Privacy Guarantees
Understand what Kasanova sees and doesn't see.
Client-Side Cryptography
Everything Sensitive Happens on Your Device:
What We NEVER See
❌ Your seed phrase ❌ Your private keys ❌ Your addresses ❌ Your balance ❌ Your transaction history ❌ Who you send to ❌ Who sends to you ❌ Your token holdings ❌ Your NFT collection ❌ Your marketplace activity
How It Works
Wallet Creation:
Seed phrase generated on device
Never transmitted anywhere
Stored in secure device storage
iOS: Secure Enclave
Android: Keystore
Transaction Signing:
Transaction created locally
Signed with private key on device
Only signed transaction broadcast
Private key never leaves device
Address Generation:
HD wallet derives addresses locally
From seed phrase, on device
Kasanova servers never see them
What We DO See
Public Data Only
✅ Token metadata (names, icons, descriptions) ✅ Market prices (public data) ✅ Marketplace listings (public) ✅ Network status ✅ Block heights
Why We Need This
Provide token information in app
Display current prices
Show marketplace listings
Ensure app functions properly
What We Provide
Our servers are "dumb pipes":
Return public token data
Provide price feeds
Relay marketplace listings
Proxy to blockchain (but don't log)
How Your Data is Protected
Secure Storage
iOS:
Keychain (hardware-encrypted)
Secure Enclave (if available)
Face ID/Touch ID protected
Android:
Keystore (hardware-backed when available)
Fingerprint/Face protected
Encrypted storage
Network Security
All Connections:
HTTPS/TLS encrypted
Certificate pinning
No plaintext transmission
Even public data encrypted in transit
No Accounts
No registration required
No email addresses
No phone numbers
No KYC
No personal information
Blockchain Privacy
What's Public on Kaspa Blockchain
⚠️ Anyone Can See:
All transactions
All addresses
All balances
Token holdings
NFT ownership
Transaction amounts
Timestamps
What's NOT Public
✅ Cannot See:
Who owns an address (unless revealed)
Real identity
Geographic location
Connection between addresses (unless revealed)
Privacy Tips
Use Different Addresses:
Different purposes = different addresses
Public receives vs private savings
Marketplace vs personal use
Reduces linkability
Don't Reveal Links:
Don't post "my address is..."
Don't link addresses to identity publicly
Consider privacy when sharing
Understand Trade-offs:
Convenience vs privacy
Reusing addresses is easier
But reduces privacy
Choose based on needs
Kasanova's Business Model
How We Make Money:
Marketplace fees (1-2% on sales)
Not from selling your data
Not from transaction fees (go to miners)
Transparent and aligned with users
What This Means:
No incentive to track you
Privacy is our priority
No ads
No data sales
Third-Party Services
We Use:
Kaspa nodes (public blockchain access)
Price APIs (public market data)
Analytics (anonymous, opt-in)
We Don't Use:
Tracking pixels
Advertising networks
Data brokers
Third-party profilers
Your Control
You Decide:
What to share
When to transact
Privacy preferences
Analytics opt-in/out
You Own:
Your keys
Your data
Your privacy
Your funds
Comparison
Kasanova vs Custodial Wallets
Custodial (Coinbase, Binance, etc.):
They hold your keys
They see everything
They control funds
Can freeze accounts
Must KYC
Track all activity
Kasanova:
You hold keys
We see nothing sensitive
You control funds
Cannot freeze
No KYC
Minimal tracking
Kasanova vs Other Non-Custodial Wallets
Most Non-Custodial:
Also client-side crypto
May phone home with data
May track analytics
Varies by wallet
Kasanova:
Client-side crypto
Minimal data collection
Transparent about what we see
Privacy-focused design
Limitations
What We Can't Guarantee:
Blockchain is public (by design)
Your device security (your responsibility)
Your seed phrase storage (your responsibility)
Third-party wallet privacy (if you import seed phrase elsewhere)
Your Responsibilities:
Secure your device
Protect seed phrase
Understand blockchain is public
Practice good privacy hygiene
Trust but Verify
Open Source (Future):
Plans to open source client code
Community can audit
Verify privacy claims
Build trust
For Now:
Our architecture is client-side
Servers are stateless
No databases of user data
Verifiable by testing (try monitoring network traffic)
Next Steps
Last updated