StealthLedger
Terms Security Verify build Home →
Privacy

Privacy Policy

StealthLedger is built so we know as little about you as possible. This page lists, plainly, everything we collect, everything we don't, and exactly what we can and cannot see inside your vault.

Operator: AI Solutions Website: stealthledger.net Effective: 2 September 2026
In one sentence: we store your username and an encrypted blob we cannot read. We do not collect your email, we do not run analytics or trackers, and we do not log your activity. This is a deliberate design choice, not a legal minimum.

1. What we collect

DataWhy
Username To identify your account. No real name, email, or phone number is required to create one.
Encrypted vault blob Your portfolio data (labels, notes, wallet addresses you've added), encrypted on your device with AES-256-GCM before it is sent to us. We store the ciphertext only.
Session cookie Keeps you signed in. Cleared when you sign out or the session expires.
CSRF token A security token that prevents forged requests from other sites. Not used to track you.
Device signing key (optional) If you pair a device for passwordless unlock, a public key for that device is registered so it can prove it's yours. The corresponding private key never leaves your device's secure hardware.

2. What we do not collect

  • No email address. An account can be created and used without one.
  • No analytics or tracking pixels. We do not run Google Analytics, Meta Pixel, or any third-party behavioural tracker.
  • No advertising identifiers. We do not build advertising profiles and we do not sell data, because there is no data of yours to sell.
  • No plaintext vault contents. We cannot see your portfolio labels, notes, or balances you've entered, because they are encrypted before they reach us and we do not hold the key.
  • No passphrase. Your vault passphrase, recovery code, and recovery phrase are never transmitted to us in a form we could read; they are used locally to derive keys.

3. What we cannot see, technically

Your vault content is encrypted client-side using a content key derived through scrypt (N = 65536, r = 8, p = 1) and AES-256-GCM authenticated encryption, before it is ever sent over the network. The server receives and stores only the resulting ciphertext envelope. We have no master key, no key-escrow system, and no way to decrypt a vault without the passphrase, recovery code, or recovery phrase that only you hold. The cryptographic design is published; see the Security page to verify this yourself.

4. Public blockchain data and third-party lookups

When you add a wallet address to track its balance, that address is a public blockchain address, not a secret. To display balances and prices, the Service queries public blockchain data and market price sources. Depending on the feature, these lookups may be made from your own device directly to a third-party data provider, in which case that provider (and any network intermediary) may see the wallet address being queried and the IP address making the request, subject to that provider's own privacy practices. We choose privacy-respecting providers where practical, but we do not control their data handling. We recommend not adding addresses you are not comfortable having associated with a lookup request.

5. Server logs and IP addresses

Like virtually all web services, our hosting infrastructure necessarily processes your IP address at the network level to deliver a response (this is how the internet works, not something we can opt out of). We do not maintain a separate analytics log tying IP addresses to accounts, and we do not use IP addresses to build a profile of you. Ephemeral infrastructure logs kept by our hosting provider for security and abuse prevention are retained only as long as reasonably necessary for that purpose.

6. Cookies

We use two cookies, both strictly necessary for the Service to function: a session cookie and a CSRF token. Neither is used for advertising or cross-site tracking, and we do not use any third-party cookies. Because these cookies are essential to sign-in and security, there is no cookie consent banner; disabling them will prevent the Service from working.

7. How your data is stored and protected

Your encrypted vault is stored on our infrastructure until you delete your account. Because the content is encrypted client-side, a breach of our servers would expose ciphertext, not your portfolio data, absent a separate compromise of your passphrase or recovery materials. We apply standard technical safeguards (encryption in transit via HTTPS, access controls on infrastructure) on top of the client-side encryption described above.

8. Data retention

We retain your account and encrypted vault for as long as your account is active. You can export or delete your data, or close your account entirely, at any time from within the Service. On deletion, your encrypted vault is removed from active storage; residual copies in backups are purged on our standard backup rotation schedule.

9. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to certain processing. Because we hold so little identifying information about you, and cannot read your vault contents, most of these rights are already exercised by you directly within the Service (for example, exporting or deleting your vault). For anything else, contact us using the details in Section 12.

If you are in Australia, we handle personal information consistently with the Australian Privacy Principles under the Privacy Act 1988 (Cth). If you are in the European Economic Area or United Kingdom, you have rights under the GDPR/UK GDPR. If you are a California resident, you have rights under the CCPA. In each case, the practical effect is the same: we collect very little, and what little we do collect, we will help you access or remove on request.

10. Children's privacy

The Service is not directed to children and is not intended for use by anyone under 18. We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will take reasonable steps to close it.

11. International data transfers

Our infrastructure may be located outside your country of residence. As the data we hold about you is minimal, and your vault content is encrypted before it leaves your device, the practical privacy impact of any such transfer is limited. Where required, we rely on appropriate legal safeguards for cross-border transfers.

12. Contact and complaints

For privacy questions, data access or deletion requests, or complaints, contact us through the Service or at the address published on the Security page. If you are in Australia and remain unsatisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by a new effective date at the top of this page and, where practical, notified to active users within the Service.

Terms of Service Security Verify build Home

StealthLedger · AI Solutions · Encrypted on device. The operator cannot read your vault.