MarvelousPrivacy

Privacy

What this site stores, and what it sends.

Short version: there is no account, no analytics and no server-side record of you. Everything the product remembers lives in your browser. The server relays read-only blockchain queries and contract-verification lookups on your behalf.

Stored in your browser

DataWhereForm
Vault header (KDF parameters, salt, wrapped key)IndexedDBParameters in clear; the key itself is encrypted
Files and their names, types, sizes, timestampsIndexedDBAES-256-GCM ciphertext only
Activity logIndexedDBEvent kind, counts, timestamps, inspected hashes and shortened wallet addresses in clear; file names sealed under the vault key
Preferences (auto-lock, motion, network, RPC overrides)localStorageClear (nothing secret)
Wallet connection shimlocalStorage (wagmi)Connector id and last connected state

Your passphrase and the raw vault key are never stored. Clearing site data, or “Clear all local data” in Settings, removes all of the above.

Network requests this site makes

No vault data, file name, passphrase or decrypted content is ever part of any request. The relay refuses every method that could sign or broadcast.

Public blockchains

Transactions on Robinhood Chain, Ethereum and Arbitrum are public and permanent. Inspecting one here does not make it any more or less visible; sending one from your wallet publishes it forever. Clearing the local activity log changes nothing on any chain.

Hosting

The site is a Next.js application. A hosting provider that serves it may keep standard access logs (IP address, user agent, requested path, time) as any web host does. The application itself adds no identifiers and sets no cookies.

Changes

This page describes the current build. When behaviour changes, this page and the documentation change with it in the same release.

Privacy · MarvelousPrivacy