WYRR ("we," "our," or "us") operates the WYRR mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
Summary: WYRR collects location, device, financial, and usage data to power its marketplace, gig economy, AR, and crypto wallet features. We do not sell your personal data. You can request deletion of your data at any time.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, phone number, profile photo.
- Financial & Wallet Data: Cryptocurrency wallet addresses, transaction history, payment method details processed via Stripe. We never store your private keys or recovery phrases on our servers.
- Contacts: With your permission, we access your device contacts to help you find other WYRR users.
- User Content: Marketplace listings, reviews, messages, and gig postings.
- Identity Verification: Biometric authentication data (Face ID / Touch ID) is processed entirely on your device by Apple's Secure Enclave. We do not receive or store biometric templates.
1.2 Information Collected Automatically
| Data Type | Purpose | Linked to Identity |
| Precise & Coarse Location | AR contract discovery, nearby user features, gig matching | Yes |
| Device Identifiers | Analytics, fraud prevention | Yes |
| Usage Data / Product Interaction | App improvement, personalization | Yes |
| Crash & Performance Data | Diagnostics, stability | No |
| Bluetooth & NFC Data | Peer discovery, wallet address exchange, mesh networking | No |
| Camera & AR Data | QR scanning, AR contract discovery, profile photos | No |
| Motion & Sensor Data | Step tracking, shake gestures, AR navigation | No |
| Microphone / Speech | Voice commands for AR hands-free navigation | No |
1.3 Blockchain Data
Blockchain transactions are inherently public. When you initiate on-chain transactions through WYRR, your wallet address and transaction details are recorded on the public blockchain. This data cannot be deleted or modified by us or anyone else due to the immutable nature of distributed ledger technology.
2. How We Use Your Information
- Provide, maintain, and improve the Service.
- Process marketplace transactions and gig payments.
- Enable AR contract discovery and location-based features.
- Facilitate peer-to-peer connections via Bluetooth, NFC, and mesh networking.
- Authenticate your identity and secure your wallet.
- Send transaction confirmations, service updates, and (with consent) promotional communications.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
- Personalize your experience (with your tracking consent via Apple's App Tracking Transparency).
3. Third-Party Services
We share data with the following categories of third-party service providers:
| Provider | Purpose | Data Shared |
| Firebase (Google) | Authentication, push notifications, analytics, crash reporting | Device ID, usage data, crash logs |
| Stripe | Payment processing | Payment method details, transaction amounts |
| Amazon Web Services (AWS) | Cloud infrastructure, data storage | All service data (encrypted at rest and in transit) |
| Alchemy / Blockchain RPC Providers | Blockchain node access, transaction broadcasting | Wallet addresses, transaction data |
Each third-party provider is contractually obligated to protect your data and may only use it for the purposes specified. We encourage you to review their respective privacy policies.
4. Data Retention
- Account Data: Retained while your account is active and for 30 days after deletion request to allow recovery.
- Transaction Records: Retained for 7 years to comply with financial regulations.
- Analytics & Diagnostics: Retained for 24 months, then aggregated or deleted.
- Blockchain Data: Permanently recorded on public blockchains and cannot be deleted.
- Location Data: Real-time location is not stored persistently. Historical location data associated with gig completion is retained for 90 days.
5. Data Deletion
You may request deletion of your account and associated personal data at any time by:
- Using the "Delete Account" option in Settings within the app.
- Emailing privacy@wyrr.me with the subject line "Data Deletion Request."
Upon receiving a deletion request, we will delete or anonymize your personal data within 30 days, except where retention is required by law or where data exists on public blockchains.
6. Your Rights
6.1 GDPR Rights (EEA / UK Residents)
If you are a resident of the European Economic Area or United Kingdom, you have the right to:
- Access your personal data.
- Rectify inaccurate personal data.
- Erase your personal data ("right to be forgotten").
- Restrict processing of your personal data.
- Data portability — receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time without affecting prior processing.
Our legal bases for processing are: contract performance, legitimate interests, consent, and legal obligations.
6.2 CCPA Rights (California Residents)
If you are a California resident, you have the right to:
- Know what personal information is collected, used, shared, or sold.
- Delete personal information held by us.
- Opt-out of the sale of personal information. We do not sell your personal information.
- Non-discrimination for exercising your privacy rights.
To exercise any of these rights, contact us at privacy@wyrr.me. We will respond within 45 days (CCPA) or 30 days (GDPR).
7. Cookies & Web Tracking
Our website uses the following types of cookies:
- Strictly Necessary: Authentication tokens, session management. Cannot be disabled.
- Analytics: Anonymous usage statistics to improve the Service. Can be opted out.
- Functional: Remember your preferences (language, theme). Can be opted out.
We do not use third-party advertising cookies. You can manage cookie preferences through your browser settings or our cookie consent banner.
8. Children's Privacy (COPPA)
WYRR is not intended for children under the age of 18. We do not knowingly collect personal information from anyone under 18 years of age. Given that our Service involves financial transactions, cryptocurrency, and marketplace activities, users must be of legal age in their jurisdiction.
If we learn that we have collected personal information from a child under 18, we will delete that information promptly. If you believe a child has provided us with personal data, please contact us at privacy@wyrr.me.
9. Crypto-Specific Disclosures
- Wallet Addresses: Your public wallet address is visible to transaction counterparties and recorded on public blockchains. This is inherent to blockchain technology and cannot be reversed.
- Private Keys: We never access, store, or transmit your private keys or recovery phrases. These remain solely on your device, protected by the Secure Enclave.
- NFC Wallet Exchange: When you tap devices to share wallet addresses via NFC, the address is transmitted directly between devices. We may log that an exchange occurred for analytics, but we do not intercept or store the transmitted address data on our servers.
- Smart Contract Interactions: Interactions with smart contracts are processed through third-party RPC providers. Your wallet address and transaction parameters are shared with these providers to execute transactions.
10. Data Security
We implement industry-standard security measures including:
- TLS 1.3 encryption for all data in transit.
- AES-256 encryption for data at rest.
- On-device biometric authentication via Apple Secure Enclave.
- Regular security audits and penetration testing.
- Role-based access controls for internal systems.
No system is 100% secure. If a data breach occurs that affects your personal data, we will notify you and relevant authorities as required by applicable law.
11. International Data Transfers
Your data may be transferred to and processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and, where appropriate, through in-app notifications or email. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at: