Privacy Policy
Updated 13 August 2026 · minimization by design
Nocturne is built on a simple idea: the safest data is the data we never collect. This policy explains the little we do handle and why.
What we collect
- An account credential: an email address with a salted password hash, or a one-way fingerprint of your sign-in token. The token itself and the twelve recovery words are generated on your device and are never sent to us.
- A funding reference: the on-chain transaction used to load a card.
- Messages you send us: a support thread stays a support thread, nothing more.
- Minimal technical logs: coarse, short-lived records needed to keep the service running and to prevent abuse.
What we never collect
We do not ask for, and do not store:
- Your legal name
- Government ID, passport, or document scans
- A selfie or biometric data
- Proof of address
- Source-of-funds paperwork
One honest exception: where a transfer is flagged by compliance screening (see the AML section of the terms), we or the processor may ask about that specific transfer. Anything provided for such a review is used for that review alone, kept only as long as the review requires, and never becomes an identity file.
How we use what little we have
- To provide, secure, and support the card service
- To sign you in, and to send receipts and the messages you ask for
- To detect and prevent fraud and abuse
Analytics
To understand how many people visit, which pages they read, and how our advertising performs, we use Google Analytics. It uses cookies and shares aggregate usage data (pages viewed, referrer, approximate region, and device type) with Google. It never receives your identity, card numbers, balances, or funding activity: there is no name or KYC on file to send, and we never attach account data to analytics. You can opt out with any tracker or ad blocker, or your browser’s Do Not Track / Global Privacy Control setting; it has no effect on your account or card. Beyond analytics, the site itself sets only what sign-in requires: a session cookie and a signed-in hint: no third-party trackers, no advertising pixels of our own.
Retention
We keep operational data only as long as needed for the purposes above or as required by applicable law, then delete or anonymize it. Deposit transaction references are kept for roughly 90 days for support and reconciliation, then dropped, the same figure we publish on the company page. Deleting your account destroys its credentials immediately and permanently: sign-in, recovery and every session end at that moment. Records of transactions and balances are retained for as long as financial regulation and valid legal process require, and are then disposed of on the same terms as everything else.
Security
Card details are shown once and travel encrypted. Passwords are stored as salted hashes and sign-in tokens as one-way fingerprints; neither can be read back, by us or anyone else. Because there is no identity file to begin with, there is far less to compromise.
Your choices
You can unsubscribe from messages at any time and request deletion of any contact details you shared by emailing us, or delete the account itself from your dashboard, which destroys its credentials immediately.
International
Nocturne is operated by Noctavel LLC from the United States. By using the service you understand your information may be processed there and in other locations where our providers operate.
Changes
We may update this policy; material changes will be reflected here.
Contact
Privacy questions or deletion requests: hello@nocturne.cards.