Avero Wallet / Privacy
Privacy policy
This policy describes how Avero Wallet (“Avero”, “we”) handles information in the Chrome extension, related Avero apps as they become available, and this marketing site. Avero is a self-custody wallet. There is no Avero account and no Avero cloud backup of your secret phrase or vault.
Short version: the encrypted wallet lives on your device. We do not collect the phrase, private keys, or unlock password. When you look up a balance, fetch a quote, or send a transaction, the network service you use can see the addresses and amounts in that request. This website does not set cookies or run analytics.
1. Who we are
Avero is a self-custody cryptocurrency wallet. The product lets you create or import a secret phrase, view balances, send and receive, swap along a route you confirm, and connect to websites you approve. Support and privacy questions: support@averowallet.com.
We cannot restore a lost phrase or password. Anyone who asks you to type the phrase into a webpage or email is not Avero.
2. Scope
This policy covers:
- The Avero Wallet Chrome extension (Manifest V3 toolbar popup).
- This public website, including the privacy and support pages.
- Android and iOS listings when those apps ship, unless a later policy names a change.
It does not control how a blockchain, a public RPC operator, a swap router, a price source, or a website you connect to handles data. Those parties publish their own policies.
3. What we do not collect
The developer does not collect, store on Avero servers, or sell:
- Secret phrases, private keys, or unlock passwords.
- Name, email, phone, government ID, or an Avero login — there is no Avero account.
- A cloud copy of the vault.
- Browsing history, page content, or a record of which sites you visit, except the connected-site permissions you grant, which stay on the device.
- Advertising identifiers, location traces, or analytics events from the wallet.
We do not use wallet data for advertising. We do not sell personal information.
4. What stays on your device
After you create or import a wallet, the following stay in browser or app storage
on that device (Chrome storage in the extension):
- The vault: secret material wrapped with PBKDF2 and AES-256-GCM.
- Settings, language, custom networks and tokens, and a local price cache.
- Local send and activity history that Avero shows in the popup.
- Connected-site permissions you approve or revoke.
The unlock password is used in memory to decrypt the vault. It is not written to storage in plaintext. If you forget the password or lose the phrase, Avero cannot recover the wallet.
5. What third parties may see when you use the wallet
Blockchains are public. Avero does not operate a backend that stores your wallet. When you take an action that needs the network, the service that answers that request can see what the request contains.
Balances, sends, and custom RPCs
Looking up a balance, broadcasting a transaction, or reading chain state uses HTTPS JSON-RPC (and similar) endpoints — the defaults shipped with Avero, public endpoints you can switch, or a custom RPC you add. Those operators can see the addresses, methods, and amounts in that call, plus your IP address as with any HTTPS request.
Swaps
Quotes and routes use LI.FI for EVM, Tron, and Sui, and Jupiter for Solana. Those services receive the assets, amounts, and addresses needed to build a quote. You sign the transaction in the Avero popup. LI.FI and Jupiter have their own privacy policies.
Prices
Fiat display values come from public price sources. Those requests typically include asset identifiers, not your secret phrase.
Sites you connect
A website you approve can receive the account address you share for that session, and can ask you to sign. Avero does not send the phrase to the site. Revoke access in Settings. The site’s own policy applies to anything you do there.
Email support
If you write to support, we see the address and message you send. Do not paste a secret phrase, private key, or unlock password. We keep mail only as long as needed to answer the ticket.
6. This website
The marketing site is static files. It does not set first-party analytics cookies, does not run an advertising pixel, and does not require an account. Your browser and the host that serves the files will see ordinary web logs (IP address, user agent, requested path) as with any HTTPS site. We do not use those logs to build a marketing profile.
Pages on this site include Home, Privacy, Support, and store-status information. Links to Chrome, Android, and iOS stay here while listings are in review.
7. Chrome Web Store Limited Use
Avero complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Single purpose. Avero is a self-custody cryptocurrency wallet. It shows balances, sends and swaps assets the user confirms, and connects to websites the user approves. It is not a general page reader, not an ad network, and not a cloud backup product.
User data from Chrome APIs is used only to provide that wallet. It is not sold, not used for advertising, and not transferred except as needed for the network requests the user starts (RPC, quotes, prices) or as required by law.
8. Extension permissions
storage holds the encrypted vault and the local settings listed in
section 4. It is not a developer-side database.
Host access (https://*/* and localhost) is used only for actions you
start: connect to a site you open, and call HTTPS APIs for balances, quotes, and
sending. A content script relays connect and sign messages between the page and the
extension. The extension does not scrape pages for analytics.
declarativeNetRequestWithHostAccess lets the extension attach headers
on its own HTTPS calls so public APIs that reject a chrome-extension://
origin can still answer a balance or quote request you started. It is not used to
rewrite other sites you browse, and it is not used to inject advertising.
9. Legal bases (where a privacy law asks)
Where GDPR or a similar law applies to a residual processing activity:
- Contract / requested service: running the wallet you installed, including network calls you trigger.
- Legitimate interests: answering support email you send, securing the site, and keeping this policy accurate.
- Consent: not used for tracking cookies on this site — we do not set them.
- Legal obligation: if a lawful request requires a limited disclosure of support correspondence we still hold.
On-device vault data is processed on your device under your control. We are not the host of that vault.
10. Retention
- Vault and local settings remain until you remove the extension, clear site data, or delete the wallet in Settings.
- Support email is kept only as long as needed to handle the request.
- Ordinary web-server logs, if the host records them, follow that host’s rotation. We do not mine them.
11. Security
The vault is encrypted with PBKDF2 (600,000 iterations) and AES-256-GCM before it is written to local storage. Unlock happens in the popup. We will not ask for the phrase by email. Report a vulnerability to support@averowallet.com.
Self-custody means you are responsible for the phrase. Avero cannot freeze an account or reverse a confirmed send.
12. Children
Avero is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child provided personal information through support email, write to us and we will delete that message.
13. Your choices and rights
- Do not create a wallet if you do not accept this policy.
- Remove the extension to delete the local vault from that Chrome profile.
- Revoke a connected site in Settings.
- Switch or add RPCs in network settings; those operators then see the requests you send them.
- Write to support to access, correct, or delete personal information that may exist in email we hold. There is no phrase to export from our servers — we do not have it.
Depending on where you live, you may have rights to access, deletion, restriction, or complaint to a supervisory authority. Contact us first at support@averowallet.com.
14. Changes
If this policy changes, we will update this page and the “Last updated” date. Material changes to how the extension handles user data will also be reflected in the Chrome Web Store listing as required.
15. Contact
Privacy and product questions: support@averowallet.com.
Do not send a secret phrase, private key, or unlock password. We cannot use them to help you, and you should treat any such request as hostile.