Privacy Policy
Last updated 9 August 2026
Prova is built so that we cannot see what you send or who you are. This policy describes what stays on your phone, the little we hold, and who else is involved.
What never leaves your phone
Your recovery seed, your spending keys and your PIN are generated on your device and stored in its secure hardware. We never receive them, and nobody at Prova can recover them for you.
Transfer amounts are never sent to us. Your device produces a zero-knowledge proof that a transfer is valid, and only that proof — plus values that reveal nothing on their own — is published.
Photographs of your identity documents and your liveness check are processed on your device and are not uploaded to Prova.
What we do hold
Your email address, which identifies your account and is where sign-in codes are sent.
A pseudonymous identifier derived from a key on your device. It is not reversible into your name or your identity.
The status of your identity verification, when it changed, and who decided it — required so we can show you where your application stands and evidence our decisions.
Records of transfers limited to the values published on the public blockchain, together with timestamps and status. These contain no amounts and no names.
Support conversations you start with us, so the team can answer you and refer back to what was said.
Identity verification
Verification is currently reviewed by a member of our team, normally within 24 hours. When a licensed verification provider is integrated, your documents will go directly to that provider and still not through Prova.
Approval produces a credential stored on your device stating only that you are verified, your tier, and an expiry. It contains no personal details, and it is what your device proves against when you send.
Other parties
Stellar is a public blockchain. Commitments, nullifiers and proofs written there are permanent and visible to anyone. They do not reveal amounts, names, or who paid whom.
Adding and withdrawing money involves a financial institution (an “anchor”). That institution performs its own checks and holds its own records under its own policy. This build runs on a test network with test assets that have no value.
Cloud backup, if you turn it on, stores an encrypted file in your own iCloud or Google Drive. It is encrypted with a key derived from your PIN before it leaves the device, so the storage provider cannot read it — and neither can we.
Your choices
You may stop using the app at any time and delete it; the keys on your device go with it. Because we do not hold your keys, we cannot restore an account without your backup and PIN.
You may ask us what we hold about your account and ask us to delete it. Some verification records must be retained where the law requires it, and anything already written to the blockchain cannot be removed by anyone.
Questions about this document? Use “Chat with us” in your profile, or email prova.payment@gmail.com, and a member of the team will reply — usually within 24 hours.