Privacy Notice
NimCarry keeps human profiles separate from Nimiq custody authority. This notice explains what the voluntary profile stores and what changes when you use the protocol.
What we collect
When you create a NimCarry profile, we store your name and email, the version and time of your privacy consent, technical profile timestamps, and one-way hashes of private profile/session tokens. Your email is not public and is not used to authorize custody.
When you sign in as a returning user, NimCarry uses your email to deliver a short-lived one-time code. We store the code only as a one-way keyed hash together with its expiry, attempt count, and used/unused state. A successful code verifies the email for profile recovery and creates a separate browser session without replacing your other active sessions. To let an interrupted sign-in resume after a refresh, the browser may temporarily keep only the sign-in stage, an opaque challenge identifier, and its expiry; NimCarry does not store the email address or one-time code in that browser checkpoint.
If you later link Nimiq, we store the verified wallet address and short-lived wallet-link challenge records. If you take protocol actions, mission, participant, custody, finality, and related audit records may also be stored.
Why we use it
The voluntary profile data is used to create and maintain your NimCarry identity, let you recover the same profile on another browser or inside Nimiq Pay, distinguish real registered users from protocol participation, measure genuine product usage, and operate the service. For voluntary profile registration, NimCarry relies on your informed consent. Login challenge/session records and protocol security records are used to authenticate returning users, prevent abuse, provide requested custody functionality, and preserve verification integrity.
Nimiq and public-chain evidence
A NimCarry profile does not require a wallet. A Nimiq wallet becomes necessary only for custody-sensitive actions. Wallet signatures, not email, authorize custody. Public blockchain transactions are outside NimCarry's ability to erase or rewrite.
Retention and deletion
You can delete your profile from the profile card in NimCarry. That deletes the profile row and cascades linked-wallet records, profile sessions, login challenges, and unused wallet-link challenges associated with that profile. Protocol records already created for a mission, independently verified finality evidence, and public blockchain history may remain where needed to preserve protocol integrity and cannot be rewritten by deleting a profile.
Sharing
NimCarry does not sell profile data. Infrastructure providers used to operate the service may process data as necessary to host the application and database. A transactional email provider may process your email address only to deliver requested sign-in codes. Profile emails are not displayed publicly by NimCarry.
Your choice
Profile creation is optional. You must actively check the consent box before registration. If you do not consent, do not create a profile. You can still view public NimCarry surfaces; protocol actions may separately require Nimiq.
Last updated September 19, 2026.A NimCarry profile may link more than one verified Nimiq wallet. When the current holder authorizes a pass, already-verified wallets on that same profile may be frozen as eligible payment sources for that pass. This does not transfer custody; only an independently verified FINAL handoff does.