Home/Privacy Policy

Privacy Policy

Last updated: January 2025

1. Introduction

CC Bot Wallet ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we handle information when you use our self-custodial cryptocurrency wallet service on Telegram, built on Canton Network.

2. Self-Custodial Nature

CC Bot Wallet is a self-custodial wallet using 2-of-3 Shamir Secret Sharing. This means:

  • check_circleYour Ed25519 private key is split into three shares. We only hold one encrypted share
  • check_circleWe cannot reconstruct your key or access your funds with a single share
  • check_circleYou have full control and responsibility over your assets
  • check_circleRecovery requires your Passkey. We cannot recover your wallet alone

3. Information We Collect

Due to our self-custodial architecture, we collect minimal information:

  • Telegram User ID: To identify your wallet within the Telegram Mini App
  • Public Wallet Address: To facilitate transactions on Canton Network
  • Encrypted Server Share: One of three Shamir shares, stored in AES-256-GCM encrypted form
  • CNS Names: If you register a Canton Name Service identifier

4. Information We Do NOT Collect

  • cancelComplete private keys (only one encrypted share)
  • cancelPINs or Passkey credentials (processed locally on your device only)
  • cancelBiometric data (processed locally by your device)
  • cancelPersonal identification documents

5. How We Use Information

The limited information we collect is used to:

  • check_circleProvide and maintain our wallet services
  • check_circleProcess transactions on Canton Network
  • check_circleEnable username-based transfers within Telegram
  • check_circleProvide customer support when requested

6. Data Security

We implement the following security measures:

  • check_circleAES-256-GCM encryption for stored key shares
  • check_circleWebAuthn / Passkey authentication support
  • check_circlePIN brute-force protection with progressive lockouts
  • check_circleRate limiting on all sensitive API endpoints
  • check_circleZero-memory key handling. Keys never stored in plaintext

7. Third-Party Services

Our service integrates with:

  • Telegram: For the Mini App platform
  • Canton Network: For blockchain transactions
  • Circle & xReserve: For cross-chain bridging

Please review their respective privacy policies for information about their data practices.

8. Your Rights

You have the right to:

  • check_circleExport your wallet data at any time
  • check_circleDelete your account and associated data
  • check_circleAccess information we have about you
  • check_circleOpt-out of non-essential communications

9. Contact Us

If you have questions about this Privacy Policy:

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of any material changes through our Telegram channel or within the app. Your continued use of CC Bot Wallet after changes constitutes acceptance of the updated policy.