Kebijakan Privasi
Non-custodial, and what that costs
Maha Wallet is a non-custodial wallet for the Canton Network. The keys are yours: they are created on your device, encrypted there, and we cannot use them, copy them, or recover them for you.
We cannot recover your wallet. If you lose your recovery phrase, nobody can restore access, including us. That is the direct cost of non-custodial, and it is why the wallet asks you to write the phrase down.
What never leaves your device
- Your private keys
- Your recovery phrase
- Your password and PIN
These are never transmitted, never backed up by us, and never visible to us. Your keys are encrypted with a key derived from your password (AES-GCM, PBKDF2-SHA256, 210,000 iterations) and stored only in your browser's extension storage.
While the wallet is unlocked the decrypted key is held in memory, for as long as you are using it and at most 30 minutes of inactivity. It is never written to disk in readable form, and closing your browser clears it.
What is stored on your device
- The encrypted vault described above
- Your settings: language, theme, currency, per-token Auto Approval
- The list of websites you have connected to
- A local copy of your balances and history, rebuilt from the Canton ledger
Uninstalling the extension removes all of it. Nothing survives on our side.
What our server receives
The extension talks to exactly one server, api.mahawallet.xyz, which forwards requests to the Canton Network. It cannot sign anything: transactions are built and signed on your device, and the server only relays the signed result.
- Your Canton party id: your address on the network
- Your IP address, as with any internet request
- The requests themselves: balance reads, transaction submissions, swap quotes
Each session is authorised by a signature from your own key and lasts about fifteen minutes. A session for one party cannot read another party's data. We do not use any of it to build a profile, and we do not sell or share it.
Your email, if you give us one
Access is currently by invitation. If you join the waitlist we store your email address and the access code issued to you, in our Supabase database.
When you set up a wallet, that code becomes associated with your Canton party id, so the record links an email address to an address on a public ledger. We treat it accordingly: not shared, not sold, not used for marketing.
Ask us and we will delete your waitlist record. Transactions already on the Canton ledger cannot be deleted by anyone, including us.
Websites you connect to
A website sees nothing until you approve a connection. After you approve, it can see the account address you approved, and nothing else.
It cannot see your balances, your history, your other accounts, or your keys. It cannot move anything: every action needs a signature you give it, one action at a time, on a screen that shows what you are signing. You can disconnect any site at any time from the wallet.
The Telegram tip bot, if you link it
Linking is optional and off by default. Your key never goes into Telegram and never reaches the bot.
The link does authorise the bot to spend from the account you linked, whenever your Telegram account asks it to. Link a separate tipping account rather than the one holding your savings. Unlink at any time from the wallet.
Other services
- Canton Network: the ledger your transactions settle on. Canton is privacy-enabled: your transactions are visible to you and the parties you transact with, not published to everyone. Party ids themselves are visible on public explorers.
- Cantex and OneSwap: the swap services, reached through our server. They receive the details of a swap you choose to make.
- CoinGecko: token prices, fetched by our server rather than by your browser, so CoinGecko does not receive your IP address.
What we do not do
- No analytics. No telemetry, no tracking, no usage statistics, no fingerprinting, no advertising identifiers.
- No selling or sharing of personal data with third parties.
- No use of your data for anything unrelated to running the wallet.
- No credit scoring and no lending decisions.
Permissions the extension asks for
- Storage: to keep the encrypted vault and your settings on your device.
- Tabs: only to reopen the wallet's own full-tab view instead of a second copy. It reads no other tab.
- Access to api.mahawallet.xyz: the single server described above.
- Running on all websites: so a Canton application can detect the wallet when its page loads. The script exposes nothing about you until you approve a connection.
Children
Maha Wallet is not intended for anyone under 18, and we do not knowingly collect data from children.
Changes
If this policy changes materially we will update the date above and note the change on this page.
Contact
contact@mahawallet.xyz
For deletion of a waitlist record, write from the address you registered with.