Privacy Policy
TapRay Wallet and tapray.fi · Effective 25 July 2026
TapRay Wallet is a self-custodial RGB-on-Bitcoin browser extension. It is built so that your keys and wallet state stay on your device. This policy explains what the extension does and does not do with your information, and — under Website and waitlist and Your rights under the GDPR — how we handle the one piece of personal data the tapray.fi site can hold: a waitlist email address.
Summary
- The extension collects nothing. The website sets no cookies and runs no analytics; the only personal data we ever hold is a waitlist email you choose to give us, which you can have deleted at any time.
- Your recovery phrase and private keys are generated on your device and stored locally, encrypted. They are never sent anywhere.
- There are no accounts, no sign-up, no analytics, and no tracking.
Information the extension collects
None. TapRay Wallet has no backend that receives your data. We do not collect names, emails, IP addresses, device identifiers, analytics, or usage telemetry.
Information stored on your device
The extension stores the following locally, in the browser's extension storage, and never transmits it:
- Your wallet vault (recovery phrase / private keys), encrypted at rest under a key derived from your password.
- Your RGB asset state ("stock") and a cache of your Bitcoin UTXOs and verified block data, used to display balances and build transactions.
- Your list of approved dApp connections.
This data lives only in your browser profile. Removing the extension removes it. If you lose your recovery phrase, it cannot be recovered — there is no copy off your device.
Network connections
The extension makes only these outbound connections, and none of them carry your keys or recovery phrase:
- Public Bitcoin indexer (mempool.space): to read on-chain data — transaction status, your address UTXOs, and block headers for SPV verification. These are standard blockchain queries; your public addresses are visible to the indexer, as they are to any Bitcoin node.
- dApps and the exchange broker: only after you explicitly approve a connection for a given site (a per-origin approval, like MetaMask). Swap transactions are exchanged with the site you chose to interact with; the wallet signs locally and never shares your private keys.
We operate no servers that receive your keys, recovery phrase, or wallet state.
Permissions
The extension uses browser permissions only as described:
- Storage — keep the encrypted vault, RGB state, and caches on your device.
- Alarms — run background blockchain syncing and asset-import processing.
- Idle — automatically lock the wallet after inactivity or when your screen locks.
-
Host access (the TapRay dApp,
mempool.space) — inject the wallet provider into the TapRay dApp on your approval, and read public blockchain data.
Data security
Your secrets are encrypted at rest and the wallet auto-locks after a period of inactivity or when your operating system locks, clearing the in-memory key. Signing happens locally in the extension; the transaction details you see are derived by the wallet itself, not supplied by the site requesting a signature.
Website and waitlist (tapray.fi)
The tapray.fi website sets no cookies, runs no analytics, and loads no third-party scripts or fonts — nothing is stored on your device, so there is no consent banner to dismiss.
The one exception is the mainnet waitlist form:
- What we hold: the email address you type in, the form it came from, and the date you submitted it.
- Why: to email you once, when mainnet goes live.
- Lawful basis: your consent (GDPR Art. 6(1)(a)), given by submitting the form. You can withdraw it at any time.
- How long: until mainnet launch and the announcement that follows, or until you ask us to delete it — whichever comes first.
- Who else sees it: nobody. We do not sell, rent, or share the list. It is stored in a Cloudflare D1 database, and Cloudflare hosts the site; Cloudflare acts as our processor and its edge logs may briefly record request metadata such as IP addresses.
Your rights under the GDPR
If you are in the EU or UK, you have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time without affecting processing already carried out.
To exercise any of these, email privacy@tapray.fi from the address you signed up with. We will action it within 30 days; deletion requests are usually done the same week. You also have the right to lodge a complaint with your national data protection authority.
The data controller for tapray.fi is TapRay, reachable at privacy@tapray.fi. There is no automated decision-making or profiling, and no transfer of your data outside our processor's infrastructure.
Children
TapRay Wallet is not directed to children under 13 and does not knowingly collect any data from anyone.
Changes to this policy
We may update this policy as the extension evolves. Material changes will be reflected by a new effective date on this page.
Contact
Questions about this policy: privacy@tapray.fi.