Terms & Privacy Policy

Two documents in one place: the rules for using P2PChat, and what we do with your data. Both apply to the P2PChat mobile application, the browser extension and the website.

P2PChat Terms of Use

Last updated: 11.08.2026

These terms set out the rules for using P2PChat: who may use the service, how the non-custodial wallet works, what is not allowed, and who is responsible for what.

1Who we are and what these terms cover

P2PChat is operated by Private Company «Mervey Ltd.» («Mervey», «we», «us»), registered at the Astana International Financial Centre, Republic of Kazakhstan.

These terms govern your use of the P2PChat mobile application for iOS and Android, the browser extension, the website and related services (together, the «service»).

By creating an account or otherwise using the service, you accept these terms. If you do not accept them, do not use the service.

These terms of use and the privacy policy are two separate documents published on one page. The terms describe the rules of using P2PChat; the privacy policy describes what we do with your data.

2Who may use P2PChat

You may use the service only if you are at least 18 years old and have the legal capacity to enter into a binding agreement.

  • use the service for yourself, and not on behalf of another person without their authority;
  • you must not be located in, or a resident of, a country or territory subject to comprehensive sanctions, and you must not appear on an applicable sanctions list;
  • you are responsible for checking that using a crypto wallet and a messenger is lawful where you are;
  • we may refuse or end access where the law requires it or where these conditions are not met.

3Your account

An account is created on your device. Neither a phone number nor an email address is required to register.

Access is protected by a PIN and, if you enable it, by biometrics. Keep your device, your PIN and your recovery phrase secure: whoever obtains them controls the account and the wallet.

You are responsible for everything done through your account. Write to [email protected] if you believe someone else has gained access to it.

We can neither reset your PIN nor restore access to an account whose recovery phrase has been lost. That is a direct consequence of the design described in the next section.

4Your wallet is non-custodial

The wallet is non-custodial. Your recovery phrase and private keys are generated on your device and are never sent to us. We do not hold your assets, we cannot move, freeze or recover them, and we never act as your custodian, broker or exchange.

You alone are responsible for keeping your recovery phrase. If you lose it and have no backup, access to the funds is lost permanently — for everyone, including us.

If you save an encrypted backup to iCloud or Google Drive, you also choose the password that protects it. We never receive that password and cannot recover the backup without it.

Never disclose your recovery phrase, private key or PIN to anyone. We will never ask you for them — under any circumstances, on any channel.

5Transactions, networks and fees

Transactions are executed on public blockchain networks. Once a transaction has been broadcast it cannot be recalled, reversed or cancelled — neither by you nor by us.

You are responsible for the details you enter: the recipient address, the network, the asset and the amount. Assets sent to a wrong address or over a wrong network are normally unrecoverable.

Network fees are set by the network, not by us. Where we charge a service fee for an operation, it is shown before you confirm it.

Confirmation times, network availability and the rates quoted by exchange providers are outside our control. A quoted rate is indicative until the operation is confirmed.

6Compliance checks and restrictions

Transactions may be screened automatically for anti-money-laundering (AML) and sanctions risk before they are executed.

Where the law requires it, or where an operation or an account presents a clear risk of fraud or of unlawful activity, we may delay or refuse the operation, request additional information, restrict functions or block the account.

We may disclose information to regulators and law-enforcement authorities where the law requires it. What we hold, and for how long, is set out in the privacy policy.

7Identity verification and merchant status

Identity verification (KYC) is optional for basic use of the service and can be skipped during registration. Some functions and limits become available only after verification.

Verification is carried out by a separate provider. You are responsible for the accuracy of the documents and information you submit; submitting another person’s documents or forged documents ends your access.

Where merchant status is offered, its requirements are shown in the app at the moment you apply for it. We may withdraw the status if those requirements stop being met.

8Rules for messages, calls and content

You are responsible for what you send through the messenger. Chats are not end-to-end encrypted — the technical detail is in the privacy policy.

The following is not allowed:

  • unlawful content, and content that promotes or organises unlawful activity;
  • fraud, phishing, and impersonation of another person, of a company or of P2PChat support;
  • requests for another user’s recovery phrase, private key or PIN, under any pretext;
  • spam, mass unsolicited messaging and automated distribution;
  • malware, and links intended to compromise another user’s device or wallet;
  • threats, harassment and incitement to hatred or violence;
  • sexual content involving minors, and any content that exploits or endangers a child;
  • publication of another person’s private data without their consent.
We may remove content and restrict an account when these rules are broken. Reports go to [email protected].

9Deals between users

P2PChat lets users find one another and communicate. Where you agree a deal with another user, that agreement is between the two of you: we are not a party to it, we do not guarantee that the other side will perform, and we do not act as a broker, dealer or exchange in it.

Where the app provides tools for a deal, the conditions of those tools are shown in the app at the moment you use them and apply in addition to these terms.

Check who you are dealing with. A counterparty’s rating, verification status or history is information, not a guarantee.

10Third-party services

Parts of the service depend on providers we do not control: identity verification, push notification delivery by Apple and Google, cloud backups in iCloud and Google Drive, exchange providers and blockchain infrastructure.

Their own terms and privacy policies apply to what they do. We are not responsible for their availability, and an interruption on their side may interrupt the corresponding function of P2PChat.

11Prohibited use

In addition to the content rules above, you must not:

  • use the service for money laundering, terrorist financing, sanctions evasion or any other unlawful purpose;
  • circumvent, or attempt to circumvent, security controls, verification, limits or a block;
  • access the service by automated means, scrape it, or place unreasonable load on it;
  • decompile, reverse-engineer or modify the applications, except where the law expressly permits it;
  • resell the service or provide it commercially to third parties without our written consent;
  • create a new account in order to replace a blocked one.

12Suspension and termination

We may suspend or terminate access — in whole or in part — where these terms are broken, where the law or a regulator requires it, or where there is a clear risk to other users, to us or to the security of the service.

Where it is possible and lawful to do so, we tell you the reason. A block does not affect your funds: they remain on the blockchain, controlled by your recovery phrase, and the wallet can be restored in any compatible application.

You may stop using the service at any time and delete your account — in the app, or through our account deletion page, which works without the app.

Deleting an account does not lift a block. A blocked wallet address stays blocked, so registering the same recovery phrase again will be refused.

13Intellectual property

The applications, the website, their design, code, trade marks and content belong to Mervey Ltd. or to our licensors. We grant you a personal, non-exclusive, non-transferable and revocable right to use the service for its intended purpose.

Content you create remains yours. You grant us only the rights we need in order to store it, transmit it and display it to the recipients you choose.

The cryptographic protocol specification is published separately and does not change the ownership of the software.

14No financial or investment advice

Nothing in the service is financial, investment, tax or legal advice, and nothing in it is a recommendation to acquire or dispose of any asset.

Crypto-asset prices are volatile and the value of an asset can fall to zero. You make your own decisions and bear their consequences.

15Disclaimers and limitation of liability

The service is provided «as is» and «as available». We do not warrant uninterrupted or error-free operation, and we do not warrant the accuracy of rates, balances or other data obtained from external sources.

To the extent permitted by law, we are not liable for loss of profit, loss of data, or indirect or consequential loss, nor for loss caused by the loss or disclosure of your recovery phrase, private key or PIN, by a transaction sent to a wrong address or network, by the acts of another user, or by a failure of a blockchain network or a third-party provider.

Nothing in these terms excludes liability that cannot be excluded under applicable law.

16Changes to these terms

We may update these terms as the product and the law change. The current version is always published on this page together with the date it was updated.

Where a change is material, we notify you in the app or through another available channel. Continuing to use the service after a change takes effect means you accept the updated terms.

17Governing law and disputes

These terms are governed by the law of the Astana International Financial Centre (AIFC), Republic of Kazakhstan.

If a dispute arises, write to us at [email protected] first — most matters are resolved without a formal procedure. Disputes that cannot be resolved that way are subject to the AIFC Court, unless a mandatory rule of your country of residence gives you the right to another forum.

18Contact

Questions about these terms, abuse reports and legal notices: [email protected].

Operator: Private Company «Mervey Ltd.», Astana International Financial Centre, 010000, Astana, Esil district, 29 Alikhan Bokeikhan, office 42.

P2PChat Privacy Policy

Last updated: 07.08.2026

This policy explains what data P2PChat collects, why, who it is shared with, how long it is kept and how you can control it.

1Scope and our relationship with users

This policy covers the P2PChat mobile application for iOS and Android, the browser extension, the website, and related services. By using the product, you accept the data processing described here.

We follow data minimisation: we collect only what the messenger and the wallet need to work, plus authentication, security, and — if you choose it — identity verification.

An account is created on your device. Neither a phone number nor an email address is required to register.

2What data we collect and why

The table below lists everything that leaves your device, and everything we deliberately do not collect.

Your IP address is processed in transit only — for routing, abuse prevention, and regional compliance.

CategoryCollectedWhat exactly, and why
ProfileYesfirst and last name, username, phone number (if you provide one), bio, city, country, language, time zone, avatar — for your profile and for messaging
Messages and mediaYesmessage text, photos, voice messages and files; stored on our server — see §4
LocationYesprecise coordinates — only when you choose to send your location as a message in a chat; see §3
Wallet dataYespublic wallet addresses and portfolio composition; your recovery phrase and private keys stay on the device — see §5
Transaction dataYesoperation history, amounts, timestamps — to display and process your operations
Authentication dataYesuser ID, session tokens, security flags — for access and account protection
Push token and envelope keyYesthe APNs or FCM device token and the notification encryption key — see §7
Identity document and selfieYes, optionalonly if you complete identity verification; processed by Didit — see §6
Contacts (address book)Nothe permission is never requested
Email addressNothe app never sends it to the server
Browsing history and website contentNothe extension does not read the pages you visit
Analytics, crash reports, advertisingNono analytics or crash-reporting SDK and no advertising identifiers are present
We do not sell personal data and we do not use it for behavioural advertising. No tracking across apps or websites takes place.

3Device permissions and location

Permissions are requested for a specific feature, at the moment that feature needs them.

  • camera — scanning QR codes, and capturing your document and selfie during identity verification;
  • microphone — voice calls, and the liveness check during identity verification;
  • photos — choosing an avatar and reading a QR code from an image;
  • biometrics — unlocking the app and the wallet instead of entering your PIN; biometric data is handled by the operating system and is never sent to us;
  • location — only when you choose to send your location as a message in a chat.
Location is never collected in the background and is never used for advertising or profiling. Declining any permission does not block the app — only the corresponding feature becomes unavailable.

4Messages, media and calls

Messages and attachments travel over a secure channel (TLS) and are stored on our server so they can be delivered to your devices and synchronised between them.

Chats are not end-to-end encrypted. This means we are technically able to access message content on the server. We do not read your conversations in the ordinary operation of the service, but we do not claim that doing so is impossible.

Voice call audio travels directly between devices, or through a relay server when a direct connection cannot be established. We do not record or store call audio.

5Wallet and recovery phrase backup

The wallet is non-custodial: your recovery phrase and private keys are generated on your device, stored encrypted in the platform's secure storage, and never sent to us. We cannot access your funds.

Public wallet addresses are sent to the server — they are needed to calculate and display your portfolio composition and operation history.

If you choose to, you can save a wallet backup to your own cloud account: iCloud on iOS or Google Drive on Android. Only ciphertext reaches the cloud, encrypted with a password you set specifically for that backup. We never receive or store that password.

If you forget your backup password, nobody can recover the backup — not you, not us, not the cloud provider. That is a direct consequence of you being the only holder of the key.

6Identity verification

Identity verification is optional: the app works fully without it, and you can skip it during registration.

If you do complete it, the image of your identity document and your selfie are processed by Didit — a separate verification provider acting as an independent processor of that data. Capture happens on your device, after which the images are transmitted to Didit.

What comes back to us is the verification result and its related statuses, not the images themselves.

Processing of your document and selfie is also governed by Didit's privacy policy — we recommend reading it before starting verification.

7Push notifications

To deliver notifications, the app registers a device token with Apple (APNs) or Google (FCM) and sends it to us.

Notification content is encrypted on our side with a key that is generated on your device and sent to us once, during device registration. As a result, notification text does not pass through Apple's or Google's infrastructure in the clear.

The key is held in the platform's secure storage and is discarded when you sign out. The technical parameters are published in our cryptographic protocol specification.

8Cookies and similar technologies

On the website we use cookies and similar technologies to remember settings and keep core functionality working.

The mobile app and the browser extension do not use cookies for tracking.

Where required by law, you can manage your cookie preferences.

9How and why we share data

We share data only where it is necessary to operate the service.

  • Didit — your document image and selfie during identity verification (§6);
  • Apple and Google — push notification delivery; the notification content is encrypted (§7);
  • iCloud or Google Drive — your wallet backup, as ciphertext only and only when you initiate it (§5);
  • infrastructure providers — hosting, call relaying, abuse prevention; they act under contract and limited instructions;
  • regulators and law-enforcement authorities — where the law requires it;
  • a successor entity in the event of corporate restructuring — with the protections of this policy preserved.
We do not sell personal data and we do not share it with data brokers.

10International transfers

Some data may be processed on infrastructure outside your country.

For such transfers we apply contractual and organisational safeguards and work with providers that maintain appropriate data protection standards.

11Data security

No internet-connected system can be guaranteed secure, so we continuously improve our controls and response procedures.

  • PIN or biometric unlock, with automatic app locking;
  • the wallet recovery phrase is stored encrypted only, under a key derived from your PIN;
  • encryption and cryptographic controls for sensitive data; every algorithm is a published international standard;
  • a least-privilege access model;
  • security monitoring and anti-abuse controls.

12Data retention

We keep data for as long as needed to provide the service, meet legal obligations, and resolve disputes.

When data is no longer needed, we delete or anonymise it. Where immediate deletion is not possible (in backups, for example), the data is isolated until deletion becomes feasible.

13Your privacy rights

To exercise your rights, write to us at [email protected]. You can delete your account yourself inside the app — see §14.

  • request access to your personal data;
  • request correction of inaccurate data;
  • request deletion where legally applicable;
  • request restriction of processing, or withdraw consent, where applicable;
  • request data portability where legally supported.

14Deleting your account

You can delete your account directly in the app: Profile → Edit profile → Delete account. No separate request and no correspondence with support is needed.

On deletion we remove your profile, your messages, and the data associated with your account on the server. Individual records may be kept longer where the law requires it; such data is isolated and is not used in the ordinary operation of the service.

Deleting your account does not delete your wallet: the recovery phrase remains with you, and the wallet can be restored from it in any compatible application.

If the app is no longer installed, you can send a deletion request on our account deletion page — it works without the app and is linked in the footer of this site.

A backup stored in iCloud or Google Drive must be deleted separately — it lives in your own cloud account and we have no access to it. If you uninstall the app without deleting your account, the server-side data remains.

15Children

The service is not intended for children. We do not knowingly collect personal data from children.

If you believe a child has shared personal data with us, contact us and we will take appropriate action under applicable law.

16Policy updates

We may update this policy as the product evolves and legal requirements change.

The current version is always published on this page, together with the date it was updated.

17Contact us

For privacy questions and data requests: [email protected].

For product support questions, please use the P2PChat support channels.

Operator: Private Company «Mervey Ltd.», Astana International Financial Centre, 010000, Astana, Esil district, 29 Alikhan Bokeikhan, office 42.

Terms & Privacy Policy | P2PChat