CORSO @CorsoHQ

Privacy Policy

Effective: 10 August 2026

Last updated: 25 August 2026

Corso is a self-custody Solana wallet published by Dinario Technologies Inc. ("Corso", "we", "us"). This policy explains what Corso collects, what it does not collect, and which independent companies handle information when you use parts of the app.

1. The short version

2. Information Corso handles

a. Wallet address

Your public Solana address is sent to Corso's own service when you request a swap quote or start a Buy session, because neither can be built without it. It is also sent to the Solana network and to the providers described in Section 5.

In Corso's product analytics your address is shortened before it leaves the app (for example 7xKp…9fQm), and it is shortened a second time on Corso's server as a backstop.

b. App usage events

Corso records events such as opening the app, finishing onboarding, starting a swap, and opening or returning from Buy. Each event carries:

Before an event leaves your device, and again on Corso's server, Corso removes any field named like a secret (recovery phrase, seed, private key, password, passcode, email address, or an authentication token), removes anything that looks like a 12- or 24-word recovery phrase, and shortens anything that looks like a wallet address.

Analytics are on by default. You can turn them off at any time in Profile → Privacy. Turning them off stops new events from leaving the device immediately; events already sent are not removed automatically. To request deletion of Corso-side analytics data, use the Account & Data Deletion page.

c. Transaction requests

To quote and submit a swap, Corso's service passes the tokens, the amount, and your address to the routing provider, and passes the transaction you already signed on your device to be submitted to the network. Corso keeps a short-lived record linking a quote to its transaction so the transaction you approve is the transaction that gets submitted. That record expires within minutes.

d. Support messages

If you email support at support@corso.trade, Corso receives whatever you choose to put in the message. Never send your recovery phrase or private key to Corso support, or to anyone else. No genuine Corso message will ever ask for it.

e. Technical logs

Corso's service and its hosting provider record ordinary technical information about requests (such as timing and error information) in order to run and debug the service. These are kept for 30 days.

f. Website (corso.trade)

The Corso website does not have an email form. It does not ask for a wallet address, does not ask you to connect a wallet, and never asks you to sign anything.

If you previously entered an email address on an older version of the site, Corso may still hold that address so it can send one message. Corso does not sell it, does not share it for advertising, and does not add you to a newsletter. Hosting and database providers see it because the address has to be stored, and an email delivery provider sees it if that one message is sent. Nobody else. To ask for it to be deleted, email support@corso.trade.

The website also counts anonymous page and control events, to see which parts of the page people use. Those counts set no cookie, store no identifier on your device, and follow you to no other site. Your email address is never attached to them.

3. Information Corso does not collect

Corso does not collect, request, store, or transmit:

Corso does not sell your personal information, and does not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws.

4. Why Corso handles this information

Corso is available in the United States at launch and is not offered in the EEA or the UK, so this policy does not set out a GDPR legal-basis table. If that changes, this section will be updated before the app is offered there.

5. Independent companies involved

These companies are not Corso. Each handles information under its own terms and privacy policy, and each holds things Corso deliberately does not.

a. Privy, sign-in and embedded wallets

If you choose Sign in with email, Apple, or Google, Privy authenticates you and provisions and operates an embedded Solana wallet for you. Privy holds your account identifier (your email address, or the identifier your Apple/Google sign-in supplies) and the key material for that wallet. Corso holds no share of that wallet's keys and cannot recover it for you.

Consequence worth stating plainly: on this sign-in path, whoever controls your email or Apple/Google account is on the path to your wallet. Corso does not yet offer an additional security check on top of that sign-in, so protecting that account is the only mitigation available to you today. We are building one. If you want a wallet that does not depend on your email or Apple/Google account, connect a wallet you already control instead.

If you import a recovery phrase or connect a wallet you already use, Privy holds nothing about your keys, the phrase stays in secure storage on your device, and a connected wallet's keys stay in that wallet's app.

Privy Privacy Policy

b. MoonPay, buying crypto with money

If you use Buy, you leave Corso for MoonPay's checkout. MoonPay is an independent company that performs its own identity verification and processes your payment under MoonPay's own terms and privacy policy. MoonPay, not Corso, collects and holds your card or bank details, your identity documents, and the record of your purchase.

Corso sends MoonPay the wallet address the assets should be delivered to, the asset you selected (SOL, or USDC on Solana), the amount and currency, and a reference code so the app can recognise your return. Corso does not receive your payment details or your identity documents from MoonPay, and Corso cannot access, correct, or delete MoonPay's records. Requests about those records go to MoonPay.

MoonPay Terms of Use · MoonPay Privacy Policy

c. PostHog, product analytics

The events described in Section 2b are forwarded from Corso's own server to PostHog, an analytics provider. The app itself contains no analytics tracker, so nothing is sent to PostHog directly from your device. PostHog Privacy Policy · 90 days

d. Solana network access providers

To show balances and history and to submit transactions, the app contacts a Solana network provider. That provider necessarily sees the addresses being looked up and, as with any internet request, the network information that comes with the request. Corso's current primary provider is Helius. Helius Privacy Policy

e. Jupiter, swap routing

Swap quotes and submissions are routed through Jupiter's aggregator via Corso's service. Jupiter receives the tokens, the amount, and the address the swap is for, which are needed to build the route. Jupiter Legal

f. Expo / EAS, app delivery and updates

Corso is built with Expo and may deliver over-the-air updates through Expo's update service, which receives the ordinary request information needed to serve an update to your app version and platform. Expo Privacy Policy

g. Apple, Google, and the Solana dApp Store

However you installed Corso, that store has its own relationship with you and its own privacy policy. Corso does not receive your store account details.

6. Blockchain data is public and permanent

Sending, receiving, and swapping on Solana creates public records. Addresses, amounts, tokens, and timestamps are visible to anyone, are copied by many independent parties, and are permanent.

Corso cannot delete, hide, edit, or reverse anything recorded on the blockchain. This is a property of the network, not a Corso policy choice, and it is not something any deletion request can change. See Account & Data Deletion.

6a. Key export page

If you export a private key, Corso opens a page on a domain that Corso operates. Your key is displayed inside that page by Privy, the sign-in and wallet provider described in Section 5. Corso does not receive it, store it, log it, or transmit it.

What the page loads. The page runs Privy's software, which it loads from and communicates with Privy's own servers (auth.privy.io and api.privy.io). Privy's software may store sign-in state in your browser. The page loads no analytics and no advertising, and it loads no other third-party code.

What Privy sees. Because Privy performs the export, Privy knows that an export happened, for which wallet, and when. Privy records that under its own privacy policy, and its retention of that record is governed by Privy, not by Corso.

What the host records. The server that hosts the page records standard web request information, meaning IP address, browser user agent, and the time of the request, for security purposes, and keeps it for 30 days. Your wallet address is never included in the page address, so it does not appear in those records.

The acknowledgement record. Corso records that you acknowledged the export warning: an app install identifier, which version of the warning you saw, and when. That record contains no key and no wallet address. It uses the same random install identifier described in Section 2, so it can be associated with your other app usage. It is kept for 90 days, as shown in Section 7.

7. How long information is kept

WhatKeptFor how long
Analytics eventsPostHog, on Corso's behalf90 days
Technical/service logsCorso's hosting provider30 days
Key export page request logs (IP, user agent, time)Corso's hosting provider30 days
Export warning acknowledgement (install id, warning version, time)Corso's service90 days
Quote-to-transaction recordsCorso's service, in memory onlyMinutes; they expire automatically
Buy session referencesCorso's service90 days
Support emailCorso's mailbox1 year
Your wallet, recovery phrase, keysNever held by Corson/a
Sign-in account, MFA enrolmentPrivyPer Privy's policy
Payment and identity recordsMoonPayPer MoonPay's policy
Blockchain transactionsThe Solana networkPermanent; not deletable by anyone

8. Your choices and rights

9. Security

Corso is built so that the most sensitive material never reaches it: recovery phrases and private keys are never transmitted to Corso, and payment details never touch Corso at all. On the device, an imported recovery phrase is held in the operating system's secure storage behind your biometric or passcode, and screen capture is discouraged where the platform allows. Traffic between the app and Corso's service uses HTTPS.

No system is perfectly secure, and Corso cannot protect you against a compromised device, a phishing site, a malicious wallet app, or someone who obtains your recovery phrase.

10. International transfers

The independent companies named in Section 5 operate internationally, so information they hold may be processed outside the country you live in, under their own policies and safeguards. Corso itself is a United States company and holds the limited information described in Section 2 in the United States.

11. Children

Corso is not directed to children and is intended only for people aged 18 or over. Corso does not knowingly collect information from anyone under 18. If you believe a child has used Corso, email support@corso.trade and Corso will delete what it holds.

12. Changes

If this policy changes materially, the updated version will be posted at https://corso.trade/privacy with a new "Last updated" date, and, where required, you will be notified in the app.

13. Contact

Dinario Technologies Inc.

390 NE 191st St STE 94833, Miami, FL 33179, US

Contact: support@corso.trade