Privacy Policy
Effective September 26, 2026
- Your recovery phrase, private keys and password never leave your device. We never receive them and cannot recover them for you.
- We run no servers that collect your data. There are no analytics, no tracking and no ads.
- The wallet talks to the Arc Mainnet network, and to websites only after you connect them. Blockchain data is public by design.
- We do not sell, rent or share your data.
Who we are
ASPAD Wallet is a self-custody browser extension wallet for the Arc Mainnet blockchain, made by the team behind ArcStockpad. It is not an official product of Circle or of the Arc network. In this policy, "we" means the ASPAD Wallet team and "the wallet" means the extension.
What the wallet keeps on your device
This data is stored in your browser's storage for the extension, on your device only:
- Your encrypted wallet. Your recovery phrase and any private keys you import are encrypted with your password (AES-256-GCM, with a key derived from your password using PBKDF2-SHA256 at 600,000 iterations) before they are saved. Without your password they cannot be read.
- Your accounts: their public addresses and the names you give them.
- Connected sites: each website you allowed to connect, the account it may see, and when it was connected and last used.
- Tokens you added, and the apps you favourite or recently opened in the Apps tab.
- Settings, such as the auto-lock timer.
While a connect, signature or transaction request is waiting for your answer, its details are held in the browser's memory-only session storage, and they are removed once you answer. A new wallet's recovery phrase is held there too, only until you confirm you have backed it up. Session storage is never written to disk and is cleared when the browser closes.
What leaves your device, and where it goes
- The Arc Mainnet network. To show balances and to send what you approve, the wallet sends requests to the Arc Mainnet RPC node at
https://rpc.mainnet.arc.io. When that node is busy or unavailable, the same request goes to a public backup node for Arc Mainnet instead:https://rpc.blockdaemon.mainnet.arc.io(Blockdaemon) orhttps://arc-rpc.publicnode.com(PublicNode). These requests include your public wallet address, and the signed transactions you approve. Transactions are recorded on a public blockchain, where anyone can see them. Like any server, each node's operator can see the IP address the requests come from. - ArcStockpad's token list and logos. To show the tokens you hold with their names and logos, the wallet downloads ArcStockpad's public token list from
https://arcstockpad.com/tokens.json(at most once an hour) and the logos in it from arcstockpad.com. These requests carry no wallet address or other information about you; like any website, arcstockpad.com can see the IP address they come from. Which tokens you hold is read from the Arc Mainnet network, as above. A copy of the wallet installed by hand (early access, which Chrome does not update) also checkshttps://arcstockpad.com/wallet.jsonat most every six hours to tell you when a newer version is out; copies from the Chrome Web Store do not. - Websites you connect. A website learns your public address only after you approve its connection request. It receives a signature or a transaction only when you press Confirm in the wallet's own window. You can disconnect any site at any time in Settings.
- Links you open. Opening an app from the Apps tab, or a transaction in the block explorer, opens that website in a new tab. That website's own privacy policy then applies.
What we never receive
We do not operate any server that the wallet reports to. We never receive your password, recovery phrase, private keys, balances, addresses, browsing activity or any other personal information. The wallet contains no analytics, tracking or advertising code. It does not read the content of the web pages you visit. Its script on web pages only passes along the requests a website makes to the wallet.
Your choices
- Lock the wallet at any time, or set it to lock itself after a period of inactivity.
- Disconnect any website, or all of them, in Settings.
- Remove the extension to delete everything it stored on your device. Keep your recovery phrase first: without it, your accounts cannot be restored.
Children
The wallet is not directed at children under 13, and we do not knowingly collect any information from them.
Changes to this policy
If the way the wallet handles data changes, we will update this page and its effective date before the new version of the wallet is published.
Contact
Questions about this policy: arcstockpad@gmail.com