Privacy Policy
Last updated: 21 August 2026
This Privacy Policy describes how the Ekiden Wallet browser extension (the “Extension”, “Wallet”, or “Service”) handles information. We aim to collect the minimum data needed to operate the Wallet and keep it secure. We do not sell personal data and we do not use data for third-party advertising.
Ekiden Wallet is a self-custodial wallet for the Canton network and the Ekiden app. It lets you store keys, connect to ekiden.fi, and approve sign-in and transactions. Keys stay on your device.
Scope. This policy covers the browser extension only. It does not cover third-party websites or apps (“dApps”) you connect to, the Ekiden trading website, app stores, or your browser vendor’s data practices.
Contact: t.me/ekiden_official · https://ekiden.fi
1) What we collect
We design Ekiden Wallet to work with minimal data. Depending on how you use it, we may handle the categories below.
A. Wallet & keys (on device)
- Private keys / recovery phrase / password: Never sent to us. Keys remain on your device. Password mode encrypts the vault locally in Chrome storage.
- Party IDs / public keys / aliases: Stored locally for your use; may be shown in the UI or copied by you.
Source: Generated or imported on your device.
Purpose: Provide core wallet functions (unlock, sign, submit).
Storage: Local (extension storage).
Retention: Until you delete local data or remove the extension.
B. Account identifiers & approved activity
- Canton party ID and public key, so the wallet can allocate a party, show balances, and authorize your Ekiden session.
- Transaction commands you confirm in the popup (deposits, withdrawals, transfers, sub-account setup, and similar Canton operations).
- Origins of sites you explicitly connect, so the wallet can remember approvals and notify those tabs if you switch account. This is not a history of every page you visit.
Source: You, when you create a wallet, connect a site, or approve a request.
Purpose: Run the wallet and complete actions you approved.
Storage: Local for connected sites; party/transaction data is sent to Ekiden Canton infrastructure to execute the request.
C. Usage & device diagnostics (minimal)
- Technical connection metadata created by a normal HTTPS/WSS request (for example IP address, user-agent, timestamps, error responses). We do not run a separate analytics or crash SDK in the extension.
Source: Automatically created when the extension talks to our APIs.
Purpose: Operate and secure the Service; debug failures.
Retention: Ordinary server logs, typically a short operational window unless needed for a security investigation.
D. Support
If you write to us (for example via Telegram), we will see whatever you send: messages, screenshots, or attachments. Used only to respond to your request.
E. Public blockchain / ledger data
We read and display public Canton data (balances, contracts, transactions, party info). This data is public by design and not created by us.
What we do not collect
- Name, email, postal address, or government ID through the extension
- Health information
- Card numbers or bank credentials
- Browsing history, clicks, mouse position, scroll, or keystroke logging
- GPS or precise location
- The text, images, or other content of websites you visit
The extension injects a wallet provider on web pages only to receive connection and signing requests that the page sends. It does not scrape site content.
2) How we use data
- Provide the Service: wallet operations, connect to Ekiden, submit approved transactions.
- Security & integrity: keep the vault locked, show approval prompts, talk to known Ekiden hosts only.
- Reliability: diagnose errors from API responses.
- Support: respond if you contact us.
- Compliance: meet legal obligations if required.
We do not use data for third-party advertising, and we do not sell personal data. We do not use or transfer user data to determine creditworthiness or for lending purposes.
The use of information received from the extension and related APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
3) Sharing
We share limited data only with the infrastructure needed to run the Wallet, and only for the purposes stated.
| Category | What may be shared | Purpose | Recipient |
|---|---|---|---|
| Ekiden Canton APIs | Party ID, public key, signed messages, approved transaction payloads | Allocate party, balances, authorize session, submit transactions | Ekiden hosts under *.ekiden.fi |
| Trading session | Authenticated API/websocket traffic after you sign in | Keep the Ekiden trading session in sync | api.ekiden.fi, api.canton.ekiden.fi |
| Token metadata | Instrument lookup requests | Resolve Canton token-standard registry data | api.utilities.digitalasset-staging.com |
| Connected dApp | Public account info and signatures you approved | Let the site you connected complete the action | The origin you explicitly connected |
| Legal / compliance | Data required by law | Comply with lawful requests | Authorities when legally required |
We do not share, sell, or license personal data to advertisers or data brokers.
We do not share private keys, passwords, or recovery phrases with any party.
Third-party dApps & sites. When you connect to a dApp or website, that third party may request signatures or view your public party ID. Their data practices are governed by their policies; we do not control them.
Browser & store vendors. Your browser and the Chrome Web Store may collect their own diagnostics under their policies.
Public ledger. Activity you submit is public on Canton, like any blockchain transaction.
4) Storage, location, and retention
- On device: Keys and wallet data stay on your device; the vault is encrypted locally.
- Servers: Party identifiers, approved commands, and technical connection metadata may be processed on Ekiden infrastructure in order to provide the Service.
- Retention:
- Local vault: until you remove the extension or reset the wallet.
- Connected-site list: until you disconnect the site or reset the wallet.
- Technical logs: ordinary operational window; longer only if needed for security.
- On-chain data: public; not controlled by us.
5) Security
We apply technical measures appropriate to a self-custodial wallet (encryption in transit, encrypted local vault, user confirmation before connect/sign/submit). No method is 100% secure. Because keys never leave your device, device security (OS updates, malware protection, a strong password, a backup of your recovery phrase) is essential.
6) Extension permissions (and why)
We request only the permissions needed to operate the Wallet:
- storage — save the encrypted vault, accounts, and connected-site list locally (never raw private keys on our servers).
- tabs — notify open Ekiden dApp tabs when you connect, disconnect, or switch account. We do not read browsing history.
- content scripts — inject the wallet provider so a site can request connect/sign; we only handle messages the page sends to the wallet.
- host permissions — talk to Ekiden Canton APIs, trading websockets, and the token-standard registry listed above.
We do not request the browsingHistory permission and we do not collect your browsing history.
Actioned only by you: Connect to a site, sign a message, and submit a transaction are user-initiated (or user-approved) actions.
7) Your choices & rights
Local wallet data
Wallet data stored locally can be deleted by signing out / resetting the wallet in the extension, or by removing the extension from your browser. We cannot restore a deleted recovery phrase. Back it up first.
- Reject any connect or transaction prompt
- Disconnect a site
- Lock the wallet when you are done
Your privacy rights
Depending on where you live, you may have rights regarding personal data we hold on our servers (for example party identifiers tied to API use), including access, correction, deletion, restriction or objection, and data portability, subject to legal limits. On-chain data cannot be erased from Canton.
If you are a California resident, you may also have CCPA/CPRA rights to know, delete, and correct personal information, and to opt out of sale or sharing. We do not sell or share personal information for advertising.
To exercise these rights, contact us via Telegram. We will not discriminate against you for exercising your rights.
8) Children
The Extension is aimed at general audiences and professionals. It is not directed to children, and we do not knowingly collect personal data from anyone under 18.
9) Changes
If we change this policy, we will update the date above and, where appropriate, show an in-product or Chrome Web Store notice for material changes.
10) Contact
Telegram: t.me/ekiden_official
Website: https://ekiden.fi