Overview
This policy applies only to the Rialo Testnet Wallet browser extension. The wallet is an independent project. It is not an official Rialo product and is not affiliated with or endorsed by Rialo.
The extension has no wallet-publisher account or analytics service. It does not include advertising or tracking. It handles wallet information locally and connects directly to the Rialo Testnet RPC when you use network features.
Stored on your device
When you create or import a wallet, the recovery phrase is encrypted in the browser profile using a key derived from your password. The encrypted vault is stored with Chrome extension storage. Your password is used locally to unlock the vault and is not saved by the extension.
While the wallet is unlocked, the decrypted recovery phrase is kept in session storage for wallet operations. Locking the wallet clears that session value; browser session storage is also cleared when the browser session ends. The phrase and private key are used locally to derive addresses and sign only after you approve an action.
The extension publisher does not receive your password, recovery phrase, or private key. If you choose to reveal or copy a recovery phrase or private key, it is displayed in the extension or copied to your device clipboard at your request. Other applications on your device may be able to read clipboard contents.
Network and transaction data
To show balances and recent activity, and to request test RLO or send a transaction, the wallet sends requests directly to the Rialo Testnet RPC endpoint at https://testnet.rialo.io:4101.
- The public wallet address is sent to look up its balance and public transaction history.
- A test-RLO request includes the public address you selected.
- When you send a transaction from the wallet, the signed transaction is submitted to the RPC endpoint for broadcasting.
These requests are made over HTTPS. Blockchain addresses and confirmed transactions are public on the testnet and may remain visible in network records. The RPC operator may receive your IP address and technical request metadata as part of a normal network connection. The wallet publisher does not receive the IP address from these direct RPC requests and does not control the RPC operator’s logging or retention practices.
Connected sites
Compatible websites can ask to connect to the wallet. If you approve, the requesting site receives your public wallet address. A site may then ask you to sign a message or transaction. The wallet shows an approval prompt; if you approve, the resulting signature or signed transaction is returned to that site. A site may submit a signed transaction to the network.
Connected websites are independent third parties. Review each site before connecting or signing, and read its own privacy policy. The wallet does not share your recovery phrase or private key with a connected site.
Retention and deletion
The encrypted wallet vault remains in your browser profile until you remove the extension or its stored data. Locking the wallet clears the unlocked session value; it does not delete the encrypted vault. Removing local wallet data does not remove transactions already recorded on the public testnet.
Permissions
- Storage: saves the encrypted wallet vault and temporary session data needed to unlock and approve wallet requests.
- Clipboard: copies an address or secret only when you use a copy action.
- Windows: opens focused approval windows for connection and signing requests.
- Site and host access: provides the wallet connection interface on supported Rialo network and dApp pages, and permits direct requests to the Rialo Testnet RPC.
Contact and updates
For privacy questions, use the publisher contact shown on the Rialo Testnet Wallet Chrome Web Store listing.
This policy may be updated if the wallet’s data practices change. The effective date at the top will be revised when that happens.