Wallet Service Terms

Last updated: 2026-06-27 Version: 2.1 Effective: Upon publication on www.swaps.app.

These Wallet Service Terms govern the Swaps Wallet Service ("Wallet Service" or "Wallet"). They supplement the Terms of Service, and in the event of a conflict between these terms and the main Terms for matters specific to the Wallet Service, these terms control.


1. Status — live in Beta, non-custodial

The Swaps Wallet is live and these terms are in effect. The Wallet Service is available to all users as a Beta product. It is a non-custodial passkey wallet on the Tempo network (Tempo mainnet, chain ID 4217), where you can hold, receive, and send supported USD stablecoins, and pay a Swaps Payment Link directly from your wallet balance.

"Beta" means the Wallet Service is offered and operational but is still being refined; features and behaviour may change, and you should expect that a Beta product may contain bugs or have rough edges. Operating in Beta does not change the non-custodial design described in these terms.

Supported Wallet features are only those shown in the product at the time you use it. Direct Tempo receive/send uses your Tempo wallet address and is the clean wallet-only path. Supported cross-network receive or send routes may be offered through third-party infrastructure, protocols, or Providers in transit; those routes are separate from direct Tempo Wallet use and remain subject to the route, asset, network, amount, and fee details shown before you proceed. There is no fiat buy or sell inside the Wallet. Any generic "Buy" or "Sell" entry point is a handoff to the regular Swaps provider-routing product rather than a Wallet-native fiat rail.

2. What the Wallet Service is — non-custodial

The Swaps Wallet is a non-custodial passkey wallet. It lets you hold and operate a self-controlled blockchain wallet on Tempo whose signing material is created and held exclusively by you, on your own device, browser, or password manager.

Swaps is a software interface to a wallet you control. Swaps is not a counterparty, an exchanger, a custodian, or a payment institution in respect of the Wallet (see the Terms of Service §1.2-§1.4). Swaps never receives, holds, transmits, or takes custody of cryptocurrency or fiat through the Wallet Service.

Swaps may display balances, prepare transaction data, submit user-authorized signed transactions to the network or a supported route, and show transaction status. That technical broadcast and status role does not give Swaps unilateral ability to sign for, move, freeze, recover, or settle Wallet funds.

3. No private-key custody — what your device holds vs what Swaps stores

Your device holds the signing material. The spending key (your passkey / signing credential) is created and held exclusively by your device, browser, or password manager (for example iCloud Keychain, Windows Hello, Google Password Manager, or an authenticator built into your browser). Swaps never stores private keys, seed phrases, passkey secrets, or any credential signing material.

What Swaps stores is only public metadata necessary to display and operate the Wallet, including: the credential identifier, the credential public key, the authenticator GUID (AAGUID), the declared transports, the relying-party identifier (swaps.app), the wallet address, status, and audit-log entries. None of this is secret. Because the server knows only your wallet address, your balances are viewable in the interface; the server cannot move your funds, because it holds no signing material. The fields Swaps stores are described in the Privacy Policy.

4. Session signing key — browser-local, never sent to Swaps

Some Wallet-connected flows are not supported by pure per-transaction passkey signing. Where that is the case, signing may use a short-lived session access key that lives only in your browser for a limited time (on the order of approximately 15 minutes). This session key is generated locally and is used only to sign your own user-authorized transactions on your own device during that short window.

This session key is never sent to, and is never stored on, the Swaps server. It is browser-local. When it expires, you sign again with your passkey to establish a new short-lived session. The session key is a convenience mechanism for in-session signing; it does not give Swaps the ability to move your funds, and it does not make the Wallet custodial.

5. "Remove from Swaps" is not the same as deleting your device passkey

When you choose to "Remove from Swaps" for a Wallet, Swaps will disable the Swaps-side wallet row and detach the stored credential metadata. This only removes the wallet from the Swaps interface. It cannot and does not delete the passkey from your device, browser, or password manager.

To fully remove a passkey from your device, you must do so yourself in your device or password-manager settings (iCloud Keychain, Windows Hello, Google Password Manager, or the equivalent for your browser or operating system). This separation reflects the WebAuthn standard and is not a limitation Swaps can override. The same behaviour applies to the Tempo Lab today — see the Terms of Service §24.5.

6. Loss and recovery — Swaps cannot recover your Wallet

You control your passkey and your device. If you lose access to the device or password manager that holds your passkey, Swaps cannot recover the Wallet for you, because Swaps holds no signing material — no private key, no seed phrase, no credential secret. There is no Swaps-side "reset" that can restore signing access to a wallet whose passkey you have lost.

Cross-device passkey synchronisation, if any, is provided by your password-manager vendor under that vendor's terms — not by Swaps. Whether your passkey is backed up or synced, and how, is a function of your device, operating system, and password-manager configuration. You are responsible for understanding and maintaining your own backup and recovery arrangements with your vendor. Swaps makes no representation as to whether any such sync exists for your setup.

7. Where the Wallet works — it is bound to Swaps

Your wallet passkey is a WebAuthn credential bound to the swaps.app domain. This has practical consequences you should understand:

7.1 — The Wallet works only on Swaps. You can view, receive, and send with your Wallet only on swaps.app and its subdomains. Your wallet passkey cannot be used to sign on any other website or application, including other Tempo-network apps or wallets (for example, a wallet site operated by Tempo or by a third party). This is a property of the WebAuthn standard's domain binding, not a limitation Swaps can remove.

7.2 — You cannot import an external wallet into Swaps. A wallet created on another website or app uses a credential bound to that other domain. Swaps cannot adopt, import, or sign for a wallet whose credential was created elsewhere, and Swaps does not offer seed-phrase or private-key import.

7.3 — You cannot export the Swaps Wallet to sign elsewhere. Because Swaps never holds your signing material and the credential is domain-bound, there is no export of a private key or seed phrase that would let another application sign for your Swaps Wallet.

7.4 — Receiving is not the same as signing. Your wallet address is a public Tempo blockchain address: anyone using a compatible Tempo wallet or a supported route shown by the Wallet can send supported assets to it, and those assets are yours. The domain binding affects only signing (sending, spending), which can be done only on Swaps.

7.5 — Cross-device, not cross-site. Where your password-manager vendor synchronises your passkey across your own devices (see §6), you can use your Wallet on those devices — but always on swaps.app, never on another site. Cross-device sync is not cross-site portability.

7.6 — Liability. Consistent with the Terms of Service §16, Swaps is not responsible for any attempt to use your Wallet or its passkey on a site or application other than Swaps, for any attempt to import a wallet created elsewhere, or for assets sent to or from an address or credential that Swaps does not operate.

8. Fees

There is no Swaps fee for holding your Wallet balance or for direct Tempo receive/send. On-chain transactions may require network fees ("gas"), which are determined by the relevant blockchain and not by Swaps. Supported cross-network Send routes may include a Swaps software, routing, or interface fee and third-party, provider, or network costs; all such route costs are disclosed before you approve the transaction. Any Swaps fee on a cross-network Send route is not custody, money transmission, exchange, or payment execution by Swaps.

9. Network, supported assets, gas, and KYC

9.1 — Network. The Wallet Service operates on the Tempo network (Tempo mainnet, chain ID 4217). Your Wallet balance and direct Wallet address are on Tempo. Supported cross-network receive or send routes may be shown in the Wallet where Swaps has enabled third-party infrastructure for a specific asset, network, route, and amount. Networks and assets are supported only when they are shown in the product for that transaction.

9.2 — Supported assets. The Wallet supports holding, receiving, and sending supported USD stablecoins on Tempo, including USDC.e (Bridged USDC), pathUSD, USDT0, USD1, and cUSD where available. Cross-network routes may support a narrower set of assets. Do not send an asset unless it is shown as supported for the exact route in the product.

9.3 — Network (gas) fees. Direct Tempo on-chain transactions require a network fee ("gas"), which is paid in a stablecoin and is determined by the Tempo network, not by Swaps. At present this is on the order of approximately $0.03 per transfer; it may vary with network conditions and is outside Swaps' control. Cross-network routes may include additional network or provider costs shown before approval.

9.4 — No Swaps KYC for wallet-only on-Tempo use. Because the Wallet is non-custodial, Swaps does not require you to complete Swaps identity verification (KYC) to hold, receive, or send supported stablecoins directly on Tempo. Provider verification may apply where a non-Wallet provider service is used, including fiat buy/sell, cross-network routes, Payment Links, Pay Invoice, Payroll, or other regulated provider flows.

9.5 — Fiat buy/sell is outside the Wallet. Any fiat on-ramp or off-ramp opened from a generic Swaps "Buy" or "Sell" route is performed by an independent Provider that may perform its own KYC and operates under its own terms and authorisations — not by Swaps and not as Wallet custody. Swaps remains a non-custodial routing and interface layer, consistent with the Terms of Service §1.1-§1.4.

10. Separation from login (authentication) passkeys

A wallet passkey is distinct from any login (authentication) passkey or password you use to sign in to your Swaps Account. The two are separate credentials with separate purposes:

  • A login passkey is only a faster way to sign in to your Swaps Account. It does not create a wallet, does not authorise wallet transactions, and does not give Swaps custody of funds or access to your private keys (see the Terms of Service §9.3).
  • Removing or revoking one credential does not affect the other. Removing a login passkey does not touch your wallet; removing a wallet does not touch your ability to sign in.

Swaps will never ask you for your password, seed phrase, or any signing secret. Anyone claiming to be Swaps support and asking for your seed phrase or signing material is impersonating us.

11. Compliance basis — current design

Based on the current non-custodial design, the Wallet Service is intended to operate as non-custodial wallet software rather than custody, exchange, payment account, e-money, or transfer service by Swaps. Swaps holds no private keys and no funds, and does not execute, custody, or exchange assets on your behalf. If Swaps adds fiat rails, custodial balances, provider-side accounts, safeguarding or control over means of access, or execution in its own name, that activity must be separately reviewed before launch. Any regulated activity associated with a fiat ramp or provider route is carried out by an independently regulated Provider, not by Swaps.

12. Risk

Self-custody carries risk. You are solely responsible for safeguarding your device, passkey, and any password-manager backups. Loss of your passkey may mean permanent loss of access to your Wallet, with no recovery available from Swaps. Blockchain transactions are generally irreversible, addresses are case-sensitive, and network conditions are outside Swaps' control. Funds sent as the wrong asset, to the wrong network, to a stale amount-bound deposit address, or outside the route shown in the product may be delayed or permanently lost. Any recovery review is best effort and is not guaranteed until the normal settlement path completes. Before using the Wallet Service, you should read and understand the Risk Disclosure, which applies to the Wallet Service in addition to these terms.

13. Privacy

Swaps' handling of the public Wallet metadata it stores (credential identifier, public key, AAGUID, transports, relying-party identifier, wallet address, status, and audit-log entries) is governed by the Privacy Policy. Swaps does not store, and cannot disclose, signing material it never holds. On-chain activity associated with your wallet address is public by the nature of the blockchain and is not controlled by Swaps.

14. Liability

The limitation of liability in the Terms of Service §16 applies to the Wallet Service in full, including the liability cap, the excluded categories of damages, and the EU/UK statutory carveout. Nothing in these terms expands Swaps' liability beyond what §16 provides. In particular, and consistent with the non-custodial design described above, Swaps is not liable for loss of access to a wallet caused by loss of your device or passkey, for the acts or terms of your password-manager vendor, for the acts or terms of any Provider or third-party route infrastructure, for funds sent outside the route instructions shown in the product, or for blockchain network conditions.

15. Relationship to the Tempo Passkey Wallet Lab (Terms §24)

These Wallet Service Terms govern the live, public Swaps Wallet Service. Separately, the Terms of Service §24 governs the historical Tempo Passkey Wallet Lab — a testnet-only, allowlisted experiment that preceded the public Wallet Service.

  • The public Wallet Service is governed by this document (together with the Terms of Service).
  • To the extent any Lab capability remains accessible, it continues to be governed only by §24, operates on the Tempo Moderato testnet, and may be limited, modified, suspended, or terminated at any time (§24.7).
  • If a conflict arises between this document and §24 in respect of the public Wallet Service, this document controls; §24 controls only for the testnet-only Lab.

16. Changes

Swaps may update these terms as the Wallet Service evolves, as permitted by the Terms of Service. Material changes will be reflected by updating the Last updated date and version above and by the notice mechanism in the Terms. Because the Wallet Service is offered in Beta, its features and these terms may change.

17. Contact

Questions about these Wallet Service Terms can be sent to legal@swaps.app.


Contact: legal@swaps.app Operator: Supa Labs OÜ · Registry 17399414 · Oru tn 2, Tallinn 10127, Estonia

Related Pages