Privacy
Seeds, private spend keys, private view keys, and wallet passwords must remain inside the browser. The QWC wallet beta will not use analytics, ads, third-party scripts, or remote crypto libraries.
Network Requests
The first backend component is a key-blind RPC proxy for allowlisted QWC daemon calls. It must not receive wallet secrets.
Local Storage
Persistent wallet data must be encrypted before storage. Plaintext seeds in LocalStorage, SessionStorage, IndexedDB, URLs, or logs are forbidden.