Oxyon Wallet / Privacy
Oxyon Wallet Privacy Policy
Last updated: 2 October 2026 · Oxyon Wallet was formerly GeoWallet
Oxyon Wallet is a self-custodial wallet (browser extension and web app). It does not have user accounts, does not run analytics, and does not collect, sell, or share personal information. Your keys and recovery phrase are generated and stored only on your own device.
What we store, and where
- Your recovery phrase and private keys are encrypted with your password and stored locally in your browser. They are never transmitted to us or anyone else. We cannot see, recover, or reset them.
- Local preferences such as selected networks, custom RPC URLs, address book labels, and optional API keys are stored locally in your browser only.
- Messaging data — your message inbox, the senders you have accepted or blocked, and how far the wallet has scanned — is stored locally in your browser only. Private messages are kept in their encrypted form and decrypted in memory only while the wallet is unlocked.
- Optional fingerprint unlock uses your device's WebAuthn authenticator to wrap your password locally; no biometric data leaves your device.
Network requests
Like any wallet, Oxyon Wallet must talk to public infrastructure to function. These requests may expose your public wallet address and IP address to the endpoint you are contacting.
- Blockchain RPC endpoints — to read balances and broadcast transactions that you approve.
- XL1 RPC and the XL1 data lake — to send messages and to find messages sent to your address. The browser extension checks for new messages in the background every few minutes, using only your public XL1 address.
- CoinGecko — to display token prices in USD.
- Alchemy / Etherscan — only if enabled or configured, to show NFTs and transaction history.
- WalletConnect / Reown relay — only if enabled, to connect to mobile dApps.
We do not add tracking parameters, identifiers, or analytics to these requests.
Messages you send
- Public messages are written to the XL1 public blockchain and its data lake. They are permanent and readable by anyone, and cannot be edited or deleted — by you or by us.
- Private messages are end-to-end encrypted on your device so only the recipient's wallet can read them. Like every blockchain transaction, the sender and recipient addresses, the time, the size, and any XL1 attached remain publicly visible.
- Enabling private messages publishes your wallet's messaging public key on XL1 so others can encrypt to you. It never publishes your recovery phrase, private keys, or signing key.
- Never send secrets, passwords, or recovery phrases in a message.
Permissions
storage— to keep your encrypted vault, inbox, and local settings on your device.tabs— to identify which site is making a connection or signing request so approvals and responses go to the correct page.alarms— to check for new messages every few minutes.notifications— to tell you when a message arrives from someone you know. Notifications never include the message text, and first-time senders never trigger one.- Host permissions / content scripts — to inject the wallet provider so decentralized apps can request a connection. You approve every connection and signature.
What we never do
- We never collect or transmit your recovery phrase, private keys, or password.
- We never run third-party analytics, advertising, or trackers.
- We never sell or share your data.
Data deletion
Using Reset in the wallet, removing the extension, or clearing browser data permanently deletes locally stored Oxyon Wallet data from your device. Because nothing is stored on our servers, there is nothing for us to delete on your behalf. Messages and transactions already written to a public blockchain cannot be deleted by anyone.
Children
Oxyon Wallet is not directed to children under 16.
Changes
We may update this policy; material changes will be reflected by the “Last updated” date above.
Contact
Questions or requests: the WinLEW community Discord