Draft: Complete and verify the operator's name and postal address, hosting, actual server logs, recipients and retention periods before public release.
[Insert full legal name/company and postal address]
Thomas@stompi.de
Recovery words are stored encrypted using Android Keystore on the device. The app does not transmit recovery words or private keys to Stompi servers. Saved contact names and recipient addresses stay on the device and are not synchronised with the server. Deleting a wallet removes its locally encrypted wallet data and associated contacts on that device. This does not erase existing backups or published blockchain transactions.
The app requests confirmed activity, available outputs for the first address, and news from stompi.tech over HTTPS. The servers receive the queried public Stompi address and connection data including your IP address. When sending, the app transmits a locally signed raw transaction to the Stompi server for broadcast to the network. Transaction information is publicly traceable; recovery words are not transmitted. Public blockchain data may be linked to a person and cannot be deleted by us from independent nodes.
If you enable notifications, the app periodically checks news and confirmed incoming payments to the first receiving address. These checks run on your device against public HTTPS endpoints. Android and, where applicable, Google services may support notification delivery. You can disable this feature in the app settings.
The app's own code contains no advertising or analytics SDKs. [Verify hosting, reverse proxy, bundled libraries and their actual data handling; specify server logs, purposes, GDPR Article 6 legal basis, recipients, international transfers, retention periods and deletion procedures.]
Subject to GDPR conditions, you may request access, rectification, erasure, restriction or portability, object to processing and lodge a complaint with a supervisory authority. Contact Thomas@stompi.de. [Insert competent authority.] You can remove local app data by deleting the wallet or the app; public blockchain records remain in the network.
Last updated: 1 October 2026. These sections supplement the existing information about the controller, hosting, explorer, payments and data protection rights.
The app creates a separate access key in Android Keystore. This is not a wallet key. Its private part is not sent to the server. On its first successful connection, the app sends the public access key and a signed proof of possession to stompi.tech. The server stores the public key, a derived installation identifier, registration time and any revocation status. Our app code does not request a hardware identifier or Google account. The installation identifier is pseudonymous; it is not an anonymous statistic.
Registration is attempted automatically when the app opens. If it fails, the app retries on the next launch or payment attempt. Local wallet functions remain available offline. The new mobile broadcast endpoint requires successful registration. Deleting one wallet does not delete the installation registration.
Before sending, the app submits its installation identifier, the SHA-256 hash of the signed transaction and an access proof. The server issues a random challenge valid for 90 seconds. The app signs the challenge together with the transaction hash and submits the signed raw transaction. The server checks the access proof and then checks the transaction using the node. These data can associate transactions with an installation. The blockchain transaction is still signed locally using wallet keys.
The website publishes only the total number of registered installation keys. Public keys, identifiers and registration timestamps are not published in that counter. A key counts once. Reinstallation, Keystore loss or clearing app data may result in another registration. This is not an exact count of people or Google Play users.
The current server version does not automatically delete registrations after a fixed period. They remain until administrative deletion. Revocation blocks access but retains the record. Successfully used challenges are removed; expired records are cleaned up during subsequent challenge or broadcast requests. The 90-second validity is not a guaranteed physical deletion deadline. Technical rate-limit counters are cleaned during subsequent requests. Server and proxy logs are covered by the existing hosting and logging information in this notice.
For access, deletion or objection requests concerning server-side registration, contact Thomas@stompi.de. Deletion does not prevent the app registering again later. We cannot remove published blockchain transactions from independently operated nodes.
Optional scanning uses Google Code Scanner through Google Play Services. Google states that image processing takes place on the device and that the scanner does not store image data or scan results. Once a scanned address is used, public addresses and signed transactions may be sent to Stompi as described above. The scanner module may be downloaded on first use. Manual address entry remains available without compatible Google services. Receiving QR codes are generated locally.
Google also documents collection of technical device and app information, device or installation identifiers, performance measurements and feature/error events for ML Kit diagnostics and usage analytics. The app does not enable automatic zoom. Google processing and any international transfers must be assessed against the SDK version and Google services in use. Further information: Google: ML Kit data disclosure, Google Code Scanner and Google Privacy Policy.
Optional app protection uses Android device authentication, such as a fingerprint or device PIN. Stompi receives no fingerprint templates or device PIN, only an authentication result. Language, display preferences, contacts and payment status are stored locally. The app does not offer user-account sign-in.