Bishiki™ VisaUSD™ Launcher Privacy Policy
Updated September 30, 2026 · Publisher: Digital Debit® Group
About this policy
This policy describes the Bishiki™ VisaUSD™ Launcher and the linked VisaUSD™ Cloud Wallet at visausd.xyz. The publisher is Digital Debit® Group. It reflects the implementation reviewed on September 30, 2026.
The launcher and embedded wallet
The launcher displays a branded panel with an Open VisaUSD™ button in ChatGPT. It provides access to the wallet website; it does not read wallet balances, private keys, or recovery phrases, and it does not execute transfers through ChatGPT.
The browser destination at visausd-chatgpt-panel.alleong.chatgpt.site embeds visausd.xyz. The wallet inside that frame performs its own storage and network operations. Browsers may partition or restrict embedded storage, so a wallet opened there may use a different storage area from a direct visit, another browser, or an installed app.
ChatGPT and the launch-panel hosting service process requests under their own policies. The public panel includes Cloudflare security code. Opening it exposes ordinary connection information to those services; this policy does not assert that their infrastructure collects no data.
Information stored in your browser
- Wallet IndexedDB: the database usdc-wallet-db contains an encrypted recovery phrase, public wallet addresses, encryption parameters and retry metadata, wallet settings and policies, preferred RPC configuration, token records, and local transaction activity and notes. New wallets use a four-digit PIN. The reviewed PIN module does not persist the PIN, plaintext recovery phrase, or derived encryption key. Recovery material is available in memory while the wallet is unlocked for signing. Existing passkey vaults may still be supported.
- Local and session storage: a pending payment request is saved under mcwallet:pendingSend. This can include an address, asset, amount, and the full payment-request URL.
- Gaming credits: on supported Android browsers, a separate IndexedDB database, visausd-bishiki-gaming-v1, stores a public-address-linked game-point balance, daily reset data, counterparties, amounts, transfer identifiers, timestamps, status, history, and pending confirmations. These records are not the encrypted wallet vault.
- Site assets: the installed progressive-web-app functionality can use a service worker and browser caches. The reviewed wallet and gaming modules do not write their own cookies; WordPress, account, security, and other hosting features may use cookies or similar technologies.
Payment notes normally remain in local activity. A note you choose to include in a shared payment request is included in that request and is visible to its recipient.
Blockchain requests and third-party services
The wallet queries public addresses, balances, token information, and transaction status and sends signed transactions to blockchain RPC services. Those services receive the requested public data or transaction payload and ordinary connection metadata such as your IP address. The wallet supports Solana and Polygon; the launcher’s intended P2P use is preloaded USDC on Solana.
Built-in RPC hosts include solana-mainnet.infura.io, api.mainnet-beta.solana.com, polygon-mainnet.infura.io, polygon.publicnode.com, polygon.drpc.org, tenderly.rpc.polygon.community, and 1rpc.io. A preferred Solana RPC endpoint can also be saved in wallet settings. Which endpoint receives a request depends on the network, configuration, and fallback behavior.
Transaction-explorer links open Solscan or Polygonscan. Accepted Suno and Bishiki media codes open their destination websites. Those destinations receive browser requests and apply their own policies. The website also loads WordPress/Jetpack assets and fonts, including WordPress-hosted font endpoints; the wallet source references Google Fonts. Service availability, retention, and downstream processing by these providers are not independently controlled or verified by the publisher in this implementation review.
Camera and microphone
The wallet scanner requests camera access and decodes camera frames or a selected image in the browser. The reviewed scanner does not implement image uploads and does not need microphone access. Following a recognized link connects to that destination.
The separate Android Gaming Credits feature can request microphone access after a Send, Receive, Resume, or retry action. It processes live audio locally with Web Audio and ggWave; no audio recording storage or upload is implemented in that module. Acoustic messages share a public address, credit amount, transfer identifier, daily period, and pairing information with nearby devices. Nearby listeners may receive those messages. Close or stop the feature to end its microphone session; retry acknowledgments can briefly continue after receipt.
WordPress hosting, analytics, accounts, and forms
The site is hosted by WordPress.com/Automattic. Jetpack Stats is enabled, and the public site includes hosting performance code (Bilmur) and WordPress/Jetpack resources. Hosting can process IP addresses, requested URLs, browser and device information, referrers, timestamps, performance information, and security events. Exact server-log retention and all provider-side processing have not been independently verified.
WordPress.com login, comments, subscriptions, or other account features, when used, may process submitted information and account cookies separately from the wallet PIN. The inspected wallet has no dedicated contact form. Jetpack’s contact-form capability is enabled, but no published support form was found; no form is added by these pages. A separate Google Analytics tracking script was not observed in the checked public pages.
See Automattic’s Privacy Policy and Cookie Policy for its hosting, account, logging, and cookie practices. Provider practices may change independently of the wallet.
Public records, recovery links, and deletion
Blockchain addresses and confirmed transactions are public. Deleting browser data or contacting the publisher cannot remove confirmed blockchain records or copies held by others.
Keep your recovery phrase, private keys, recovery links, and Retail/recovery codes private. Some recovery codes or links contain recovery material. Opening a secret-bearing URL can expose it to browser history or hosting logs before the application removes recovery parameters. Never send these items to support or put them into ChatGPT.
Before clearing site data, save your recovery phrase securely offline and confirm it belongs to the wallet you intend to keep. Your browser’s site-data controls can remove IndexedDB, local storage, cookies, and caches; session storage generally lasts for the tab session. The wallet’s own reset operation clears its wallet database stores, but is not a promise to erase every browser cache or storage area.
Clearing data, changing browsers, using private browsing, or switching between direct and embedded access can make a local wallet appear missing. A PIN alone cannot restore a deleted vault. The correct recovery phrase can restore access to wallet keys, but does not restore all local notes, history, settings, or the separate gaming-credit ledger. The reviewed gaming feature has no server backup or recovery service.
Publisher and help
Publisher: Digital Debit® Group.
Read the Launcher Support page for practical help. A direct public privacy/support contact channel has not yet been designated. Do not use example contact details or send recovery phrases or private keys to anyone claiming to provide support.