Chrome Web Store
Yap Signer Privacy Policy
Last updated: September 20, 2026
Yap Signer is a self-custodial Chrome extension. It creates and stores a Solana bot wallet on your device. Yap does not operate a key server for this extension. This policy also covers the public site at https://yap-pay.xyz.
What is stored locally in the extension
- Your wallet address, balances cache, signing rules, activity log, and a hash of a platform access token in Chrome local storage. The plaintext token is shown once in the popup and is not stored.
- Your 24-word recovery phrase inside an AES-256-GCM vault. The vault key is derived from your password with PBKDF2-SHA256 (600,000 iterations) and bound to your wallet address so ciphertext cannot be swapped onto another account. Salt, IV, and ciphertext are stored as binary encodings. That is not encryption of the private key with Base64.
- The Solana private key is derived in memory after you unlock. It is never written to Chrome storage as Base64 or plaintext. Locking the wallet or restarting Chrome wipes it.
- No private key, mnemonic, or password is sent to Yap servers.
What this website stores
- If you visit with a
?ref=value, this site may keep that public username or wallet address in your browser'slocalStorageso a later Chrome Web Store install can still see who invited you. Referral values are public identity only. This site does not implement referral rewards, accounts, or email capture. - This website does not receive your seed phrase, password, or private key. Page scripts may ask the extension for
pingandgetStatusonly.
What leaves the device
- Public RPC requests for balances, recipient checks, sending SOL, and broadcasting swaps. These go to
https://yap-ecosystem.onrender.com/api/solana/rpcand, if needed,https://api.mainnet-beta.solana.com. Requests include your public address and unsigned or signed transaction bytes for broadcast, not your password or seed phrase. - Quote, price, chart, and token-search requests to Jupiter, DexScreener, and CoinGecko. These use public mint addresses, swap quotes, and CoinGecko market charts. They do not receive your private key, mnemonic, password, or platform access token.
- Help and Refer a friend open
https://yap-pay.xyzin a browser tab. A referral link may include your public username or wallet address in the URL. That is public wallet identity, not the seed or password. - Allowlisted Yap websites can ask the extension for public wallet status and username. Silent signatures require the extension to be unlocked, Silent mode, a live platform access token presented by the site, and a transaction inspection (fee payer, DEX allowlist, SOL-out cap).
Sites that can talk to the extension
The content script runs only on these origins:
- https://yap.ai and https://www.yap.ai
- https://yap-ecosystem.ai and https://www.yap-ecosystem.ai
- https://yap-wallet.ai and https://www.yap-wallet.ai
- https://yap-pay.xyz and https://www.yap-pay.xyz
- https://yap-pilot.onrender.com
- https://yap-ecosystem.onrender.com
Those pages cannot create, import, export, delete, or reset the wallet. They cannot change signing rules. Activity logs are not exposed to pages.
Hosting of this website
https://yap-pay.xyz is served by Vercel. Like most hosts, Vercel may process standard request logs such as IP address, user agent, and the requested URL in order to operate the site. This website includes Vercel Analytics for page views. It does not receive your seed, vault password, or private key. The Yap Signer extension does not include that SDK.
What we do not collect
- We do not sell personal data.
- We do not use analytics SDKs in the Yap Signer extension.
- We do not read your browsing history outside the allowlisted Yap origins above.
- We do not operate accounts or mailing lists on this site.
Contact
Questions about this policy: privacy@yap-pay.xyz. You may also use the Chrome Web Store support email listed on the Yap Signer listing once that listing is public.
