Privacy Policy

Effective · April 27, 2026  ·  Last updated · June 6, 2026

Short version: Zafu is local-first. External calls are limited to blockchain data providers, threat checks, signed-in community-report functions, optional anonymous Network Mode counts, aggregate Cloudflare Web Analytics for the website, waitlist signup, optional Google Sign-In, and optional account sync when you choose it. TRON paste-time checks stay local-first; TRON wallet import can query native TRX and all TRC-20 history, while TRON Intel can query public balance, account type, and activity. No advertising analytics or cross-site tracking. No private keys or seed phrases ever.

If you join a Zafu waitlist, we store your email address, selected product interest, source page, signup time, and optional campaign labels from public marketing links such as utm_source, utm_medium, and utm_campaign. Waitlist emails are used only for Zafu product updates and launch or news notifications for the interests you selected. Waitlist forms do not collect address data, wallet data, clipboard text, full query strings, referrer URLs, Telegram chat text, Google IDs, install IDs, IP addresses, user agents, or browser fingerprints.

1. What Zafu Is

Zafu is a Chrome browser extension that checks cryptocurrency address paste events on wallet and exchange websites, can record local source evidence when you copy an address from Telegram Web, and checks address-only pastes inside Telegram Web before they are inserted. It detects address poisoning, possible copy/paste mismatches, route/address-family mismatches, and post-paste address changes before you confirm a transaction. Supports EVM chains, Solana, TRON address validation, and stablecoin history review for saved contacts.

2. Data Stored Locally

Wallet data is stored in chrome.storage.local on your device. Optional Google Sign-In can back up saved wallets, trusted contacts, labels, notes, and descriptions so you can recover them after reinstalling Chrome or switching computers. Generated transaction-history indexes, suspicion lists, API keys, local metrics, Network Mode aggregate counters, community cache, prices, and install IDs are not account-synced.

DataPurposeSent anywhere?
Wallet addresses you add (EVM + Solana + TRON) Used to fetch EVM/Solana/TRON transaction history, review wallet-history import candidates, or run local paste-time checks EVM/Solana/TRON public addresses are sent to Etherscan, Solscan, or Tronscan only when you fetch history, run review, or scan a wallet (see §3). Paste-time TRON format and copy checks run locally.
Transaction history index (trusted/suspicion) Built locally to classify pasted addresses Never sent anywhere
Address labels and notes User-assigned names shown in the address book Synced to Zafu only if you sign in with Google
Exceptions list ("Mark as Safe") Addresses you have manually allowed after reviewing them Never sent anywhere
Etherscan / Solscan / Tronscan API keys User-provided keys for higher API rate limits Sent only to the matching explorer provider when fetching or reviewing history. Stored locally, never account-synced.
Settings Transfer Check toggle, Network Mode toggle, community-reporting toggle, onboarding state Never sent anywhere
Telegram Web copy source evidence Recent address-only copy evidence used to confirm whether a pasted address still matches the Telegram-copied address, plus address-only Telegram Web paste checks Stored locally in session storage. Never includes chat text, sender identity, group/channel names, message IDs, URLs, or full clipboard contents beyond the copied address.
Network Mode aggregate counters Anonymous counts for product improvement: Transfer Checks, warning states, Telegram Web matches/mismatches, chain type totals, contacts saved, protected wallets, and Intel actions Sent to Zafu only if you enable Network Mode. Never includes addresses, labels, notes, clipboard text, chat text, URLs, transaction hashes, amounts, balances, Google ID, or email.
Website campaign labels Path-only landing/source page plus optional UTM or campaign labels used to understand which public marketing links lead to waitlist signups Sent to Zafu only when you submit a waitlist form. Never includes full query strings, referrer URLs, wallet addresses, clipboard text, Telegram data, IP addresses, user agents, or browser fingerprints.
Random install ID Installation identifier attached to signed-in community reports (see §6) Sent only with signed-in community submissions, alongside the verified account ID used for deduplication and abuse prevention
Google profile email, name, and avatar Creates your optional Zafu account for backup and restore Sent to Zafu only if you sign in with Google

3. Third-Party Services

Zafu calls the following external APIs. These calls are initiated only by you (when you add a wallet, paste an address, opt in to automatic threat signals, or sign in) — they are not automatic background calls beyond the scheduled 24h refresh you can disable.

ServiceData sentWhen
Etherscan Your public EVM wallet address, your optional API key Only when you click "Fetch History" for an EVM wallet, or on 24h auto-refresh
Solscan (public-api.solscan.io, pro-api.solscan.io) Your public Solana wallet address, your optional API key Only when you click "Fetch History" for a Solana wallet, or on 24h auto-refresh
Tronscan (apilist.tronscanapi.com) Your public TRON wallet/contact address, your optional TRON-PRO-API-KEY Only when you scan a TRON wallet for wallet-history import or run address Intel on a TRON address. Wallet-history import reads your public native TRX transfers and all TRC-20 token transfers to discover counterparties (USDT/USDC routes are highlighted); address Intel reads the public account balance, account type (wallet vs contract), and activity. Never for paste-time address checks, which stay local.
Cloudflare ETH RPC ENS name or address you paste Resolve ENS names to Ethereum addresses
The Graph ENS name ENS forward resolution fallback
GoPlus Security The crypto address you pasted Real-time scam check, called only when paste is detected on a wallet/exchange page (EVM only)
Zafu community pool (Supabase edge functions) Attacker addresses (not your wallet), signal type, random install ID, and verified Google account ID Only while signed in, when you flag an address or opt in to automatic threat signals (see §6). The account ID deduplicates reports and prevents one installation from spoofing the threshold.
Zafu Network Mode (Supabase edge function) Anonymous aggregate counts only: Transfer Checks, warning states, Telegram Web matches/mismatches, chain type totals, contacts saved, protected wallets, Address Intel actions, and extension version Only if you enable Network Mode. Does not require Google Sign-In and does not send addresses, labels, notes, clipboard text, chat text, URLs, transaction hashes, amounts, balances, Google ID, email, or install ID.
Cloudflare Web Analytics Aggregate website usage and performance metrics such as page views, referrers, countries, device/browser type, and page performance Used only for aggregate website analytics. Zafu does not use it for advertising retargeting, cross-site tracking, wallet profiling, or user-level behavior reconstruction.
Zafu waitlist (Supabase edge function) Email address, selected product interest, source page, signup time, path-only landing page, and optional UTM or campaign labels Only when you submit a waitlist form. Used for Zafu product updates, launch/news notifications for selected interests, and aggregate campaign attribution.
Zafu account sync (Supabase edge functions) Your Google ID plus saved wallets, trusted contacts, labels, notes, descriptions, favourites, and deletion markers Only after you choose Google Sign-In. Used for backup and restore across Chrome installs.

These services have their own privacy policies. Zafu does not control how they process the data they receive.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

4. Browser Permissions

Zafu requests three Chrome extension permissions. The average Chrome extension requests 17.

PermissionWhy Zafu needs it
storageSaves wallet list and address index locally on device. User-authored contacts and saved wallets sync only after optional Google Sign-In.
alarmsSchedules 24h auto-refresh of wallet history and community report data.
identityOptional Google Sign-In for address-book backup and restore. Never used unless you sign in.

Zafu also uses <all_urls> host access so the content script can detect paste events on wallet, exchange, dapp, and Telegram Web pages. Chrome may describe this as access to "read and change" website data. Zafu uses that access to check crypto-address paste events before the destination field accepts them, and on Telegram Web only when the pasted text is exactly one supported crypto address. During Transfer Check, Zafu may read nearby visible labels around the active field to show asset, network, memo/tag, and recipient-field context when visible. It does not request tabs or activeTab, does not read browser history, balances, account names, emails, KYC data, order history, portfolio data, exchange API keys, or wallet signing APIs, does not run advertising analytics, does not intercept Telegram mixed text or bot commands, and gates address-checking logic to crypto-relevant contexts.

5. Optional Google Sign-In

Sign-in is optional for address checks, warning downloads, recipient memory, and Network Mode. It is required only for account backup/sync and contributing addresses to the shared community-report pool; signed-out flags remain local.

If you choose to sign in with Google, Zafu uses the Chrome identity permission to obtain your Google account email, display name, avatar, and Google account ID. This is used to:

You can sign out at any time from Settings. Sign-out clears your session token. Your locally stored data is unaffected.

6. Community Threat Intelligence

When signed in, flagging an address can submit that attacker address (never your wallet address), signal type, a randomly generated install ID, and your verified Google account ID to the Zafu community pool. The account ID is used to deduplicate and rate-limit reports; a caller-selected signal cannot cross the warning threshold alone. If you opt in to automatic threat signals, Zafu may also submit attacker-pattern addresses detected from wallet-history dust or trusted external confirmations. When signed out, flags stay on your device and are not submitted. You can disable automatic threat signals in Community settings.

Submitted addresses must reach a signal threshold before they warn other users as community-reported. Community-reported does not mean confirmed malicious. Stronger labels require team review or trusted external confirmation. Address owners can dispute incorrect flags directly from the overlay.

7. What Zafu Does NOT Collect

8. Your Control Over Data

9. Children

Zafu is not directed at children under 13. We do not knowingly collect data from children.

10. Changes to This Policy

If we make material changes, we will update the "Last updated" date at the top of this page. Continued use of the extension after changes constitutes acceptance.

11. Contact

Questions or concerns: security@stayzafu.com