Privacy Policy
Last updated: June 7, 2026
1. Who We Are
Piggy ("the App") is operated by OrkLabs S.A.S., a company incorporated under the laws of the Argentine Republic ("we," "us," or "our"). This Privacy Policy describes how we handle information in connection with the Piggy mobile application and the website at pig.gy.
By using the App, you agree to the practices described in this Privacy Policy.
2. Self-Custody Architecture
Piggy is a self-custody Bitcoin wallet built on the Spark (spark.money) protocol. The App supports multiple deposit methods — including Lightning payments, onchain Bitcoin, stablecoins, and other cryptocurrencies (such as ETH, SOL, and similar) — all of which are converted to and held as Bitcoin on Spark. Your private keys are derived on your device from your passkey (WebAuthn) credential using the PRF (Pseudo-Random Function) extension. We do not hold, manage, or have access to your private keys, passkey credentials, seed phrases, or any key material at any time.
Your passkey is automatically synced and backed up by your device's passkey provider (e.g., Apple iCloud Keychain, Google Password Manager). We do not operate or control this backup. The App also allows you to export a recovery seed phrase — derived from the same passkey/PRF process — as an additional backup. Your seed phrase is generated and displayed locally on your device — we never receive, store, or transmit it. Anyone who obtains your seed phrase can access your funds. If you lose access to both your passkey provider account and your seed phrase, we cannot recover your funds. You are solely responsible for maintaining access to your passkey and safeguarding your seed phrase.
3. Information We Have Access To
Because Piggy operates on the Spark protocol, certain information is inherently public on the network. The information we may have access to includes:
- Your public key — this is public information by nature on the Spark network and does not reveal your identity.
- Transaction and invoice data — when the App creates Lightning invoices or processes transactions on your behalf, this data passes through the Spark protocol and may be visible to us and other network participants. This is publicly available information on the protocol and is not private or proprietary data.
- Publicly available Spark network data — any information that is already publicly accessible through the Spark protocol.
- Free-tier profile data — every Piggy has a publicly accessible address page at pig.gy/[handle] so that anyone can send sats to it. For a free-tier Piggy, this page shows only the default skin and a randomly generated Lightning address (e.g.,
oink-a3f2@pig.gy). No name, AI personality, message history, or custom data is stored. - Upgraded profile data — if you upgrade your Piggy, we additionally store your Piggy's custom name, custom skin, AI personality, Lightning address, and public message feed on our servers to enable profile, messaging, and Nostr features. This data is not linked to your real-world identity.
We do not correlate this publicly available data with your real-world identity. Using the App itself does not require us to collect identifying information about you.
4. Information We Do Not Collect
Except as described in Section 6 (which applies only if you buy Bitcoin with Apple Pay or Google Pay), we do not collect, store, or process:
- Private keys, passkey credentials, seed phrases, or key derivation material
- Government-issued identification documents (not required to use the App)
- Personal names, physical addresses, or contact information — apart from the email address and phone number you provide to buy Bitcoin (Section 6), or if you contact us directly
- Financial or banking information — when you buy Bitcoin, your card and payment details are handled by Apple Pay or Google Pay and Coinbase; we never see your card number or bank details
- Social Security numbers or dates of birth — if you raise your purchase limits, the last four digits of your SSN and your date of birth pass directly to Coinbase and are never stored by us
- Detailed transaction history. Non-identifying wallet context may be shared with AI providers solely for generating personality responses, but is not stored, logged, or linked to your identity.
We do not share your in-app identity, Piggy profile, or personal information with Flashnet or any other third-party DEX. Deposit addresses and amounts processed by Flashnet are not linked to your identity within the App.
5. Information We May Collect
To maintain and improve the App, we may collect minimal, non-identifying data:
- Device information — device model, operating system version, and app version for crash diagnostics.
- Anonymous usage analytics — aggregated, non-identifiable interaction data (e.g., which screens are visited) to improve the user experience. No analytics data is linked to your identity or wallet.
- Push notification tokens — if you opt in to notifications, we store a device token to deliver alerts. This token is not linked to your wallet or identity.
We do not use cookies or similar tracking technologies on the App or the pig.gy website.
6. Buying Bitcoin with Apple Pay or Google Pay
You can buy Bitcoin in the App with Apple Pay or Google Pay. This feature is powered by Coinbase and is currently available only to users in the United States. Coinbase provides the purchase and Apple Pay or Google Pay processes payment — we never see or store your card number or bank details.
To complete a purchase we process a limited amount of personal information, solely to enable the purchase and meet Coinbase's and the payment networks' requirements. We never use it for marketing.
Email and phone number. You must verify your email address and a non-VoIP mobile number. We confirm they are yours by sending a one-time code to each via Twilio, our verification provider, then transmit them to Coinbase to process your purchase and meet its compliance and fraud-prevention requirements. We store them encrypted only for this purpose — to re-verify your phone roughly every 60 days as Coinbase requires, and to let you buy again without re-entering them.
Higher limits. Purchases are subject to limits set by Coinbase. To raise them, Coinbase requires the last four digits of your Social Security Number and your date of birth. We pass these directly to Coinbase and never store them.
Coinbase's terms. Before buying, you must agree to Coinbase's Guest Checkout Terms of Service, User Agreement, and Privacy Policy. Coinbase processes payment, verifies identity, and settles your purchase under its own terms, which we do not control.
Bitcoin you buy is delivered directly to your self-custody wallet — we never custody it.
7. Piggy Characters & Public Profiles
Every Piggy — free or upgraded — has a publicly accessible page at pig.gy/[handle] that displays the Piggy's skin and Lightning address so that anyone can send sats to it. The amount of data stored on our servers, and what appears on that page, depends on whether the Piggy is upgraded.
Free-tier Piggy. The App generates a random Lightning address (e.g., oink-a3f2@pig.gy) and assigns a default skin. We store only this minimal data — the handle, the address routing, and the default skin selection — to make the address payable. The public page shows only the default skin and the address. No custom name, no AI personality, no message history, no Nostr identity.
Upgraded Piggy. When you upgrade your Piggy, the following additional data is stored on our servers:
- Character data — your Piggy's custom name, custom skin selection, AI personality description, and generated title and biography.
- Lightning address — your custom handle (e.g., name@pig.gy) and associated routing data for receiving payments.
- Public profile — the page at pig.gy/[handle] now displays your custom name, skin, AI-generated responses, and message feed.
- Message feed — messages received from other users via Lightning payments, along with your Piggy's AI-generated responses. On the public profile, messages are displayed without sender names or payment amounts. Within the App, the Piggy owner can see sender names and amounts.
- Nostr identity — a public Nostr identity (npub) is generated for your Piggy and published to public Nostr relays so that the Piggy can be discovered, followed, and zapped on the Nostr network. The Nostr identity is generated separately from your wallet keys — it cannot be used to access your funds. The profile metadata published to Nostr relays includes your Piggy's name, skin image, and Lightning address (lud16).
Your private keys and passkey credentials are never stored on our servers, and they are never used to derive the Piggy's Nostr identity. They remain exclusively on your device.
If you destroy your Piggy, all associated server-side data — including your profile, message history, name, personality, and Lightning address — is permanently and irreversibly deleted from our servers. The name and Lightning address are retired and cannot be reused. For an upgraded Piggy, we also broadcast a deletion request to the Nostr relays we publish to, but we cannot guarantee that all relays will honor it — Nostr is a decentralized protocol, and previously published data may persist on relays we do not control.
8. Use of Artificial Intelligence
The App uses artificial intelligence (AI) to power certain features, including Piggy character interactions and personality generation. AI processing may occur on-device or via third-party AI service providers.
When third-party AI services are used, we send limited, non-identifying context to generate personality responses. This may include character traits, conversation prompts, non-identifying wallet context, and incoming messages from other users. We do not send your private keys, passkey credentials, seed phrases, transaction history, or personal identity information to any AI provider.
AI-powered moderation is applied to incoming messages. Messages identified as toxic, harmful, or containing personal information are silently filtered and not displayed. Sats attached to filtered messages are still deposited to your wallet.
Third-party AI providers operate under their own privacy policies and data handling practices.
9. Third-Party Services
The App interacts with the Spark (spark.money) protocol and the Bitcoin Lightning Network to process transactions. These are decentralized protocols; we do not control them and are not responsible for their operation, availability, or privacy practices.
The App uses Flashnet (flashnet.xyz), a third-party decentralized exchange built on Spark, to process onchain Bitcoin, stablecoin, and other-cryptocurrency deposits. When you make such a deposit, Flashnet can see the deposit address and amount associated with your transaction in order to execute the conversion to Bitcoin on Spark. However, this data is not linked to your in-app identity, Piggy profile, or any personal information — Flashnet has no access to your username, Piggy character, or account details. Flashnet operates under its own terms and privacy practices, which we do not control.
The App displays deeplinks to popular third-party Bitcoin Lightning wallets (such as Cash App, Strike, and Wallet of Satoshi) as a convenience for paying invoices. When you tap a deeplink, the App opens the third-party wallet with the relevant Lightning invoice or address pre-filled. The deeplink contains only the public Lightning invoice or address — no personal information about you is sent to those wallets. We do not track which wallet you choose. We do not own, operate, or have a commercial relationship with these wallets, and they operate under their own terms and privacy practices.
For an upgraded Piggy, the App publishes Nostr profile metadata (Piggy name, skin image, and Lightning address) to public Nostr relays so the Piggy can be discovered on the Nostr network. Nostr is a decentralized open protocol — relays are operated by independent parties around the world, and we do not control them. Once data is published to a Nostr relay, that relay may store and serve the data indefinitely. We broadcast deletion events when a Piggy is destroyed, but cannot guarantee removal from every relay.
When you buy Bitcoin, the App uses Coinbase (coinbase.com) to provide the purchase and the Apple Pay or Google Pay networks to process payment. We transmit the data described in Section 6 to Coinbase to complete the transaction, and use Twilio (twilio.com) to deliver the one-time codes that verify your email address and phone number. Coinbase, Twilio, and the payment networks operate under their own terms and privacy policies, which we do not control.
We may use third-party services for crash reporting and anonymous analytics. These services operate under their own privacy policies.
10. Data Storage & Security
All sensitive data (private keys, wallet credentials) is derived from your passkey credential and secured using platform-native encryption (iOS Keychain / Android Keystore). Your passkey is synced and backed up by your passkey provider (Apple, Google) — we have no access to this process. If you export a recovery seed phrase, it is displayed locally on your device; we do not store, transmit, or have access to it.
If you upgrade your Piggy, character metadata (name, skin, personality, Lightning address, and message feed) is stored on our servers. This data is not linked to your real-world identity and is permanently deleted if you destroy your Piggy. Server-side data is protected using industry-standard encryption and access controls. Onchain, stablecoin, and other-cryptocurrency deposit data (addresses and amounts) is processed by Flashnet at the time of the transaction — we do not store this data on our servers or link it to your identity.
Where we do process minimal data (such as analytics or push tokens), we implement reasonable technical and organizational measures to protect it. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
The email address and phone number you provide to buy Bitcoin are stored encrypted and used only to enable purchases through Coinbase (Section 6). The last four digits of your SSN and your date of birth are passed directly to Coinbase and never stored by us.
Analytics and push notification data is retained only as long as necessary for its stated purpose and is periodically purged. In the event of a data breach affecting personal data, we will notify affected users and relevant authorities as required by applicable law.
11. International Data Transfers
OrkLabs S.A.S. is based in Argentina. If you access the App from outside Argentina, including from the United States or the European Union, any limited data we process (such as analytics or crash reports) may be transferred to and processed in Argentina or other countries where our service providers operate. By using the App, you consent to such transfers.
12. Your Rights
Given our self-custody architecture, we hold minimal to no personal data. Depending on your jurisdiction, you may have rights regarding your personal data, including the right to access, correct, delete, or restrict its use.
- United States residents: If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and the right to request deletion. Given our minimal data collection, we do not sell personal information.
- EU/EEA residents: You may have rights under the General Data Protection Regulation (GDPR), including the right to access, rectification, erasure, and data portability.
To exercise any of these rights, contact us at hello@pig.gy. We will respond within the timeframe required by applicable law.
13. Children's Privacy
Piggy is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We will make reasonable efforts to notify you of material changes through the App or other communication channels. Continued use of the App after changes constitutes acceptance.
15. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the Argentine Republic.
16. Contact
If you have questions about this Privacy Policy, contact us at:
OrkLabs S.A.S. — hello@pig.gy