MyCryptoTrail
  • Home
  • How It Works
  • Pricing
  • FAQs
Sign In Get Started

Last Updated: August 28, 2026

Privacy Policy

MyCryptoTrail.com — Find Your Way Back, LLC, a California limited liability company.
Please read this Policy together with our Terms of Service. This Policy is incorporated into, and is part of, the Terms of Service.

1. Introduction, Scope, and Relationship to the Terms of Service

This Privacy Policy (the “Policy”) explains how Find Your Way Back, LLC, a California limited liability company doing business as My Crypto Trail (“My Crypto Trail,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when you use our websites, our iOS application, our desktop application, our planner products, and the related services we provide (together, the “Service”). It also explains the choices and rights you have.

This Policy is incorporated by reference into our Terms of Service (the “Terms”) and forms part of your agreement with us. Capitalized terms used but not defined here have the meanings given in the Terms, including “Service,” “Your Content,” and “Trusted Contacts.” Where this Policy describes a practice that the Terms also address, the two documents are intended to be read together; if a genuine conflict exists as to how we handle personal information, this Policy controls, except that Sections 6, 9, 19, 20, 24, and 26 of the Terms control as to their subject matter.

We are the “controller” of the personal information described in this Policy for purposes of the EU and UK General Data Protection Regulation, and a “business” for purposes of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”). This Policy is available within the app, on our websites, and is linked from our App Store listing and our Etsy shop.

The Service is intended only for individuals 18 years of age or older. See Section 21.

2. Summary of Key Points

This summary is provided for convenience only. It is not a substitute for the full Policy, and the sections referenced below control.

  • We are not a custodian. We never hold your cryptocurrency, wallets, or private keys, and the Service does not connect to your wallets, exchanges, or financial accounts. See Section 3 of the Terms.
  • You choose what goes into your trails. We strongly recommend that you record clues and instructions rather than full seed phrases, recovery phrases, or passwords. See Sections 3.1(b) and 11.
  • We do not track you. We use one strictly necessary cookie to keep you signed in. We use no analytics, advertising, or tracking cookies, no pixels, tags, SDKs, session replay, or fingerprinting, and no cross-site or cross-app tracking. See Section 8.
  • We do not sell your personal information and we do not share it for cross-context behavioral advertising. See Section 7.
  • We are not a zero-knowledge service. We manage the encryption keys on our own infrastructure, which means we have the technical ability to access information in your account. See Section 10.2.
  • We do record support communications. Calls, chats, and tickets may be recorded and transcribed, with notice and consent. See Section 9.
  • Recording a Trusted Contact is not a legal designation and is not an “online tool” under the California Revised Uniform Fiduciary Access to Digital Assets Act. See Section 12.
  • California, EEA, UK, and other state residents have specific rights. See Sections 17, 18, and 19, and Section 25 for how to exercise them.

3. Information We Collect

3.1 Information you provide to us

(a) Account information. Your email address, any name or profile details you provide, your password in hashed form, and, if you enable it, multi-factor authentication settings.

(b) Trail content. The notes, clues, instructions, wallet and exchange names, locations, and other information you enter into your trails. You may also choose to enter highly sensitive details, such as private keys, recovery phrases, seed phrases, PINs, or wallet passwords. We recommend against storing full secrets and encourage you to record clues instead. See Sections 10 and 11 of this Policy and Sections 3(d) and 8 of the Terms.

(c) Uploads and recordings. Files, photographs, documents, screen recordings, audio, and video recordings you add to your trails.

(d) Trusted-contact information. The names and contact details of the people you list as Trusted Contacts, together with any message you record for them. See Section 12.

(e) Purchase and order information. For planner products, the shipping name and postal address you provide, order contents, and delivery status. Physical planners are currently sold through our Etsy shop and shipped by us by USPS Priority Mail. See Section 7 of the Terms.

(f) Communications. The content of messages, support tickets, chat sessions, in-product messages, emails, and telephone calls between you and us, including any recordings, transcriptions, and metadata. See Section 9.

(g) Mobile number, if you provide one. If you affirmatively opt in to text messages under Section 24.12 of the Terms, we collect and use the mobile number you give us for that purpose.

3.2 Information we collect automatically

We collect, on our own servers, only the technical information necessary to operate, secure, authenticate, and troubleshoot the Service: your IP address, device type and operating system, browser and application version, session and device identifiers, log and error data, authentication events and timestamps, and the approximate region derived from your IP address. We do not collect precise geolocation and do not use GPS, Bluetooth beacons, or Wi-Fi triangulation. This collection is server-side and operational. It is not tracking of your activity across other websites or applications, and it is not used to build advertising or behavioral profiles. Section 8 describes cookies and similar technologies, and Sections 24.3 through 24.5 of the Terms set out the corresponding consents.

3.3 Payment information

We do not collect or store full payment-card numbers. Purchases made inside the iOS application are processed by Apple through its In-App Purchase system. Purchases made on our website are processed by Stripe. Planner purchases are processed by Etsy and its payment processors. From those providers we receive limited transaction information, such as confirmation that a payment succeeded, the plan purchased, the last four digits and card brand where made available to us, subscription status, and refund and chargeback information. We also retain the records of your affirmative consent to automatic renewal required by Section 6.2(d) of the Terms, including the terms displayed to you and the date, time, and method of consent.

3.4 Information about other people

Some information you give us is about someone other than you, including Trusted Contacts and any person appearing or heard in a recording you upload. You represent in Sections 8 and 9.6 of the Terms that you have that person’s permission to provide their information to us and, where the law of their jurisdiction requires it, their consent to the recording. We process that information solely to provide the Service to you and as described in Section 12. If you are located in the EEA or the UK, you may be acting as a controller of that information in your own right; we act as your processor for it and, separately, as a controller for the limited purposes of operating and securing the Service.

3.5 Sensitive information

Certain information described above is treated as sensitive under applicable law. This includes account log-in credentials, security-question answers, and the private keys, seed phrases, recovery phrases, PINs, and wallet passwords you may choose to enter into a trail, together with financial-account information you record. We collect this information only because you choose to enter it, and we use it only to store, encrypt, secure, back up, and display it back to you, to provide support at your request, and as otherwise required by law. We do not use or disclose sensitive information to infer characteristics about you. See Sections 10 and 17.5.

4. How We Use Information

We use personal information for the following purposes:

  • To create, authenticate, and administer your account, including password recovery;
  • To store, encrypt, transmit, back up, and display Your Content, and to make it available to you and to those you authorize;
  • To process subscriptions, payments, refunds, and planner orders, and to fulfill and ship physical products;
  • To send the transactional and service communications described in the Terms, including the automatic-renewal disclosures, acknowledgments, renewal reminders, price-change notices, and cancellation confirmations required by Section 6.2;
  • To provide customer support and to respond to your inquiries, including by reviewing recordings and transcripts of communications as described in Section 9;
  • To secure the Service, authenticate users, detect and prevent fraud, abuse, and unauthorized access, and to enforce the Terms;
  • To operate, maintain, debug, and improve the Service, including through de-identified and aggregated data as described in Section 15;
  • To comply with legal obligations, respond to lawful requests, establish or defend legal claims, and maintain records required by law, including the automatic-renewal consent records described in Section 3.3;
  • To send you news and marketing about the Service, where you have consented or where permitted by law, subject to your right to opt out at any time; and
  • For any other purpose you separately authorize.

We do not use Your Content to advertise to you, and we do not use Your Content to train machine-learning models.

5. Legal Bases for Processing (EEA and UK Users)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we process personal information on the following legal bases: performance of our contract with you, for account administration, storage and delivery of Your Content, payments, and support; our legitimate interests, for security, fraud prevention, service improvement, and defense of legal claims, balanced against your rights; compliance with a legal obligation, for tax, accounting, consumer-protection, and law-enforcement requirements; and your consent, for marketing communications and for the processing of sensitive credentials where consent is the applicable basis. Because we use only a strictly necessary cookie, we rely on the exemption in Article 5(3) of the ePrivacy Directive and do not seek consent for cookies. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

6. How We Disclose Information

We disclose personal information only as described below. We do not sell it. See Section 7.

(a) Service providers. With vendors who help us operate the Service under written contracts that limit their use of the information to performing services for us and prohibit their retention, use, or disclosure of it for any other purpose. These currently include Amazon Web Services and Hostinger (hosting and storage), Stripe (website payments), Apple (iOS payments and distribution), Etsy (planner sales), USPS (shipping), and our software-development provider. As stated in Section 24.6 of the Terms, each acts as our agent and as a party to the communication for purposes of the California Invasion of Privacy Act and the federal Wiretap Act.

(b) Development provider access. Our software-development provider has database access as part of building and maintaining the Service, and accesses that data from outside the United States. As described in Section 10.1, the most sensitive credentials receive additional field-level encryption designed so that they are not readable in plain text even with that access. All personnel and providers are bound by written confidentiality obligations.

(c) Trusted Contacts. If we receive credible notice of your death or incapacity, we may, in our discretion and with no obligation to do so, notify the people you have named and pass along the contact information or message you recorded for that purpose. We do not give a Trusted Contact access to your account, your credentials, or Your Content. See Section 12 of this Policy and Section 9 of the Terms.

(d) Marketplaces and platforms. With Apple and Etsy as necessary to complete and support transactions you initiate on those platforms, subject to their own privacy policies.

(e) Professional advisers and insurers. With our attorneys, accountants, auditors, and insurers, under duties of confidentiality, where reasonably necessary.

(f) Legal and safety. As described in Section 22.

(g) Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of all or part of our assets, or in bankruptcy or a similar proceeding, subject to this Policy and to notice where required by law.

(h) With your direction. With any other person or entity at your direction or with your consent.

Disclosure of the contents of Your Content is additionally governed by the Stored Communications Act consent in Section 24.8 of the Terms and by Section 22 of this Policy.

7. We Do Not Sell or Share Personal Information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined in the CCPA. We have not sold or shared personal information in the preceding twelve months, including the personal information of consumers under 16 years of age. We do not disclose personal information to third parties for their own direct-marketing purposes within the meaning of California Civil Code section 1798.83.

We disclose personal information to service providers and contractors for the business purposes described in Section 6, under contracts that meet the requirements of California Civil Code section 1798.140(ag) and (j). If our practices change, we will update this Policy before the change takes effect and provide the notice and the opt-out mechanisms required by law.

8. Cookies and Tracking Technologies

8.1 What we use

We use only one strictly necessary cookie, to keep you signed in during your session. We do not use analytics, advertising, or tracking cookies, and we do not use a consent banner because we do not use non-essential cookies. Because we do not track you across other sites or over time, we do not respond differently to browser “Do Not Track” signals. If our practices change, we will update this policy and provide any required consent controls.

8.2 What that means in practice

We do not use tracking pixels, tags, web beacons, third-party analytics or advertising SDKs, session-replay technology, keystroke capture, device fingerprinting, or any technology that follows you across other websites, applications, or devices. No advertising network, data broker, or analytics vendor receives information about your use of the Service. The server-side operational data described in Section 3.2 — IP address, device and session identifiers, log and error records — is collected because the Service cannot be delivered or secured without it, and is used only for the purposes stated there.

8.3 Opt-out preference signals

Where applicable law requires, we treat a valid opt-out preference signal, including Global Privacy Control, as a request to opt out of the sale or sharing of personal information for the browser or device from which it is sent and, where we can associate the signal with your account, for that account. Because we neither sell nor share personal information, such a signal does not change how we handle your information, and we honor it as a matter of course.

8.4 What happens if this changes

Section 8.1 is a statement of our current practice, not a reservation of rights. Before we deploy any analytics, advertising, session-replay, or other non-essential technology, we will update this Policy to identify the technology, the vendor, the data collected, and the purpose; make available a cookie and tracking preferences control within the Service; and, where applicable law requires consent, obtain that consent through that control before the technology operates. As stated in Section 24.9 of the Terms, no consent in the Terms extends to any such technology, and nothing in the Terms may be read as your consent to a practice we have represented we do not engage in.

9. Recording and Monitoring of Communications

As set out in Section 24.2 of the Terms, we may record, monitor, store, transcribe, review, and analyze communications between you and us, including chat sessions, in-product messages, support tickets, email, and telephone calls, for quality assurance, training, security, fraud prevention, dispute resolution, compliance, and improvement of the Service. California is an all-party consent jurisdiction for confidential communications under California Penal Code sections 632 and 632.7, so where applicable law requires it we give an audible notice at the start of a call and a visible notice at the start of a chat, and your continuing after that notice is your consent.

You may decline to be recorded by not using the recorded channel and instead writing to us by mail at the address in Section 25, and we will not refuse to provide support because you did so. Recordings and transcripts are retained under Section 13 and are disclosed only as described in Sections 6 and 22. We do not record or monitor the content of your trails except as necessary to store, encrypt, back up, and deliver them, to respond to a support request you make, or as described in Section 10.2.

10. How We Protect Information

We use administrative, technical, and organizational safeguards designed to protect personal information. Specifically:

10.1 Encryption

We encrypt information in transit and at rest. In addition, certain highly sensitive fields you may choose to enter, including private keys, seed phrases, recovery phrases, PINs, and wallet passwords, receive additional field-level encryption designed so that they are not readable in plain text through our databases, routine backups, or system logs.

10.2 Our access to your data

We manage the encryption keys used to protect your information on our own server infrastructure. This means that, unlike a “zero-knowledge” service, My Crypto Trail has the technical ability to access information in your account, including to provide the password-recovery feature that lets you regain access if you forget your credentials. We limit that access to what is needed to operate, support, secure, and improve the Service and to comply with law, and Section 24.8 of the Terms records your consent to that access under the Stored Communications Act and related law. We state this plainly because it is material to how you decide what to store: if you require that no one but you can ever access a secret, do not enter that secret into the Service.

10.3 Personnel and providers

A limited number of our personnel and service providers have administrative or database access necessary to run the Service, subject to written confidentiality obligations and access controls. The additional field-level encryption described in Section 10.1 is designed so that the most sensitive credentials are not readable in plain text even by those persons.

10.4 Store clues, not secrets

My Crypto Trail is designed for you to record clues and instructions, not to be a place to type your full seed phrases, recovery phrases, or passwords. We recommend that you never enter complete seed phrases or passwords on any device and that you follow the in-app guidance to record clues instead. The same warning applies to our planner products under Section 7(c) of the Terms.

10.5 No guarantee

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Section 18 of the Terms disclaims warranties, and Section 19 of the Terms limits our liability, in each case subject to Section 19.4 of the Terms, which preserves liability for fraud, willful injury, violation of law, gross negligence, and any other liability that may not lawfully be limited.

11. Your Security Responsibilities

You play an essential role in keeping your information safe. Keep your password confidential, enable available security features, keep your devices secure and up to date, and be alert to phishing and social-engineering attacks. As stated in Section 5 of the Terms, we will never ask you for your seed phrase, recovery phrase, private key, or wallet password, and any message that does so is fraudulent and is not from us. Because we recommend that you store clues rather than full secrets, we ask that you not enter complete seed phrases, recovery phrases, or passwords into the Service. You are responsible for the security of the accounts and devices you use to access the Service and for maintaining your own independent records of, and means of access to, your digital assets.

12. Trusted Contacts, Death, and Incapacity

This Section describes the privacy handling of Trusted Contact information. Section 9 of the Terms governs what the feature is and is not, and controls as to its legal effect.

12.1 What we do with the information

We store the names, contact details, and any message you record for the people you designate. We use that information only to display it back to you, to let you edit or delete it, and, if the circumstances in Section 12.3 arise, to attempt the notification described there.

12.2 Not a legal designation and not an online tool

Recording a Trusted Contact is not a will, trust, beneficiary designation, payable-on-death or transfer-on-death designation, power of attorney, or other testamentary or nonprobate instrument, and it does not grant the person named any right of access to your account, your credentials, your trails, or Your Content. The Trusted Contacts feature is not, and is not offered or intended as, an “online tool” for the disclosure or nondisclosure of digital assets within the meaning of the California Revised Uniform Fiduciary Access to Digital Assets Act, California Probate Code sections 870 through 884, or any corresponding provision of the law of any other state. Any direction you wish to give about disclosure of your digital assets after your death or incapacity must be made in your will, trust, power of attorney, or other written record, and we will treat that instrument, together with applicable law and valid legal process, as controlling. See Sections 9.2 through 9.4 of the Terms.

12.3 Notification, and what we do not promise

If we receive credible notice of your death or incapacity, we may, in our discretion and without any obligation to do so, notify the people you named that you maintained an account and pass along the contact information or message you recorded. We have no duty to verify any report of death or incapacity, to investigate, to locate any person, to confirm that any notification was received, or to send any notification at all. We owe no duty of care to any person you name and have no obligation to monitor your status.

12.4 Requests from fiduciaries and family members

If a personal representative, executor, trustee, agent under a power of attorney, conservator, or family member asks us for access to or deletion of an account, we will require documentation of the requester’s authority and of the death or incapacity, and we will act only as required or permitted by applicable law and valid legal process, including the Stored Communications Act, which restricts our disclosure of the contents of a subscriber’s communications. We may decline a request we cannot verify, and we may notify other interested persons where permitted. Nothing in this Section creates an obligation to disclose the contents of an account to any person.

12.5 No vault-access feature today

The broader feature that would allow a person you designate to obtain access to specified content after your death or incapacity is a planned future feature and is not active. As stated in Section 9.7 of the Terms, if and when it is offered, it will be governed by separate additional terms, will require your separate affirmative enrollment, and will be accompanied by an updated Privacy Policy describing the associated data handling.

13. Data Retention

We retain personal information for as long as your account is active and as needed to provide the Service, and thereafter only as required to comply with law, resolve disputes, enforce our agreements, and maintain the records described below. Our general practice is as follows, subject to any legal hold:

  • Account and trail content: for the life of the account. When you delete an item, it is removed from the Service and purged from routine backups within the ordinary backup rotation cycle.
  • Closed or deleted accounts: we delete or de-identify personal information within a reasonable period, ordinarily not more than 30 days after deletion, except where retention is required.
  • Automatic-renewal consent records: for the period required by applicable law, as described in Section 6.2(d) of the Terms.
  • Transaction, tax, and accounting records: for the period required by applicable tax and accounting law.
  • Communication recordings and transcripts: 12 months, unless needed for an open matter.
  • Security, access, and error logs: 12 months, or longer where needed to investigate an incident.

Inactive accounts are handled under Section 17 of the Terms. If your account remains inactive for an extended period, we may notify you and, after further notice, suspend or close the account. We will not delete a paid account for inactivity without notice and an opportunity to respond.

14. Security Incidents and Notification

If we become aware of a security incident affecting your personal information, we will promptly investigate, take reasonable steps to contain and remediate it, and notify affected individuals and regulators where and as required by applicable law, including California Civil Code sections 1798.29 and 1798.82 and, for individuals in the EEA or the UK, Articles 33 and 34 of the GDPR. Our notice will describe, to the extent then known, the categories of information involved, the date or estimated date of the incident, what we are doing in response, and steps you can take. We will not delay notice beyond what applicable law permits, and we will not condition notice on your agreement to any release.

15. De-identified and Aggregated Data

We may create de-identified or aggregated data that does not identify you and cannot reasonably be used to identify you, for example to understand usage and improve the Service. We maintain and use such data only in de-identified or aggregated form, we take reasonable measures to ensure it cannot be associated with you, we publicly commit to maintain and use it only in that form, and we contractually obligate any recipient to do the same. We will not attempt to re-identify it, except as permitted by law to test the effectiveness of our de-identification.

16. Your Choices and Rights

These rights are available to everyone, whether or not you live in a jurisdiction that requires them:

  • Access and correction. You can review and update your account information and Your Content in the app at any time, and you can ask us for a copy of the personal information we hold about you.
  • Export. You can request an export of Your Content in a portable format. Section 22 of the Terms gives you a window to export Your Content before deletion in most termination scenarios.
  • Deletion. You can delete individual items, or close your account, at any time. Closing your account does not by itself cancel a paid subscription; cancellation is governed by Section 6 of the Terms.
  • Marketing. You can opt out of marketing email at any time using the unsubscribe link or by contacting us, and you can stop text messages by replying STOP. We will still send transactional and service messages while your account is active, including the notices required by Section 6.2 of the Terms.
  • Recording. You can decline to be recorded as described in Section 9.

To make a request, use the contact information in Section 25. We will respond within the time required by applicable law. We may need to verify your identity before acting, and we will not use information you provide for verification for any other purpose.

17. California Privacy Rights

This Section applies to California residents and supplements the rest of this Policy. It also serves as our notice at collection under the CCPA.

17.1 Categories of personal information we collect

In the preceding twelve months, we have collected the following categories of personal information. We collect each category from you, from your device, and from the service providers and platforms identified in Section 6, and we disclose each category to service providers for the business purposes described in Section 4. We do not sell or share any category.

CCPA category What this includes for us Purposes
Identifiers Name, email address, shipping address, account username, IP address, session and device identifiers, order numbers. Account, delivery, support, security, legal compliance.
Customer records (Civ. Code § 1798.80(e)) Name, postal address, telephone number where you provide it, and payment-related information held by our processors. Payments, fulfillment, support, recordkeeping.
Commercial information Subscription plan and status, purchase and refund history, planner orders, automatic-renewal consent records. Billing, fulfillment, legal compliance.
Internet or network activity Server-side log and error data, authentication events, application version. No cross-site or cross-app activity is collected. Operation, security, debugging.
Geolocation data Approximate region derived from IP address only. No precise geolocation. Security and fraud prevention.
Audio, electronic, visual, or similar information Photographs, documents, screen recordings, audio and video you upload; recordings and transcripts of communications with us. Storage and delivery of Your Content; support and quality assurance.
Sensitive personal information Account log-in credentials; and the private keys, seed phrases, recovery phrases, PINs, wallet passwords, and financial-account information you choose to enter. Storage, encryption, and display back to you; support at your request. See Section 17.5.
Inferences None. We do not profile you or draw inferences about your characteristics. Not applicable.

17.2 Your California rights

  • Right to know. You may request the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties and service providers to whom we disclose it, for the twelve-month period preceding your request, or for a longer period where you request it and it is not impossible or disproportionately difficult for us to provide.
  • Right to delete. You may request that we delete personal information we collected from you, subject to the exceptions in the CCPA, including where retention is necessary to complete a transaction, provide a good or service you requested, detect security incidents, comply with a legal obligation, or exercise or defend legal claims.
  • Right to correct. You may request that we correct inaccurate personal information, taking into account its nature and the purposes of processing.
  • Right to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. We honor valid opt-out preference signals as described in Section 8.3.
  • Right to limit the use of sensitive personal information. See Section 17.5.
  • Right to non-discrimination. We will not deny you goods or services, charge you a different price, or provide a different level or quality of service because you exercised a privacy right. We do not offer financial incentives for personal information.

17.3 How to submit a request

Submit a request by emailing support@mycryptotrail.com. Because we operate exclusively online and have a direct relationship with you, email is our designated method under the CCPA. We will acknowledge your request within ten business days and respond within forty-five calendar days, which we may extend by an additional forty-five days with notice to you.

17.4 Verification and authorized agents

To protect your information, we must verify your identity before we act on a request to know, delete, or correct. We will ordinarily verify you by confirming control of the email address on the account and, for requests involving sensitive personal information or specific pieces of information, by additional means proportionate to the sensitivity of the information. An authorized agent may submit a request on your behalf with your written permission, and we may require you to verify your identity directly with us and to confirm that you gave the agent permission. An agent acting under a valid power of attorney under California Probate Code sections 4000 through 4465 need not provide separate written permission.

17.5 Sensitive personal information and the right to limit

We collect the sensitive personal information described in Section 17.1 only because you choose to enter it, and we use and disclose it solely to perform the services you requested, to store and secure it, to prevent and investigate security incidents and fraud, to verify or maintain the quality of the Service, and as otherwise permitted by California Code of Regulations, title 11, section 7027(m). Because we do not use or disclose sensitive personal information to infer characteristics about you or for any purpose beyond those permitted uses, the right to limit its use and disclosure does not apply. You may nonetheless delete any sensitive information you have entered, at any time, directly in the app, and you may request deletion under Section 17.2.

17.6 Retention

We do not retain personal information for longer than reasonably necessary for the purposes described in this Policy. Our retention periods by category are set out in Section 13.

17.7 Disclosures of Personal Information

California Civil Code section 1798.83 permits California residents to request information about disclosures of personal information to third parties for those third parties’ direct-marketing purposes. We do not make such disclosures.

17.8 Other California notices

Nothing in this Policy or in the Terms operates as a waiver of any right that is non-waivable under California law, including under the California Consumer Privacy Act, California Civil Code section 1798.150, or the California Invasion of Privacy Act, California Penal Code section 637.2, as confirmed in Section 19.5 of the Terms. The consents in Section 24 of the Terms are limited to the practices described in this Policy and do not authorize any other collection, interception, or disclosure. Complaints may be directed to the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs, 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, (800) 952-5210.

18. Other U.S. State Privacy Rights

If you are a resident of a state with a comprehensive consumer privacy law, including Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to confirm whether we process your personal data and to access it, to correct inaccuracies, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and profiling with legal or similarly significant effects. We do not engage in targeted advertising, do not sell personal data, and do not conduct such profiling. Where your state requires consent to process sensitive data, we rely on the consent you give when you choose to enter that data, and you may withdraw it by deleting the data or closing your account.

To exercise these rights, contact us as described in Section 25. If we decline a request, you may appeal by replying to our response or writing to the same address; we will respond to an appeal within the time your state’s law requires and will tell you how to contact your state attorney general if you remain dissatisfied. Nevada residents may submit a request that we not sell covered information under Nevada Revised Statutes chapter 603A; we do not engage in such sales.

19. Rights of Users in the EEA, the UK, and Switzerland

Subject to applicable law, you have the right to access your personal information, to have it corrected or erased, to restrict or object to its processing, including objecting to processing based on our legitimate interests, to data portability, to withdraw consent at any time, and to lodge a complaint with your supervisory authority. In the UK you may complain to the Information Commissioner’s Office; in the EEA, to the data protection authority of your habitual residence, place of work, or the place of the alleged infringement. We do not use automated decision-making that produces legal or similarly significant effects. To exercise these rights, contact us as described in Section 25.

20. International Data Transfers

We are based in the United States and store and process personal information in the United States. Our software-development provider accesses data from outside the United States. Laws in the United States and in the countries from which our providers operate may differ from those in your country and may permit access by public authorities in circumstances that differ from those in your country.

If we make the Service available to users in the EEA, the UK, or Switzerland, transfers of personal information out of those regions will be made under an approved transfer mechanism, such as the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer impact assessment and appropriate supplementary measures. You may request a copy of the relevant mechanism, with commercially sensitive terms redacted, using the contact information in Section 25.

21. Children’s Privacy

The Service is intended solely for adults 18 years of age and older, consistent with Section 2 of the Terms. We do not knowingly collect personal information from anyone under 18, and the Service is not directed to children under 13 within the meaning of the U.S. Children’s Online Privacy Protection Act, 15 U.S.C. sections 6501 through 6506, and its implementing rule. We do not knowingly sell or share the personal information of consumers under 16. If you believe a minor has provided us information, contact us at support@mycryptotrail.com and we will delete it and terminate the account.

22. Legal Requests and Disclosures

We may access, preserve, and disclose personal information when we reasonably believe it is required by law, legal process, or a governmental request, or is necessary to protect the rights, property, or safety of My Crypto Trail, our users, or the public. To the extent we are a provider of electronic communication service or remote computing service under the Stored Communications Act, 18 U.S.C. sections 2701 through 2713, we will require the legal process that statute requires before disclosing the contents of Your Content to a governmental entity, and we will not disclose contents voluntarily to a governmental entity except as that statute permits. The consent you give in Section 24.8 of the Terms is not consent to voluntary disclosure of contents to a governmental entity.

Where we are permitted to do so, we will make reasonable efforts to notify you of a legal demand for your information before we respond, so that you may seek to protect your interests, unless we are prohibited from giving notice, notice would be futile or ineffective, or there is an emergency involving a risk of death or serious physical injury. We will object to or move to narrow demands that we consider overbroad or legally deficient. This Section corresponds to Section 23 of the Terms.

23. Third-Party Services and Links

The Service relies on and may link to third parties, including Apple, Stripe, Etsy, cloud hosting providers, and the wallet and exchange providers you use. Those parties have their own privacy practices, and we are not responsible for them. We encourage you to review their policies. As stated in Section 3(b) of the Terms, the Service does not connect to your wallets, exchanges, or financial accounts through any application programming interface or automated link, and we do not receive information from them.

24. Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy with a new “Last updated” date and, for material changes, provide notice by email and in the app before the change takes effect. Where applicable law requires your affirmative consent to a change, we will obtain it before the change applies to you. A change to the practices stated in Section 8.1 is governed by Section 8.4 and by Section 24.9 of the Terms. A change to the Terms is governed by Section 28 of the Terms.

25. Contact Us

For privacy questions, or to exercise any right described in this Policy:

My Crypto Trail (Find Your Way Back, LLC)
1883 W Royal Hunte Dr, STE 200A, Cedar City, UT 84720
Email: support@mycryptotrail.com

26. Disputes

Any dispute, claim, or controversy arising out of or relating to this Policy is governed by Section 26 of the Terms, which requires binding individual arbitration in Los Angeles County, California, administered by the American Arbitration Association, and which contains a class action waiver. Section 20 of the Terms limits the time to file a claim. Section 20.2 of the Terms preserves the full statutory period for claims under California Civil Code section 1798.150, California Penal Code section 637.2, the Consumers Legal Remedies Act, California Business and Professions Code sections 17200 et seq. and 17600 et seq., and 18 U.S.C. sections 2520 and 2707. Nothing in this Policy or in the Terms waives a non-waivable statutory right.

MyCryptoTrail

Join our community on social media

Quick Links

Home Pricing Features
Privacy Policy Terms of Service FAQ

For support

Email us at support@mycryptotrail.com


COPYRIGHT ©️ 2026 FIND YOUR WAY BACK, LLC ALL RIGHTS RESERVED.

MCT Guide Usually replies instantly