Privacy Policy

Last updated: May 4, 2026

planB values your privacy. This Privacy Policy describes how planB handles personal data when you use the planB mobile application and website (the "App"). Read this Policy together with our Terms of Use. The data controller is OtoCo Base WY LLC – planB – Series 88, a Wyoming-registered series LLC, United States. The same address serves as the public contact for our Data Protection Officer / Encarregado de Proteção de Dados (LGPD): contact@planb.army.

1. Information We Collect

  • Account & contact data (collected by planB): Email address (via Privy login), or Sign in with Apple / Google identifier; optional phone number and any profile information you provide. Used for login, support, security and account-related communications.
  • Technical & log data (collected by planB): IP address (used briefly for security, rate limiting and geofencing), device model, OS version, app version, language, timezone, crash reports and performance data. Used to operate, secure and debug the App. Includes product-interaction events used for analytics.
  • KYC, identity & financial data (collected by partners, not by planB): Full name, date of birth, phone number, physical address, CPF (Brazilian users), government-issued photo ID (RG, CNH or passport), selfie/biometric and bank-account details required for PIX, the planB Visa card and other regulated services. This data is submitted directly to our regulated partners (Avenia — avenia.com — for PIX rails; Gnosis Pay Ltd. — gnosispay.com — and UAB Monavate — monavate.com — for card issuance, and other licensed providers we may engage). planB does not retain copies. On-chain identifiers (your public wallet addresses, transaction history, account balances), your push-notification token and your Privy decentralized identifier (DID) are also processed by planB to operate the App.
  • Self-custody data — NOT collected by planB: Your private keys and recovery phrases for both your USD wallet (EVM embedded wallet via Privy) and your Bitcoin wallet (Bitcoin Layer-2 self-custody) are generated and stored locally on your device. planB does not have access to this data, cannot recover it on your behalf, and cannot move funds without your authorization. This is a fundamental property of self-custody.

2. How We Use Information

  • To provide, maintain, secure and improve the App and the Services.
  • To enable integrations with regulated partners (PIX cash-in/out, card issuance, embedded-wallet authentication).
  • To comply with legal and regulatory obligations applicable to planB or to our partners (KYC, AML/CFT, sanctions screening).
  • To detect, prevent and investigate fraud, abuse, account takeover and unauthorised use.
  • To respond to your support requests and to send service-related communications (security alerts, terms updates, transactional notifications).

3. Data Sharing with Sub-processors

To operate the planB app, we share personal data with sub-processors that deliver essential services. In compliance with LGPD Art. 9, V, we disclose below the categories of sub-processors and the types of data each category processes. We do not sell your personal data and we do not share it for third-party advertising purposes.
Category: Pix processing Identified sub-processor: Avenia (Brazilian payments provider operating within the Brazilian Central Bank regulatory framework via authorized banking partners). Purpose: Pix cash-in and cash-out. Data shared: full KYC data (name, tax ID, address, date of birth, identity documents, selfie), banking data, transaction details.
Category: Visa card issuance Identified sub-processors: Gnosis Pay Ltd. (gnosispay.com) and UAB Monavate (monavate.com - Lithuania, regulated by the Bank of Lithuania) for card issuance. Purpose: issuance and operation of the international Visa card. Data shared: full KYC data, spending and statement data. Card data (number and CVV) is tokenized via the issuer's SDK; planB never has access to this data in plaintext.
Category: Authentication and embedded-wallet management Identified sub-processor: Privy Inc. (authentication provider and custodian of encrypted-shard cryptographic keys under user control). Purpose: app login and user-controlled custody of cryptographic keys. Data shared: email, OAuth identifiers, encrypted private-key shards (under exclusive user control).
Category: Identity verification (KYC) Identified sub-processor: Sumsub (identity verification platform used to capture and verify identity documents and biometrics at onboarding). Purpose: identity verification, document and biometric checks, sanctions and PEP screening at onboarding. Data shared: full KYC data (name, tax ID, address, date of birth, identity documents, selfie/biometric).
The remaining categories of sub-processors that support the app, described as categories without public naming:
Self-custodial cryptocurrency wallet infrastructure providers. Purpose: operation of Bitcoin wallets under user control. Data shared: public wallet addresses and public user-signed transactions.
Decentralized exchange (DEX) aggregator protocols. Purpose: routing and execution of currency conversion operations on public networks (on-chain). Data shared: public wallet addresses, operation parameters, public transactions.
Blockchain data and RPC providers. Purpose: reading balances and public on-chain transaction history. Data shared: public wallet addresses (no personal data).
Application monitoring providers. Purpose: detection and diagnosis of application errors. Data shared: device identifiers, technical error traces, session identifiers. Configured not to capture personal data.
Customer support providers. Purpose: human and AI-assisted chat support. Data shared: support messages voluntarily sent by the user and any contact information voluntarily provided.
Cloud infrastructure providers. Purpose: hosting of the application back-end. Data shared: database encrypted at rest.
Push notification providers. Purpose: delivery of push notifications to the device. Data shared: device push token and notification content.
The specific named list of each sub-processor, along with the corresponding data processing agreements, is available upon request at contact@planb.army. Each sub-processor operates under its own terms of service and privacy policy, and planB selects only sub-processors that provide adequate guarantees in compliance with LGPD. We may also disclose information when required by law, by valid legal process or to protect the rights and safety of planB, our partners or other users; in case of merger, acquisition or sale of assets, data may be transferred to the new entity under the same privacy standards.

4. Your Control

  • You control your wallet and private keys; planB has no access.
  • You can update your account data and request a copy or deletion of the personal data planB controls by writing to contact@planb.army.
  • To access or delete KYC/identity data submitted to a regulated partner you must contact the partner directly — those records are controlled by the partner under their own privacy policy.

5. Data Security

  • planB applies the security controls described in our Information Security Policy (see planb.army/security).
  • However, no system is 100% secure. You are responsible for securing your device, wallet credentials and recovery phrase.

Information Security Policy: For details on our security controls and the role of our regulated partners, read the Information Security Policy.

6. Blockchain & Data Rights

Transactions executed through the App are recorded on public blockchains. By the technical design of those networks, on-chain data — including your public wallet address and transaction history — is public, immutable and outside planB's control. As a consequence, planB cannot delete, anonymise, alter or restrict on-chain records, and data-protection rights such as the LGPD right to deletion apply only to data held in planB's own systems and cannot be enforced over public-blockchain records.

7. Your Rights — LGPD (Brazil)

If you are a data subject in Brazil, the Brazilian General Data Protection Law (Law nº 13.709/2018 — "LGPD") gives you the following rights with respect to personal data planB processes about you:

  • Confirmation that processing exists and access to your personal data.
  • Correction of incomplete, inaccurate or out-of-date data.
  • Anonymisation, blocking or deletion of unnecessary data, excessive data, or data processed in non-compliance with the law (subject to legal retention obligations).
  • Portability of your data to another service provider, in accordance with ANPD regulations.
  • Information on the public and private entities with which planB has shared your data.
  • Information about the possibility of refusing consent and the consequences of such refusal.
  • Withdrawal of consent at any time, without prejudice to processing carried out before withdrawal.

planB relies on the following legal bases under LGPD: (i) your consent (e.g. for marketing communications); (ii) execution of a contract or pre-contractual procedures (to provide the App and the Services); (iii) compliance with legal or regulatory obligations (KYC/AML are operated by our partners); (iv) legitimate interests of planB or third parties, balanced against your rights and freedoms; and (v) regular exercise of rights in judicial, administrative or arbitration proceedings. To exercise your LGPD rights, write to contact@planb.army.

Response time: planB will respond to your LGPD rights request within 15 days of receipt of a complete request, in line with ANPD guidance.

8. Your Rights — Other Jurisdictions

planB is launched in Brazil and the privacy framework above is built around the LGPD. If you are a data subject in a jurisdiction other than Brazil (including the European Economic Area, the United Kingdom, the United States, Canada or other markets), the data-protection rights available to you depend on the law of your residence. planB will respond in good faith to lawful data-protection requests. Note that some Services available through the App are provided by partners that may process your data under their own jurisdictional regimes; for those Services, the partner's privacy policy applies in addition to this Policy. To exercise such rights, write to contact@planb.army.

9. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy and to comply with our legal obligations. Specific retention periods:

  • Account data (email, profile) — While the account is active + 30 days after deletion.
  • KYC documents (held by Avenia, Gnosis Pay, UAB Monavate and Sumsub) — 5 years after account closure (Brazilian Banco Central regulatory obligations).
  • Transaction history on planB servers — 5 years after account closure (tax / AML obligation).
  • On-chain transactions — Permanent and public on the blockchain. planB cannot delete them.
  • Crash and performance data — 30 days.
  • Customer-support chat history — 12 months after the last interaction.
  • Application logs (security, rate limiting) — Up to 90 days, then aggregated/anonymised.

10. Cookies & Web Analytics

The planb.army website uses Google Analytics (tracking ID `G-QQT0QT7DZR`) to understand aggregated usage patterns. The mobile App does NOT use cookies. You can opt out of Google Analytics tracking by installing the [Google Analytics Opt-out Browser Add-on](https://tools.google.com/dlpage/gaoptout). Your right to be informed about and to refuse cookies is respected; see our LGPD rights section above.

11. Account Deletion

You can delete your planB account at any time directly in the App: open Settings → Security → Delete Account. A 7-day grace period applies — you may cancel the deletion by signing back in within that window. After the grace period, your data is permanently deleted in accordance with the retention table in §9. You can also request deletion by writing to contact@planb.army. Important: deleting your planB account does NOT delete your funds on the blockchain. Withdraw your USD and Bitcoin to another wallet you control BEFORE deleting your account, otherwise you risk losing access to those funds (because we never had your keys to recover them).

12. Children's Privacy

The App is not intended for individuals under 18 (KYC verification requires legal majority). planB does not knowingly collect personal data from minors. If you believe a minor has provided personal data, please contact contact@planb.army so we can take appropriate action.

13. Changes

planB may update this Privacy Policy from time to time. The most recent version published at planb.army/privacy supersedes any previous version. Continued use of the App after an update constitutes acceptance of the updated Policy.

14. Contact

Privacy questions, data-protection requests and complaints can be sent to:

📧 contact@planb.army