Privacy policy

What leaves your device, and what never does.

QNovaa Wallet is self-custody software. We have no user accounts, no sign-up, and no analytics. Two things do leave your device, and both are named below.

Applies to the QNovaa Wallet browser extension · Last updated 7 August 2026

The short version

We never see your keys. We can see your address.

Your recovery phrase, private keys, and passphrase are generated and used inside an isolated worker in your own browser. They are encrypted before they are stored, and they are never transmitted to QNovaa or to anyone else. We could not recover them for you if we wanted to, and we cannot be compelled to hand over what we do not have.

What we can see is a wallet address, if you leave the incoming-transfers feature on. That is a first-party server receiving an address alongside your IP address, and we treat it as personal data rather than pretending it is not.

Never collected

What never leaves your device.

Recovery phrase (seed words)Never transmitted · encrypted at rest
Private keys and derived key materialNever transmitted · worker-only
Your unlock passphraseNever transmitted · never stored in plaintext
Passkey / biometric dataStays in your operating system's secure store
Name, email, phone, or any identity dataNever requested

There is no account to create and nothing to log in to. The extension requests a single browser permission — storage — which it uses only to keep your encrypted wallet on your own machine.

What is transmitted

Four network paths, and who sees what.

1. Public blockchain nodes. To show balances and broadcast transactions, the wallet queries public RPC endpoints for BNB Smart Chain, Ethereum and Polygon. Those operators can see your wallet address and IP address. This is unavoidable for any wallet that does not run its own node, and it is not specific to QNovaa.

2. The QNovaa history proxy — on by default. To show transfers you have received, the wallet asks a QNovaa-operated proxy for your transaction history. The proxy attaches a shared blockchain-explorer API key on the server side so you do not have to register for one.

The proxy receives your wallet address, the chain you are querying, and your IP address. It keeps no logs of either, sets no cookies, and cannot identify you beyond that request. It is a closed relay: it accepts only transaction-list queries for chains we support, so it cannot be repurposed as a general-purpose API key by anyone who finds it.

To be exact about what is briefly held rather than logged: a response is cached for 45 seconds so repeated views do not re-query the explorer, and a per-IP request counter used for rate limiting expires after 60 seconds. Nothing else is retained, and neither is written to a log.

3. Price data — off by default. If you turn on USD value display in Settings, the wallet asks CoinGecko for exchange rates. CoinGecko sees your IP address and nothing else: no wallet address, no balances, and no cookies are sent.

It cannot infer what you hold, and that is deliberate rather than incidental. The wallet asks for the price of every coin and token it supports, in one request, never the ones you actually own — so the request is byte-for-byte identical for every QNovaa user, and reveals nothing about any of them. Asking only for what you hold would be a smaller request and a worse one.

Because test networks have no real prices, the default install never contacts CoinGecko at all: test coins are worthless by construction, so no price is requested for them. This path opens only when you switch USD display on and move to a live network.

4. Crash reports — only if enabled. When crash reporting is configured for a build, uncaught errors are sent to Sentry. Wallet addresses, transaction hashes, and any long hexadecimal string are stripped before sending. There is no session replay, no performance tracing, and the component that handles your keys has no reporting path at all.

🔒 Stated plainly because it matters: there is currently no in-app switch to turn crash reporting off. It is disabled unless a build is configured with a reporting endpoint. We would rather say that than imply a control that does not exist.

Your controls

Two ways to stop talking to us entirely.

Turn incoming transfers off. In Settings, disable incoming transfers and the wallet sends zero requests to the QNovaa proxy. You keep a full record of transactions you send; you simply stop seeing ones you receive. This is verified by an automated test on every release.

Or bring your own key. Paste your own free explorer API key in Settings and your requests go directly to that explorer, bypassing QNovaa completely. Nothing of yours touches our servers. Your key is stored locally and is erased when you wipe the wallet.

Uninstalling the extension removes everything it stored. Because the wallet is self-custody, that includes your only copy of the encrypted wallet — keep your recovery phrase.

What we do not do

No selling, no profiling, no ads.

We do not sell or transfer your data to third parties. We do not use it for anything unrelated to running the wallet. We do not use it to determine creditworthiness or for lending. We do not build advertising profiles, and there are no third-party trackers or analytics scripts on any screen that can hold an unlocked wallet.

The extension ships no remote code: everything it executes is contained in the package reviewed and published on the Chrome Web Store.

It requests exactly one browser permission — storage — so your encrypted vault survives a browser restart. It asks for no host permissions, injects no content scripts, reads no web page, and exposes nothing to the sites you visit.

Post-quantum features

What the PQ Lab screen does with your data.

The wallet includes a PQ Lab screen that demonstrates post-quantum signing. It generates an ML-DSA-44 signature from a key derived from your own recovery phrase, signs a message the wallet composes itself, and verifies the result — all locally, on your device.

Nothing from PQ Lab is transmitted anywhere. It has no address, holds no funds, and is a demonstration of the wallet’s cryptography, not protection of your balances. Your funds are secured by conventional ECDSA signatures.

Contact

Questions, or a privacy request.

Email privacy@qnovaa.com. Because we hold no account data, most access or deletion requests are satisfied by uninstalling the extension — but if you believe we hold something of yours, ask and we will tell you plainly.

If this policy changes materially, the date at the top changes and the update is noted in the extension’s release notes.

QNovaa is operated from India, and this policy is governed by Indian law. The wallet is not directed at children under 18, and we do not knowingly collect data from them — there is no sign-up, so we hold no age information either way.