Privacy Policy

Product information updated 27 September 2026.

Scope

This notice describes RapidWallet Web v1 at rapidwallet.org and its local custody and public-data flows. RapidWallet is independently operated and does not use CoinSpace account-unlock services.

Wallet material on your device

The application keeps an encrypted vault in browser storage, together with public asset choices and preferences. Recovery material and signing are processed locally. The application is designed not to send recovery phrases, seed material, private keys, passwords or unlock material to our server or blockchain providers. Browser encryption is not hardware-backed seed storage and does not protect against every compromised browser or device.

Public network requests

When you enable public network reads, existing indexer requests go through the bounded RapidWallet public-data service to configured CoinSpace providers. That relay processes public addresses and asset identifiers transiently, and those providers see the relay connection IP. Enabled Send preparation and selected token balances also use direct browser requests to fixed Blockstream or chain-specific public RPC providers. Direct providers can see your connection IP, public addresses, contracts and transaction lookup data. Bitcoin discovery can link multiple receive and change addresses. Only public blockchain data is included; seed, password and private keys are not needed for these requests. Application access logging and proxy request logging are disabled. Cloudflare can still process connection and security metadata. Price and logo requests may reveal asset interests. Public addresses can be linked to transaction activity, so this information is not assumed anonymous. Locking the current session disables further optional reads until enabled again. Existing provider records are not erased by disabling reads.

Website delivery

The domain uses Cloudflare for proxied delivery. Cloudflare and the hosting system can process connection information, requested paths and security events when serving the site. HTTPS protects transport but does not hide connection data from the service terminating that connection. Provider locations, log retention and operational access are not represented as limited to one location or fixed period; this notice makes no promise that all data remains in a particular country.

Storage, cookies and analytics

The current application uses local browser storage for its encrypted vault, preferences and public transaction journal (including signed transaction bytes). Signed bytes contain no spending key, but anyone possessing them can relay that specific signed transaction. It has no application advertising, third-party analytics bootstrap or automatic remote wallet backup. Edge services may use security mechanisms under their own policies. A claim that the deployed site uses no cookies at all has not been verified. Application source maps and raw exception telemetry are not intentionally published or uploaded by this build.

Transactions

For enabled assets, explicit Send shares signed transaction bytes directly with the fixed network provider; blockchain networks may make the resulting addresses, values and transaction history permanently public. Public blockchain records cannot generally be erased by deleting browser data or contacting the site operator.

Your choices

You can leave network reads disabled, lock the wallet, or clear local site data using browser controls. Back up recovery material offline before removing local data. Clearing it cannot remove public blockchain records or independent provider logs. Do not include wallet secrets in support reports. This application does not create a server-side wallet account.

Sharing, retention and changes

Public providers and infrastructure services process the information necessary for their roles. No blanket promise about their retention, international transfers or contractual protections is made until reviewed. Requests required by applicable law can concern data actually held; the local-only design provides no server wallet-unlock capability. This policy must be updated when deployed data flows or providers change, with a dated version and verified operator contact.