Skip to content

Privacy Policy

Last updated: 30 September 2026

This policy explains what we collect when you use LockFi inside Telegram, meaning the LockFi app and the LockFi bot, and when you visit our website, lockfi.io, who it goes to and what we do with it.

Who we are

LockFi is operated by LockFi Ltd, a company incorporated in Hong Kong, which runs both lockfi.io and LockFi inside Telegram. We handle your personal data in line with Hong Kong's Personal Data (Privacy) Ordinance and the other laws that apply to us. For anything about your personal data, contact us at legal@lockfi.io.

What we collect

When you use LockFi inside Telegram

Your Telegram account. When you open LockFi, Telegram sends it your Telegram account ID, first and last name, username, language and a link to your profile photo, signed by Telegram so we know they come from your account. We check that signature on every request. We keep your account ID, which identifies you in LockFi, your name and username, which other LockFi users see when you pay each other, and your language, for our messages. We do not keep your profile photo, and Telegram does not give us your phone number.

Your wallet. Your wallet's key is split into three shares, and any two are needed to approve a transaction. One share is kept by LockFi, encrypted with a key held apart from our database. One is kept on your phone, in its secure storage. The third is your recovery backup. LockFi cannot move your funds on its own. We keep your wallet's public key and your phone's public key; your wallet addresses follow from them. We look up your addresses' balances and deposits on the blockchain to show them to you.

Your recovery backup. When you set a recovery password, the app uses it to encrypt your recovery share on your phone, and saves the encrypted copy in your Telegram cloud storage. Your password never leaves your phone. We never see it or the unencrypted share, and we cannot reset it for you.

Your activity. When you send, receive, swap or pay, we record the amounts, assets and networks, the wallet addresses involved and the transaction IDs on the blockchain. For a QR payment we also record the merchant's name, the payment scheme and the country; for a card payment, the merchant; and for a payment between LockFi users, both people's names. This is your activity history, and our financial record.

Your passcode and biometric unlock. We keep your passcode only as a one-way hash that cannot be turned back into the passcode, along with the number of wrong attempts. If you turn on Face ID or fingerprint unlock, the check happens on your phone, through Telegram, and we never receive biometric data: your phone keeps a random unlock key in Telegram's biometric storage, and we keep only a hash of it. Each unlock gives the app a code that works for 30 minutes.

Your email address. Before the identity check, we ask for your email address and confirm it with a one-time code, sent by our email provider, Resend. We keep the code only as a hash, and it expires after 10 minutes. We use your email address for your account with our card provider and to contact you about your account.

Your identity check. QR Payments, Cards and eSIM need one identity check, run by our card provider, Interlace. To set it up, we send Interlace your email address, your name as it appears in Telegram, and a reference that includes your Telegram account ID. You then send your ID document and selfie to Interlace directly, on its own page; they do not pass through our servers. We keep your Interlace account ID, the result of the check and when it happened, not your documents.

Cards. LockFi Cards are Visa cards, issued by Interlace. You fund a card from your wallet, and once you do, Interlace holds that card balance, not LockFi and not your wallet. We keep your card's last four digits, network and status, and your card payments, including the merchant and amount. We never receive or store your full card number or security code: when you choose to show them, Interlace displays them in its own secure window inside the app.

QR Payments. QR payments are completed by SQRIL through the local QR payment scheme. SQRIL receives the QR code, the amount and the payer details it requires to process a QR payment. We keep the customer ID SQRIL gives us, and the payment details described under Your activity.

Swaps. Swaps are priced and routed by deBridge. It receives your wallet addresses and the tokens, networks and amounts of the swap, not who you are.

eSIMs. eSIM data bundles come from eSIM Go, and you pay for them in USDT on Tron from your wallet balance. eSIM Go does not receive any of your personal data. We keep your order, including the bundle, the price, the eSIM's ICCID and the details needed to install it. eSIM Go tells us as a bundle's data is used up, and we keep a record of that.

Invites. If you join through a friend's invite link, we record who invited you. Your friend can see your first name, when you joined, whether you have completed the identity check and got a card, and whether you have made your first card payment. Their invite rewards are based on your card spending: one reward after your first card payment, then a share of what LockFi earns from your card payments.

Messages from the LockFi bot. The bot messages you in Telegram about money you receive, deposits, QR payments, your card and card payments, your identity check and your invite rewards. These messages are on unless you turn them off in Settings. Security alerts, such as a passcode reset or a wallet recovery, are always sent. The bot does not send marketing.

Technical data. Our servers record each request's time, the address requested, the result and how long it took, to run LockFi, keep it secure and fix errors. What you send in a request, such as your passcode, is not part of these records. Cloudflare, which delivers the app to you and carries traffic to our servers, processes your IP address and standard request information.

On your device. Your language, theme and card design, and the swaps you have confirmed until they finish, are saved in your Telegram cloud storage, so they follow you to your other devices. The app keeps a random ID for your device, and while LockFi is open, it keeps the details Telegram opened it with in your browser's session storage. The app sets no cookies and uses no analytics or advertising trackers.

Precious metals. A precious metals purchase, sale or trade is recorded in your activity like any other transaction: what you bought or sold, the amount and the price. The provider that completes it and holds the metal for you receives the details it needs to do so.

When you visit lockfi.io

Your email address, if you subscribe. That is the only thing the subscribe form asks for. The form also carries a hidden field that people never see and automated spam usually fills in; if it arrives filled, we discard the submission. A Cloudflare Turnstile check also runs on the form to keep out automated spam.

If you email us at support@lockfi.io or hello@lockfi.io, we receive your address, your message and anything you choose to include in it.

Partner and investor meetings. If you book a meeting with us, the booking is handled by Cal.com. We receive your name, email address and your answers to the booking questions, such as your fund or company and website.

Deck requests. If you request our deck, we receive your name, email address, fund or company, investor type, website, and your typical cheque size and message if you choose to give them. A Cloudflare Turnstile check runs on the form to keep out automated spam.

Technical data. When you visit the site, our hosting provider processes standard request information, such as your IP address, browser type and the pages requested, to deliver the site, keep it secure and diagnose errors.

Visit statistics. We use Cloudflare Web Analytics to count visits and measure how quickly pages load. It does not use cookies, does not track you across other websites and does not build a profile of you.

We do not use advertising trackers, social media pixels or advertising cookies, and the site sets no cookies of its own.

How we use it

In the app. We use your information to run your account and wallet, carry out what you ask for, such as sends, swaps, payments, cards, precious metals and eSIMs, show you your activity, and send you bot messages. We also use it to check your identity where a product needs it, meet our legal duties, such as anti-money-laundering, sanctions and record keeping, keep LockFi secure and prevent fraud, and pay invite rewards.

On lockfi.io. We use your email address to send you LockFi news and product updates, and for nothing else. We process it because you asked us to by subscribing, and you can withdraw that consent at any time. We use anything you send us by email only to answer you. We use meeting details and deck requests only to send you the deck, prepare for and follow up on meetings, and respond to your interest in LockFi. We do not add them to our newsletter or use them for marketing.

We do not sell or rent your information, we do not use it for advertising, and we do not share it with anyone for their own marketing.

Who can see it

  • Other LockFi users. Anyone you share your receive link or code with, or who pays your @username, sees your name and username. A payment between LockFi users shows each person's name to the other. The friend who invited you sees what is described under Invites.
  • Anyone, on the blockchain. Blockchains are public. Your wallet addresses, and the amounts and transactions they send and receive, can be seen by anyone and cannot be removed, by us or by anyone else.
  • Authorities. We share information with courts, regulators or law enforcement when the law requires it.

Who processes it for us

We use a small number of service providers who handle data only for the purposes described here:

  • Telegram, where LockFi runs. It delivers our bot messages and keeps your encrypted recovery backup, your app settings and your biometric unlock key in your Telegram account.
  • Cloudflare, which hosts lockfi.io and the app (on Cloudflare Workers), carries traffic to our servers, provides the website's visit statistics and runs the Turnstile spam check.
  • LockFi's own servers, which run LockFi's back end.
  • Supabase, which hosts our database, and runs the code behind the subscribe and deck request forms, keeping a copy of what you submit.
  • Resend, which stores the newsletter subscriber list, sends our emails, and sends the one-time code that confirms your email address in the app.
  • Cal.com, which runs our booking calendar for partner and investor meetings. Cal.com may set cookies needed for the booking to work.
  • Interlace, our card provider, which runs the identity check, issues your Visa card and holds the card balance.
  • SQRIL, which completes QR payments.
  • deBridge, which prices and routes swaps.
  • Our precious metals provider, which completes precious metals purchases, sales and trades and holds the metal for you.
  • eSIM Go, which provides eSIM data bundles.
  • QuickNode, which connects us to the blockchain networks. It sees the wallet addresses we look up and the transactions we send.

International transfers

Your information is processed outside Hong Kong. LockFi's own servers are in Germany, our database is hosted in the European Union (Frankfurt, Germany), and our other providers may process data in the United States and other countries. Where that happens, they rely on recognised legal safeguards for international transfers.

How long we keep it

In the app. We keep your information while your account is in use, and after that for as long as we need it to meet our legal and accounting obligations. Records of money moving in and out of your wallet and card are kept as financial records, and our ledger is built so that its records cannot be changed or deleted. Unlock codes expire after 30 minutes and are then deleted, and our record of each email code we send is deleted after two days. Interlace and SQRIL keep what they hold under their own legal duties. Your recovery backup and settings stay in your Telegram account until they are replaced or you remove them. Removing LockFi from Telegram does not close your LockFi account.

On lockfi.io. We keep your email address while the list is active, and delete it when you unsubscribe or ask us to remove it. We keep meeting details and deck requests for as long as we are in conversation with you, and delete them when you ask us to. Technical request data is kept only as long as our hosting provider needs it for security and troubleshooting. To stop abuse of our forms, we keep your IP address with each form submission for up to 24 hours, then delete it.

You can ask us to delete your information at any time by writing to legal@lockfi.io.

Your rights

Depending on where you live, you can ask us to access, correct or delete your personal data, restrict or object to how we use it, or receive a copy of it. You can also complain to your local data protection authority. We may need to keep some information after you ask us to delete it, where the law requires us to, and nobody can delete records from a public blockchain.

You can turn bot messages off at any time in the app's Settings, and every email we send includes an unsubscribe link. For any other request, contact us at legal@lockfi.io.

How we protect it

Every request is checked against Telegram's signature. Your wallet's key is never whole in one place, our share is encrypted, and your recovery share is encrypted with a password only you know. Sending money and showing card details need your passcode or biometric unlock, and repeated wrong passcodes lock the app for a while.

Children

LockFi, lockfi.io and our newsletter are not intended for anyone under 18, and we do not knowingly collect their information.

Changes to this policy

If we change this policy, we will post the new version here and update the date at the top. If a change affects how we use your information, we will tell you first: in the app if you use LockFi, and by email if it affects how we use your newsletter email address.

Back to LockFi