Privacy policy

Your keys, your password and your 24 words never leave your device. This page lists everything else that does, where it goes, and how long it is kept.

Effective 2 October 2026. OpenWallet has no analytics, no advertising, no crash reporting and no tracking, and it does not sell or rent personal data.

What this covers

Three parts, each run by OpenWallet:

  • The OpenWallet extension for Chrome, Edge and Firefox.
  • OpenWallet ID at wallet.openapps.network: the sign-in that protects and recovers a wallet, and "Sign in with OpenWallet" for other apps.
  • The remote MCP server at mcp.openapps.network, which AI apps use to ask for payments.

The XRP Ledger is a public network that OpenWallet does not run. Anything written to it is public and permanent.

What stays on your device

The extension keeps these in the browser's extension storage, and never sends them anywhere:

  • your keys and your 24 words, only inside a wallet file encrypted with your password;
  • your settings, the tokens you added, the names you gave your accounts, and recent price snapshots, kept for 3 days;
  • the sites you allowed or blocked for Nostr, and what you allowed each one to do;
  • the keys this browser uses to identify itself to OpenWallet ID.

The extension adds window.nostr to https pages so that Nostr apps can ask for a signature. It reads nothing from the page and sends nothing anywhere unless the page calls it, and you approve each request in OpenWallet's own window.

What the extension sends, and to whom

WhereWhatWhen
XRP Ledger public servers run by Ripple (s1.ripple.com, s2.ripple.com; on Testnet and Devnet, the rippletest.net servers)Your public account addresses, balance and history requests, and the transactions you sign. Like any web server, they see your IP address.While the wallet is open. Prices are read from the ledger's own Mainnet pools.
Testnet and Devnet faucets (rippletest.net)Your Testnet or Devnet address.Only when you ask for test XRP.
OpenWallet ID (${ID_HOST})This browser's public keys and name (Chrome, Edge or Firefox), your email, the codes you type, one encrypted part of your wallet, an encrypted backup of your Nostr keys, the key for your Google Drive backup and a fingerprint of the file (never the file or your Drive access), your Nostr public key if you add it to your profile, and what you approve when you sign in to an app.Only if you protect your wallet with OpenWallet ID, sign in, recover, or use Sign in with OpenWallet.
Google (accounts.google.com)Google sign-in, in the browser's own sign-in window.Only if you choose to sign in with Google, or to turn on Google Drive backup.
Google Drive (www.googleapis.com)One encrypted backup file, written to and read from OpenWallet's hidden app folder in your Drive, with the access token Google gave the extension. See Google Drive backup.Only if you turn on Google Drive backup: when it is made or checked, and when you recover with it.
Remote MCP server (mcp.openapps.network)This browser's public keys, the connections you approve, the limits you set, and the payments you sign.Only if you connect an AI app.
A merchant's websiteThe extension asks the merchant for its price itself before it signs, from your IP address, with no cookies.Only for a payment you approve, after you allow that one site.

Links to block explorers and other sites open in a normal tab, and only when you click them.

What OpenWallet ID keeps

WhatWhyHow long
Your email address (encrypted), and your Google account's id if you sign in with Google. The Google email itself is not kept.To sign you in and send security emails.As long as your account exists.
Your authenticator app's secret (encrypted).To check your authenticator codes.As long as your account exists.
One of the three parts of your wallet, encrypted. One part alone cannot rebuild a wallet or move funds.To recover your wallet with your sign-in and your Recovery Kit.Until it is replaced; replaced parts are destroyed.
If you turn on Google Drive backup: the key that opens that backup (encrypted, and stored apart from your wallet part) and a fingerprint of the file. Never the file itself, and never access to your Drive.To release the key, with your wallet part, at the end of a recovery that used the backup.Until you remove the backup or make new backups (the old key is destroyed), or delete your OpenWallet ID.
An encrypted backup of your Nostr keys.To restore them after a recovery.The two newest versions. When a new backup replaces one, the replaced one is also kept for at least 72 hours, so a backup you did not make cannot erase yours at once.
Your devices: public keys, the browser name, and when each was added or removed.To know which browsers may act for you, and to tell you when one is added.As long as your account exists.
For each sign-in, recovery and app sign-in: the time, the IP address and the browser it came from. For an app sign-in, also the app, what you shared with it (your email, one account address, your Nostr key) and the address you chose.To show and email you the details of a sign-in or recovery, so you can stop one you did not start, and to investigate abuse.As long as your account exists. The security log cannot be edited or deleted: after you delete your OpenWallet ID it keeps these records (times, IP addresses, browsers), but nothing in it leads to your email address or Google account any more.
Each app sign-in that is started: the app, the IP address and browser of the page that started it, and a hash of the page's one-time secret.To let only the OpenWallet extension in the browser that asked approve it.The IP address and browser are deleted a day after the request ends, and the request itself after 30 days.
Counters per IP address and per account.To limit repeated attempts.Until the limit's window ends: an hour to 7 days.

OpenWallet ID sets first-party cookies on its sign-in, recovery and app sign-in pages only. They are needed for those pages to work and last at most 24 hours. The site's other pages set no cookies and run no scripts.

Sign in with OpenWallet

When an app offers "Sign in with OpenWallet", its sign-in page on wallet.openapps.network has one button, Approve in OpenWallet. The OpenWallet extension in that same browser opens its own window, where you see the app, where it returns to and what it asks for, and approve with Touch ID or your password. There is no code to type or read out, and an approval only counts in the browser where the sign-in page is open.

When you sign in to another app with OpenWallet, that app receives a private id for you and only what you tick on the approval screen: your email, one account's public address, your Nostr public key. The id is per website: it stays the same each time you sign in to apps on one website (mail.example.com and calendar.example.com are one website, example.com), and is different on every other website. An app that OpenWallet registered directly, and that runs several products under one sign-in, gives all of them the same id. The approval screen shows the website, or the registered app, and where you return to. The company's own privacy policy then applies to what it received.

Google Drive backup (optional)

You can choose to keep a backup of one recovery part of your wallet in your own Google Drive, so you can recover without a file to keep. It is off unless you turn it on.

  • Only the app folder. OpenWallet asks Google only for the drive.appdata permission. That is a hidden folder that OpenWallet creates in your Drive for its own data. It is not your files: OpenWallet cannot see, list, open or change any other file in your Drive, and never tries to.
  • One encrypted file. OpenWallet keeps one backup file per wallet there. It holds one recovery part of your wallet. One part alone cannot rebuild a wallet or move funds.
  • Encrypted before it leaves your browser. The file cannot be opened without a key that OpenWallet ID keeps. OpenWallet ID releases that key only at the end of a recovery: after the full sign-in, the authenticator code and the 72-hour wait, during which you are emailed and can stop it. Neither Google nor OpenWallet ID can open the backup alone.
  • The access stays in the extension. The access token Google gives the extension, and the file itself, stay in the extension. They are never sent to OpenWallet ID or any other OpenWallet server, which receives only a fingerprint of the file, to check later that the backup is still the right one.
  • How long. The file stays in your Drive until you remove it.
  • How to remove it. In the extension: Settings → Recovery → remove Google Drive backup. This deletes the file and the key that OpenWallet ID kept for it. You can also remove OpenWallet's access to your Drive at myaccount.google.com/permissions, and delete the hidden app data in Google Drive (Settings → Manage apps → OpenWallet → Delete hidden app data). If you delete your OpenWallet ID, the key is destroyed and a file left in your Drive can no longer be opened.

What the remote MCP server keeps

WhatWhyHow long
Each connected AI app: its name, where it sends you back, and the IP address that registered it.To show you which app is asking.As long as the connection exists. Apps never used are removed after 30 days.
Each connection: the agent wallet's public address, its limits and the grant you signed, your masked email and the browser that approved it.To check every payment against the limits you set.As long as your account exists. Disconnecting stops it at once.
Each payment request: the merchant's address, the amount, the asset, who gets paid, the AI app's stated reason and the request it said you made, and the transaction's result.To show you the request before you approve it, and to keep a record of what was paid.Kept as the payment record. The request headers and body, which can carry the merchant's access key, are deleted 1 hour after the request closes, and the merchant's response 1 hour after it is fetched.

Other companies involved

  • Resend sends OpenWallet ID's emails. It receives your email address and the email's content: codes, and for security alerts the time, IP address and browser of the request.
  • Google, only if you sign in with Google or turn on Google Drive backup. Your backup file is stored in your own Google account, under Google's terms.
  • Ripple runs the public XRP Ledger servers the extension talks to.
  • Our hosting provider hosts wallet.openapps.network and mcp.openapps.network. The web servers' access logs record each request's IP address and browser.

Encrypted backups of both services' databases are kept for 14 days.

How long we keep it

WhatHow long
Your email address (encrypted)As long as your OpenWallet ID exists. Deleting your OpenWallet ID deletes it at once.
Your Google account's id (if you sign in with Google)As long as your OpenWallet ID exists. Deleting your OpenWallet ID deletes it at once. The Google email itself is not kept.
Your authenticator secret, your wallets' parts, the Google Drive backup's key and your Nostr key backupsAs long as your OpenWallet ID exists, or until replaced or removed. Deleting your OpenWallet ID destroys them at once.
Security records (sign-ins, recoveries, app sign-ins, and changes to your account: times, IP addresses, browsers)Kept, and cannot be edited or deleted, so that a sign-in or recovery can always be investigated. After you delete your OpenWallet ID, nothing in them leads to your email address or Google account any more.
App sign-in requestsThe page's IP address and browser are deleted a day after the request ends, the request itself after 30 days.
Counters per IP address and per accountUntil the limit's window ends: an hour to 7 days.
Your Google Drive backup fileIn your own Drive, until you remove it (see Google Drive backup).
Backups of our databasesEncrypted, and kept for 14 days. Something deleted from the service is gone from every backup within 14 days. Your wallets' parts can never be read from a backup: the keys they are encrypted under are never backed up.

Your choices

  • You can use the wallet without OpenWallet ID. Then nothing about you is sent to OpenWallet. Only the XRP Ledger servers are contacted.
  • You can remove a browser from your account, remove your Nostr key from your profile, and disconnect any AI app, in the extension.
  • You can delete your OpenWallet ID yourself, in the extension: Settings → OpenWallet ID → Delete OpenWallet ID. It asks you to sign in again first. It deletes your email address, your Google account's id, your authenticator secret, every wallet's part held by OpenWallet ID, your encrypted Nostr key backups and your app sign-in ids, cancels any recovery that is waiting, and removes every browser from it. Nobody at OpenWallet can delete or change your OpenWallet ID for you.
  • You can remove a Google Drive backup in Settings → Recovery, or remove OpenWallet's access to your Drive at myaccount.google.com/permissions.
  • After a deletion your wallets stay in the browsers where they are installed, and their 24 words still restore them. Your Recovery Kit no longer works with OpenWallet ID, a Google Drive backup can no longer be opened, and OpenWallet ID can no longer help you recover a wallet. The same email address or Google account can be used for a new OpenWallet ID.
  • To ask what OpenWallet ID or the MCP server holds about you, email privacy@openapps.network.

Chrome Web Store user data

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. OpenWallet uses what the extension handles only to provide its single purpose, a self-custodial wallet. It does not transfer that information to others except as this page describes. It does not use it for advertising, and does not use or transfer it to determine creditworthiness or for lending.

Google user data

OpenWallet's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This covers both kinds of Google user data OpenWallet handles:

  • Google sign-in: your Google account's id, and your Google email address, which is checked at sign-in and not kept. They are used only to sign you in to OpenWallet ID and to send you its security emails.
  • Google Drive (drive.appdata only): OpenWallet's own backup file in its hidden app folder, used only to make, check and restore your recovery backup. It stays in the extension and is never sent to OpenWallet's servers.

OpenWallet does not use Google user data for advertising, does not sell it, does not use it to train AI models, does not transfer it to others except as this page describes, and no person at OpenWallet reads it.

Children

OpenWallet is not meant for children under 16 and does not knowingly hold their data.

Changes and contact

A change to this policy is published on this page with a new date. A change that affects what leaves your device also comes with a new extension version. Questions: privacy@openapps.network. Security issues: security@openapps.network.