Privacy
What this site stores, and what it sends.
Short version: there is no account, no analytics and no server-side record of you. Everything the product remembers lives in your browser. The server relays read-only blockchain queries and contract-verification lookups on your behalf.
Stored in your browser
| Data | Where | Form |
|---|---|---|
| Vault header (KDF parameters, salt, wrapped key) | IndexedDB | Parameters in clear; the key itself is encrypted |
| Files and their names, types, sizes, timestamps | IndexedDB | AES-256-GCM ciphertext only |
| Activity log | IndexedDB | Event kind, counts, timestamps, inspected hashes and shortened wallet addresses in clear; file names sealed under the vault key |
| Preferences (auto-lock, motion, network, RPC overrides) | localStorage | Clear (nothing secret) |
| Wallet connection shim | localStorage (wagmi) | Connector id and last connected state |
Your passphrase and the raw vault key are never stored. Clearing site data, or “Clear all local data” in Settings, removes all of the above.
Network requests this site makes
- Pages, scripts, fonts — from this origin only. Fonts are self-hosted. There are no third-party scripts, pixels, session replay or error reporters.
- /api/rpc (this origin) — read-only JSON-RPC relay used by Transaction Review and the wallet connection. The server forwards your query (addresses, hashes, calldata) to a public RPC provider for the selected network. The provider sees the server's IP, not yours. The server keeps no log of query contents beyond ordinary hosting logs.
- /api/abi (this origin) — forwards a contract address to Sourcify to fetch a verified ABI.
- /api/selector (this origin) — forwards a 4-byte function selector to the OpenChain signature database.
- /api/status (this origin) — asks each configured network for its latest block to report reachability.
- /api/broadcast (this origin) — the one write path: forwards a transaction you already signed in the browser (stealth-address withdrawals) to the network unchanged. It checks the bytes are a signed transaction for the chosen chain and relays
eth_sendRawTransaction; it never holds a key. - Stealth keys — derived in the browser from one wallet signature and kept in memory; optionally saved as an encrypted file in your vault. Scanning announcements reads public logs through the relay and caches them locally; matching happens in memory.
- Your own RPC — only if you set one in Settings. Your browser then talks to that provider directly, and it sees your IP and every query.
- Your wallet — an injected wallet extension may make its own network requests; those are governed by the wallet, not by this site.
No vault data, file name, passphrase or decrypted content is ever part of any request. The relay refuses every method that could sign or broadcast.
Public blockchains
Transactions on Robinhood Chain, Ethereum and Arbitrum are public and permanent. Inspecting one here does not make it any more or less visible; sending one from your wallet publishes it forever. Clearing the local activity log changes nothing on any chain.
Hosting
The site is a Next.js application. A hosting provider that serves it may keep standard access logs (IP address, user agent, requested path, time) as any web host does. The application itself adds no identifiers and sets no cookies.
Changes
This page describes the current build. When behaviour changes, this page and the documentation change with it in the same release.