Privacy
The Qwertycoin Web Wallet is non-custodial. Your seed and private keys are processed in your browser, while network requests pass through Qwertycoin RPC infrastructure or a node you configure.
What we do not collect
- Your seed phrase — never transmitted, never logged, never leaves your browser tab. All key derivation runs locally inside your tab using JavaScript that you can read in DevTools.
- Your private spend key — stays in your browser tab. Used locally to sign transactions. Never transmitted to any server.
- Your private view key — used by the browser scanner and never transmitted to the RPC gateway.
- Analytics IDs — the wallet contains no analytics or advertising tracker.
- Email addresses — there is no signup, no newsletter, no waitlist.
- IP addresses — Cloudflare (our CDN) sees the IP that requests each page, like every web host on the planet does, but we have no logging on top of that and never inspect Cloudflare's analytics for individual visitors.
What the wallet does send over the network
1. Blockchain scanning requests
The dashboard scans the Qwertycoin chain in your browser and sends restricted RPC requests through same-origin endpoints such as /qwc-rpc and /gethashes.bin:
get_infoandget_block_count— current network height and connection state.get_fee_estimate— the recommended transaction fee.
These requests can reveal network-access patterns to the endpoint operator, but do not include your seed or private keys.
2. Transaction broadcast
When you send QWC, the wallet constructs and signs the transaction inside your browser. Only the completed signed transaction is submitted to the restricted RPC gateway for broadcast.
- Restricted blockchain queries sent by your browser
- Your signed transaction when you choose to broadcast QWC
- Standard request metadata such as IP address and user agent at the CDN edge
- Your private spend key or private view key
- Your seed phrase — never sent.
- Your session password — used client-side only.
You can point the wallet at your own restricted qwertycoind RPC endpoint or follow the self-hosting guide to control this network path yourself.
What Cloudflare can see
wallet.qwertycoin.org is hosted on Cloudflare Pages and sits behind Cloudflare's CDN. As with any CDN, Cloudflare's edge servers see:
- The HTTP requests for the static files (HTML, JS, fonts, images)
- The HTTP requests for the restricted Qwertycoin RPC endpoints
- Visitor IP addresses and standard request metadata
None of the information that flows through Cloudflare contains your seed, your keys, or your wallet contents. It is exactly the same set of information any visit to any website on the public internet exposes.
If your threat model requires hiding that you visited wallet.qwertycoin.org, use a suitable privacy network or self-host the wallet and RPC endpoint.
Sessions and storage
When you derive a wallet, the resulting keys are stored in your browser's sessionStorage — which means they live only in the current tab and are wiped automatically when you close it. You can also set an optional session password; if you do, your keys are AES-GCM encrypted in sessionStorage using a key derived from that password (PBKDF2-SHA256, 250 000 iterations) and decrypted only on demand.
The wallet has an idle auto-lock that fires after 10 minutes of inactivity. With a session password set, locking only wipes the in-memory keys — you can re-unlock by re-entering the password without re-deriving from your seed. Without a password, locking wipes everything and bounces you back to the seed entry screen.
Third parties
The application assets and fonts are self-hosted. Cloudflare Turnstile may load from challenges.cloudflare.com as an abuse-control step for transaction submission. Specifically:
- No Google Analytics, Plausible, Fathom, or any other analytics service
- No Google Fonts — fonts are self-hosted at
/fonts/ - No external QR generator — the QR code in the receive modal is rendered by a vendored pure-JavaScript library
- No CDN-hosted libraries — every script comes from our own origin
- Cloudflare Turnstile — used only where configured to protect transaction submission from abuse
For the curious
Everything described here can be verified in the public source repository or in your browser's DevTools network panel. The disclosure policy is in SECURITY.md.
Changes to this page
If anything on this page changes, the change will be visible in the git history of privacy.html in the public repository. There is no other notification mechanism because there is no mailing list and no user accounts.