Idioma / Language: Português · English
Regulatory
Last updated: August 25, 2026
This document describes Picnic's operating model and the regulatory framework that we understand to apply to it. It supplements the Terms of Use and the Privacy Policy, which prevail in the event of any conflict.
Picnic is operated by DeFiBasket Labs Inc., BVI Business Company No. 2085144, incorporated in the British Virgin Islands.
1. Picnic's legal nature
Picnic is a non-custodial software interface. Its function is to allow the user to interact directly with public blockchain networks and decentralized protocols, and to integrate, into a single interface, services provided by independent third parties authorized in their respective jurisdictions.
The legal relationship between Picnic and the user is a software license (Terms of Use, cl. 1.4). Picnic is not a party, counterparty, representative, broker, custodian, manager, or agent of the user in any transaction carried out through the interface.
In the layered architecture commonly described in the literature on decentralized finance (Schär, 2021), Picnic operates at the aggregation layer: it brings together access to protocols and services operated by third parties, without operating any of them.
2. How transactions take place
Picnic combines two types of steps, each with a distinct legal treatment. Steps recorded on a blockchain — transfers, exchanges between virtual assets, and interactions with protocols — are carried out by the users themselves, from their self-custodial wallets. Steps involving fiat currency — Pix and Brazilian reais, US dollars, euros, and the card — are provided by regulated partners and are described in section 4.
2.1. Private keys. The private key that controls the user's wallet is not held by Picnic. In accounts that use a passkey, authentication follows the WebAuthn (FIDO2) standard and the key is generated on the user's device. Depending on the configuration chosen by the user in their operating system, the passkey may be synchronized by the credential manager of the relevant manufacturer. Picnic stores only the public key (Terms of Use, cl. 14.2). In accounts that do not use a passkey, the key is protected by a hardware security module operated by Magic, an independent service provider, and remains accessible only to the user. Under neither configuration is Picnic a signer of the user's wallet.
2.2. Signature. Every transaction depends on the user's digital signature, performed on their device. Picnic's software translates the user's intent into a technical instruction; it does not execute the instruction on the user's behalf.
2.3. Settlement. Settlement occurs on the blockchain, between the user's wallet and the smart contracts involved. Assets do not pass through any bank account or wallet owned by Picnic, and Picnic does not maintain an internal record of balances that replaces the on-chain record. The balance displayed in the interface is a reading of the network state, not a promise of payment by Picnic. In steps involving fiat currency, settlement follows the operating flows of the responsible regulated partner, which may include accounts and addresses owned by that partner or by service providers it has engaged before the asset is delivered to the user's wallet.
2.4. Transactions between virtual assets. In transactions carried out entirely on a blockchain — transfers, exchanges between virtual assets, and interactions with protocols —, the user acts in their own name and for their own account. Picnic does not receive orders, execute them, match them with orders from other users, maintain an order book, set prices, or act as counterparty. At no time does Picnic act for the account and on the instructions of a third party. These transactions are recorded on a blockchain and authorized by the user, either directly or through permissions the user has previously granted.
The analogy is an internet browser: it allows the user to access their bank's website and make a payment, but it is neither the bank nor the intermediary in the transaction. The legal relationship is user ↔ blockchain.
3. Picnic's regulatory framework
3.1. We are not custodians. Qualification as a custodian depends on control of the private keys or on the technical ability to move funds on behalf of the customer. Picnic does not hold the user's private key and is not a signer of the user's wallet. Without that control, Picnic has no ability to transfer, block, or dispose of the assets, and there is no power to exclude third parties that would give rise to the custodian's heightened duty of care.
3.2. We are not intermediaries. The core of intermediation is acting for the account and on the instructions of a third party: receiving the customer's order and executing it in the market on the customer's behalf, or managing third-party resources. Picnic engages in none of these activities. The user transacts in their own name, directly on the network, using their private key. Picnic does not hold, move, or block the user's funds.
3.3. We are not a broker or exchange. Brokers combine custody and intermediation and maintain an internal order book that matches orders. None of these elements is present in Picnic's architecture.
3.4. Conclusion and caveat. Based on the architecture currently adopted, Picnic understands that the self-custodial core of the interface is software in nature and does not, in itself, constitute custody of third-party assets, operation of a centralized exchange, or discretionary management of resources. Specific features and integrations are assessed separately, according to the activity actually performed in each case. Final legal classification rests with the competent authorities and regulatory bodies.
This is Picnic's interpretive position, based on the current technical architecture. It does not constitute a statement, authorization, or recognition by any regulatory authority, nor does it constitute legal or tax advice to the user, who remains responsible for assessing the treatment of their own transactions. Changes to the architecture, applicable regulation, or the interpretation of competent authorities may change this analysis. Picnic reassesses this framework with each new feature or integration.
4. Provision of services by regulated partners
The fact that Picnic is not classified as a custodian, intermediary, or virtual asset service provider does not mean that transactions take place outside the regulatory framework.
Every step involving fiat currency — inflows to and outflows from the traditional financial system, conversion between fiat currency and virtual assets, and card issuance and processing — is provided by a third party authorized to provide it in the relevant jurisdiction, in accordance with the authorization or registration held by that party and verified by Picnic as part of the due diligence described in section 5. Each partner provides these services in its own name and for its own account, under its own authorization and regulatory responsibility, and is directly responsible for the obligations applicable to it: customer identification and verification (KYC), transaction monitoring, recordkeeping, and reporting to the competent authorities.
Picnic's role in these steps is exclusively technical: integrating the partner's service into the interface and presenting the user with the flows defined by the partner. Picnic does not provide the regulated service, subcontract it, or act as the partner's agent or representative, and the regulatory obligations for these steps rest with the partner that performs them. This does not exclude any obligations that may apply directly to Picnic due to its activity, which are assessed on an ongoing basis.
5. Picnic's own controls
Although, in our understanding, the interface does not constitute an activity subject to the obligations applicable to an obliged entity for anti-money laundering purposes, Picnic maintains its own risk-based AML/CFT policy (risk-based approach), calibrated to the risks actually present at the interface layer — and not to custody or intermediation risks, which do not arise from the interface architecture.
Internal controls include:
- controls to prevent and detect fraud in the use of the interface;
- transaction monitoring based on risk criteria, with internal escalation of alerts;
- screening of wallet addresses and transactions against applicable sanctions lists;
- access restrictions from sanctioned or prohibited jurisdictions;
- an express contractual prohibition on unlawful use (Terms of Use, cls. 1.2(B) and 1.3);
- recording and retaining the information necessary to respond to legitimate requests from competent authorities.
Detection parameters, thresholds, and rules are not publicly disclosed, in order to preserve their effectiveness.
Partner due diligence (KYP). Picnic performs initial due diligence and periodic reviews of its partners, verifying authorization or registration, AML/CFT policies, regulatory history, and operational capacity. We adopt and replicate in the interface the controls, parameters, and instructions defined by each partner, including subsequent changes, whenever applicable to the integrated flow.
KYC. Registration in the interface does not involve KYC. Identity verification takes place with the regulated partner responsible for each rail, when the user chooses to enable it, and follows the requirements defined by that partner.
Scope of the controls. These controls are Picnic's own and are voluntary in relation to its regulatory classification. They neither replace nor overlap with the controls of regulated partners, do not transfer to Picnic any regulatory responsibility assigned by law to a third party, and do not exempt the user from their own legal obligations (Terms of Use, cl. 1.3). Picnic continuously assesses its own obligations and complies with them when applicable.
6. Tax reporting
Brazilian Federal Revenue Normative Instruction No. 2,291/2025 governs the reporting of information on transactions involving virtual assets. The rule distinguishes cases in which the information is provided by the cryptoasset service provider from those in which it is provided by the user who is resident or domiciled in Brazil, and subjects each case to its own criteria and thresholds.
Tax and reporting obligations depend on the user's residence, the nature and value of the transactions, and the means by which they were carried out. Picnic assesses the obligations applicable to it and provides information when required by law or by a competent authority. Partners are responsible for the obligations related to the activities they provide. Users must assess their own obligations and seek professional advice when necessary.
With respect to the self-custodial core of the interface, Picnic understands that it corresponds to the concept of a decentralized platform used by the rule: Picnic does not hold assets in custody, does not process transactions centrally, and is not headquartered in Brazil. In this case, we understand that responsibility for reporting information relating to those transactions rests with the user who is resident or domiciled in Brazil, subject to the criteria and thresholds in the rule itself. This is Picnic's interpretation, subject to review in light of any statement by the Brazilian Federal Revenue Service or any regulatory change, and it does not replace the user's individual assessment.
This does not mean there is no reporting within the chain: each regulated partner is responsible for the reports required of it in relation to the transactions it performs itself — including, in Brazil, transactions in Brazilian reais processed by the partner authorized by the Central Bank.
Registration data. Picnic stores user registration data, including CPF and email address, for two reasons: (i) to transmit it to the regulated partner that requires identification to enable a specific rail; and (ii) to allow the interface to operate without repeated registration. Collection follows the principles of purpose limitation, necessity, and adequacy, and sharing with each partner is limited to the data it requires for the relevant rail, as provided in the Privacy Policy.
7. Continuity
If Picnic ceases to operate, the assets remain in the user's wallet, on the blockchain. Access does not depend on Picnic continuing to operate as a company.
8. Effective date
This document reflects the operating structure in effect on the date indicated at the top and may be revised at any time. In the event of any conflict, the Terms of Use and the Privacy Policy prevail.
Picnic communicates exclusively through the @usepicnic.com domain. Communications received from any other domain or channel should be treated as an attempted fraud and reported to oi@usepicnic.com.
Questions about this document: legal@usepicnic.com.
Regulatório
Última atualização: 25 de agosto de 2026
Este documento descreve o modelo operacional do Picnic e o enquadramento regulatório que entendemos aplicável a ele. Complementa os Termos de Uso e a Política de Privacidade, que prevalecem em caso de divergência.
O Picnic é operado pela DeFiBasket Labs Inc., BVI Business Company nº 2085144, constituída nas Ilhas Virgens Britânicas.
1. Natureza jurídica do Picnic
O Picnic é uma interface de software não-custodial. Sua função é permitir que o usuário interaja diretamente com redes blockchain públicas e com protocolos descentralizados, e integrar, em uma única interface, serviços prestados por terceiros independentes autorizados nas respectivas jurisdições.
A relação jurídica entre o Picnic e o usuário é de licenciamento de uso de software (Termos de Uso, cl. 1.4). O Picnic não é parte, contraparte, mandatário, corretor, custodiante, gestor ou agente do usuário em nenhuma operação realizada por meio da interface.
Na arquitetura em camadas usualmente descrita na literatura sobre finanças descentralizadas (Schär, 2021), o Picnic atua na camada de agregação: reúne o acesso a protocolos e serviços operados por terceiros, sem operar nenhum deles.
2. Como as operações ocorrem
O Picnic combina dois tipos de etapa, com tratamento jurídico distinto. As etapas registradas em blockchain — transferências, trocas entre ativos virtuais e interações com protocolos — são realizadas pelo próprio usuário, a partir de sua carteira autocustodial. As etapas que envolvem moeda fiduciária — Pix e reais, dólares, euros e o cartão — são prestadas por parceiros regulados e estão descritas na seção 4.
2.1. Chaves privadas. A chave privada que controla a carteira do usuário não é detida pelo Picnic. Nas contas com passkey, a autenticação segue o padrão WebAuthn (FIDO2) e a chave é gerada no dispositivo do usuário. Conforme a configuração escolhida pelo usuário em seu sistema operacional, a passkey pode ser sincronizada pelo gerenciador de credenciais do respectivo fabricante. O Picnic armazena apenas a chave pública (Termos de Uso, cl. 14.2). Nas contas que não utilizam passkey, a chave é protegida por módulo de segurança de hardware operado pela Magic, prestadora independente, e permanece acessível apenas ao usuário. Em nenhuma das duas configurações o Picnic é signatário da carteira do usuário.
2.2. Assinatura. Toda operação depende de assinatura digital pelo usuário, realizada em seu dispositivo. O software do Picnic traduz a intenção do usuário em uma instrução técnica; não a executa por ele.
2.3. Liquidação. A liquidação ocorre na blockchain, entre a carteira do usuário e os contratos inteligentes envolvidos. Os ativos não transitam por conta bancária ou carteira de titularidade do Picnic, e o Picnic não mantém registro interno de saldos que substitua o registro on-chain. O saldo exibido na interface é a leitura do estado da rede, não promessa de pagamento do Picnic. Nas etapas que envolvem moeda fiduciária, a liquidação observa os fluxos operacionais do parceiro regulado responsável, que podem incluir contas e endereços de titularidade dele ou de prestadores por ele contratados antes da entrega do ativo à carteira do usuário.
2.4. Operações entre ativos virtuais. Nas operações realizadas inteiramente em blockchain — transferências, trocas entre ativos virtuais e interações com protocolos —, o usuário atua em nome próprio e por conta própria. O Picnic não recebe ordens, não as executa, não as casa com ordens de outros usuários, não mantém livro de ofertas (order book), não forma preço e não é contraparte. Em nenhum momento atua por conta e ordem de terceiro. Essas operações são registradas em blockchain e autorizadas pelo usuário, diretamente ou por meio de permissões que ele tenha previamente concedido.
A analogia é a do navegador de internet: ele permite que o usuário acesse o site do seu banco e realize um pagamento, mas não é o banco nem o intermediário da operação. A relação jurídica é usuário ↔ blockchain.
3. Enquadramento do Picnic
3.1. Não somos custodiantes. A qualificação como custodiante depende do controle das chaves privadas ou da capacidade técnica de movimentar fundos em nome do cliente. O Picnic não detém a chave privada do usuário e não é signatário de sua carteira. Sem esse controle, não há capacidade de transferir, bloquear ou dispor dos ativos, e não se verifica o poder de exclusão de terceiros que atrai o dever de diligência qualificado do custodiante.
3.2. Não somos intermediários. O núcleo da atividade de intermediação é a atuação por conta e ordem de terceiro: receber a ordem do cliente e executá-la no mercado em seu lugar, ou administrar recursos de terceiros. O Picnic não pratica nenhuma dessas condutas. O usuário transaciona em nome próprio, diretamente na rede, munido de sua chave privada. O Picnic não detém, não movimenta e não bloqueia os fundos do usuário.
3.3. Não somos corretora ou exchange. As corretoras combinam custódia e intermediação, e mantêm livro de ofertas interno com casamento de ordens. Nenhum desses elementos está presente na arquitetura do Picnic.
3.4. Conclusão e ressalva. Com base na arquitetura atualmente adotada, o Picnic entende que o núcleo autocustodial da interface tem natureza de software e não corresponde, por si só, à custódia de ativos de terceiros, à manutenção de uma exchange centralizada ou à gestão discricionária de recursos. Funcionalidades específicas e integrações são avaliadas separadamente, conforme a atividade efetivamente desempenhada em cada caso. A qualificação jurídica definitiva compete às autoridades e aos órgãos reguladores competentes.
Esta é a posição interpretativa do Picnic, fundada na arquitetura técnica vigente. Não constitui manifestação, autorização ou reconhecimento por qualquer autoridade regulatória, nem aconselhamento jurídico ou tributário ao usuário, que permanece responsável por avaliar o enquadramento de suas próprias operações. Alterações na arquitetura, na regulação aplicável ou na interpretação das autoridades competentes podem alterar essa análise. O Picnic reavalia esse enquadramento a cada nova funcionalidade ou integração.
4. Prestação de serviços por parceiros regulados
A ausência de enquadramento do Picnic como custodiante, intermediário ou prestador de serviços de ativos virtuais não significa que a operação ocorra à margem da regulação.
Toda etapa que envolve moeda fiduciária — entrada e saída de recursos do sistema financeiro tradicional, conversão entre moeda fiduciária e ativos virtuais, emissão e processamento de cartão — é prestada por um terceiro habilitado a prestá-la na jurisdição correspondente, conforme a autorização ou o registro por ele detido e verificado pelo Picnic no âmbito da diligência descrita na seção 5. Cada parceiro presta esses serviços em nome próprio e por sua própria conta, sob sua própria autorização e responsabilidade regulatória, e responde diretamente pelas obrigações que lhe são aplicáveis: identificação e verificação de clientes (KYC), monitoramento de operações, guarda de registros e reportes às autoridades competentes.
O papel do Picnic nessas etapas é exclusivamente técnico: integrar o serviço do parceiro à interface e apresentar ao usuário os fluxos definidos por ele. O Picnic não presta o serviço regulado, não o subcontrata, não atua como agente ou representante do parceiro e as obrigações regulatórias dessas etapas recaem sobre o parceiro que as executa. Isso não afasta obrigações próprias que venham a ser aplicáveis ao Picnic em razão de sua atividade, as quais são avaliadas de forma permanente.
5. Controles próprios do Picnic
Ainda que a interface não configure, em nosso entendimento, atividade sujeita a obrigações de pessoa obrigada em matéria de prevenção à lavagem de dinheiro, o Picnic mantém política própria de PLD/FT com abordagem baseada em risco (risk-based approach), calibrada aos riscos efetivamente presentes na camada de interface — e não aos riscos de custódia ou de intermediação, que não decorrem da arquitetura da interface.
Os controles internos incluem:
- controles de prevenção e detecção de fraude no uso da interface;
- monitoramento de transações segundo critérios de risco, com escalonamento interno de alertas;
- verificação de endereços de carteira e transações contra listas de sanções aplicáveis;
- restrição de acesso a partir de jurisdições sancionadas ou vedadas;
- vedação contratual expressa de uso ilícito (Termos de Uso, cls. 1.2(B) e 1.3);
- registro e retenção das informações necessárias ao atendimento de demandas legítimas de autoridades competentes.
Os parâmetros, limiares e regras de detecção não são divulgados publicamente, para preservar sua eficácia.
Diligência sobre parceiros (KYP). O Picnic realiza diligência prévia e revisões periódicas sobre seus parceiros, verificando autorização ou registro, políticas de PLD/FT, histórico regulatório e capacidade operacional. Adotamos e replicamos na interface os controles, parâmetros e instruções definidos por cada parceiro, inclusive suas alterações supervenientes, sempre que aplicáveis ao fluxo integrado.
KYC. O cadastro na interface não envolve KYC. A verificação de identidade ocorre no parceiro regulado responsável por cada trilho, no momento em que o usuário opta por liberá-lo, e segue os requisitos definidos por esse parceiro.
Alcance dos controles. Esses controles são próprios do Picnic e voluntários em relação ao seu enquadramento. Não substituem nem se sobrepõem aos controles dos parceiros regulados, não transferem ao Picnic responsabilidade regulatória atribuída por lei a terceiro e não isentam o usuário de suas próprias obrigações legais (Termos de Uso, cl. 1.3). O Picnic avalia de forma permanente as obrigações que lhe sejam próprias e as cumpre quando aplicáveis.
6. Reportes fiscais
A Instrução Normativa RFB nº 2.291/2025 disciplina a prestação de informações sobre operações com ativos virtuais. A norma distingue as hipóteses em que a informação é prestada pelo prestador de serviços de criptoativos daquelas em que é prestada pelo próprio usuário residente ou domiciliado no Brasil, e sujeita cada uma delas a critérios e limites próprios.
As obrigações fiscais e de prestação de informações dependem da residência do usuário, da natureza e do valor das operações e do meio pelo qual foram realizadas. O Picnic avalia as obrigações que lhe sejam aplicáveis e presta informações quando exigido pela legislação ou por autoridade competente. Os parceiros respondem pelas obrigações relacionadas às atividades que prestam. O usuário deve avaliar suas próprias obrigações e buscar orientação profissional quando necessário.
Quanto ao núcleo autocustodial da interface, o entendimento do Picnic é o de que ele corresponde ao conceito de plataforma descentralizada empregado pela norma: o Picnic não detém custódia, não processa transações de forma centralizada e não está sediado no Brasil. Nessa hipótese, entendemos que a prestação de informações relativa a essas operações cabe ao usuário residente ou domiciliado no Brasil, observados os critérios e limites da própria norma. Trata-se de entendimento interpretativo do Picnic, sujeito a revisão diante de manifestação da Receita Federal do Brasil ou de alteração normativa, e que não substitui a avaliação individual do usuário.
Isso não significa ausência de reporte na cadeia: cada parceiro regulado responde pelos reportes que lhe são exigidos em relação às operações que ele próprio executa — inclusive, no Brasil, as operações em reais processadas pelo parceiro autorizado perante o Banco Central.
Sobre os dados cadastrais. O Picnic armazena dados cadastrais do usuário, incluindo CPF e e-mail, por duas razões: (i) transmiti-los ao parceiro regulado que exige identificação para liberar um trilho específico; e (ii) viabilizar o funcionamento da interface sem repetição de cadastro. A coleta observa os princípios de finalidade, necessidade e adequação, e o compartilhamento com cada parceiro limita-se aos dados exigidos por ele para o trilho correspondente, conforme a Política de Privacidade.
7. Continuidade
Se o Picnic deixar de operar, os ativos permanecem na carteira do usuário, na blockchain. O acesso não depende da continuidade do Picnic como empresa.
8. Vigência
Este documento reflete a estrutura operacional vigente na data indicada no topo e pode ser revisado a qualquer tempo. Em caso de divergência, prevalecem os Termos de Uso e a Política de Privacidade.
O Picnic comunica-se exclusivamente pelo domínio @usepicnic.com. Comunicações recebidas de qualquer outro domínio ou canal devem ser tratadas como tentativa de fraude e reportadas a oi@usepicnic.com.
Dúvidas sobre este documento: legal@usepicnic.com.