Privacy Policy
Effective: 25 July 2026 · Applies to riddlewallet.com and suite apps
1. Who we are
“Riddle”, “Riddle Wallet”, and the suite apps (Swap, Bridge, Creator, Scanner, Cafe, and the hub at riddlewallet.com) are referred to as we / us. Wallet lives at wallet.riddlewallet.com.
2. What we collect
Depending on how you use the products, we may process:
- Technical data — IP address, browser type, device, pages viewed, and basic logs from hosting (e.g. Vercel) for security and reliability
- Wallet-related public data — classic addresses, transaction hashes, and payloads you choose to create or sign (public blockchain data is not private by nature)
- Communications — email content you send to hello@riddlewallet.com
- Local storage — preferences or caches stored in your browser (e.g. token catalog cache on Swap)
We do not ask for or store seed phrases, private keys, or recovery words. If anyone claiming to represent Riddle asks for them, do not share — contact hello@riddlewallet.com.
3. How we use data
- Operate and secure the websites and APIs
- Improve product performance and fix bugs
- Respond to support and partnership requests
- Comply with law and prevent abuse
4. Third parties
Our apps may call or load services such as:
- Hosting and CDN (e.g. Vercel)
- Public XRPL infrastructure and indexers (e.g. xrpl.to, public websockets)
- Xaman / Xumm for signing payloads (subject to their policies)
- Fonts or analytics if enabled in a given deployment
Those providers process data under their own terms. Blockchain transactions are public and permanent.
5. Cookies & local storage
We use storage required for the apps to function. Optional analytics storage is used only after you accept via the consent banner. We do not sell personal data. You can clear site data in your browser at any time.
Strictly necessary (always used)
| Name | Where | Purpose |
|---|---|---|
riddle_wallet_session | Cookie / storage | Wallet session continuity |
rdl_sess | Cookie / storage | Suite session marker |
riddle_dev_entitlement_v1 | localStorage | DevTools entitlement cache |
rdl_dev | Cookie / storage | Dev surface flags |
rdl_consent | Cookie + localStorage | Stores your analytics consent choice |
Re-auth timestamps | localStorage / session | Idle re-auth and session safety |
Optional (consent-gated)
Vercel Analytics — anonymous usage metrics. Loaded only after you accept analytics in the consent banner.
6. Analytics disclosure
Optional analytics load only after you accept analytics in the suite consent banner. If you reject optional cookies, or have not yet chosen, we do not inject the analytics script.
7. Your data rights
- Email hello@riddlewallet.com for support correspondence we hold
- Stop using the sites and clear browser storage at any time
- Use privacy features of your wallet and OS
8. Retention
Server logs are retained only as long as needed for operations and security. Emails to hello@riddlewallet.com are retained as needed to handle your request. Local strictly-necessary keys remain until you clear site data or sign out where applicable.
9. Children
The suite is not directed at children under 16 (or the age of digital consent in your region). Do not use the services if you are under the applicable age.
10. Changes
We may update this policy. The “Effective” date at the top will change when we do. Continued use after updates means you accept the revised policy.
11. Contact
Privacy requests: hello@riddlewallet.com