01General Provisions
Safe Core Labs Co., Ltd. (the "Company") takes the protection of users' personal information seriously and complies with the Personal Information Protection Act and all relevant regulations. This policy explains how personal information is collected, used, and protected.
02Information Collected
The Company collects the minimum personal information required to provide the service (such as email and inquiry content) and information automatically generated in the course of service use (cookies, access logs, and similar).
03Purpose of Use
Personal information is used solely for service provision, responding to inquiries, service improvement, and compliance with applicable laws.
04Retention and Disposal
The Company disposes of personal information without delay once the purpose of collection has been fulfilled, except where retention is required by law.
05Disclosure to Third Parties
The Company does not disclose personal information to external parties, except where the user has given prior consent or where required by law.
06Processing Delegation
The Company delegates the processing of personal information only within the minimum scope required for service operation, and discloses the processor and the delegated work as follows while supervising them in accordance with applicable laws. Processor: Amazon Web Services (AWS, Seoul region) · Delegated work: server and data hosting. Any change to the delegation will be announced through this policy.
07User Rights
Users may request access to, correction of, deletion of, or suspension of the processing of their personal information at any time. The Company will act without undue delay.
08Safeguards
The Company implements technical, administrative, and physical measures — including access control, encryption, and access logging — to ensure the security of personal information.
09Cookies
The Company may use cookies to improve the service and user experience. Users may disable cookies through their browser settings.
10Privacy Officer & Contact
The Company designates the following Privacy Officer responsible for overseeing personal information processing. Privacy Officer: Sage Lee · Title: CEO · Contact: master@safecorelabs.com · Tel. +82-10-5969-7876. Please direct privacy-related inquiries, complaints, and remedy requests to the contact above.
11Remedies for Rights Infringement
Data subjects may apply to the following authorities for dispute resolution or consultation regarding personal information infringement: Personal Information Dispute Mediation Committee (kopico.go.kr / +82-1833-6972), Personal Information Infringement Report Center (privacy.kisa.or.kr / 118), Supreme Prosecutors' Office Cybercrime Investigation (spo.go.kr / 1301), and National Police Agency Cyber Bureau (ecrm.police.go.kr / 182).
SafeWallet Mobile Application — Supplementary Notice
This addendum applies exclusively to SafeWallet (Android · iOS), the non-custodial TRON USDT wallet application provided by the Company. In the event of any conflict with the main body, this addendum prevails with respect to SafeWallet.
A1Non-custodial Architecture
- SafeWallet does not transmit or store the user's seed phrase (mnemonic), private key, or PIN to or in any Company server or external system.
- These secrets are kept only in the device's secure area — Android Keystore (StrongBox preferred) or iOS Secure Enclave / Keychain — protected with authenticated encryption (AEAD, AES-GCM).
- The user bears sole responsibility for backing up and safeguarding the seed phrase. If lost, the Company cannot recover the associated assets.
A2Mobile Permissions and Purposes (Android · iOS)
SafeWallet uses mobile permissions or system APIs only for the features listed below. Camera frames are processed on-device only; images and preview frames are never stored or transmitted.
| Feature | Android | iOS | Purpose | External Transmission |
|---|---|---|---|---|
| Camera (QR scanning) | CAMERA | NSCameraUsageDescription | Scan TRON wallet address QR codes when sending or receiving | None |
| Notifications | POST_NOTIFICATIONS | UNUserNotificationCenter (user consent) | Transaction progress and completion alerts | Push token |
| Network | INTERNET, ACCESS_NETWORK_STATE | URLSession (no separate permission) | Query balances and transactions directly from TronGrid (a public blockchain node), and communicate with app services | Wallet public address |
| Haptics | VIBRATE | Core Haptics / UIImpactFeedback | UI haptic feedback | None |
| Background processing | FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC | BGTaskScheduler · Background Modes | Poll for confirmation status after a transfer | Wallet public address |
A3Information Processed by the Company
Due to the non-custodial architecture, seed phrases, private keys, and PINs are never processed. Transaction information such as balances, transfers, and swaps is queried directly by the user's app from TronGrid (a public blockchain node) and is neither stored nor handled by Company servers. The Company processes only the following:
- Wallet public address — public information observable by anyone on the blockchain
- Identity verification token (hash) — a hashed identifier derived from Korean mobile identity verification (KCP). The Company does not store source identity data such as name, date of birth, or contact number; it retains only the hash to prevent duplicate sign-ups and protect accounts.
- Anonymous diagnostic data for application stability analysis
A4Third-party Service Integrations
| Service | Purpose | Information Shared |
|---|---|---|
| TronGrid (TRON Foundation) | TRON blockchain queries | Wallet public address |
| ExchangeRate-API | USD ↔ KRW exchange rates | None |
| Binance Public API | TRX/USDT market price | None |
| SunSwap V2 (TRON DEX) | On-chain token swaps | Wallet public address, swap parameters |
A5Data Retention and Disposal
- When the user deletes the app, the seed phrase, private key, and PIN held on the device are immediately and permanently erased.
- The wallet public address and identity verification hash retained on Company servers are kept for three (3) years from the user's last use, after which they are disposed of.
- Users may request deletion of the wallet public address and identity verification hash stored on Company servers directly, via the in-app 'Delete Wallet' function or by emailing master@safecorelabs.com; the Company will dispose of such data without delay unless a retention obligation applies under applicable law.
A6Notice of Policy Changes
If this policy is amended, notice will be provided through the Company website and the SafeWallet in-app notice board at least seven (7) days before the effective date — or thirty (30) days for material changes.
A7Cross-border Transfer of Personal Information
SafeWallet's blockchain/price lookup and swap features may communicate with third-party services located outside Korea (TronGrid, ExchangeRate-API, Binance, SunSwap, and similar). The information transferred is limited to the publicly visible wallet address and transaction request data on the blockchain. Sensitive information such as the seed phrase, private key, and PIN is never transferred, whether domestically or abroad.
Effective date of addendum: May 4, 2026