Google OAuth Permissions
& Privacy Policy
Last updated: July 15, 2026 Effective: July 15, 2026
Safewire Technologies Ltd, "Safewire", "we", "us") operates the Safewire NBC Wallet and the Safewire Merchant Terminal (together, the "Apps"). This policy explains what we collect, what we do not collect, and how we handle data you connect to the Apps — including data from your Google Account.
1. The short version
Safewire is non-custodial. Your cryptographic keys are generated on your device and stay on your device. We cannot move, freeze, or access your funds, and we cannot read your wallet backup. This is enforced by architecture, not by promise: the private keys and recovery material never exist anywhere in the Safewire systems.
2. Information we collect
2.1 Information you provide
Data Why we need it Where it lives
Email address Account sign-in, security notices Safewire servers
Name Account identification Safewire servers
Phone number (optional) Two-factor authentication Safewire servers
Business details Merchant onboarding, compliance Safewire servers
​
2.2 Information collected automatically
-
Public blockchain addresses you enroll (public data only — never private keys)
-
Device type, operating system, and app version
-
Diagnostic and crash logs
-
IP address and approximate region, for fraud prevention and security
2.3 What we never collect
We do not collect, receive, transmit, or store:
-
Private keys
-
Seed phrases or mnemonics
-
Wallet recovery passwords
-
Any material that could be used to sign a transaction on your behalf
None of the above exists in Safewire code, environment variables, secret storage, or databases. Every movement of funds requires a signature you produce on your own device.
3. Google user data
This section describes how the Safewire NBC Wallet accesses, uses, stores, and shares data from your Google Account. It applies only if you choose to enable Google Drive backup. The feature is optional and off by default.
3.1 What we request, and why
The Wallet requests exactly one Google Drive permission:
Scope What it grants
https://www.googleapis.com/auth/drive.file Create files in your Google Drive, and access only those files the Wallet itself created
We also receive your Google Account email address and basic profile information as part of signing in to Google, so we can show you which account the backup is attached to.
We request this scope so you can store an encrypted backup of your wallet recovery data in your own Google Drive, and restore your wallet on a new device if you lose or replace your phone.
​
3.2 What this permission does not allow
The drive.file scope is narrowly limited by Google's own design. Using it, the Wallet cannot:
-
See, read, or list any of your existing Google Drive files
-
Access photos, documents, spreadsheets, or any other content in your Drive
-
Access files created by any other application
-
Share anything from your Drive with anyone
The Wallet can only see the backup files it created itself. Everything else in your Drive is invisible to it.
We deliberately chose the narrowest scope capable of supporting this feature. We do not request broader Drive access, and the Apps have no functionality that would use it.
​
3.3 How the backup is stored
-
Your recovery data is encrypted on your device, before anything is uploaded, using a key derived from a password that you choose.
-
Only the encrypted result is uploaded — to your Google Drive, saved as a file ending in .safewire_backup. This file is visible in your Drive, and you can move, rename, or delete it like any other file. Deleting it removes your ability to restore from it.
-
The backup never passes through, and is never stored on, Safewire servers.
-
Safewire never receives your backup password and cannot derive it. If you lose that password, neither you nor we can decrypt the backup.
Restoring works in reverse: the encrypted file is downloaded to your device and decrypted locally with your password.
3.4 How we use Google user data
Google user data obtained through the Drive API is used for exactly one purpose: to store and retrieve your encrypted wallet backup, at your request.
We do not, and will not:
-
Transfer or sell Google user data to third parties, including advertising platforms, data brokers, or information resellers
-
Use Google user data for advertising, retargeting, or personalized or interest-based ads
-
Use Google user data to assess credit-worthiness or for lending purposes
-
Use Google user data to train generalized or personalized AI or machine learning models
-
Allow humans to read Google user data
No Safewire employee, contractor, or agent reads the contents of your app-data folder. As a practical matter they could not: the contents are encrypted with a key we do not possess.
The only exceptions to the above are the narrow ones Google's policy permits: where we have your affirmative consent, where it is necessary for security purposes such as investigating abuse, or where we are required to comply with applicable law.
3.5 Limited Use commitment
Safewire's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3.6 Retention and deletion
Your encrypted backup stays in your Google Drive until you delete it. It is your file, in your Drive, under your control.
To remove it and revoke our access:
-
Delete the backup file — either from within the Wallet, or directly in Google Drive by deleting the .safewire_backup file and emptying your Drive trash.
-
Revoke Safewire's access to your Google Account — go to myaccount.google.com/permissions, select Safewire, and choose Remove Access.
Revoking access does not affect your wallet on your device, and it does not affect your funds.
4. How we use your other information
-
To operate, maintain, and secure the Apps
-
To authenticate you and protect your account
-
To communicate service and security notices
-
To detect, investigate, and prevent fraud and abuse
-
To meet legal, regulatory, and compliance obligations
We do not sell your personal information.
5. Sharing
We share information only with:
-
Service providers who help us run the Apps (cloud hosting, blockchain data providers, error monitoring), bound by contract to protect it and use it only for the services they provide to us
-
Authorities, where required by law, valid legal process, or to protect rights and safety
We do not share Google user data with any of them. Your encrypted backup never reaches us in the first place.
6. Security
-
All data in transit is encrypted using TLS
-
All secrets are held in a managed secrets service, never in source code
-
Wallet backups are encrypted on your device before upload, with a key we never see
-
Access to production systems is restricted and logged
No system is perfectly secure, and we cannot guarantee absolute security. But because of the non-custodial design, a breach of Safewire's systems would not expose your keys or your funds — they are not there to expose.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing. To exercise any of these, contact us at compliance@safewireworld.com. We respond within 2 days.
You can exercise your rights over your Google Drive backup directly, at any time, using the steps in section 3.6 — no request to us required.
8. Children
The Apps are not directed to anyone under 16, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact compliance@safewireworld.com and we will delete it.
9. International transfers
Your information may be processed in the Unites States of America. Where we transfer data across borders, we rely on appropriate safeguards as required by applicable law.
10. Changes
We will post any changes to this policy on this page and update the "Last updated" date. For material changes affecting how we handle your data, we will notify you in the Apps or by email before the change takes effect.
11. Contact
Safewire Technologies Ltd
20 Wenlock Road
London
N1 7GU United Kingdom
Privacy Contact: compliance@safewireworld.com
Support: support@safewireworld.com
​