Privacy
Your wallet is local. Network connections still disclose information.
Winnow requires no account or wallet-history service and includes no analytics, advertising SDK, or app-managed crash reporting. Websites, discovery services, and the census endpoint receive ordinary request metadata; this policy does not claim their hosting providers keep no logs.
On your device
Keys. Seed material is generated on-device and stored in the iOS Keychain with this-device-only protection. The Keychain checks user presence before releasing it. Automatic iCloud backup creates a separate encrypted recovery copy when available. You can turn it off in Advanced; the normal signing key remains device-only.
Receive labels. You can label an address before sharing it or skip. The note matches outputs locally and stays with that address when you request a new one. It does not verify a sender or create a return-payment destination. It is excluded from QR codes, copied or shared addresses, payment cards, and manual wallet backups. Encrypted iCloud recovery includes the labels. Deleting or replacing the wallet removes these labels.
Payment names. A received payment can keep a local name without an address. You can later attach an address you supplied or explicitly select a local or explorer suggestion. Funding-address suggestions are unverified; they do not identify senders, and reuse can reduce privacy.
What leaves the device
| Recipient | Information disclosed | When |
|---|---|---|
| Bitcoin peers | Requested blocks, timing, and relay activity. Clearnet peers also see your connection's IP address; Tor and I2P peers reached through your gateways do not. Signed transactions become public. | Wallet sync, receiving, and broadcasting, and short background checks when iOS allows them. |
| Explorer | The transaction ID and your connection's IP address, or your Tor gateway's exit when clearnet is off. | Only after consent for each lookup. |
| Peer catalog | Request metadata including your IP address, or your Tor gateway's exit when clearnet is off; no wallet address or transaction ID. | Automatically on mainnet when the saved catalog is missing or expired, or when you request a refresh. |
| Your Tor and I2P gateways | Which Tor and I2P peers you connect to, with timing and traffic volume. Finding them asks Tailscale's resolver (100.100.100.100) for two names and sends each gateway a SOCKS greeting. | Automatic routing checks when networking starts, in the foreground or for a background check, and on reconnect or retry; routed connections while syncing. |
| Websites and discovery services | Ordinary request metadata. An external browser exposes its own connection's IP address. | When a request or visit is made. |
Winnow downloads compact block filters (BIP157/158) from Bitcoin full-node peers and matches them locally. While Receive is open, it also matches ordinary transaction-relay traffic locally. Neither sends your watch list, but block requests, relay activity, and timing can reveal information to peers and network observers.
No Tor or VPN is built in. Connections use your device's network connection unless they go through your own gateways, below. The embedded Tor option in versions 0.6–0.7.0 was removed in 0.7.1 because its dependencies had not been independently reviewed for this integration. Transport research →
Your own Tor and I2P gateways. If you run Tor or I2P on machines in your Tailscale network, Winnow can send Bitcoin peer connections through them. Automatic routing, the default, looks for gateways named winnow-tor-gateway and winnow-i2p-gateway on your tailnet and, when either answers, uses only them, so no peer sees your IP address; when neither answers it falls back to ordinary peers and the home screen says so. Advanced settings can require Tor or I2P instead. A gateway sees which peers you connect to and can block connections, so use one you run or trust. Winnow does not include Tor, I2P or Tailscale. Gateway setup →
Cloud and optional services
Explorer lookups require consent explaining the transaction-ID and IP disclosures. You must choose a returned destination; even a sole result is never selected automatically. Opening an external browser has a separate disclosure warning.
iCloud backup is on by default, with a persistent switch in Advanced to turn it off. Creation and restoration reuse their device authentication; existing wallets may ask once on foreground initialization. It uploads encrypted copies of this phone’s signing key, wallet history, shared accounts, saved people and payment cards, sender names, receive labels, display name and interface mode to your private iCloud database. A separate encryption key synchronizes through iCloud Keychain. Apple receives the backup size, network, save date and ordinary account/connection metadata. Access to the backup and that key allows wallet recovery. Automatic updates run while Winnow is open and wait for pending payments to confirm. Stopping updates or deleting the local wallet leaves the saved cloud copy available for recovery. Restoring resumes automatic backups using a new independent record. The app reports a successful save only after that record reaches iCloud. Manual file backups remain unchanged; peer and explorer endpoints remain device-local.
Census refresh downloads the public candidate catalog from census.winnowwallet.com automatically on mainnet when the saved catalog is missing or expired, and when requested in Advanced settings. When clearnet is off, it is fetched through your Tor gateway; when peer routing is set to I2P alone, the same signed catalog is fetched from its I2P mirror through your I2P gateway instead, and no public website is contacted. Failed automatic attempts are retried while the app is open, at most once per minute. Invalid data does not replace good data, and a refresh does not disconnect active peers. Reset and shuffle peers is a separate action that preserves manual settings and the downloaded catalog.
Exports and recovery words
Recovery displays and exports you request can disclose sensitive wallet material. A default manual file backup excludes recovery words. Choosing Include recovery phrase adds the phone's signing secret. Protect that file as you would the recovery words; even a file without them contains private wallet history.
Third-party code
The pinned swift-secp256k1 package supplies Bitcoin cryptography and is the app's only third-party package dependency. The repository records its version and dependency security review.