Como podemos ajudar?
Search for the articles here or browse the categories below.
Browse by topic
Find guides, tutorials, and answers organised by category.
What's New
Announcements and important changes at Picnic: new features, product updates and deprecations.
Account, Registration & Limits
How to create your account, complete identity verification (KYC) and understand Picnic account limits.
Security & Access
Passkeys, login, account recovery and how to keep your Picnic account safe.
Pix Deposits (BRL)
How to deposit Brazilian reais into Picnic using Pix and what to do when a deposit doesn't arrive.
USD & EUR Deposits
USD deposits via ACH, EUR deposits via IBAN and third-party payments via Monerium.
Crypto Deposits
How to safely send crypto to Picnic, supported networks and common issues.
Withdrawals
Withdrawals via Pix, to European accounts (IBAN), in USD via ACH and at ATMs.
Card: Using Your Card
Activation, PIN, limits, fees and everyday use of the Picnic Visa card, including Apple Pay and Google Pay.
Card: Issues & Declines
Why a purchase was declined and how to fix problems with your Picnic card.
Balances, Transactions & Refunds
Understanding your card balance, tracking transactions and how refunds work.
Crypto Wallet
Balance and transactions of the Picnic crypto wallet: swaps, tokens, networks and self-custody.
Rewards & Referrals
Zero-fee conversion, the referral program, GNO, OG NFT and the (discontinued) card cashback.
Fees, Reports & Documents
Fees, tax documentation, reports and receipts for your operations.
Legal
Picnic's Terms of Service, Privacy Policy and other legal documents.
Popular articles
What other people are reading right now.
ACH Push vs. ACH Pull: avoid returns and fees
Picnic does not accept deposits initiated through external apps (ACH Pull). What is ACH Pull This is when you try to use your dollar account details at another bank or brokerage to "pull" money from there to your Picnic account. This method works like a pre-authorized or automatic debit on a third-party platform. Understand the difference - ACH Push (supported): you initiate the transfer from your bank/brokerage to Picnic. - ACH Pull (not supported): the brokerage/bank tries to withdraw to the Picnic account as if it were an automatic debit Frequently Asked Questions Will ACH Pull work in the future? We are always improving the experience, but at the moment ACH Pull is not supported. Can Picnic "manually authorize" a pending ACH Pull? No. Since this type of debit is not supported, there is no way to manually approve a Pull attempt. Is Direct Deposit Push or Pull? It is usually Push (Credit), as it is a transfer to the account (inbound). However, the name may vary by institution. See also ACH Transfer: What it is and which methods are accepted How long will it take for my Dollar deposit to clear
🔐 Security & AccessHow to Permanently Delete Your Account
Deleting the account is irreversible and ends access to the features linked to it. Account deletion is not the way to change your email or move your profile to another account. What You Should Know Before Closing Due to the nature of blockchain technology, it's important to understand how your data is handled: - Personal Data: All your identification information and access to Picnic are deleted from our servers. - Blockchain Address: Your digital wallet will continue to exist on the blockchain network. As it is a public and immutable infrastructure, it is not possible to delete an address from the network. - Functionalities: If you try to log in again after deletion, the wallet will still exist, but your account will no longer have active functionalities, such as using Pix. Before deleting: 1. Withdraw all assets (investments, balances, cryptocurrencies) 2. Cancel physical card and remove from digital wallets 3. Confirm there are no pending transactions How to do it: - In the app (iOS/Android) — this is the only way to close your account yourself: open the Settings menu and tap Delete account. Follow the steps to confirm (you must have no remaining balance and confirm by typing the displayed code and the account email). - On the web (usepicnic.com): there is no account-closure button on the website. If you can't use the app, contact our support through the chat and our team will close the account for you. ⚠️ Important: the Account settings → KYC Management → Remove option on the web does NOT close your account. It only unlinks your KYC profile from that account — the account stays active. If you intend to use another email, read How to Add Personal Data to Another Account Correctly before removing it. To actually close your account, use the app or contact support.
⚖️ LegalTerms of Use - English
PICNIC TERMS OF USE Last Updated: June 15, 2026 Express acceptance: access to and use of the Platform are conditioned upon the express acceptance of these Terms at the time of registration (onboarding), by means of an affirmative action by the User, such as checking an acceptance box. By manifesting such acceptance, the User declares to have read, understood, and agreed to these Terms, including the Privacy Policy, which is an integral part hereof. These Terms of Use constitute a binding agreement between you (the “User”) and DeFiBasket Labs Inc., the company that owns the PICNIC brand, incorporated under the laws of the British Virgin Islands (BVI). For the purposes of this agreement, “PICNIC” refers to the website usepicnic.com, the set of software protocols, the technological interfaces that make up the PICNIC Platform, and the associated mobile applications. By using our technology, the user acknowledges that PICNIC is a self-custodial and distributed technology software. Unlike traditional financial institutions, the PICNIC software is not “located” or headquartered in a single physical jurisdiction. It operates through a decentralized cloud infrastructure, executing locally on the user's device and directly on public blockchain networks. The software functions as an interface for the user to interact directly with the blockchain. DeFiBasket Labs Inc. does not have access to, control over, or custody of the user’s private keys, recovery phrases (seeds), or digital assets. READ CAREFULLY BEFORE PROCEEDING: PICNIC IS NOT A BANK, IS NOT A FINANCIAL INSTITUTION, IS NOT A CUSTODIAL EXCHANGE, NOR DOES IT INTERMEDIATE ANY TRANSACTION. PICNIC IS EXCLUSIVELY AN INTERFACE SOFTWARE PROVIDER. BY USING THIS PLATFORM, YOU ACKNOWLEDGE THAT THE OPERATING MODEL IS SELF-CUSTODY. THIS MEANS THAT: THE POSSESSION, SECURITY, AND CONTROL OF YOUR PRIVATE KEY, YOUR DEVICE, YOUR PASSKEY, AND YOUR RECOVERY PHRASE (SEED PHRASE) ARE YOUR SOLE AND ENTIRE RESPONSIBILITY. WE DO NOT STORE, DO NOT HAVE A COPY OF, AND DO NOT HAVE ACCESS TO YOUR PRIVATE KEYS, YOUR DEVICES, OR YOUR ASSETS ON THE BLOCKCHAIN. IMPOSSIBILITY OF RECOVERY: IF YOU LOSE ACCESS TO YOUR PRIVATE KEY OR YOUR RECOVERY PHRASE, PICNIC'S TECHNICAL SUPPORT DOES NOT HAVE THE TECHNICAL CAPACITY TO RECOVER WALLET PASSWORDS, REVERSE TRANSACTIONS, OR REFUND LOST VALUES, AS WE DO NOT HOLD CUSTODY OF THE FUNDS. BY USING A SERVICE THAT OPERATES ON A BLOCKCHAIN, YOU AGREE AND ARE AWARE THAT YOUR TRANSACTIONS ARE IRREVERSIBLE AND THAT SMART CONTRACTS, BLOCKCHAIN NETWORKS, AND THIRD-PARTY PROVIDERS INVOLVE RISKS, AND THAT PICNIC CANNOT RECOVER YOUR KEYS NOR REVERSE YOUR TRANSACTIONS. USER RISK: BY ACCEPTING THESE TERMS, YOU FULLY ASSUME THE TECHNOLOGICAL RISK OF SELF-CUSTODY AND RELEASE PICNIC FROM ANY LIABILITY REGARDING THE LOSS OF ACCESS TO YOUR DIGITAL WALLET. By registering or connecting your wallet to use PICNIC's graphical interface (the “Site” or “App”), you agree that you have read, understood, and accept all terms and conditions contained in this Agreement, including our Privacy Policy, which is an integral part of these Terms of Use. INFRASTRUCTURE PARTNERS AND THIRD-PARTY SERVICES: By accepting these Terms of Use and utilizing the products and features provided through the Picnic software, you acknowledge and agree that certain operations are enabled by external infrastructure partners. Accordingly, when using specific services, you declare that you are aware of and fully agree to our partners' specific terms of use, including but not limited to: - Asset Conversion: Operations involving the conversion of crypto assets to fiat currency and vice versa; - Picnic Card: The use of the physical or virtual card; - Custody and Settlement: Other payment processing services and network infrastructure. The continued use of these features implies automatic acceptance of the terms and conditions established by such partners, over which Picnic has no direct control. The operation of the entry and exit ramps is the sole responsibility of the respective third-party companies, and Picnic is exempt from any liability in this regard. 1. ELIGIBILITY AND JURISDICTIONAL SCOPE 1.1. Nature of Software and Location. The User acknowledges that PICNIC is technology software of a self-custodial and distributed nature. Unlike traditional institutions, PICNIC's software is not “located” or headquartered in a single physical jurisdiction but operates through decentralized cloud infrastructure and runs locally on the User's device and on the public blockchain network. 1.2. Due to its global nature, PICNIC is not necessarily subject to the governing laws of a specific country, except regarding the direct obligations of its developers. (A) Local Compliance: This does not imply legal immunity. PICNIC complies with all standards applicable to its operating model in the countries where it operates. The User is responsible for ensuring that access to and use of the Platform are permitted by the laws of the jurisdiction in which the User resides, is domiciled, or from which they access the services. (B) Illicit Use: It is strictly prohibited to use PICNIC software for purposes that are considered illicit in the User's jurisdiction or under international standards, including but not limited to: money laundering, currency evasion, terrorist financing, fraud, or purchase of illegal goods. 1.3. Anti-Money Laundering (AML) and Control. Although PICNIC is a technology provider and not a financial custodian, we maintain proprietary monitoring and control policies and tools to prevent the use of the tool for illicit purposes (Anti-Money Laundering – AML and Combating the Financing of Terrorism – CFT), as detailed in these Terms. Shared Responsibility: The existence of these internal control tools by PICNIC does not transfer legal responsibility to the company, nor does it exempt the User from their civil and criminal obligations. The User must cooperate with the proper use of the Platform, providing truthful information when requested and AGREEING TO NEVER USE THE PLATFORM FOR ANY ILLICIT ACTIVITY. 1.4. The legal relationship established between the user and Picnic is a software license agreement, whereby the technological tool allows the user to exercise financial sovereignty, maintaining exclusive control over their private keys and the final execution of any transaction. Technologically, PICNIC operates under a non-custodial software architecture. This means that our platform acts strictly as a graphical interface for interaction with the Blockchain, without ever intermediating or holding possession of the assets. 1.5. "Trader" Status – European Union (DSA). For the exclusive purposes of complying with Regulation (EU) 2022/2065 (Digital Services Act - DSA) and consumer protection standards applicable in the European Union: (A) PICNIC declares itself as a "Trader" strictly in the sense of a provider of a technological tool and digital software. (B) This designation MUST NOT be interpreted as a statement that PICNIC acts as a financial intermediary, broker, or payment service provider. The product marketed by PICNIC is the license to use the interface and the aggregated technology services, and not the purchase and sale of financial assets, which occurs directly between the User and the blockchain network. 1.6. Legal capacity and prohibition of use by minors. The User declares to be over 18 (eighteen) years of age and fully capable of performing acts of civil life. The PICNIC Platform and Technology Services are not intended for minors under 18 years of age, and their use, registration, or access by legally incapable persons is prohibited. (A) The User is responsible for ensuring that they will not allow minors to access their credentials, their device, or the functionalities linked to their Account. (B) Upon identification of use by a minor or by a person lacking legal capacity, PICNIC may suspend access to the interface, subject to the technical impossibility of accessing self-custodied assets without the Private Key or Recovery Phrase. (C) The processing of data eventually associated with minors shall observe the data protection and child and adolescent protection legislation applicable in the User's domicile. 2. SERVICES 2.1. Nature of Services: Technology Provider. PICNIC acts exclusively as a provider of Technology Services, making available to users a software usage license (the “Platform”) intended to facilitate the user's direct interaction with decentralized blockchain networks. By using PICNIC, the user expressly acknowledges and agrees that: (A) PICNIC solely makes available the software infrastructure and digital tools that allow the viewing, reading, and transmission of instructions directly to the blockchain; (B) PICNIC does not hold, store, keep, process, or control the User's Virtual Assets at any time; and (C) All transactions are executed directly by the user on the respective blockchain network, without any intervention, approval, or financial settlement by PICNIC. 2.2. Non-Existence of Financial Management or Brokerage. Unlike centralized exchanges, PICNIC DOES NOT perform the purchase, sale, or transfer of virtual assets on behalf of third parties. For the avoidance of doubt, it is established that: (i) Strictly Technological Role: PICNIC does not acquire or sell assets in its own name on behalf of the user; (ii) Absence of Powers: PICNIC does not possess powers to represent the user or make decisions regarding their assets; (iii) Direct Relationship: The user transacts directly with the decentralized protocol or with other users of the network (P2P/DeFi), with PICNIC being responsible only for providing the connection software; (iv) Self-Custody: PICNIC does not maintain possession of the user's private keys or funds. Responsibility for safeguarding access credentials and private keys lies exclusively with the user. 2.3. The PICNIC Platform functions as an access portal (“Gateway”) that translates user commands into language compatible with the blockchain. Thus: (i) The user connects their own wallet or generates new access credentials through the provided technology; (ii) The user signs transactions with their own private key; (iii) PICNIC only transmits this signed transaction to the public blockchain network for processing by network validators. Furthermore, the User understands that the "PICNIC Interface" (the web software/app) is distinct from the underlying "Decentralized Protocols" (the Smart Contracts running on the Blockchain). (A) PICNIC provides the Interface, which is merely a visual tool. (B) PICNIC does not control, does not operate, and cannot halt the Decentralized Protocols with which the Interface interacts. If there is a failure in the Protocol (e.g., calculation error in the Pool's Smart Contract), PICNIC has no liability, as it is not the owner of the decentralized network. 2.4. Since PICNIC provides only Technology Services and not financial settlement: (A) PICNIC does not guarantee the execution, settlement, or immutability of transactions, which depend exclusively on the functioning of the underlying blockchain network; (B) PICNIC does not have the technical capacity to reverse, cancel, or modify transactions once they have been transmitted by the user to the blockchain network; (C) Network fees (“Gas Fees”) are paid directly by the user to the network validators and do not constitute revenue for PICNIC. 2.5. Integrations, Web3 Browser, and Third-Party Services. The PICNIC interface may include virtual asset browser functionalities (“Web3 Browser”) or direct links allowing the user to access Decentralized Applications (“dApps”) and Decentralized Exchanges (“DEXs”) operated by third parties. (A) Browser Nature: By using the Web3 Browser, the user understands they are navigating outside the environment controlled by PICNIC. The software acts only as a connection bridge. PICNIC does not control, endorse, audit, or guarantee the security, legitimacy, or functionality of any dApp or DEX accessed. (B) If the user interacts with a malicious dApp, falls for phishing scams, or suffers losses due to failures in third-party smart contracts accessed via the PICNIC interface, responsibility lies exclusively with the user. PICNIC has no power to reverse such interactions. 2.6. Additional Services. In addition to the main Technology Services, PICNIC may develop and make available additional functionalities or integrations with third-party systems (the “Additional Services”), aimed at expanding the Platform's utility. 2.6.1. The PICNIC Card and Partnerships. Should the user choose to use functionalities such as the prepaid card integrated into the Platform (the “PICNIC Card”): (A) Issuance by Third Parties: The user acknowledges that the card is issued and administered by a partner financial or payment institution, duly regulated, and not by PICNIC. (B) Technological Connection: PICNIC's role is limited to providing the technology that allows the user to connect their self-custodial wallet to the issuing partner's system. (C) Subjection to Third-Party Terms: The use of Additional Services requires the user to accept terms and conditions of the issuing partners. (D) Nature of the Card: The PICNIC Card is a prepaid payment instrument, backed by USDC. It does not constitute a debit or credit card in the traditional regulatory sense, nor does it confer upon the User the protections typical of banking products, such as deposit guarantees. Conversion, network, and spread fees may apply. 2.6.2. Card partner infrastructure and policies. The functionality of the PICNIC Card depends on the infrastructure and services provided by Gnosis Pay and its issuing network. The use of the PICNIC Card is subject to the proprietary policies of these partners, who may, according to their own risk and compliance criteria and procedures, approve, refuse, limit, suspend, or cancel the card and access to the respective functionality. As the PICNIC Card uses the infrastructure of these partners, such decisions are made by them, and not by PICNIC, which has no interference over their merits, even if they impact the use of the card within the Platform. 2.7. Fees and Remuneration. For the use of the Platform and Additional Services, PICNIC may charge software licensing or service fees, which will always be presented transparently on the Platform. (A) Distinction of Fees: The user declares awareness that fees charged by PICNIC (for the use of Technology Services) are distinct from network fees (Gas Fees) and distinct from any financial fees charged by third-party partners. (B) Responsibility: The user agrees to be responsible for the payment of all applicable fees presented on the Platform at the time of the transaction. 2.8. Non-Existence of Fiduciary Duty. This Agreement is not intended to create, and does not create, any fiduciary duties on the part of PICNIC towards the User. To the maximum extent permitted by law, the User acknowledges and agrees that PICNIC owes no loyalty, duty of financial care, or asset management to the User. Our only obligations are the strictly technical ones described in these Terms (software provision). 2.9. Routing and Price Execution. PICNIC's smart routing technology seeks to find efficient routes for User trades. However: (A) Due to Blockchain volatility and speed, PICNIC does not guarantee that the price displayed in the simulation will be exactly the executed price, nor that it will be the best price available in the entire global market at that millisecond. (B) The User acknowledges that the final price may vary between the time of signing and the time of the transaction. 3. ACCOUNT CONFIGURATION AND IDENTITY 3.1. Access Account Registration. To use PICNIC's Technology Services, it may be necessary to register a user profile on the Platform (a “PICNIC Account”). Registration involves providing data such as name, email address, and creating software access credentials. 3.1.1. Nature of the Account. The PICNIC Account is intended exclusively to: (i) manage software settings; (ii) allow technological access to Additional Services; and (iii) store activity history. The PICNIC Account is not a bank, payment, or deposit account. Creating a PICNIC Account does not imply, under any circumstances, the transfer of possession of the user's assets to PICNIC. 3.2. Identity Verification (KYC) for Software Security. Although PICNIC acts strictly as a Technology Provider, digital environment security and compliance with global standards require user identification, especially to enable integrations with regulated partners (e.g., card issuers). Thus, the user agrees to provide requested information for identity verification, risk analysis, and anti-money laundering policies (KYC / AML). 3.2.1. Use of Information. The user authorizes PICNIC to use their data to validate their identity and, when the user chooses to use the PICNIC Card, to share such data with partner financial institutions, strictly to enable the service provision by the partner. 3.3. Account Password vs. Private Key. It is fundamental that the user understands the difference between PICNIC Account credentials and their Wallet credentials: (A) PICNIC Account Credentials: (Login/Password). Allow access to the software/application. (B) Private Key or Recovery Phrase (Seed Phrase): These are the mathematical codes that control Virtual Assets on the blockchain. PICNIC HAS NO ACCESS, DOES NOT STORE, AND CANNOT RECOVER YOUR PRIVATE KEY. PICNIC's operating model is self-custodial. If the user loses their Private Key, they will lose access to their assets, without PICNIC being able to intervene. The use of the platform and the technology services provided imply total and unrestricted awareness of this aspect of the provided technology. 4. TRANSACTIONS AND INTERACTION WITH THE BLOCKCHAIN 4.1. The technology made available by PICNIC allows the user to manage their own funds and interact directly with public blockchain networks. By initiating a transaction through the Platform (whether sending, receiving, swapping, or interacting with smart contracts), the user acknowledges that: (A) The transaction is signed exclusively by the User's Private Key, stored locally on the user's device (or in an encrypted personal cloud solution), without PICNIC having access to this signature; (B) PICNIC does not act as a counterparty in the transaction. Buying and selling occur between the user and decentralized protocols (Smart Contracts) or other network users (P2P); (C) PICNIC's software acts only as a transmitter of the message signed by the user to the blockchain network nodes. 4.2. Integration with Fiat Currency (Fiat On-Ramp/Off-Ramp). PICNIC does not receive, custody, or process fiat currency (Reais, Dollars, etc.). To facilitate conversion between fiat currency and Virtual Assets, the Platform may technologically integrate services provided by third parties (“Liquidity Partners”). (A) By choosing to buy or sell cryptoassets using Reais (BRL), the user establishes a direct contractual relationship with the Liquidity Partner. (B) PICNIC only provides the viewing window (widget) for access to the Partner's service. Financial settlement, exchange, and regulatory compliance of this operation are the sole responsibility of the Liquidity Partner. (C) The User understands that the digital assets resulting from the conversion are delivered to their self-custodial wallet address at the end of the flow. The intermediate conversion steps — including any issuance, settlement, or conversion of assets — are executed by the regulated Liquidity Partner, in its own infrastructure and custody, according to the technical design of each operation. At no time does PICNIC receive, hold, or control the User's fiat currency or intermediate assets. 4.2.1. Failures in fiat rails (PIX, card, and other fiat means). The User acknowledges that operations dependent on fiat rails — such as PIX settlement in the conversion between fiat currency and digital assets, or transactions carried out with the PICNIC Card — are operated and settled by the regulated Partners, and not by PICNIC. (A) Distinction in relation to on-chain irreversibility: the impossibility of reversal provided for in these Terms applies exclusively to transactions already transmitted to the blockchain network, and is not to be confused with any operational failures in the fiat rails, which follow the responsible Partner's own procedure. (B) Treatment of failures: in the event of a transient failure in the settlement of a fiat operation, the operation may be automatically resubmitted once; should a failure of a permanent nature persist, the corresponding amounts will be returned to the User, preferably by crediting the corresponding digital asset to their self-custodial wallet address, according to the Partner's technical design. (C) Handling channel: without prejudice to the regulated Partner's operational responsibility, the User may report failures through the support channels indicated in Clause 10, which will forward the matter to the competent Partner. (D) This Clause does not expand PICNIC's obligations beyond the provision of the technological interface, nor does it transfer to PICNIC the responsibility for financial settlement, which remains exclusively with the regulated Partner. 4.2.2. Autonomy of fiat conversion Partners. The operations of conversion between fiat currency and digital assets (on-ramp and off-ramp) are executed by regulated Partners, subject to their own rules, licenses, and regulatory and compliance obligations. The User acknowledges and agrees that: (A) PICNIC selects its Partners through prior due diligence, prioritizing providers that demonstrate anti-money laundering, counter-terrorist-financing, and fraud-prevention controls aligned with applicable global standards; (B) the Platform reflects, in real time, the policies, limits, and restrictions imposed by these Partners, such that their decisions — including temporary or permanent blocks, changes to limits, refusals of operation, additional verification requirements, or suspension of access — may affect the availability and use of functionalities within PICNIC; (C) such decisions are within the exclusive competence of the regulated Partners, adopted according to their own criteria and procedures, and PICNIC has no interference over their merits, even if they impact the use of the Services; (D) the User is prohibited from employing means to circumvent such restrictions, such as the use of VPNs to mask their jurisdiction, under penalty of violation of these Terms. 4.2.3. Unavailability of withdrawal via fiat rail. Should a withdrawal via a fiat rail — for example, via PIX — remain blocked or unfeasible and it is not possible to obtain an alternative with the responsible Partner, the User may move the corresponding digital asset, held in their self-custodial wallet, to another wallet of their ownership and carry out the withdrawal by another available means. PICNIC does not replace the regulated Partner in financial settlement, nor does it guarantee the existence of an alternative means of withdrawal, the User remaining with full control of the digital asset in self-custody. 4.3. Unlike traditional banking systems or centralized exchanges, transactions on the blockchain are, by nature, irreversible. (A) Once the user signs and transmits a transaction through PICNIC technology to the network, it cannot be canceled, reversed, or modified. PICNIC has no technical capability to refund transactions, even in cases of error, theft, or fraud. (B) It is the user's sole responsibility to verify the destination address, selected network, and values before signing the transaction. 4.4. Network Fees (Gas Fees) and Service Fees. (A) Network Fees (Miners/Validators): Every blockchain transaction incurs a processing fee (Gas Fee) paid to the network validators. The User acknowledges that PICNIC may, at its sole discretion and for greater convenience, facilitate the payment of this fee through fee abstraction mechanisms. In such cases, PICNIC may advance the payment of the network fee on behalf of the User, being fully reimbursed by withholding the corresponding amount in the specific token used for the transaction. (B) Fee Independence: In cases where the facilitation mentioned in item (A) is not provided, the fee fluctuates according to network demand and is not defined or controlled by PICNIC. (C) Technology Fees: For the use of the technological solution that facilitates interaction (such as intelligent swap routing or the convenience of fee payment), PICNIC may charge a service fee, which will be added to the transaction and clearly displayed to the User prior to signing. 4.5. As a non-custodial wallet, the user's address on the blockchain can technically receive any asset compatible with that network. However, the PICNIC Platform filters and displays only a selected list of Virtual Assets (“Viewable Assets”) to ensure a better user experience and security. (A) Sending Unlisted Assets: If the user sends an asset to their address that is not visually supported by PICNIC software, the asset is not lost (as it is on the blockchain) but may not appear in the graphical interface. The user may need to import their Recovery Phrase into other compatible software to view/move this asset. (B) Termination of Support: PICNIC may stop displaying certain assets on the interface at any time. This does not affect the user's ownership of the asset, only the visualization through the PICNIC tool. 4.6. Specific Risks of DeFi Protocols and DEXs. PICNIC technology allows access to Decentralized Finance (DeFi) protocols and DEXs for asset exchange or liquidity provision. Unlike centralized exchanges that curate listed assets, DEXs are open environments. (A) High-Risk Assets: The user acknowledges that DEXs and dApps may list assets without any prior verification. This includes assets with high risk of illiquidity, extreme volatility, blocking risk, or fraudulent tokens (scam tokens/rug pulls). It is the user's sole responsibility to verify the asset's contract address before trading. (B) Third-Party Prices and Fees: The user may incur fees imposed by the dApps or DEXs themselves (in addition to network fees). PICNIC neither receives nor controls these third-party fees. 4.7. Blockchain networks may undergo protocol changes (“Forks”). PICNIC does not control these changes. (A) Discretion: PICNIC reserves the right to decide whether to update its software to support a specific Fork. (B) No Obligation: PICNIC has no obligation to support new chains resulting from forks, nor to guarantee that the user receives tokens generated in forks (Fork Airdrops). 4.8. (A) All Virtual Assets associated with the user's wallet address are the exclusive property and direct possession of the user. (B) PICNIC DOES NOT hold, does not keep title, has no custody, and does not manage user assets. Assets remain off PICNIC's balance sheet. (C) Only the holder of the Private Key (the user) can move the assets. PICNIC has no technical means to freeze, confiscate, or move user funds, even under court order (as technology does not permit such access). 4.9. Since PICNIC does not have access to private keys, PICNIC cannot recover wallets whose passwords or Recovery Phrases have been lost by the user. Backup management is the user's full responsibility. 4.10. It is strictly prohibited to use the PICNIC interface to perform or attempt to perform: (A) Market Manipulation: Practices violating market integrity, including but not limited to tactics known as Rug Pulls, Pump and Dump, and Wash Trading; (B) Cyber Attacks: Any activity seeking to interfere, intercept, or compromise the integrity of Smart Contracts, including reentrancy attacks, malicious front-running, or exploitation of protocol bugs; (C) Securities Violation: Offer or trading of assets that may be characterized as unregistered securities or prohibited derivatives in the User's jurisdiction. 4.11. Assumption of Technological Risk. Blockchain technology carries inherent risks. The User acknowledges and accepts that smart contracts, blockchain networks, and the protocols accessed through the PICNIC interface may contain bugs or be subject to exploits, hacker attacks, or other failures or vulnerabilities, which may result in the partial or total loss of the assets involved. Because PICNIC provides only an interface and does not control this underlying technology, it cannot and does not guarantee that operations will be free of such risks. The User knowingly and voluntarily assumes these technological risks, without prejudice to the limitations of liability set out in Clause 7. 5. SOFTWARE OPERATIONAL LIMITS 5.1. The use of PICNIC Technology Services and, especially, Additional Services (such as fiat currency conversion or PICNIC Card use), is subject to operational limits. Such limits may restrict financial volume, transaction frequency, or access to certain Platform functionalities within a given period. 5.2. Limits are established based on security criteria, fraud prevention, and regulatory compliance, and may vary according to: (i) The level of Identity Verification (KYC) completed by the user; (ii) Requirements imposed by operational Partners and card issuers; (iii) Software usage history and risk assessment. 6. SUSPENSION AND TERMINATION OF ACCESS 6.1. Without prejudice to other rights provided in these Terms, PICNIC, as the software license provider, may: (A) Refuse to process or transmit any technical instruction from the user to the blockchain network (e.g., if the transaction is identified as malicious, fraud, or destined for internationally sanctioned addresses); (B) Temporarily or permanently block the user's login to the PICNIC Platform; (C) Restrict access to specific Additional Services (such as suspending PICNIC Card use) without necessarily blocking wallet viewing access. 6.1.1. Blocking by order of an authority or compliance requirement. In compliance with a court order, determination by a competent authority, requirement of a regulated Partner, or compliance obligation, including international sanctions, PICNIC may refuse to transmit instructions to the network, block access to the interface, or restrict Additional Services. Given the non-custodial nature of the technology, such measures do not confer upon PICNIC possession, control, or ownership over the User's assets and do not constitute appropriation, the User remaining able to access their assets directly on the blockchain. 6.1.2. Emergency protective measures. In situations of force majeure, security incident or failure, cyber attack (including hacking and exploitation of vulnerabilities), loss of parity (de-peg) of stablecoins, relevant technical instability, or other demonstrated need, PICNIC may adopt, within the scope of the interface and software under its control, the measures it deems necessary to protect Users, preserve the integrity of the Platform, and safeguard Users' funds, including suspending the interface in whole or in part, pausing or disabling specific functionalities, interrupting the routing or transmission of instructions to the network, and restricting access. (A) Such measures fall exclusively upon the software resources under PICNIC's control and, given the non-custodial nature of the technology, do not confer upon PICNIC possession, control, or ownership over the User's assets, not constituting custody or appropriation. (B) The User remains, at any time, able to access and move their assets directly on the blockchain by means of their Private Key or Recovery Phrase, regardless of the measures adopted on the interface. (C) PICNIC will use reasonable efforts to limit such measures to what is strictly necessary and for the necessary time, restoring regular operation as soon as the cause has ceased. 6.2. Grounds for Suspension or Termination. Such measures may be taken, including with immediate effect, if: (i) The user violates any provision of these Terms; (ii) There is reasonable suspicion that the PICNIC Account is being used for illicit activities, money laundering, fraud, or currency evasion; (iii) A court order or determination by a competent authority requires blocking access to the software; (iv) The user's use of technology puts the Platform's technical stability at risk. Any suspension or termination of the user's account on the PICNIC platform does not confer upon PICNIC the ability to access or transfer user funds. The user's wallet remains accessible on the blockchain through other platforms. 6.3. Consequences of Termination/Suspension: As PICNIC does not hold custody of assets, termination of Platform access does not imply confiscation of assets on the blockchain, provided the user possesses their self-custody credentials. (A) Should PICNIC terminate the user's access to the software, the user may access and move their Virtual Assets using their Private Key or Recovery Phrase (Seed Phrase) in any other compatible wallet software available on the market (e.g., hardware wallets or other open-source applications). (B) Termination of the PICNIC Account will result in loss of access to transaction history, custom settings, and data stored on PICNIC servers, but will not affect the immutable record of transactions on the blockchain. (C) Should the user have financial obligations related to Additional Services (e.g., outstanding card balance or unpaid service fees), the user remains legally obligated to settle them, even after access suspension. 6.4. Impossibility of Reversion. The user acknowledges that, due to the immutable nature of the blockchain, PICNIC lacks the technical capacity to reverse, cancel, or refund transactions already transmitted to the network, even in cases of account suspension. Service suspension only prevents the initiation of new transactions through the PICNIC interface. 6.5. Whenever possible and provided it does not violate applicable laws or compromise security investigations, PICNIC will notify the user regarding suspension or termination of access, presenting the general reasons for the decision. 6.6. PICNIC may, at its sole discretion, discontinue, modify, or alter the Platform architecture or any Technology Service at any time. In case of total discontinuity of PICNIC operations, the user will continue to have full control over their assets through their Recovery Phrase, regardless of the PICNIC platform's existence, reinforcing the uncensorable nature of self-custody. 6.6.1. Cessation of operation and exit window. In the event of a planned discontinuation of the Platform or of Additional Services, PICNIC will use reasonable efforts to notify the User with adequate advance notice, so as to allow the use of fiat functionalities, such as conversion and withdrawal through the Partners, before the cessation. Once operation has ceased, access to the fiat rails intermediated by Partners may end, the User remaining with full control of their assets on the blockchain by means of their Recovery Phrase, regardless of the existence of the Platform. 7. LIABILITY AND LIMITATIONS Highlighted notice (careful reading). This Section 7, as well as Clauses 10.3, 10.4, and 15.8, contains provisions that limit rights and liabilities. Such clauses must be read carefully before acceptance. 7.1. If the user has a dispute with third parties, including but not limited to: (i) other users; (ii) smart contract developers; (iii) token issuers; (iv) liquidity partners or card issuers; (v) blockchain network validators; (vi) hackers, the user expressly agrees to release PICNIC, directors, and employees from any claims, demands, and damages of any nature arising from or related to such disputes. PICNIC provides only the access tool (interface); it is not a party to transactions performed on the blockchain. 7.2. The user agrees to indemnify and hold harmless PICNIC and its technological partners against any costs, losses, liabilities, and expenses (including reasonable attorney's fees) arising from: (A) Misuse of Technology Services or violation of these Terms by the user; (B) Violation of any applicable law or regulation by the user. 7.3. Limitation of Financial Liability (Indemnity Cap). CONSIDERING THAT PICNIC IS A SOFTWARE PROVIDER AND NOT AN ASSET CUSTODIAN: Except in cases of willful misconduct or proven gross negligence, PICNIC's total and cumulative liability for any damages or losses suffered by the user shall be strictly limited to the total amount of service fees paid by the user to PICNIC (excluding gas fees and partner fees) in the 12 (twelve) months prior to the event generating the claim. Under no circumstances shall PICNIC's liability be calculated based on the value of Virtual Assets held by the user on the blockchain, as PICNIC does not hold possession or control of such assets. 7.4. Specific Exclusion of Damages (Technology Risks). In addition to the limitations above, PICNIC SHALL NOT be liable for losses arising from: (A) Loss of Keys: Loss, theft, forgetting, or compromise of the Recovery Phrase (Seed Phrase), Private Key, or user passwords. PICNIC does not hold a copy of this data and cannot recover it; (B) Blockchain Failures: Network congestion, high transaction fees, consensus failures, 51% attacks, or bugs in the underlying blockchain protocol; (C) User Errors: Sending assets to incorrect addresses, incompatible networks, or interaction with malicious contracts (Honeypots, Phishing); (D) Third-Party Risks: Bankruptcy, insolvency, or technical failures of Liquidity Partners, hacks or exploits in third-party products, protocols, or services made available or accessible through the platform, card issuers, or DeFi protocols accessed through the interface; (E) Lost Profits: Loss of profit opportunity, loss of expected revenue, or damages arising from market volatility; (F) Smart Contract Exploits: Bugs, vulnerabilities, exploits, or attacks affecting smart contracts accessed through the interface or developed or deployed by PICNIC, except in cases of PICNIC's willful misconduct or proven gross negligence (Clause 7.3). 7.5. PICNIC Technology Services are provided "as is" and "as available". (A) PICNIC does not guarantee that transactions transmitted to the blockchain will be mined/validated on time or at a specific cost. (B) No information displayed on the Platform constitutes investment advice, legal, or tax consultancy. The user operates at their own risk. (C) Like any software, the PICNIC Platform may contain errors (bugs) or undergo instabilities. PICNIC does not guarantee that the service will be uninterrupted or error-free, although it will use best efforts to correct flaws promptly. 7.6. Non-Existence of Profit Guarantee. The User acknowledges and agrees that any yield-generating functionality available on the Platform is based on interactions with third-party decentralized protocols and variable digital assets. PICNIC does not, under any circumstances, guarantee any profit, fixed yield, or specific financial return. 7.7. Any rates of return displayed on the interface are mere estimates based on historical data or real-time data from underlying protocols, and may be subject to drastic and immediate fluctuations due to market volatility, changes in DeFi protocol rules, or blockchain network conditions. The actual return may be significantly lower than estimated and may, in some cases, be zero or negative. 7.8. By using any yield strategy, the User declares to be fully aware of and releases Picnic from any material loss they may incur arising from: (A) Autonomous Decision: The choice of asset and strategy is the User's sole responsibility; (B) Market Risks: The value of the underlying assets may drop sharply, impacting the total value invested, regardless of the yield generated; (C) Technological Risks: The User accepts the risks of "bugs," cyberattacks, hackers, or the loss of parity (de-peg) of stablecoins within the protocols where the assets are allocated. 7.9. PICNIC, as a software provider, does not act as an investment advisor or wealth manager. The User hereby releases PICNIC from any liability for financial losses, direct or indirect damages arising from price variations or the performance of the assets chosen within the platform. 7.9.1. Non-financial nature of the yield functionalities. The yield functionalities available on the Platform constitute technological tools that allow the User to interact, autonomously and in self-custody, with third-party decentralized protocols. They do not constitute, and must not be interpreted as: (A) an offering of an investment product, financial investment, remunerated deposit, or collection of public savings; (B) a public offering of securities, a collective investment contract, or a collective investment scheme; (C) an activity of administration or management of third-party resources. PICNIC is not a financial institution, virtual asset service provider (VASP), administrator, or resource manager, and does not promise, guarantee, or assure any yield. The rates of return eventually displayed are variable and may, in some cases, be zero or negative, as already set forth in Clauses 7.6 to 7.9. 7.9.2. Prohibition of leverage loop operations. The User is expressly prohibited from using credit, a loan, or any resource obtained through credit protocols accessed via the PICNIC interface to acquire, directly or indirectly, new digital assets through the Platform itself with the objective of constituting leveraged positions in a loop (leverage loop). PICNIC reserves the right to restrict, suspend, or prevent, technically or contractually, functionalities that enable such practice, without this constituting a duty of continuous monitoring of the User's autonomous operations. 7.10. Force Majeure and Network Events. PICNIC shall not be liable for delays or failures in fulfilling its obligations resulting from events beyond its reasonable control, including but not limited to: governmental acts, wars, terrorism, pandemics, global internet infrastructure failures, or critical blockchain network events (such as hacker attacks, bugs in smart contracts, contentious forks, network halts, loss of parity (de-peg) of stablecoins, censorship of transactions by validators, chain reorganization (chain reorg), or price oracle failures). 8. AVAILABILITY AND ACCURACY OF TECHNOLOGY SERVICES 8.1. Access and Software Availability. Access to PICNIC Technology Services may suffer degradation, slowness, or temporary unavailability due to technical maintenance, third-party server failures, or periods of high congestion on supported blockchain networks. (A) Although PICNIC is dedicated to maintaining Platform stability, we do not guarantee that the technological solution will be available uninterruptedly or error-free. (B) The user acknowledges that delays in transaction confirmation or failures in order transmission may occur due to instabilities in the blockchain network itself (miners/validators), factors totally beyond PICNIC's technical control. (C) PICNIC emphasizes that, due to the non-custodial nature of the services, any unavailability of the PICNIC Platform DOES NOT prevent the user from accessing their Virtual Assets. Should PICNIC software be unavailable, the user may, at any time, use their Recovery Phrase (Seed Phrase) or Private Key to access and move their funds through other compatible software or wallets available on the market. For this reason, PICNIC shall not be liable for any damages, loss of opportunity, or asset devaluation resulting from temporary impossibility to use the Platform, since access to assets on the blockchain is independent of PICNIC software availability. 8.2. Accuracy of Information and Network Data. The PICNIC Platform acts as a viewer of public data recorded on the blockchain and third-party price sources (Oracles or market APIs). (A) Although PICNIC seeks to present information (such as balances, history, and quotes) accurately and up-to-date, there may be latency (delay) between data recording on the blockchain and its visualization on the Platform. (B) The user acknowledges that the "source of truth" regarding their balances and transactions is the immutable record on the blockchain network, not the cached visualization presented by PICNIC software. In case of divergence, blockchain network data prevails. (C) Displayed Virtual Asset price quotes are estimates based on third-party data. PICNIC does not guarantee the accuracy of these quotes and is not liable for purchase or sale decisions made by the user based on this visual information. 8.3. Content and Third-Party Links. The Platform may display links, news, or integrations with third-party services (including block explorers, DeFi protocols, and liquidity partners). The user acknowledges and agrees that PICNIC does not control, endorse, and assumes no responsibility for the content, accuracy, policies, or practices of these third-party services. Access to such external resources is at the user's sole responsibility and risk. 9. PROMOTIONAL CAMPAIGNS, BONUSES AND REWARDS 9.1. PICNIC may, at its sole discretion, offer promotions, referral programs, sign-up bonuses, or other rewards ("Promotions"). User participation in any Promotions is conditioned upon acceptance and compliance with the specific terms of each campaign, as well as eligibility rules, regional restrictions, and account verification in force at the time of participation. 9.2. PICNIC reserves the right to, at any time and without prior notice, modify, suspend, or terminate any Promotion, as well as alter eligibility criteria or reward value, creating no acquired right for the User regarding future bonuses or discontinued campaigns. 9.3. PICNIC reserves the right to disqualify the User, block the account, and revoke, refund, or cancel any rewards (even if already credited) if it identifies, at its sole discretion, including but not limited to: a) Creation of multiple accounts or use of false data; b) Use of robotic means, emulators, VPNs to bypass geographical restrictions, or automation scripts; c) Self-referral or collusion between accounts to manipulate the rewards system; d) Any violation of the acceptable use policy or suspicion of fraud. 9.4. The User acknowledges that rewards paid in cryptoassets are subject to market volatility. PICNIC is not responsible for value fluctuations, technical failures preventing immediate participation, or manifest material errors in bonus configuration, reserving the right to correct such failures and adjust balances as necessary. 9.5. Validity, expiration, and anti-fraud measures. PICNIC may establish validity periods and expiration conditions for points, bonuses, or rewards, as well as adopt proportionate anti-fraud measures. The expiration of points or rewards not used within the informed period does not give rise to any right to indemnification or compensation, subject to any mandatory rules applicable in the User's domicile. 10. CUSTOMER SERVICE, FEEDBACK AND DISPUTE RESOLUTION 10.1. Should the user have questions, suggestions, feedback, or encounter technical difficulties in using the Platform, they must contact the PICNIC Technical Support team via email oi@usepicnic.com or official channels indicated on the usepicnic.com page. For purposes of receiving judicial citations or formal extrajudicial notifications, PICNIC indicates the following physical/electronic address: legal@usepicnic.com 10.2. Support Scope and Limitations. The user acknowledges that support offered by PICNIC is strictly limited to the functioning of technology and software interface. (A) What we cover: Login problems in PICNIC Account, viewing errors in the app, difficulties integrating with partner services (Card), and interface bugs. (B) What we CANNOT cover: PICNIC support has no technical means to recover funds sent to wrong addresses, reverse transactions on the blockchain, recover Private Keys lost by the user, or accelerate pending transactions on the network. Complaints of this nature will be technically impossible to be solved by PICNIC. 10.3. Amicable Dispute Resolution. Except where prohibited by applicable law, before initiating any judicial or administrative proceeding against PICNIC, the user agrees to first contact our support team to try to resolve the issue amicably. The user agrees to grant PICNIC a period of up to 30 (thirty) days, counting from the formal receipt of the complaint with all necessary information, to analyze the case and propose a technical solution or clarification. Should the user initiate a dispute without first exhausting this attempt at amicable resolution, PICNIC reserves the right to request suspension of the process until the support procedure is concluded. 10.4. These Terms are governed by the laws of the British Virgin Islands. 11. DATA PROTECTION AND PRIVACY 11.1. Personal Data Processing. By using PICNIC Technology Services, the user acknowledges that PICNIC may collect and process personal data, in compliance with PICNIC's Privacy Policy, an integral part of these Terms. Data processing is performed for the purposes of: (i) Providing the software usage license and personalizing the user experience; (ii) Complying with legal and regulatory obligations (including fraud prevention and money laundering); (iii) Enabling integration with Additional Services (such as fiat currency conversion or PICNIC Card issuance with banking partners). 11.2. Data on Blockchain (Public Data). The user understands and accepts a fundamental characteristic of blockchain technology: Transparency and Immutability. By performing a transaction through the PICNIC interface, the user's public wallet address and transaction details are permanently recorded on the blockchain. (A) Public Data: This data is public, decentralized, and not controlled or stored on PICNIC servers. (B) Impossibility of Deletion: The user acknowledges that PICNIC lacks the technical capacity to alter, anonymize, or delete data already recorded on the blockchain. Therefore, rights of deletion or forgetting provided in data protection legislation are not applicable to immutable blockchain records, but only to data kept in PICNIC's internal databases (such as email registration and name). 11.3. Sharing with Partners. For the provision of Additional Services (especially connected financial services, such as the PICNIC Card), the user authorizes PICNIC to share their registration and identification data with partner institutions (card issuers, banks, or liquidity partners), strictly for contract execution and compliance with regulatory standards (Compliance) of those institutions. 11.3.1. Disclosure to authorities and legal requests. PICNIC may disclose User data to competent public authorities upon a valid legal request or in order to comply with a legal or regulatory obligation. Such disclosure shall observe the principles of necessity and proportionality, being limited to the data strictly necessary to meet the request, with the suppression (redaction) of third-party data not covered by the order whenever technically and legally possible. Where permitted, PICNIC may inform the User regarding the request. 11.4. User Declarations. The user declares that all information provided to PICNIC is true and current. The user commits to keeping their data updated on the Platform and acknowledges that reading and accepting the Privacy Policy is an indispensable condition for using the services. 12. SECURITY AND USER PROTECTION 12.1. Responsibility for Credentials and Devices. To use PICNIC software, the user must create Platform access credentials (Login and Password). The user is solely and fully responsible for their electronic device security and for maintaining proper control of their security data. 12.2. Critical Security Distinction (App vs. Blockchain). The user must understand the difference between two security levels: (A) PICNIC Account Security: Refers to access to the application interface. PICNIC can assist in app password recovery (password reset via email), should the user forget it. (B) Wallet Security (Self-Custody): Refers to the Private Key or Recovery Phrase (Seed Phrase) controlling funds on the Blockchain. PICNIC NEVER requests, stores, or has access to your Private Key. ATTENTION: If the user loses, forgets, or has their Private Key/Seed Phrase stolen, PICNIC CANNOT recover access to funds, nor reverse transactions. Private Key security is the user's sole responsibility. 12.3. Phishing and Scam Prevention. Picnic is not liable for damages arising from access to external links, third-party ads (on search engines or social networks), or fraudulent sites simulating the official service interface. It is the User's duty to verify URL authenticity and ensure they are in an official environment before entering any data or performing transactions. 12.3.1. Inducement and social engineering. The User acknowledges that, should they be induced, through social engineering, phishing, or third-party fraud, to sign a transaction, reveal credentials, install applications, or grant access to their device, PICNIC has no technical means to reverse the signed transaction nor to recover the transferred assets. Verifying the legitimacy of any request is the User's sole responsibility. 12.4. Security Breach. If the user suspects their PICNIC Account (app access) has been compromised: (A) The user must IMMEDIATELY notify PICNIC Support for temporary interface access blocking; (B) The user must IMMEDIATELY use their Recovery Phrase (Seed Phrase) in another secure interface to transfer their funds to a new secure wallet, since PICNIC has no power to "freeze" funds on the blockchain. 12.5. Picnic declares that it adopts technical, organizational, and administrative information security measures strictly aligned with standards required by the General Data Protection Law (Law No. 13.709/2018 - LGPD) and applicable regulatory standards. Such measures aim to protect personal data against unauthorized access and accidental or illicit situations of destruction, loss, or alteration. 13. INTEGRATION WITH NOAH SERVICES 13.1. By using the functionalities for conversion between fiat currency and cryptoassets available on the platform, the User acknowledges and agrees that these services are provided directly by Noah Savings Inc. ("Noah") and its banking partners, and not by Picnic. Thus: 13.2. Acceptance of Third-Party Terms: To use these services, the User automatically adheres to and must observe Noah's Terms of Service and Privacy Policy. 13.3. Data Sharing: The User authorizes Picnic to share their registration data, KYC (Know Your Customer) information, and wallet details with Noah for identity validation and anti-money laundering purposes, as required by applicable regulation. 13.4. Geographical Restrictions and Sanctions: The service is not available to Users residing in, citizens of, or attempting to access the platform from jurisdictions classified as "Prohibited Countries" by Noah. The User declares having no ties to the following locations: Afghanistan, Albania, Algeria, Bangladesh, Belarus, Qatar, China, Congo (Democratic Republic of the), North Korea, Cuba, Eritrea, Ethiopia, Gaza Strip, Yemen, Iran, Iraq, Kosovo, Lebanon, Libya, North Macedonia, Mali, Morocco, Myanmar, Nepal, Nicaragua, Niger, Pakistan, Central African Republic, Russia, Syria, Somalia, Sudan, South Sudan, Ukraine, Venezuela, West Bank, and Zimbabwe. 13.5. Limitation of Liability: Picnic acts only as a technological integrator. Any failure, delay, custody of values, or dispute related to currency conversion or financial settlement is the sole responsibility of Noah, with Picnic being exempt from liability for losses arising from these specific services. 13.6. Nature of the foreign currency conversion and withdrawal functionality. The functionality for conversion and eventual withdrawal in foreign currency through Noah constitutes an additional tool, of optional use, intended to allow the User to manage and convert assets of their own ownership. The User acknowledges and agrees that: (A) PICNIC is a non-custodial technical interface and is not a virtual asset service provider (VASP) subject to Brazilian regulation, not performing the triggering event set forth in art. 76-A of BCB Resolution No. 521/2025; (B) each step involving fiat currency is operated by a provider regulated in the respective jurisdiction: the step in reais, when applicable, by a partner regulated before the Central Bank of Brazil; and the step in United States dollars by Noah Savings Inc., registered with FinCEN and operating under United States regulation; (C) the conversion between USDC and United States dollars occurs abroad, under United States regulation, with no inflow or outflow of reais from Brazilian territory by reason of that operation; (D) the delivery of USDC to the User's self-custodial wallet, as well as the subsequent remittance of USDC from that wallet to the partner, constitute transfers to and from self-custody, of assets owned by the User themselves; (E) the operation consists of the maintenance and conversion of the User's own assets, as a resident, in foreign currency abroad, not configuring an international remittance of capital. The characterizations contained in this Clause reflect PICNIC's understanding based on the technical architecture in force, and do not constitute legal or tax advice to the User, who remains responsible for assessing the classification of their own operations. 14. PASSKEYS 14.1. As of April 6, 2026, the use of passkeys is mandatory for all accounts created via email on Picnic. Accounts created via external wallets remain subject to their original access conditions and are not affected by this Clause. 14.2. The Passkey is generated and stored exclusively within the secure hardware of the User's device. Picnic does not have access to the User's Private Key under any circumstances and cannot request it. Picnic stores only the Public Key, which is required to verify the authenticity of cryptographic signatures. 14.3. Passkeys implemented by Picnic follow the WebAuthn (FIDO2) standard, the same adopted by Apple, Google, and Microsoft for passwordless authentication. Biometric authentication occurs locally on the user's device. No biometric data is transmitted to Picnic or any third party. 14.4. Each transaction requires individual and direct biometric approval by the User on their device. There is no persistent session; every action requires confirmation at the moment it is performed. 14.5. By design of the WebAuthn standard, the User's Passkey is bound to the origin usepicnic.com. The Passkey will not function on any other domain or application, even if visually identical to Picnic. Picnic will never ask the User to provide, export, or share their Passkey or any biometric data. ℹ NOTE: Biometric authentication (Face ID, Touch ID, fingerprint) occurs locally on your device. Your biometric data is never sent to Picnic, the blockchain, or any third party. The network receives only the cryptographic signature produced by your device. 14.6. USER RESPONSIBILITIES 14.6.1. The User is solely responsible for the custody, security, and control of the device on which the Passkey is stored. Picnic bears no responsibility for losses resulting from theft, loss, unauthorized access, or compromise of the User's device. 14.6.2. The User is responsible for controlling who has access to the biometrics registered on their device. Any individual whose face or fingerprint is registered on the User's device may authenticate transactions on Picnic. Picnic has no means of distinguishing between the User and authorized third parties on the device. 14.6.3. The User is responsible for managing their account within the Passkey Manager of the platform they utilize (Apple ID, Google Account, or compatible manager). Passkey synchronization across devices is a third-party functionality over which Picnic has no control. 14.6.4. The User is strongly encouraged to configure their Passkey before April 6, 2026. After this date, account access will be contingent upon the completion of this setup. Assets remain secure on the blockchain regardless, but access to the Picnic interface will require an active Passkey. 14.6.5. The User is responsible for monitoring notifications sent by Picnic during the Protection Period of a recovery process. Picnic will send daily notifications during the 7-day Protection Period. The User must immediately cancel any recovery process they did not initiate. 14.6.6. The User acknowledges and accepts that the Passkey is the sole mechanism for authorizing transactions in their Smart Wallet. The definitive loss of access to the Passkey, without the possibility of recovery via the Recovery Guard, entails the permanent loss of access to assets. Picnic cannot intervene in this situation. USER RESPONSIBILITY: You are the sole guardian of your Passkey. Picnic has no way to recover your access outside of the process described in Clause 14.6. If you lose your device and your Recovery Guard simultaneously, without access to a Passkey Manager, access to your assets may be permanently lost. 14.7. TECHNICAL LIMITATIONS AND EXCLUSION OF PICNIC'S LIABILITY. 14.7.1. Picnic does not have access to, does not store, and cannot recover the User’s Private Key under any circumstances. This is a structural technical component, not an operational policy. 14.7.2. Picnic has no control over third-party Passkey Managers (Apple, Google, 1Password, Bitwarden, or others). Picnic is not liable for failures, unavailability, policy changes, or discontinuation of these services that affect the User's access to their Passkey. 14.7.3. Picnic is not responsible for failures in secure hardware (Secure Enclave or equivalent), operating system updates that affect passkey functionality, or any other technical limitations of the User's devices. 14.7.4. Picnic is not liable for transactions performed by third parties who have obtained access to the User's device, to the biometrics registered on the device, or to the User's Passkey Manager, except in cases of proven exclusive fault by Picnic. 14.8. ACCOUNT RECOVERY 14.8.1. The only account recovery mechanism available on Picnic is the process described in this Clause 14.8. Picnic does not offer any other recovery channel, whether through human support, administrative reset, or any other means. 14.8.2. The Recovery Guard is the Magic wallet previously linked to the User's email. Following the adoption of passkeys, the Recovery Guard does not have signing powers in the primary transaction flow—it acts exclusively as a recovery mechanism within the Smart Wallet's social recovery module. 14.8.3. To initiate a recovery, the User must: (i) Access Picnic on a new device; (ii) Authenticate with the email associated with the Account, activating the Recovery Guard; (iii) Register a new Passkey on the new device; (iv) Wait for the Protection Period of 7 (seven) calendar days; (v) Confirm the activation of the new Passkey at the end of the Protection Period. 14.8.4. The 7-day Protection Period is a security safeguard and not an operational limitation. It exists to ensure that any unauthorized recovery attempt—such as one initiated by someone with access to the User's email—can be detected and canceled by the legitimate User before it takes effect. 14.8.5. During the 7-day Protection Period, Picnic will send the User: (a) Immediate notification at the start of the recovery; (b) Daily reminder notifications while the process is active; (c) A final notification when the new Passkey is ready to be activated. 14.8.6. If the User receives notification of a recovery they did not initiate, they must cancel it immediately through the channel indicated in the notification. Picnic is not responsible for recoveries completed during the Protection Period where the User received notifications and failed to take action to cancel. 14.8.7. If the User simultaneously loses: (a) access to the Passkey; (b) access to the Passkey Manager; and (c) access to the email associated with the Recovery Guard—the account may be permanently unrecoverable. Assets will remain on the blockchain, but no technical mechanism will be available to authorize transactions. Picnic has no capacity to intervene in this situation. CRITICAL ATTENTION: The email associated with your account is your safety net. Maintain access to it. If you lose your Passkey and email access at the same time, without the possibility of recovery via a Passkey Manager, your assets may become permanently inaccessible. 14.9. CROSS-DEVICE SYNCHRONIZATION. 14.9.1. Passkey synchronization between devices is a feature provided exclusively by the User's Passkey Manager, not by Picnic. Picnic has no control over the synchronization process, its availability, or its technical requirements. 14.9.2. Picnic's passkey implementation is compatible with the following Passkey Managers, without guarantee of future availability or compatibility: (a) Apple iCloud Keychain — synchronization between Apple devices connected to the same Apple ID; (b) Google Password Manager — synchronization between Android devices and Chrome browsers connected to the same Google account; (c) WebAuthn-compliant password managers, including 1Password, Bitwarden, and Dashlane, among others; (d) Cross-platform authentication (mobile and computer) via QR Code and Bluetooth proximity. 14.9.3. In the event of migration between ecosystems (e.g., from Android to iPhone), the Passkey may not transfer automatically. In such cases, the User must use the recovery process described in Clause 14.8 to register a new Passkey on the new platform. 14.9.4. The User is responsible for ensuring that Passkey synchronization is correctly configured on their devices. Picnic is not responsible for access failures resulting from improper configuration of the Passkey Manager. 14.10. TECHNOLOGICAL UPDATES AND CHANGES TO THE PASSKEY SYSTEM. 14.10.1. Picnic reserves the right to update, modify, or replace the passkey system described in this Clause 14 due to technological evolutions, security requirements, or regulatory changes, provided adequate prior notice is given to the User. 14.10.2. Material changes to the authentication and signing system will be communicated to the User at least 30 (thirty) days in advance, except in cases of security emergencies requiring an immediate response. 14.10.3. Picnic commits to maintaining compatibility with the WebAuthn (FIDO2) standard as long as it remains the industry standard for passwordless authentication. Any change in technological standards will be communicated pursuant to Clause 14.10.2. 14.11. The User's use of the passkey functionality constitutes express acceptance of all terms in this Clause 14, including the responsibilities assigned to the User and Picnic’s limitations of liability. 14.12. This Clause 14 must be read in conjunction with the other clauses of these Terms of Use, especially those relating to Picnic's nature as a software interface, the self-custody of assets, and general limitations of liability. 15. GENERAL PROVISIONS 15.1. The user agrees to use PICNIC Technology Services in strict compliance with applicable laws, including anti-money laundering standards. The user declares that funds moved through the interface have a lawful origin. The User further declares that they do not appear on any international sanctions or trade restriction lists and that they will not use the Platform to conceal assets, evade currency, or finance illicit activities. 15.2. All content, design, source code, logos, graphics, and interfaces made available by PICNIC (“Content”) are the exclusive property of PICNIC or its licensors. Use of the Platform grants the user only a limited, revocable, non-exclusive, and non-transferable license for personal software use. Copying, reverse engineering, or redistributing Content without express authorization is prohibited. 15.3. These Terms do not create any partnership, joint venture, mandate, franchise, or employment relationship between the user and PICNIC. 15.4. Tax Aspects. Due to the non-custodial nature, PICNIC does not withhold taxes at source on cryptoasset transactions. The user is solely responsible for calculating, declaring, and collecting any taxes applicable to their capital gains arising from transactions facilitated by the Platform. PICNIC does not provide tax advice. 15.4.1. Scope of tax responsibility. The User's tax responsibility encompasses the assessment and collection of taxes levied not only on capital gains, but also on any income, rewards, or other results obtained through the Platform's functionalities. The User acknowledges that, as this is decentralized and self-custodial technology, any ancillary obligations of information or declaration before the tax authorities of their domicile fall upon the User themselves. PICNIC does not withhold, declare, or collect taxes on behalf of the User, nor does it provide tax advice. 15.5. Inapplicability of "Unclaimed Property". Unlike banks or custodial exchanges, PICNIC does not hold possession of assets. Therefore, the concept of "dormant account" or "unclaimed property" subject to appropriation or transfer to the State by PICNIC does not exist. If the user stops using the Platform for years, their assets will remain safe on the blockchain, accessible only by whoever holds the Private Key. 15.6. Succession, Death, and Incapacity. PICNIC warns that, due to blockchain encryption, it is not possible to transfer the deceased user's funds to heirs if they do not possess the Recovery Phrase (Seed Phrase). (A) Account Access: Upon presentation of a valid Inventory or Court Order, PICNIC may transfer ownership of the PICNIC Account (login/interface access) to the executor or heir. (B) Access to Funds: Transferring the login DOES NOT guarantee access to funds if the deceased has not left the Private Key/Password accessible to heirs. PICNIC has no technical means to "break" wallet encryption to deliver values to the estate. It is the user's sole responsibility to carry out their digital estate planning. 15.6.1. Supervening incapacity. The technical limitations described in this Clause apply equally to the hypotheses of supervening incapacity of the User. Upon presentation of a valid judicial document, such as a guardianship instrument, PICNIC may transfer ownership of the PICNIC Account to the legal representative, subject to the technical impossibility of accessing self-custodied assets without the Private Key or Recovery Phrase. 15.7. Entire Agreement and Assignment. These Terms constitute the entire agreement between the parties. PICNIC may assign or transfer its rights and obligations under this contract (in case of merger, acquisition, or asset sale) without prior user consent, provided notification is ensured. 15.8. Changes to Terms. PICNIC may alter these Terms at any time. Alterations will take effect on the date of their publication on the Platform. Continued use of services after alteration implies tacit acceptance. Should the user not agree, they must cease using the interface immediately. 15.9. Electronic Communications. The User expressly agrees to receive all communications, contracts, documents, legal notices, disclosures, and updates to these Terms and to the Privacy Policy by electronic means (including email, in-app notifications, and notices on the Platform), which shall have the same validity and effect as written communications. The User is responsible for keeping their contact information up to date.
⚖️ LegalRegulatory
Idioma / Language: Português · English Regulatory Last updated: August 25, 2026 This document describes Picnic's operating model and the regulatory framework that we understand to apply to it. It supplements the Terms of Use and the Privacy Policy, which prevail in the event of any conflict. Picnic is operated by DeFiBasket Labs Inc., BVI Business Company No. 2085144, incorporated in the British Virgin Islands. 1. Picnic's legal nature Picnic is a non-custodial software interface. Its function is to allow the user to interact directly with public blockchain networks and decentralized protocols, and to integrate, into a single interface, services provided by independent third parties authorized in their respective jurisdictions. The legal relationship between Picnic and the user is a software license (Terms of Use, cl. 1.4). Picnic is not a party, counterparty, representative, broker, custodian, manager, or agent of the user in any transaction carried out through the interface. In the layered architecture commonly described in the literature on decentralized finance (Schär, 2021), Picnic operates at the aggregation layer: it brings together access to protocols and services operated by third parties, without operating any of them. 2. How transactions take place Picnic combines two types of steps, each with a distinct legal treatment. Steps recorded on a blockchain — transfers, exchanges between virtual assets, and interactions with protocols — are carried out by the users themselves, from their self-custodial wallets. Steps involving fiat currency — Pix and Brazilian reais, US dollars, euros, and the card — are provided by regulated partners and are described in section 4. 2.1. Private keys. The private key that controls the user's wallet is not held by Picnic. In accounts that use a passkey, authentication follows the WebAuthn (FIDO2) standard and the key is generated on the user's device. Depending on the configuration chosen by the user in their operating system, the passkey may be synchronized by the credential manager of the relevant manufacturer. Picnic stores only the public key (Terms of Use, cl. 14.2). In accounts that do not use a passkey, the key is protected by a hardware security module operated by Magic, an independent service provider, and remains accessible only to the user. Under neither configuration is Picnic a signer of the user's wallet. 2.2. Signature. Every transaction depends on the user's digital signature, performed on their device. Picnic's software translates the user's intent into a technical instruction; it does not execute the instruction on the user's behalf. 2.3. Settlement. Settlement occurs on the blockchain, between the user's wallet and the smart contracts involved. Assets do not pass through any bank account or wallet owned by Picnic, and Picnic does not maintain an internal record of balances that replaces the on-chain record. The balance displayed in the interface is a reading of the network state, not a promise of payment by Picnic. In steps involving fiat currency, settlement follows the operating flows of the responsible regulated partner, which may include accounts and addresses owned by that partner or by service providers it has engaged before the asset is delivered to the user's wallet. 2.4. Transactions between virtual assets. In transactions carried out entirely on a blockchain — transfers, exchanges between virtual assets, and interactions with protocols —, the user acts in their own name and for their own account. Picnic does not receive orders, execute them, match them with orders from other users, maintain an order book, set prices, or act as counterparty. At no time does Picnic act for the account and on the instructions of a third party. These transactions are recorded on a blockchain and authorized by the user, either directly or through permissions the user has previously granted. The analogy is an internet browser: it allows the user to access their bank's website and make a payment, but it is neither the bank nor the intermediary in the transaction. The legal relationship is user ↔ blockchain. 3. Picnic's regulatory framework 3.1. We are not custodians. Qualification as a custodian depends on control of the private keys or on the technical ability to move funds on behalf of the customer. Picnic does not hold the user's private key and is not a signer of the user's wallet. Without that control, Picnic has no ability to transfer, block, or dispose of the assets, and there is no power to exclude third parties that would give rise to the custodian's heightened duty of care. 3.2. We are not intermediaries. The core of intermediation is acting for the account and on the instructions of a third party: receiving the customer's order and executing it in the market on the customer's behalf, or managing third-party resources. Picnic engages in none of these activities. The user transacts in their own name, directly on the network, using their private key. Picnic does not hold, move, or block the user's funds. 3.3. We are not a broker or exchange. Brokers combine custody and intermediation and maintain an internal order book that matches orders. None of these elements is present in Picnic's architecture. 3.4. Conclusion and caveat. Based on the architecture currently adopted, Picnic understands that the self-custodial core of the interface is software in nature and does not, in itself, constitute custody of third-party assets, operation of a centralized exchange, or discretionary management of resources. Specific features and integrations are assessed separately, according to the activity actually performed in each case. Final legal classification rests with the competent authorities and regulatory bodies. This is Picnic's interpretive position, based on the current technical architecture. It does not constitute a statement, authorization, or recognition by any regulatory authority, nor does it constitute legal or tax advice to the user, who remains responsible for assessing the treatment of their own transactions. Changes to the architecture, applicable regulation, or the interpretation of competent authorities may change this analysis. Picnic reassesses this framework with each new feature or integration. 4. Provision of services by regulated partners The fact that Picnic is not classified as a custodian, intermediary, or virtual asset service provider does not mean that transactions take place outside the regulatory framework. Every step involving fiat currency — inflows to and outflows from the traditional financial system, conversion between fiat currency and virtual assets, and card issuance and processing — is provided by a third party authorized to provide it in the relevant jurisdiction, in accordance with the authorization or registration held by that party and verified by Picnic as part of the due diligence described in section 5. Each partner provides these services in its own name and for its own account, under its own authorization and regulatory responsibility, and is directly responsible for the obligations applicable to it: customer identification and verification (KYC), transaction monitoring, recordkeeping, and reporting to the competent authorities. Picnic's role in these steps is exclusively technical: integrating the partner's service into the interface and presenting the user with the flows defined by the partner. Picnic does not provide the regulated service, subcontract it, or act as the partner's agent or representative, and the regulatory obligations for these steps rest with the partner that performs them. This does not exclude any obligations that may apply directly to Picnic due to its activity, which are assessed on an ongoing basis. 5. Picnic's own controls Although, in our understanding, the interface does not constitute an activity subject to the obligations applicable to an obliged entity for anti-money laundering purposes, Picnic maintains its own risk-based AML/CFT policy (risk-based approach), calibrated to the risks actually present at the interface layer — and not to custody or intermediation risks, which do not arise from the interface architecture. Internal controls include: - controls to prevent and detect fraud in the use of the interface; - transaction monitoring based on risk criteria, with internal escalation of alerts; - screening of wallet addresses and transactions against applicable sanctions lists; - access restrictions from sanctioned or prohibited jurisdictions; - an express contractual prohibition on unlawful use (Terms of Use, cls. 1.2(B) and 1.3); - recording and retaining the information necessary to respond to legitimate requests from competent authorities. Detection parameters, thresholds, and rules are not publicly disclosed, in order to preserve their effectiveness. Partner due diligence (KYP). Picnic performs initial due diligence and periodic reviews of its partners, verifying authorization or registration, AML/CFT policies, regulatory history, and operational capacity. We adopt and replicate in the interface the controls, parameters, and instructions defined by each partner, including subsequent changes, whenever applicable to the integrated flow. KYC. Registration in the interface does not involve KYC. Identity verification takes place with the regulated partner responsible for each rail, when the user chooses to enable it, and follows the requirements defined by that partner. Scope of the controls. These controls are Picnic's own and are voluntary in relation to its regulatory classification. They neither replace nor overlap with the controls of regulated partners, do not transfer to Picnic any regulatory responsibility assigned by law to a third party, and do not exempt the user from their own legal obligations (Terms of Use, cl. 1.3). Picnic continuously assesses its own obligations and complies with them when applicable. 6. Tax reporting Brazilian Federal Revenue Normative Instruction No. 2,291/2025 governs the reporting of information on transactions involving virtual assets. The rule distinguishes cases in which the information is provided by the cryptoasset service provider from those in which it is provided by the user who is resident or domiciled in Brazil, and subjects each case to its own criteria and thresholds. Tax and reporting obligations depend on the user's residence, the nature and value of the transactions, and the means by which they were carried out. Picnic assesses the obligations applicable to it and provides information when required by law or by a competent authority. Partners are responsible for the obligations related to the activities they provide. Users must assess their own obligations and seek professional advice when necessary. With respect to the self-custodial core of the interface, Picnic understands that it corresponds to the concept of a decentralized platform used by the rule: Picnic does not hold assets in custody, does not process transactions centrally, and is not headquartered in Brazil. In this case, we understand that responsibility for reporting information relating to those transactions rests with the user who is resident or domiciled in Brazil, subject to the criteria and thresholds in the rule itself. This is Picnic's interpretation, subject to review in light of any statement by the Brazilian Federal Revenue Service or any regulatory change, and it does not replace the user's individual assessment. This does not mean there is no reporting within the chain: each regulated partner is responsible for the reports required of it in relation to the transactions it performs itself — including, in Brazil, transactions in Brazilian reais processed by the partner authorized by the Central Bank. Registration data. Picnic stores user registration data, including CPF and email address, for two reasons: (i) to transmit it to the regulated partner that requires identification to enable a specific rail; and (ii) to allow the interface to operate without repeated registration. Collection follows the principles of purpose limitation, necessity, and adequacy, and sharing with each partner is limited to the data it requires for the relevant rail, as provided in the Privacy Policy. 7. Continuity If Picnic ceases to operate, the assets remain in the user's wallet, on the blockchain. Access does not depend on Picnic continuing to operate as a company. 8. Effective date This document reflects the operating structure in effect on the date indicated at the top and may be revised at any time. In the event of any conflict, the Terms of Use and the Privacy Policy prevail. Picnic communicates exclusively through the @usepicnic.com domain. Communications received from any other domain or channel should be treated as an attempted fraud and reported to oi@usepicnic.com. Questions about this document: legal@usepicnic.com. Regulatório Última atualização: 25 de agosto de 2026 Este documento descreve o modelo operacional do Picnic e o enquadramento regulatório que entendemos aplicável a ele. Complementa os Termos de Uso e a Política de Privacidade, que prevalecem em caso de divergência. O Picnic é operado pela DeFiBasket Labs Inc., BVI Business Company nº 2085144, constituída nas Ilhas Virgens Britânicas. 1. Natureza jurídica do Picnic O Picnic é uma interface de software não-custodial. Sua função é permitir que o usuário interaja diretamente com redes blockchain públicas e com protocolos descentralizados, e integrar, em uma única interface, serviços prestados por terceiros independentes autorizados nas respectivas jurisdições. A relação jurídica entre o Picnic e o usuário é de licenciamento de uso de software (Termos de Uso, cl. 1.4). O Picnic não é parte, contraparte, mandatário, corretor, custodiante, gestor ou agente do usuário em nenhuma operação realizada por meio da interface. Na arquitetura em camadas usualmente descrita na literatura sobre finanças descentralizadas (Schär, 2021), o Picnic atua na camada de agregação: reúne o acesso a protocolos e serviços operados por terceiros, sem operar nenhum deles. 2. Como as operações ocorrem O Picnic combina dois tipos de etapa, com tratamento jurídico distinto. As etapas registradas em blockchain — transferências, trocas entre ativos virtuais e interações com protocolos — são realizadas pelo próprio usuário, a partir de sua carteira autocustodial. As etapas que envolvem moeda fiduciária — Pix e reais, dólares, euros e o cartão — são prestadas por parceiros regulados e estão descritas na seção 4. 2.1. Chaves privadas. A chave privada que controla a carteira do usuário não é detida pelo Picnic. Nas contas com passkey, a autenticação segue o padrão WebAuthn (FIDO2) e a chave é gerada no dispositivo do usuário. Conforme a configuração escolhida pelo usuário em seu sistema operacional, a passkey pode ser sincronizada pelo gerenciador de credenciais do respectivo fabricante. O Picnic armazena apenas a chave pública (Termos de Uso, cl. 14.2). Nas contas que não utilizam passkey, a chave é protegida por módulo de segurança de hardware operado pela Magic, prestadora independente, e permanece acessível apenas ao usuário. Em nenhuma das duas configurações o Picnic é signatário da carteira do usuário. 2.2. Assinatura. Toda operação depende de assinatura digital pelo usuário, realizada em seu dispositivo. O software do Picnic traduz a intenção do usuário em uma instrução técnica; não a executa por ele. 2.3. Liquidação. A liquidação ocorre na blockchain, entre a carteira do usuário e os contratos inteligentes envolvidos. Os ativos não transitam por conta bancária ou carteira de titularidade do Picnic, e o Picnic não mantém registro interno de saldos que substitua o registro on-chain. O saldo exibido na interface é a leitura do estado da rede, não promessa de pagamento do Picnic. Nas etapas que envolvem moeda fiduciária, a liquidação observa os fluxos operacionais do parceiro regulado responsável, que podem incluir contas e endereços de titularidade dele ou de prestadores por ele contratados antes da entrega do ativo à carteira do usuário. 2.4. Operações entre ativos virtuais. Nas operações realizadas inteiramente em blockchain — transferências, trocas entre ativos virtuais e interações com protocolos —, o usuário atua em nome próprio e por conta própria. O Picnic não recebe ordens, não as executa, não as casa com ordens de outros usuários, não mantém livro de ofertas (order book), não forma preço e não é contraparte. Em nenhum momento atua por conta e ordem de terceiro. Essas operações são registradas em blockchain e autorizadas pelo usuário, diretamente ou por meio de permissões que ele tenha previamente concedido. A analogia é a do navegador de internet: ele permite que o usuário acesse o site do seu banco e realize um pagamento, mas não é o banco nem o intermediário da operação. A relação jurídica é usuário ↔ blockchain. 3. Enquadramento do Picnic 3.1. Não somos custodiantes. A qualificação como custodiante depende do controle das chaves privadas ou da capacidade técnica de movimentar fundos em nome do cliente. O Picnic não detém a chave privada do usuário e não é signatário de sua carteira. Sem esse controle, não há capacidade de transferir, bloquear ou dispor dos ativos, e não se verifica o poder de exclusão de terceiros que atrai o dever de diligência qualificado do custodiante. 3.2. Não somos intermediários. O núcleo da atividade de intermediação é a atuação por conta e ordem de terceiro: receber a ordem do cliente e executá-la no mercado em seu lugar, ou administrar recursos de terceiros. O Picnic não pratica nenhuma dessas condutas. O usuário transaciona em nome próprio, diretamente na rede, munido de sua chave privada. O Picnic não detém, não movimenta e não bloqueia os fundos do usuário. 3.3. Não somos corretora ou exchange. As corretoras combinam custódia e intermediação, e mantêm livro de ofertas interno com casamento de ordens. Nenhum desses elementos está presente na arquitetura do Picnic. 3.4. Conclusão e ressalva. Com base na arquitetura atualmente adotada, o Picnic entende que o núcleo autocustodial da interface tem natureza de software e não corresponde, por si só, à custódia de ativos de terceiros, à manutenção de uma exchange centralizada ou à gestão discricionária de recursos. Funcionalidades específicas e integrações são avaliadas separadamente, conforme a atividade efetivamente desempenhada em cada caso. A qualificação jurídica definitiva compete às autoridades e aos órgãos reguladores competentes. Esta é a posição interpretativa do Picnic, fundada na arquitetura técnica vigente. Não constitui manifestação, autorização ou reconhecimento por qualquer autoridade regulatória, nem aconselhamento jurídico ou tributário ao usuário, que permanece responsável por avaliar o enquadramento de suas próprias operações. Alterações na arquitetura, na regulação aplicável ou na interpretação das autoridades competentes podem alterar essa análise. O Picnic reavalia esse enquadramento a cada nova funcionalidade ou integração. 4. Prestação de serviços por parceiros regulados A ausência de enquadramento do Picnic como custodiante, intermediário ou prestador de serviços de ativos virtuais não significa que a operação ocorra à margem da regulação. Toda etapa que envolve moeda fiduciária — entrada e saída de recursos do sistema financeiro tradicional, conversão entre moeda fiduciária e ativos virtuais, emissão e processamento de cartão — é prestada por um terceiro habilitado a prestá-la na jurisdição correspondente, conforme a autorização ou o registro por ele detido e verificado pelo Picnic no âmbito da diligência descrita na seção 5. Cada parceiro presta esses serviços em nome próprio e por sua própria conta, sob sua própria autorização e responsabilidade regulatória, e responde diretamente pelas obrigações que lhe são aplicáveis: identificação e verificação de clientes (KYC), monitoramento de operações, guarda de registros e reportes às autoridades competentes. O papel do Picnic nessas etapas é exclusivamente técnico: integrar o serviço do parceiro à interface e apresentar ao usuário os fluxos definidos por ele. O Picnic não presta o serviço regulado, não o subcontrata, não atua como agente ou representante do parceiro e as obrigações regulatórias dessas etapas recaem sobre o parceiro que as executa. Isso não afasta obrigações próprias que venham a ser aplicáveis ao Picnic em razão de sua atividade, as quais são avaliadas de forma permanente. 5. Controles próprios do Picnic Ainda que a interface não configure, em nosso entendimento, atividade sujeita a obrigações de pessoa obrigada em matéria de prevenção à lavagem de dinheiro, o Picnic mantém política própria de PLD/FT com abordagem baseada em risco (risk-based approach), calibrada aos riscos efetivamente presentes na camada de interface — e não aos riscos de custódia ou de intermediação, que não decorrem da arquitetura da interface. Os controles internos incluem: - controles de prevenção e detecção de fraude no uso da interface; - monitoramento de transações segundo critérios de risco, com escalonamento interno de alertas; - verificação de endereços de carteira e transações contra listas de sanções aplicáveis; - restrição de acesso a partir de jurisdições sancionadas ou vedadas; - vedação contratual expressa de uso ilícito (Termos de Uso, cls. 1.2(B) e 1.3); - registro e retenção das informações necessárias ao atendimento de demandas legítimas de autoridades competentes. Os parâmetros, limiares e regras de detecção não são divulgados publicamente, para preservar sua eficácia. Diligência sobre parceiros (KYP). O Picnic realiza diligência prévia e revisões periódicas sobre seus parceiros, verificando autorização ou registro, políticas de PLD/FT, histórico regulatório e capacidade operacional. Adotamos e replicamos na interface os controles, parâmetros e instruções definidos por cada parceiro, inclusive suas alterações supervenientes, sempre que aplicáveis ao fluxo integrado. KYC. O cadastro na interface não envolve KYC. A verificação de identidade ocorre no parceiro regulado responsável por cada trilho, no momento em que o usuário opta por liberá-lo, e segue os requisitos definidos por esse parceiro. Alcance dos controles. Esses controles são próprios do Picnic e voluntários em relação ao seu enquadramento. Não substituem nem se sobrepõem aos controles dos parceiros regulados, não transferem ao Picnic responsabilidade regulatória atribuída por lei a terceiro e não isentam o usuário de suas próprias obrigações legais (Termos de Uso, cl. 1.3). O Picnic avalia de forma permanente as obrigações que lhe sejam próprias e as cumpre quando aplicáveis. 6. Reportes fiscais A Instrução Normativa RFB nº 2.291/2025 disciplina a prestação de informações sobre operações com ativos virtuais. A norma distingue as hipóteses em que a informação é prestada pelo prestador de serviços de criptoativos daquelas em que é prestada pelo próprio usuário residente ou domiciliado no Brasil, e sujeita cada uma delas a critérios e limites próprios. As obrigações fiscais e de prestação de informações dependem da residência do usuário, da natureza e do valor das operações e do meio pelo qual foram realizadas. O Picnic avalia as obrigações que lhe sejam aplicáveis e presta informações quando exigido pela legislação ou por autoridade competente. Os parceiros respondem pelas obrigações relacionadas às atividades que prestam. O usuário deve avaliar suas próprias obrigações e buscar orientação profissional quando necessário. Quanto ao núcleo autocustodial da interface, o entendimento do Picnic é o de que ele corresponde ao conceito de plataforma descentralizada empregado pela norma: o Picnic não detém custódia, não processa transações de forma centralizada e não está sediado no Brasil. Nessa hipótese, entendemos que a prestação de informações relativa a essas operações cabe ao usuário residente ou domiciliado no Brasil, observados os critérios e limites da própria norma. Trata-se de entendimento interpretativo do Picnic, sujeito a revisão diante de manifestação da Receita Federal do Brasil ou de alteração normativa, e que não substitui a avaliação individual do usuário. Isso não significa ausência de reporte na cadeia: cada parceiro regulado responde pelos reportes que lhe são exigidos em relação às operações que ele próprio executa — inclusive, no Brasil, as operações em reais processadas pelo parceiro autorizado perante o Banco Central. Sobre os dados cadastrais. O Picnic armazena dados cadastrais do usuário, incluindo CPF e e-mail, por duas razões: (i) transmiti-los ao parceiro regulado que exige identificação para liberar um trilho específico; e (ii) viabilizar o funcionamento da interface sem repetição de cadastro. A coleta observa os princípios de finalidade, necessidade e adequação, e o compartilhamento com cada parceiro limita-se aos dados exigidos por ele para o trilho correspondente, conforme a Política de Privacidade. 7. Continuidade Se o Picnic deixar de operar, os ativos permanecem na carteira do usuário, na blockchain. O acesso não depende da continuidade do Picnic como empresa. 8. Vigência Este documento reflete a estrutura operacional vigente na data indicada no topo e pode ser revisado a qualquer tempo. Em caso de divergência, prevalecem os Termos de Uso e a Política de Privacidade. O Picnic comunica-se exclusivamente pelo domínio @usepicnic.com. Comunicações recebidas de qualquer outro domínio ou canal devem ser tratadas como tentativa de fraude e reportadas a oi@usepicnic.com. Dúvidas sobre este documento: legal@usepicnic.com.
⛓️ Crypto WalletI copied the correct wallet address, but it changed when pasted. What should I do?
If you copy the wallet address to send crypto and, when pasting, the address appears different, your device is likely infected by a clipper malware. This type of malicious program swaps the copied address with the attacker's address. Blockchain transactions are irreversible: once confirmed, Picnic cannot reverse, redirect, or recover the funds. What is clipper malware (and why the address changes) The clipper monitors your device's clipboard (the “copy/paste”). When it detects a crypto address, it silently replaces it with the criminal's address. This can happen in repackaged/fake apps (including messaging apps like Telegram and WhatsApp), extensions, and programs for mobile and computer. In some cases, the package comes with RATs (Remote Access Trojans), which give the attacker full control of the device. Warning signs - You copy an address and, when pasting, some characters change. - The sent transaction does not reach the intended recipient. - Recent installation of unofficial apps, “unknown” extensions, or “modified” versions. - Slower device, strange pop-ups, or unusual permission requests. What to do before sending crypto (quick checklist) 1. Copied? Check. Compare the address characters when pasting. 2. Validate at the destination. If possible, use a QR code or test with a small transfer. 3. Use official channels. Download apps only from official stores (Google Play / App Store) and keep your system updated. 4. Be wary of links. Do not click on links from emails, social media, or messages that promise “bonuses” or request file installations. Already sent? - Once confirmed on the blockchain, the transaction is final. - Picnic cannot cancel, reverse, change the recipient, or recover funds sent to an incorrect or malicious address. Immediate steps 1. Stop transacting until you review the device. 2. Disconnect from the internet (when possible) and securely back up what is necessary. 3. Remove unknown apps/extensions. 4. Run an updated antivirus/antimalware and perform a full scan. 5. Update the operating system and browsers. 6. Change passwords for your emails and critical services (enabling 2FA where available). 7. Clean reinstallation (if the antivirus indicates the threat persists). 8. Only then resume transacting (always starting with a small test and checking addresses when pasting). Continuous best practices - Always verify addresses (beginning and end) when pasting. - Use 2FA on relevant accounts and keep antivirus active and updated. - Log out of financial platforms when finished. - Keep your personal data private and physically protect your devices. Frequently Asked Questions Can Picnic support identify the hacker? We do not have visibility beyond what is public on the blockchain. Support can guide security measures, but cannot recover funds. Can I use a QR code to avoid errors? It helps reduce the risk of manipulation during copy/paste. Still, check the address displayed before confirming.
🚫 Card: Issues & DeclinesApp Keeps Showing Errors
⚠️ Can't log in? If the app keeps spinning, Face ID / fingerprint doesn't appear, or you switched phones, this article does not apply. Do not uninstall the app — it destroys the session and complicates passkey recovery. Search for "passkey" or "account recovery" for the right path. Update the app: - Make sure you are using the latest version of the Picnic app. - Go to your device's app store (Google Play Store for Android or Apple App Store for iOS). - Search for "Picnic" and see if there is any update available. Install it immediately. For investments and advanced features Remember that the Picnic Card mobile app is primarily focused on managing your card. - To access crypto investments, Easy Income products, and other advanced features of your smart wallet, use the web version of Picnic: - Visit usepicnic.com on a computer or mobile browser.