summo

Privacy Policy

Version 1.0, effective May 19, 2026

About this policy

This Privacy Policy explains what information Keyjen Limited (“Keyjen,” “Summo,” “we,” “us,” or “our”) collects about you, how we use it, who we share it with, and the choices you have. It applies to the Summo mobile application, the summo.cash website, and the related services we provide (together, the “Service”). Capitalized terms not defined here have the meaning given in our Terms of Service.

A few principles we want to be clear about up front: we don’t sell your personal information, we don’t share it with advertisers for cross-context behavioral advertising, and we don’t use it to train AI models.

If you are in the European Economic Area, the United Kingdom, or Switzerland, Keyjen Limited is the controller of your personal information for purposes of applicable data-protection law. If you are in California, Keyjen Limited is the “business” with respect to your personal information.

Who we are

Keyjen Limited is a Delaware corporation based in the United States. Summo is our product.

Questions, requests, or complaints? [email protected].

Information we collect

We collect the categories of information described below. We collect only what we need to run the Service, keep it secure, and improve it.

Account information. When you create a Summo account, we collect (a) an email address that you provide directly, or an Apple-relayed email if you sign in with Apple; (b) a user identifier from the identity provider you used to sign in; and (c) any display name you choose. We use these to identify your account and to send you transactional and product communications.

Wallet and blockchain data. Summo is non-custodial, so we don’t hold your private keys or any backup of your seed. We do record information that’s necessary to operate the Service, including (a) the public blockchain addresses associated with your Summo account, including your smart-account address and any externally owned accounts (EOAs) used as signers; (b) public on-chain activity for those addresses (balances, transactions, swap and bridge activity, and similar), which we read from blockchain RPC endpoints and indexers; and (c) off-chain operational metadata that the app needs to function, including your selected display currency, guardian relationships, gas-sponsorship records, and notification preferences. Public blockchain data is, by definition, public; anyone with the address can observe the same activity.

What we never collect or store. We do not collect or store your seed phrase, your backup key, or the private key on your device. Those stay on your device and with you.

Device, log, and security information. When you use the app or the website, our servers and our infrastructure providers automatically receive device identifiers, push-notification tokens, device model, operating system, and app version; IP address and approximate (country/region-level) location derived from IP; timing and metadata of your requests, including endpoints accessed, response codes, and error messages; and network and security signals used to detect abuse, fraud, and unauthorized access.

Product analytics. We collect product-analytics events (for example, which screens you visit, which features you use, and which buttons you tap) to understand how the Service is used and to improve it. Analytics events do not include your private keys or backup material. Where consent is required by law (such as in the EU/EEA, UK, or Switzerland), we collect analytics only after you accept the in-app or on-site consent prompt.

Communications. If you contact us by email or through an in-app form, we receive the content of your message, your email address, and any other information you choose to share.

On-ramp and off-ramp information. If you use a fiat on-ramp or off-ramp provider through the Service to convert between local currency and crypto, that provider collects information directly from you (including, in many cases, identity-verification information) to comply with its own legal obligations. We receive only the operational information we need to display status and history in the app, such as the timing, amount, asset, status, and the blockchain address used for that transaction. We do not collect copies of your government ID or other identity-verification documents that you submit to that provider. The on-ramp provider is the controller of the identity information you give it, and its own privacy policy applies.

Information you choose to give us. You may choose to give us additional information (for example, a profile photo, a display name, or content you submit through optional in-app features).

We don’t collect precise (GPS) location, contacts, photos, microphone, or camera input unless you give us explicit operating-system permission for a feature that needs it.

How we use your information

We use the information we collect to:

  • operate the Service, including account creation, transaction relaying, gas abstraction, notifications, and customer support;
  • detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service;
  • comply with our legal obligations, including sanctions screening (using your IP-based country signal) and responses to lawful requests;
  • send you transactional communications about your account and the Service, and product communications you can unsubscribe from at any time;
  • understand and improve the Service through product analytics (where consent is required, only after you accept); and
  • develop new features and content.

We do not use your information for cross-context behavioral advertising. We do not use your information to train AI models.

Legal bases (EU/EEA, UK, Switzerland). Where data-protection law requires a legal basis, we rely on (a) performance of a contract with you (operating the Service); (b) our legitimate interests in keeping the Service secure, preventing fraud, and improving the Service, balanced against your rights; (c) your consent, which you can withdraw at any time (analytics in regions where consent is required); and (d) compliance with legal obligations (sanctions screening, recordkeeping, lawful requests).

How we share information

We don’t sell your personal information. We share information only as described below.

Service providers. We share information with vendors who process data on our behalf, under contract, only for the purposes we direct. Vendors fall into the following categories:

  • Cloud infrastructure and hosting: servers, databases, object storage.
  • Content delivery, DDoS protection, and security tooling: the network and security layer in front of our site and APIs.
  • Product analytics: used to understand aggregate usage patterns and improve the Service, with EU data residency where available.
  • Push notifications: delivery of notifications to your device when something needs your attention.
  • Transactional and product email: delivery of email related to your account and the Service.
  • Identity providers (including Apple Sign In): used by you to sign in to the Service.
  • Blockchain RPC providers, indexers, and bundlers: used to read and submit on-chain transactions on the public network on your behalf.
  • On-ramp and off-ramp providers: used if you choose to convert between fiat currency and crypto.
  • Customer-support and error-monitoring tooling: used to respond to support requests and diagnose issues.
  • Professional services: accountants, lawyers, and auditors who advise us under confidentiality obligations.

Third-party protocols you choose to use. When you use a third-party decentralized protocol through the Service (for example, a swap router, bridge, or perpetual-futures venue), the information necessary to carry out your instructions is transmitted to the relevant smart contracts, public blockchain networks, and (where applicable) the operator of that protocol. That information may include your blockchain addresses and the parameters of your transaction. Public blockchain data is, by its nature, public.

Legal and safety. We may disclose information to law enforcement, regulators, courts, or other parties when we believe in good faith that disclosure is required by law, necessary to comply with legal process, necessary to enforce our Terms of Service, or necessary to protect the rights, property, or safety of Summo, our users, or others.

Business transactions. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, your information may be transferred as part of that transaction, subject to standard confidentiality protections.

With your consent. We may share information for other purposes with your consent.

Public on-chain activity

Public blockchains are, by design, publicly readable. Anyone who knows a blockchain address can see the transactions associated with that address. We do not control public blockchain data, and we cannot delete it. You should treat your blockchain addresses and on-chain activity as public information.

Cookies and similar storage

The website uses first-party cookies and browser storage minimally. We don’t use third-party advertising cookies, and we don’t track you across other apps or websites.

  • Consent preference: when the cookie banner is shown to you, your accept/decline choice is stored locally in your browser (in localStorage) so we don’t ask again every visit.
  • Analytics cookies: set by our analytics provider so we can understand which pages and features people use. In regions that require explicit consent (such as the EU/EEA and UK), these are set only after you accept the banner. You can decline at any time.

The mobile app uses standard mobile-operating-system storage (Keychain, the secure enclave, and the app’s sandboxed file system) for data that needs to persist between sessions. The mobile app does not use third-party advertising SDKs.

How long we keep it

We keep your information only for as long as we need it for the purposes described above and to comply with our legal obligations.

  • Account information: while your account is active, and for a reasonable period after closure to handle final operations and meet legal obligations.
  • Wallet and operational metadata: while your account is active. Public on-chain data persists on the public blockchain indefinitely and is outside our control.
  • Logs and security signals: short-term, typically less than ninety (90) days, except where retained for a specific incident investigation or to meet a legal obligation.
  • Analytics: aggregated or de-identified analytics data may be kept for longer to support trend analysis.
  • Communications: for as long as we reasonably need to respond and to maintain a record of the interaction.

If you ask us to delete your data, we will, subject to the exceptions above.

Your rights

Depending on where you live, you have rights to access, correct, delete, export, restrict, or object to certain uses of your personal information, to withdraw consent you have previously given, and to lodge a complaint with your data protection authority.

To exercise any of these rights, email [email protected]. We may need to verify your identity before acting on a request. We’ll respond within the time required by applicable law (generally 30 to 45 days).

California residents. The California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), gives California residents the rights above, plus the right to opt out of “sale” or “sharing” of personal information and the right to limit use of “sensitive personal information.” We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We honor Global Privacy Control (GPC) signals where applicable. To exercise CCPA rights, email [email protected].

EU/EEA, UK, Switzerland. You have the rights described above under the GDPR, the UK GDPR, and the Swiss FADP. You can contact your local data-protection authority if you believe we have not complied.

Marketing. You can opt out of product email at any time through the unsubscribe link in any product email or in your account settings.

International transfers

Keyjen Limited is based in the United States, and our service providers operate in multiple countries. Your information may be transferred to and processed in the United States and other countries, which may have different data-protection laws than your country. Where required, we use lawful transfer mechanisms such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent safeguards.

Security

We use technical and organizational measures designed to protect your information, including encryption in transit, access controls, secret-management via key-vault infrastructure, and audit logging. No system is perfectly secure. You can help protect yourself by keeping your device passcode and biometric lock on, keeping the app and your operating system up to date, and choosing trustworthy guardians.

Because Summo is non-custodial, the security of the funds in your smart account depends on the security of your keys, your device, and your guardians, all of which are your responsibility. We cannot recover funds lost as a result of compromised keys, lost devices, or compromised guardians.

Children

The Service isn’t intended for users under 18. We don’t knowingly collect personal information from anyone under 18. If you believe a child under 18 has provided us with personal information, please contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will post the updated policy in the app and on summo.cash, and we will update the “Effective” date above. For material changes, we will give you reasonable advance notice in the app, by email, or by another method we consider appropriate, before the changes take effect. Continued use of the Service after the updated policy takes effect means you accept it.

Contact

Keyjen Limited
For privacy questions, data requests, or anything else: [email protected]