This policy describes the current Kaspire Android app, browser extension, and website. It should be read together with the privacy terms of any dApp, relay, blockchain node, or indexer a user chooses to interact with.

01

Who this policy applies to

This Privacy Policy applies to the Kaspire Android application, the Kaspire browser extension, and the Kaspire website at kaspire.kaslab.space. Kaspire is a non-custodial wallet: the project does not hold users' funds, recovery phrases, private keys, or wallet passwords.

02

Data stored on your device

Kaspire stores wallet configuration, public addresses, preferences, address-book entries, transaction activity, pending protocol operations, and encrypted wallet material locally on the user's device. The Android app protects private wallet material using Android Keystore. The browser extension encrypts its local vault with Argon2id-derived key material and AES-256-GCM. While the extension is unlocked, decrypted wallet material is held only in the extension's local session context so that user-approved operations can be signed. Portable wallet backups are encrypted before export.

Recovery phrases, BIP39 passphrases, imported private keys, wallet passwords, application PINs, and backup passwords are not sent to Kaspire servers.

03

Blockchain and indexer requests

To display balances, UTXOs, assets, names, fees, and transaction history—and to broadcast user-approved transactions—Kaspire sends public blockchain identifiers and request data to Kaspa network services. Depending on the requested feature and service availability, these may include the Kaspire-operated Kaspa infrastructure, public Kaspa API fallbacks, Kaspa token and NFT indexers, KNS services, the kcc20.info indexer, and Kascov fallback services.

Requests can contain public wallet addresses, transaction IDs, token or covenant identifiers, domain names, and signed transactions selected for broadcast. These services necessarily receive network metadata such as an IP address. Public blockchain transactions are permanently visible on the Kaspa network and cannot be deleted by Kaspire.

04

Browser extension and connected websites

The browser extension makes the Kaspire provider available to web applications on HTTP and HTTPS pages. It does not read page text, images, unrelated form fields, cookies, or compile general browsing history. When a website deliberately calls the provider, Kaspire processes that site's origin and its wallet request. A connected dApp origin is stored locally until the user disconnects it.

A dApp receives a public wallet address or signature only after the applicable connection or approval flow. Transaction, PSKT, asset transfer, and personal-signature request payloads are processed only to display a review and perform the operation the user approves. Private keys, recovery phrases, vault passwords, and decrypted vault contents are never exposed to websites.

05

Data categories and recipients

For Chrome Web Store disclosure purposes, Kaspire handles financial information (public wallet addresses, balances, assets, transaction history, and signed transactions), authentication information (vault and backup passwords, recovery phrases, BIP39 passphrases, and private keys), and website information limited to connected dApp origins and wallet request payloads. Authentication information is processed locally and is not sent to Kaspire or third-party servers.

Public identifiers and approved transaction data may be transmitted to kaspire.kaslab.space, api.kaspa.org,kaspatoken.kaslab.space, api.kasplex.org,kcc20.info, kascov.io,krc721-indexer.kaspa.com,api.knsdomains.org, api.kaspa.com,gothdag.kaslab.space, andopen.er-api.com, depending on the feature used. These services also receive ordinary connection metadata such as the user's IP address. No data is transferred for advertising or resale.

06

Browser extension permissions

storage keeps the encrypted vault, public wallet state, settings, contacts, connected dApp origins, and activity data on the device. alarms performs the configured inactivity lock even when the extension popup is closed. Access on HTTP and HTTPS pages is used only to inject the Kaspire provider and relay explicit wallet API requests from a website to the extension.

Host access is limited to the Kaspa node, indexer, exchange-rate, metadata, and transaction-broadcast services needed to display wallet state and complete user-approved operations. The extension does not request the Chrome idle permission.

07

WalletConnect and dApp connections

When a user deliberately connects Kaspire to a dApp, WalletConnect and Reown relay infrastructure transports encrypted pairing and session messages. The dApp receives the public account selected by the user and the result of requests the user approves. Kaspire does not expose private keys or recovery phrases to dApps or relay services.

The connected dApp and relay provider process data under their own privacy terms. Users should connect only to dApps they recognize and disconnect sessions they no longer use.

08

Remote code

The Kaspire browser extension does not use remote code. Its JavaScript, WebAssembly security core, and executable logic are included in the extension package reviewed by the Chrome Web Store. Remote services return blockchain data, token metadata, exchange rates, and broadcast results; those responses are treated as data and are not executed as code.

09

Camera and biometric access

Camera permission is used only when the user opens QR scanning. Camera frames are processed on the device for barcode recognition and are not intentionally uploaded or retained by Kaspire.

Biometric checks are performed by Android system services. Kaspire receives only the authorization result and does not receive or store fingerprint, face, or other biometric templates.

10

Chrome Web Store Limited Use

Kaspire's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. User data is used only to provide and secure the self-custody wallet functions described here. Kaspire does not sell user data, use it for advertising or credit decisions, or permit humans to read private wallet data.

11

Analytics, advertising, and tracking

Kaspire does not include advertising SDKs, cross-app tracking, or behavioral analytics. The project does not sell personal data. Infrastructure providers may maintain operational security logs according to their own retention and legal obligations.

12

Data retention and deletion

Local application data remains on the device until the user removes wallets, clears application storage, or uninstalls Kaspire. Before deleting application data, users must independently secure their recovery phrase, any BIP39 passphrase, and any required encrypted backup.

Clearing local data cannot remove information already published to a public blockchain or data independently retained by a connected dApp, relay, node, indexer, or other third-party service.

13

Security

Kaspire uses local encryption, Android Keystore, authenticated backups, explicit transaction review, and local signing controls to protect wallet data. No software or transmission method can guarantee absolute security. Users remain responsible for protecting recovery material and verifying recipients and transaction details before approval.

14

Children

Kaspire is not directed to children. The application is intended for people who are legally permitted to use cryptocurrency wallet software in their jurisdiction.

15

Changes and contact

This policy may be updated when Kaspire's functionality, infrastructure, or legal obligations change. Material updates will be published at this same URL with a revised effective date.

Privacy questions can be directed to the Kaspire project through HUB21 / Kaslab. The public support contact listed on Kaspire's Google Play store listing may also be used once the listing is available.