Browser extension

Privacy policy

This policy explains how the StarSwap browser extension handles data when it connects StarSwap to a supported market page.

Last updated

Purpose and scope

The extension has one purpose: connect approved StarSwap wallets to show selected-wallet context and execute user-authorized token trades on supported market pages. BasedBot and GMGN are currently supported and are third-party services. Describing these integrations does not claim sponsorship, affiliation, or endorsement.

On a validated supported-terminal Market Buy surface, submitting a StarSwap dollar amount immediately buys that amount from every selected StarSwap wallet. On a validated Market Sell surface, choosing 25%, 50%, or 100% immediately sells that share of each selected wallet's current holding. There is no second confirmation screen. The terminal's native actions remain available.

Data the extension handles

Supported-page context
URLs and tab context on basedbot.app, gmgn.ai, and starswap.cc, plus visible control labels, links, selection state, and layout signals on supported terminal pages. These are read to identify a supported token route and an unambiguous Market Buy, Sell, or list Buy surface. During pairing, the exact initiating market URL remains in trusted extension session storage so the approval tab can return to it. The extension does not build a general browsing history.
Account and wallet context
StarSwap account, wallet, and wallet-group identifiers; wallet type, wallet and group names, group membership, public wallet addresses, selected wallet set, available balances, saved Quick Trade dollar presets, entered buy amounts, selected sell percentages, Quick Trade slippage, and the selected wallets' exact token holdings. A holding can include its symbol, raw amount, withdrawable amount, and USD value when available.
Authentication and connection data
A short-lived pairing request ID, verifier, expiry, connection state, and a distinct scoped integration credential. If the manual fallback is used, the extension also handles the master API key entered in its popup.
Quote, trade, and recovery data
The side, chain, token address, exact selected wallet set, buy amount or sell percentage, authoritative per-wallet raw amounts, settlement asset, expected and minimum outputs, fees, gas reserves, maximum debits, quote expiries, idempotency keys, quote and trade identifiers, submission state, results, and bounded recovery metadata. This data binds one action to one batch and prevents an uncertain submission from becoming another trade.
Service and security logs
StarSwap servers and infrastructure may record the request IP address, request time, API path, response status, and limited error or security metadata needed to operate, protect, and diagnose the service. The extension is designed not to put pairing verifiers or credentials in URLs, page content, content-script messages, logs, or the clipboard.

How the data is used

StarSwap uses this data only to connect the extension, show eligible wallets and balances, show the selected-token holding, preserve the user's saved amounts, slippage, and wallet selection, validate the live market and action, create and submit the authorized buys or sells, follow their status, recover an uncertain submission, revoke the connection, and maintain the security and reliability of those features.

The extension does not use this data for advertising, profiling, data brokerage, lending, or credit decisions. StarSwap does not sell user data.

Where data is processed and shared

  • On the device. Supported terminal page context is inspected locally. StarSwap wallet and trade state is processed in trusted extension contexts and displayed in a closed StarSwap interface within the page.
  • By StarSwap. The extension sends the scoped requests described above to https://starswap.cc/api/v1 over HTTPS. StarSwap stores the account, connection, quote, trade, and recovery records needed to provide and reconcile the service.
  • By operational providers. Depending on the network and available route, StarSwap may give public wallet addresses, token and chain identifiers, requested amounts, transaction data, or related routing details to infrastructure, database, security, blockchain RPC/indexing, routing, and broadcast providers. Current trading paths can use Mobula, Jupiter, LI.FI, Relay, Alchemy, and configured blockchain RPC or broadcast providers. They receive only what is needed for their part of the requested feature and operate under their own terms.
  • Third-party terminals. The extension reads supported BasedBot or GMGN pages and places the closed StarSwap interface there. It does not expose the StarSwap credential, pairing verifier, quote ID, trade ID, or recovery controls through the page. Each terminal's native controls and services remain governed by that terminal's own privacy terms.

StarSwap may also disclose data when required by law, to investigate fraud or abuse, or as part of a business transfer after obtaining any consent required by the Chrome Web Store User Data Policy. Human access is limited to user-authorized support, security or abuse investigation, legal obligations, or properly aggregated and anonymized internal operations.

Device storage, security, and retention

  • The paired connection, including its scoped credential and current account, wallet selection, balances, and preset snapshot, is encrypted with AES-GCM. Its non-extractable device key remains in extension-origin IndexedDB; Chrome local storage holds only the ciphertext and initialization vector.
  • If persistent device encryption is unavailable, paired data remains in trusted Chrome session storage only. A manually entered master API key and its account context always remain in trusted session storage only.
  • Local and session storage are restricted to trusted extension contexts. All data sent to StarSwap uses HTTPS.
  • Pairing state, including the initiating market tab and URL, expires after ten minutes and is removed when pairing ends. Expired server pairing requests are removed on a scheduled cleanup. One-click navigation and handoff intents expire after 30 seconds.
  • A newly paired scoped connection expires after 30 days. Reconnect StarSwap to continue after it expires.
  • Bound quote and trade records are kept locally for duplicate prevention and recovery. Completed records are bounded and pruned as later records are added. An unresolved submission is retained until it is resolved or the connection is removed.
  • StarSwap keeps server-side account, hashed connection-key, quote, trade, accounting, security, and log records only as long as needed to provide and reconcile the service, protect users, resolve disputes, and meet legal obligations. Public blockchain transactions cannot be deleted from the blockchain.

Your choices

You choose the exact wallets or wallet groups the extension may access when connecting. Any active wallet can be included or excluded, including the main wallet. Wallets created later are not added automatically; Manage wallets opens a new approval, and the current connection stays active until the extension claims the confirmed replacement.

You can use Disconnect in the extension to revoke a paired credential and remove its connection and recovery data from the device. Disconnect can pause while a trade is unresolved so the extension does not discard the only local recovery path. Resolve that trade, then disconnect.

Clearing extension storage or uninstalling removes device data, but uninstalling by itself may not revoke the server-side credential. Disconnect before uninstalling when possible. Disconnecting does not erase trades already recorded in the StarSwap account or on a public blockchain.

To request access, correction, or deletion of other StarSwap account data, contact the address below. Some records may be retained where security, accounting, dispute, or legal obligations require it.

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Extension data is used or transferred only as necessary to provide or improve the disclosed single purpose, maintain its security and reliability, comply with law, or address fraud and abuse. It is not transferred for personalized advertising, sold to data brokers, or used for lending or creditworthiness.

Policy changes

If the extension's data practices change, StarSwap will update this policy and prominently disclose the change before collecting or using data in the new way.

Contact

Questions or data requests: starswap.intern@proton.me