Effective: September 3, 2026 Policy version: 2026-09-03 This Privacy Policy describes data handling for Nullark websites, interfaces, documentation, and operator-run relayer services (collectively, the “Service”). Public blockchains, wallets, RPC providers, explorers, and other third parties process data under their own policies.

1. Controller

The Nullark operator controls processing performed for the hosted Service. Never include seed phrases, private keys, recovery notes, note secrets, wallet unlock signatures, or other spendable material in a request. We may ask for limited information needed to verify a request, but we will never ask for a wallet secret.

2. Data handled by the Service

Website and infrastructure data

When you load Nullark, hosting and security infrastructure may process:
  • network identifiers such as IP address and approximate region;
  • request, response, browser, device, and language information;
  • security and abuse-prevention signals.
Nullark uses Cloudflare for site delivery, security, and service infrastructure. Cloudflare describes its processing in its Privacy Policy.

Wallet and RPC data

When you connect a wallet or query a network, the browser, wallet provider, and configured RPC provider may handle:
  • your public wallet address and selected network;
  • blockchain queries, transaction requests, and transaction status;
  • wallet approval or rejection results.
Wallet providers and RPC operators can associate requests with network and device metadata. Review their policies before use.

Relayer request data

When you choose relayer submission, the relayer receives the information needed to validate and submit the transaction, including:
  • the transaction request and public data required for validation and submission;
  • network and request metadata used for reliability, security, and abuse prevention;
  • submission status and resulting public transaction identifier.
Nullark limits operator-run logging and does not intentionally log wallet or recovery secrets. Infrastructure providers may process request metadata under their own policies.

Data kept in your browser

Normal hosted flows generate proofs and handle recovery material in your browser. Browser storage may contain:
  • private-balance and recovery data needed to recognize or use funds;
  • local transaction and recovery status;
  • interface preferences and the accepted legal-document version.
Some locally stored data may enable access to funds. It stays under your browser profile unless you export, transmit, or expose it, or your device or browser is compromised. Clearing site data may delete recovery state and can make funds harder or impossible to recover without another valid backup.

Public blockchain data

Transactions sent through Nullark become public according to the network’s rules. Public data may include submitter and recipient addresses, amounts or denominations, timing, contract interactions, fees, transaction status, and other protocol-required public data. Public ledger data may be copied, indexed, inferred from, and retained by unrelated parties. Independently maintained blockchain records sit outside Nullark’s erasure or correction capability.

3. Data Nullark avoids collecting

Hosted application code contains no account-registration system, advertising pixel, behavioral analytics SDK, or marketing tracker. Nullark sells no personal information and performs no sharing for cross-context behavioral advertising. The application has no need for your seed phrase or private key. Keep them out of every Nullark field, support request, issue, and message. Cloudflare or another infrastructure provider may use essential security technologies under its own policy. Nullark application code sets no advertising or analytics cookies.

4. Why data is processed

Data is processed to:
  • deliver the website and documentation;
  • support wallet, network, contract, recovery, and relayer functions you request;
  • process and reconcile relayer submissions;
  • prevent fraud, abuse, attacks, and unintended duplicate activity;
  • diagnose failures, maintain availability, and protect users and infrastructure;
  • comply with law and establish, exercise, or defend legal claims.
Where data-protection law requires a legal basis, processing relies as applicable on performing the service you request, legitimate interests in security and reliable operation, compliance with legal obligations, and consent for optional processing introduced in the future.

5. Sharing and recipients

Data may be processed by:
  • Cloudflare for hosting, delivery, security, and operated service infrastructure;
  • your selected wallet provider;
  • configured blockchain RPC providers and network participants;
  • the Nullark relayer when you choose relayer submission;
  • public blockchains, explorers, indexers, and anyone reading public network data;
  • professional advisers, authorities, or counterparties where lawfully required or needed to protect rights and security;
  • a new operator during a merger, reorganization, financing, or transfer, subject to appropriate safeguards.
Normal hosted use does not intentionally send browser-held wallet or recovery secrets to operator systems. You control any export or disclosure of those secrets.

6. Retention

Retention depends on where data lives:
  • Browser data: remains until you clear it, the application replaces it, or browser policy removes it.
  • Legal acknowledgement: stores the current policy version locally until cleared or superseded.
  • Relayer, operational, and security data: retained only as long as reasonably needed for transaction handling, reliability, abuse prevention, dispute handling, legal obligations, and provider requirements.
  • Public blockchain data: retained according to the network and independent copies; it may be effectively permanent.
Backups and security records may persist briefly after normal deletion until their retention cycle completes.

7. Security

Nullark uses reasonable technical and organizational measures designed to minimize collection, restrict access, and protect the confidentiality and integrity of operator-controlled data. No system is perfectly secure. Device compromise, malicious extensions, unsafe wallet prompts, copied recovery material, phishing, dependency compromise, RPC misbehavior, and public-chain analysis remain risks. Use the official domain, inspect wallet requests, and keep independent recovery backups offline.

8. Your choices and rights

Depending on applicable law, you may have rights to request access, correction, deletion, restriction, portability, or an explanation of processing; object to certain processing; withdraw consent; and complain to a regulator. You may also have rights against discriminatory treatment for exercising privacy rights. We can act only on data under the operator’s control. For browser-held data, use browser controls. For wallet provider, RPC, Cloudflare, or public-chain data, contact the relevant controller or use its available controls. Nullark sells no personal information and uses no sensitive personal information to infer characteristics. A sale/share opt-out link is therefore not offered. Browser-level privacy signals do not change this because the Service performs no targeted-advertising sale or sharing.

9. International processing

Providers and public networks may process data in multiple countries. Where required, transfers rely on recognized safeguards or lawful transfer grounds. Public blockchain distribution cannot be confined to one country.

10. Changes

Material changes receive a new policy version and effective date. The app may ask you to acknowledge the revised policy before another value-moving action. Earlier versions may be retained for reference.

11. Security reports

For security vulnerabilities, follow the private-reporting guidance in Report a vulnerability. Do not place personal data or spendable secrets in a public issue.