Privacy
Privacy, to us, means control over your information, not a promise of anonymity.
We think you should be able to compare exchange rates without handing over more information than the comparison actually requires. Here is what that means in practice.
- We collect as little as reasonably necessaryComparing quotes does not require an account, a wallet connection, or any personal information from you.
- No WalletExchange account requiredYou can compare live quotes from ChangeNOW, SimpleSwap, and StealthEX without signing up for anything.
- We never ask for seed phrases or private keysWalletExchange never requests, handles, or stores this information, for any reason.
- No unnecessary wallet profilingWe do not build profiles of your wallet activity from the quotes you compare.
- Provider identity and KYC policies varyChangeNOW, SimpleSwap, and StealthEX each set their own identity-verification requirements, and those requirements can depend on the amount, the assets, or the jurisdiction involved. WalletExchange does not control this and shows only what each provider actually discloses.
- Control, not guaranteed anonymityWalletExchange helps you understand what a provider may require before you choose it. It is not an anonymity service, and we do not make claims about untraceable transactions or evading identity checks.
What we actually collect and why
- Quote requestsWhen you compare rates, WalletExchange sends the asset pair and amount you entered to each provider’s quote API to retrieve live rates. This does not require your address or any personal information.
- Transaction data, only when you choose to proceedIf you continue to create a real exchange, we collect what the provider needs to create it: the destination address (and network), the amount, and an optional refund address if you supply one. This is sent directly to the provider you selected over an authenticated API connection so they can create your exchange — it is not sold or shared for any other purpose.
- Wallet and address handlingWalletExchange never asks for, receives, or stores your private keys or seed phrase, under any circumstance. Deposit and destination addresses are used only to request and track the exchange you initiate. Where addresses appear in our own operational logs, they are partially masked before being written.
- Duplicate-submission protectionTo prevent accidentally creating two exchanges from one attempt (for example, a double click or a network retry), a short-lived record is kept identifying that attempt. A record for an exchange still in progress is kept for up to 5 minutes; a record of a finished attempt (successful or failed) is kept for up to 24 hours so a genuine retry returns the original result instead of creating a duplicate, then it is automatically deleted. These records never contain a private key and hold only the same non-secret details as the exchange itself.
Sharing with providers
To retrieve quotes and, if you proceed, to create an exchange, WalletExchange sends the necessary trade details to the provider you selected (currently ChangeNOW, SimpleSwap, or StealthEX) over an authenticated API connection. We do not share your data with providers you did not select, and we do not sell your data to third parties for advertising or any other purpose. Once your exchange reaches a provider, that provider’s own privacy policy governs how they handle your information from that point — see the provider policy panel on the Exchange page for links to each provider’s current policy.
Cookies and analytics
WalletExchange does not run third-party analytics or advertising trackers. Standard WordPress technical cookies may be set to support core site functionality (such as security nonces); these are not used to build advertising profiles or track you across other sites.
Logs and security
Server-side operational logs are written for debugging and reliability purposes only. Before anything is logged, API keys, authorization headers, and similar secrets are automatically redacted, and wallet addresses are partially masked. Connections to WalletExchange and to provider APIs use HTTPS/TLS. Provider API credentials are stored in server-side configuration and are never exposed to the browser, to logs, or to any page you can view.
Contact
Questions about this policy or your data can be sent to privacy@walletexchange.com.
