Zashi is a privacy-first pockets, and we take that critically. Meaning accessing as little knowledge as potential, and being clear concerning the knowledge we now have entry to, why it issues, and how one can management it. Right here’s what it’s essential to know:
What Information We Accumulate
Zashi doesn’t gather any knowledge. Like most software program apps, it makes use of crash stories, enabled and generated on the working system degree, to assist our workforce detect and repair bugs. However in contrast to most apps—even those who declare to prioritize privateness—Zashi doesn’t see or gather some other knowledge. Crash stories are the one knowledge we are able to see, which is uncommon amongst app builders.
Crash stories present restricted anonymized technical knowledge the only objective of which is to watch the wholesome perform of the app. They assist make the pockets extra secure and usable, nothing extra.
Necessary:
ECC and the Zashi builders don’t observe, view, or gather your pockets exercise. When a crash report is generated, it gives restricted knowledge wanted to determine what triggered the crash. We don’t see or gather names, emails, telephone numbers, contact lists, user-generated content material, or transaction particulars.
What Crash Report Instruments We Use
Crash stories are saved and processed by Google (on Android) and Apple (on iOS), and like all apps on their platforms, we should comply with strict guidelines about what knowledge is collected and the way it’s dealt with. Violating these guidelines would result in elimination from their shops.
What Crash Studies Do Not Include
Crash stories are anonymized and solely embrace technical diagnostics like system sort, app model, time of the crash, stack hint (which a part of the code crashed), error logs, and working system model.
These stories do not comprise:
Your transaction IDs or historical past
Pockets addresses
ZEC balances
Private info like title, e mail, or telephone
Consumer IDs tied to Zashi
Something that would hyperlink a transaction to a particular person
Crash stories inform us how and when the app broke, not who it occurred to.
Can You Decide Out?
Sure, in a number of methods:
iOS customers:
Apple permits customers to choose out of diagnostic knowledge sharing throughout all apps. You are able to do this in your iPhone settings. iOS doesn’t enable customers to choose out for particular person apps.
Android customers:
Google doesn’t enable builders or customers to opt-out from the default Google Play Companies knowledge assortment for Android Vitals.
To choose out, Android customers can obtain Zashi through F-Droid. The F-Droid model of Zashi is basically totally different from the Play Retailer model: it’s fully freed from proprietary analytics and crash reporting instruments.
Enhancements:
We already entry far much less knowledge than most apps, however we’ve taken extra steps to restrict knowledge assortment even additional:
For iOS, we’ve eliminated Firebase Crashlytics fully (Zashi iOS v1.5.2).
We’ve applied a risk to opt-out of Firebase Crashlytics for Android. Customers can choose out of sharing crash stories in Zashi’s Superior Settings. (Zashi Android v1.5.2)
For Android, we’ve set Firebase Crashlytics to be “Off” by default. Customers can select to choose in via Zashi’s Superior Settings or the pockets’s standing widget. (Zashi Android v2.0)
We’ve up to date the F-Droid model, eradicating the inaccurate safety warning, which falsely implied that the F-droid model collects crash stories. That was by no means the case.
F-Droid & GitHub: Full Transparency
Zashi is accessible on F-Droid, an unbiased app retailer that prioritizes open-source, privacy-respecting software program. In contrast to conventional app shops, F-Droid doesn’t observe or profile customers, and it permits for fully nameless downloads. The F-Droid model of Zashi is absolutely open-source and consists of no crash reporting instruments in any way.
The F-Droid Zashi construct is totally reproducible, and we encourage our neighborhood to construct it and confirm our work. This helps determine and mitigate potential threats to our infrastructure, processes, and the third-party providers we rely on.
You may as well construct the app your self from supply.
Zashi code is totally open supply and out there on GitHub:
Learn extra about alternative routes to obtain Zashi pockets.
Philosophy: Privateness by Design
Many wallets declare to prioritize privateness, whereas quietly accumulating analytics and person conduct. Zashi doesn’t simply declare it—we reside it.
We don’t see or gather person and app knowledge. We don’t profile customers. We don’t observe their exercise. And we exit of our strategy to decrease metadata leakage. Zashi is constructed by the identical workforce that created and maintains the Zcash protocol—probably the most superior privateness tech within the blockchain trade. We apply the identical requirements to app improvement that we do to protocol-level privateness.
We welcome scrutiny—particularly in privateness tech. However conversations about privateness and person security should be grounded in information, not concern or hypothesis. We encourage customers to use the identical excessive requirements to all of the apps and wallets they use, and to demand transparency and alter when these instruments fall quick.
Our dedication to Zashi customers is unwavering.
Shields up.