they take effect.

Version history

Version Date Changes
1.0 July 29, 2026 Initial publication.