Privacy Policy
Effective Date: March 3, 2026
1. Introduction
Ammbr ("we", "us", "our"), operates an eSIM marketplace and connectivity platform designed for Web3.0 natives. This Privacy Policy explains how we collect, use, and protect information when you use Ammbr's services, including the mobile application, web interface, and APIs.
2. Information We Collect
Ammbr is designed with a privacy-first, wallet-based identity model. We collect only the minimum data necessary to deliver and secure our services:
- Device public key (P-256, hardware-generated) for authentication and signing
- Ethereum wallet address derived locally on your device for identity (SIWE) and payment settlement
- Network status and signal metrics for service quality monitoring
- eSIM profile metadata including ICCID, carrier name, and data usage for plan management
- Firebase Cloud Messaging token for push notifications and command queue delivery
3. Information We Do NOT Collect
Ammbr's architecture is designed so that sensitive data never leaves your device:
- Private keys — never leave your device's hardware security enclave (StrongBox / Secure Enclave)
- SMS content — processed locally on-device and never transmitted to our servers
- Personal contacts or call logs — we do not access or store your address book
- Government IDs or PII — identity is wallet-based only, no KYC documents required
- Location data — we do not request or track GPS or fine-grained location
4. How We Use Information
The information we collect is used exclusively to:
- Deliver and maintain Ammbr services, including eSIM provisioning and activation
- Process blockchain based micropayment settlements
- Deliver push notifications for command queue events and service alerts
- Monitor network quality and troubleshoot connectivity issues
- Prevent fraud and enforce acceptable use policies
5. Data Storage & Security
Cryptographic keys are generated and stored within your device's hardware security module (Android StrongBox Keymaster or iOS Secure Enclave) and never exported. All data in transit is encrypted via TLS 1.3. Server-side processing occurs on Cloudflare Workers at the edge, minimizing data residency and latency. We do not maintain centralized databases of user credentials.
6. Third-Party Services
Ammbr integrates with the following third-party services, each governed by their own privacy policies:
- Firebase Cloud Messaging (Google) — push notification delivery
- Cloudflare Workers — edge computing and API hosting
- eSIM providers via eSIMAccess API — eSIM profile provisioning and carrier connectivity
- Various blockchains — USDC and other token payment settlement and transaction recording
7. Data Retention & Deletion
All cryptographic keys and wallet data are stored exclusively on your device. A factory reset or app uninstall permanently removes all local keys and credentials. Server-side data associated with your wallet address (eSIM metadata, usage records) is deleted upon account removal request sent to yalla@ammbr.com. Blockchain transaction records are immutable and cannot be deleted due to the nature of distributed ledger technology.
8. Children's Privacy
Ammbr is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with data, please contact us at yalla@ammbr.com and we will promptly delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. We encourage you to review this policy periodically. Continued use of Ammbr after changes constitutes acceptance of the revised policy.
10. Contact
If you have questions about this Privacy Policy, contact us at:
Ammbr