Privacy Policy
Effective September 6, 2026 · Kamara Labs LLC
Information you provide directly
- Wallet and account labels you choose
- Watch-only addresses you add to track
- Contact labels and recipient addresses you save
- Recovery phrase material, only at the moment you create or import a wallet on-device — written to your device's Keychain and never transmitted to Kamara Labs
Information stored locally on your device
The following is stored locally on your device rather than in a Kamara Labs account database:
- Wallet and account state
- Transaction activity history
- Browser favorites
- Connected dApp session records and permissions
- Security preferences (auto-lock timing, private browsing, notification settings)
Information sent to third parties
Using Ironhavn requires network requests to service providers and sites that Kamara Labs does not control:
Cloudflare and Alchemy — Ironhavn sends blockchain RPC requests through a Cloudflare Worker operated for Kamara Labs and forwards them to Alchemy to read balances, estimate fees, and broadcast transactions on Ethereum, Base, Arbitrum, Optimism, and Polygon. Cloudflare can process your IP address and request metadata. RPC payloads can include public wallet addresses, contract calls, and signed transaction data. The Worker does not intentionally log or persist request or response bodies.
LI.FI — to fetch cross-chain swap quotes and route swap transactions when you use the Swap tab. Requests can include wallet addresses, token selections, amounts, and network information.
CoinGecko — to display live token prices. Standard network metadata, including your IP address, may be processed by the service.
In-app browser — search queries and any site you visit are subject to those sites' own privacy practices. Ironhavn does not control what third-party sites do with your traffic.
We do not sell your data. As of this release, Ironhavn does not include any analytics, advertising, or third-party tracking SDKs.
Your controls
- Add, rename, or remove watch-only addresses at any time
- Review and revoke connected dApp permissions from the Security tab, per site and per permission
- Enable private browsing mode in the browser
- Optionally restrict direct sends to your own wallet and saved contacts
- Remove saved contacts, watch-only accounts, and connected-site permissions in the app
Security
Recovery phrases and signing keys are generated and stored on-device via Apple's Keychain, protected by Face ID, Touch ID, or your passcode. You are solely responsible for backing up your recovery phrase and keeping it offline and private. Anyone with your recovery phrase can access your funds. Kamara Labs staff will never ask you for it.
Children's privacy
Ironhavn is not directed at children and is not intended for use by anyone under 18.
Changes to this policy
We may update this policy as the app's features change. Material changes will be reflected here with an updated effective date.
Contact
Kamara Labs LLC
Email: kamaralabs@gmail.com
Support: ironhavn.com/support