Herond Browser
Privacy Policy
Part I
INTRODUCTION
Notice of Changes
1.1. This version of the Privacy Policy takes effect on 1 September 2026. It reflects the discontinuation of the swap, bridge, fiat on-ramp/off-ramp and keyless wallet features previously available through Herond Wallet, and describes the updated data-processing flows that apply to the Wallet from that date.
Introduction
2.1. Herond Labs Corporation ("we", "us", or "our") is committed to protecting the personal information of individuals who use Herond Browser ("Herond" or "Browser"). This Privacy Policy explains how we collect, use, share, and secure information obtained through your use of Herond. For the purposes of this Policy, "you" or "user" refers to individuals who use Herond and its associated services.
2.2. This Privacy Policy forms part of, and should be read together with, the Herond Browser Terms of Use. Where there is any inconsistency between this Privacy Policy and the Terms of Use on matters of data protection, this Privacy Policy will prevail.
Part II
DATA ACCESS AND USAGE
Data Access and Usage
3.1. We collect only the information necessary to provide our services.
3.2. We do not rely on a single blanket agreement to justify every use of your data. Each category of personal data is processed on its own legal basis, as set out in Article 10 (Purpose and Legal Basis). Most processing is necessary in order to provide the Service you have asked for — for example, your account email address and your synchronized browser data are processed in order to perform our agreement with you — or is based on our legitimate interest in keeping the Service secure and functioning. We may also process certain data where necessary to comply with our legal obligations.
3.3. Where processing requires your consent, that consent is requested for that specific purpose and can be withdrawn at any time without affecting your ability to use the Service. Silence, inaction or continued use of the Service is not treated as consent. If we introduce a materially new purpose for processing your personal data, we will inform you and, where the law requires consent for that purpose, ask for it.
Data Control and Transfer
4.1. Herond Browser is a product of Herond Labs Corporation, a legally registered company operating in compliance with applicable laws. Herond Labs Corporation is responsible for determining how and why data collected through Herond Browser is processed.
4.2. To support product development and business operations, Herond may integrate with certain third-party infrastructure providers ("Third-Party Services") solely to support blockchain connectivity, RPC and data-display functionality, and other non-transactional technical services. Such integrations may include, but are not limited to:
(a) Blockchain Infrastructure Services (RPC endpoints and transaction broadcasting only);
(b) Data and Display Providers.
4.3. Herond does not sell personal data. Herond processes only the categories of personal data described in this Policy: your account email address, optional synchronized browser data, wallet-related data described below, product and diagnostic data, and support or feedback data that you provide. Herond does not receive or store private keys or recovery phrases.
4.4. All such data exchanges are encrypted in transit and processed only to enable the requested functionality. Herond implements a strict data minimization policy and complies with applicable data protection regulations. Use of Third-Party Services is further subject to each provider's privacy notice and data-handling practices, which Herond does not control or audit. In the event that we are required by law or by a government authority to disclose information, Herond will cooperate fully to comply with our legal obligations.
Location
5.1 Herond may request your permission to collect and provide geolocation data if a website you visit asks for this information. You will be prompted to consent to sharing your location. If you consent, Herond will provide the website with an approximate location based on your IP address. Herond does not retain your IP address for longer than necessary to deliver the requested functionality and maintain security; however, the website you visit or third-party security services may log your IP address.
Synchronization
6.1. Herond Browser offers a secure synchronization feature (Sync) that allows users to store and synchronize their bookmarks, passwords, extensions, personalized settings, and other browser-related data across multiple devices. This data is encrypted and stored on our cloud servers. The decryption key is exclusively held by the user, ensuring complete privacy from Herond Labs Corporation. To use the Sync feature, users must create a Herond Account.
Herond Account
7.1. To create a Herond Account, we will need to collect your email address. This information is essential for providing our services and enabling you to manage your Herond experience. Your email address will be used for important communications, such as password recovery, service registration, and confirmation. Service-related communications are necessary to operate your account. Marketing communications — news, promotions and information about Herond-related events — are optional and are sent only where you have separately opted in; you may unsubscribe at any time.
7.2. If you wish to delete your Herond Account, please send an email request to contact@herond.org using the registered email address associated with your account. Within fourteen (14) days of receiving your request, we will process it and assist you in deleting your account, personal data, associated features and services settings, information, access to documents and applications, synchronized data, and linked third-party accounts. Please note that account deletion is irreversible, and your data may be permanently lost. Before deleting your account, ensure that you have backed up any important or necessary information.
Herond Wallet
8.1. Herond Wallet is a self-custodial crypto wallet built into the Herond Browser. You can create or import a wallet that you control, view balances of supported assets, receive assets, and send transfers that you authorize, on supported blockchain networks.
8.2. Herond Wallet is a non-custodial wallet. This means Herond does not at any time receive, store, or have access to your private keys, seed phrases, hardware wallet credentials, or any other means of authorizing blockchain transactions. You are solely responsible for safeguarding your credentials and for all transactions executed using them, and for backing up your private keys. Herond cannot recover or reset your private keys, seed phrases or hardware wallet credentials, and shall not be liable for any loss, compromise, unavailability, or misuse of your credentials, or for any unauthorized transactions conducted through or in connection with the Service.
8.3. Wallet data is processed in order to provide wallet functionality, as described below. Herond does not use wallet activity for behavioral advertising or profiling without your consent.
8.4. Herond Wallet relies on third-party service providers to read data from, and submit transactions to, blockchain networks. To do this, wallet addresses or transaction data typically need to be passed to those providers. In certain circumstances, such as where a provider is used by default, Herond proxies these requests so that the request is not connected to your IP address by that provider; in those cases the request passes through infrastructure operated by Herond, which receives your IP address as part of routing it. By using Herond Wallet you agree to rely on these services in order to interact with a blockchain network where necessary.
8.5. Herond does not receive, store or have access to users' private keys or recovery phrases, and does not sign transactions on behalf of users. Where you create a new wallet, the private key and recovery phrase are generated locally on your device and are never transmitted to Herond. Transactions are signed locally on your device. Herond does not operate any key-recovery mechanism. Users retain sole control of the credentials required to authorize transfers.
9.Wallet Data Categories
9.1. When you use the wallet, the data processed by Herond or by our blockchain infrastructure providers may include:
(a). public wallet addresses;
(b). blockchain and network identifiers;
(c). transaction hashes and other public on-chain data;
(d). token and NFT identifiers;
(e). metadata contained in RPC requests;
(f). your IP address, where a request is routed through infrastructure operated by Herond.
9.2. Herond does not collect private keys or recovery phrases.
Purpose and Legal Basis
10.1. We process personal data only for the purposes described in this Policy, and each purpose has a legal basis.
10.2. Most processing is necessary in order to provide the Service you have asked for: operating your Herond Account, synchronizing your browser data where you enable Sync, and displaying balances and submitting transfers where you use the wallet.
10.3. Some processing is based on our legitimate interest in keeping the Service secure and available, in preventing abuse, and in understanding how the Service is used so that we can improve it. Where we process data on this basis, we limit it to what is needed for that purpose.
10.4. Marketing communications are sent only where you have given separate consent, which you can withdraw at any time. Where any other processing requires your consent, we will ask for it for that specific purpose.
Service Providers and Recipients
11.1. We share personal data with service providers only where necessary to operate the Service. Our providers fall into the following categories: cloud hosting and synchronization storage; security and safe-browsing services; blockchain infrastructure providing RPC endpoints and transaction broadcasting; product analytics and error monitoring; and customer support tooling. Herond requires these providers to process personal data in accordance with our contractual instructions and applicable law.
Public Blockchain Data
12.1. Public blockchain data, such as wallet addresses and transaction hashes, may be permanently recorded on decentralized networks outside Herond's control. Herond cannot delete or alter data that is independently recorded on a public blockchain, but will honor data-subject requests with respect to personal data controlled by Herond, subject to applicable law.
Cookies and Similar Technologies
13.1. Herond uses cookies and similar technologies to provide the basic functionality of the websites you visit and enhance your user experience. The usage is strictly for operational purposes and is not intended to involve the collection or processing of any personally identifiable information. You can control how websites use cookies by adjusting Herond Browser settings: go to Settings > Privacy & Security > Cookies and other site data.
Access to Device Features
14.1. With your consent, Herond may access and utilize certain device features, including but not limited to the microphone and/or camera, as required by specific websites or extensions you have interacted with. You may revoke this permission at any time through your device's settings or the settings of the relevant website or extension. Please note that while Herond itself does not collect any information through this process, the website or extension requesting access may do so independently.
Part III
SECURITY AND UPDATES
Security and Updates
15.1. Herond automatically checks for updates to ensure users always have access to the latest security fixes. We track the number and type of these requests to produce aggregate statistics that help us improve our product, which does not contain identifiable information. You can also manually download the latest version from the Herond website.
15.2. Safe Browsing. To help protect users from encountering unsafe websites, downloads, and extensions, Herond utilizes Google Safe Browsing. This service maintains constantly updated lists of unsafe web resources to identify threats such as fraudulent sites and malware distributors.
15.3. Desktop: Herond leverages the Safe Browsing Update API, which involves storing a local copy of unsafe website addresses (hashed for anonymity) on your device. When browsing, Herond acts as an intermediary, sending these hashed addresses to Google's servers. This minimizes the information Google receives (excluding your IP address) and safeguards against potential user profiling.
15.4. iOS: Apple serves as the intermediary for Google Safe Browsing on iOS devices, proxying through their own server. If you're an iOS user in mainland China, Tencent Safe Browsing might also be employed. You can find more details in Apple's privacy policy: https://www.apple.com/legal/privacy/data/en/safari/
15.5. Android: Herond integrates with the SafetyNet Safe Browsing API provided by Google. When your device identifies a potentially harmful URL based on its local list, a portion of the hashed address is sent directly to Google. This approach mirrors the functionality of the Safe Browsing Update API on desktops.
Part IV
PRODUCT IMRPOVEMENT
To Improve Herond Browser
16.1. Diagnostic reports. In the event Herond encounters an unexpected issue, such as a crash or freeze, it generates a report that can be sent to us to help diagnose and resolve the issue. This report contains technical information about your computer system and the event causing the problem. Diagnostic reports are sent to error-monitoring infrastructure operated by Herond and may include your IP address and technical details of your device. You can choose whether to send them to us in your settings: go to Settings > Sync and Herond services and look for the option "Help improve Herond's features and performance".
16.2. Product Analytics. To measure and improve the Service, Herond Browser sends usage and engagement data associated with a randomly generated identifier. That identifier does not contain your name or email address, but because it persists across sessions we treat this data as personal data. It is processed only to understand how the Browser and Wallet are used and to improve them, on the basis of our legitimate interest in maintaining and improving the Service, and is retained in accordance with Article 19 (Data Retention). Herond Browser also sends a daily usage ping that lets Herond estimate the number of active users.
16.3. You can turn these off at any time in Settings > Sync and Herond services, using the options "Allow privacy-preserving product analytics (P3A)" and "Automatically send daily usage ping to Herond". You may also object to this processing through the channels described in Article 18.3.
16.4. Your feedback. Any feedback you provide to Herond is greatly appreciated and helps us enhance our product. You can voluntarily share specific details about issues or concerns you encounter while using Herond Browser. Feedback is used exclusively to improve our services, enhance your browsing experience, and address potential or outstanding issues. Please avoid including personal information that is not needed to describe the issue; any personal data inadvertently included in your feedback will be removed before the feedback is used.
Children's Privacy
17.1. Herond Browser is a general-purpose browser and is not directed to children. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without the consent of a parent or guardian, we will delete it. Third parties cooperating with us in providing services are also required to comply with children's privacy protection regulations.
17.2. If you believe that a child in your family has provided personal information without your consent, please contact us using the channels listed in Article 18.3. We encourage parents to guide their children's online activities and review this privacy statement.
Part V
YOUR RIGHTS
Exercise Your Control
18.1. We respect your right to control your information. Subject to applicable law, you have the right to: be informed about the processing of your personal data; give or withhold consent; withdraw consent; access and correct your personal data; request a copy of your personal data; request deletion of your personal data; request restriction of processing; object to processing; and lodge a complaint, denunciation or claim, or initiate legal proceedings and seek compensation.
18.2. To exercise any of these rights, contact us through the channels below. We will respond within the period required by applicable law.
(a) Community Website: https://community.herond.org/
(b) Direct Message on X (formerly Twitter): x.com/HerondBrowser
(c) Email: contact@herond.org
18.3. For a prompt and efficient response, please include a clear description of your question or concern and any relevant details that might help us understand the issue better. The information you provide in your inquiry, such as your email address and the details of your question, will only be used for the purpose of addressing your specific inquiry. We will not use this information for any other purpose without your consent.
18.4. Changes to this Privacy Policy. We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The updated policy will be available on our website. We will notify you of material changes. Where a change introduces a new processing purpose or a new category of personal data for which consent is required, we will ask for your consent as required by law. Continued use of the Service indicates that you have received notice of the change; it is not treated as consent to a new processing purpose.
Part VI
DATA RETENTION
Data Retention
19.1. We retain each category of personal data only for as long as it is needed for the purpose described in this Policy, or for as long as required by law, after which it is deleted or irreversibly de-identified.
(a) Account email address and synchronized browser data are retained while your Herond Account exists, and are deleted when you delete your account.
(b) Wallet data and IP addresses handled by our relay infrastructure are retained only for as long as needed to route requests and to detect abuse.
(c) Product, diagnostic and support data are retained only for as long as needed to diagnose and resolve issues and to understand how the Service is used.
19.2. Herond does not retain personal or payment data that was collected directly by the former third-party swap, bridge or fiat ramp providers.
Part VII
OVERSEAS TRANSFERS AND GOVERNANCE
Overseas Data Transfers and Governance
20.1. Because we work with global infrastructure and third-party providers, some personal data is transferred to and processed outside your country of residence:
(a) Wallet data, and your IP address where a request is routed through our own infrastructure, are processed in order to display balances and submit transfers that you authorize, and are passed to independent blockchain infrastructure providers. This infrastructure may be located outside your country of residence.
(b) Synchronized browser data is processed by cloud hosting providers, which may be located outside your country of residence, in order to provide cross-device synchronization.
(c) Product, diagnostic and support data are processed by analytics, error-monitoring and support providers, which may be located outside your country of residence.
20.2. We apply contractual and technical safeguards to these transfers. Where personal data of individuals in Vietnam is transferred cross-border, Herond will carry out the assessment, documentation and other measures required by applicable Vietnamese data-protection law.
20.3. Herond maintains data-protection governance and compliance documentation required by applicable law.

