Privacy Policy — LUX8 Wallet
Last updated: 13 September 2026 This document covers the LUX8 Wallet application — the app at wallet.lux8.net, the browser extension built from it, and the iOS app. It does not describe lux8.net, the website of the LUX8 validator, which is a different thing on a related domain and has its own policy. That site uses analytics; this app does not, and we would rather you did not have to guess which document you are reading. LUX8 Wallet is a self-custodial Solana wallet. We do not have accounts, we do not have a backend that stores your data, and we cannot access your funds. This page describes exactly what the app does with information — including the parts that are unavoidable.
What we never collect
- No account, no sign-up, no email. The app never asks who you are.
- No analytics, no tracking, no advertising identifiers, no cookies.
- No personal data: no name, address, phone number, document scans, or KYC of
any kind.
Your keys and recovery phrase
Your recovery phrase and private keys are generated on your device and never leave it. The phrase is encrypted with a password you choose (PBKDF2-SHA256, 310,000 iterations, then AES-GCM) and stored locally — in the browser's storage on the web version, or in the iOS Keychain in the native app. We never transmit, back up, or see your phrase or keys. **This also means we cannot recover them for you.** If you lose both your password and your recovery phrase, no one — including us — can restore access to that wallet.
What leaves your device, and where it goes
To show balances and submit transactions, the app has to talk to the Solana network. All of that traffic goes through our proxy at sol.stake-manager.net, which forwards it to infrastructure providers. In these requests the following is visible to the receiving service:
| What | Why | Who can see it |
|---|---|---|
| Your wallet address | Reading balances, staking accounts, transaction history | Our proxy, the RPC provider |
| Signed transactions | Broadcasting to the Solana network | Our proxy, the RPC provider, and then the public blockchain |
| Token mint addresses | Fetching prices | Our proxy, Jupiter |
| Swap parameters (amounts, tokens, your address) | Building a swap route | Our proxy, Jupiter |
| The address of an NFT's image | Drawing your collectibles | Our proxy, and whoever hosts that image |
| Token mint addresses | Fetching a token's logo | Our proxy, and whoever hosts that logo |
| Your address and the stake account being converted | Converting stake to a liquid token | Our proxy, Sanctum |
| Your IP address | Unavoidable in any network request | Our proxy, our CDN (Cloudflare) |
Two of those rows are there because of a deliberate choice. An NFT's image lives wherever its minter put it, and a wallet that loaded it directly would hand that host your IP address — for an unsolicited airdrop, a confirmation that your wallet is live and your address is real. The same is true of token logos. So the app never contacts those hosts: it asks our proxy, and our proxy asks them. Measured rather than asserted: over a full session on the live site — loading the app, importing a wallet, reading balances — the browser contacted two hosts, and both are ours: wallet.lux8.net for the app itself and sol.stake-manager.net for the data. It contacted no third party directly, and that is the part that matters: no outside service learns your IP address from using this wallet. We use the proxy specifically so that API keys stay on our server and are never shipped inside the app. A side effect is that these requests pass through our infrastructure. Our own logs record the request line and the address of whoever passed it on — which, because the app is served through Cloudflare, is Cloudflare's address and not yours. We do not store your IP address. Cloudflare itself does see it, and keeps its own records under its own policy, which we neither set nor control. Request bodies are never written to those logs, and everything that carries a wallet address travels in the body. Concretely, after a change made on 4 September 2026:
A custom RPC is your choice, and it changes the list above. Settings → RPC endpoint lets you point the wallet at any HTTPS node — your own, or a provider of your own. From then on balances, history, dry runs and sending go to that node, and it sees your IP address and every address the wallet asks about; whatever it keeps is under its policy, not ours. A key you put in that URL is stored on this device, unencrypted. Live updates, prices, validator and token data and icons still come through our proxy. Switching back in the same screen restores the list above.
| Request | What ends up in our log |
|---|---|
| Balances, simulation, sending a transaction, prices, building a swap | Nothing but the path — these are POST, and bodies are not logged |
| Fetching an NFT's image | The path only; the image address is no longer recorded |
| Searching for a token | The path only; what you typed is no longer recorded |
| Fetching a token's logo | The token's mint address |
| Quoting a swap | The two tokens and the amount — no wallet address |
| Converting a stake account | Which of four Sanctum routes was used |
The last row is there because of a mistake we found while writing this page: that request used to carry your address and your stake account in its query string, and those did end up in our logs. It was changed on 4 September 2026 and no longer does. Entries written before that date are still in the rotation and will be gone within 14 days of when they were made. We would rather say this than write a sentence that is true only about today. Since that change, no line in our logs names a wallet. These logs are kept for 14 days and then deleted. Note on the blockchain itself: Solana is a public ledger. Every transaction you make — addresses, amounts, timestamps — is permanently public and is not something either you or we can delete.
Third parties
- Jupiter (
jup.ag) — token prices and swap routing. - Sanctum — converting a stake account into a liquid staking token.
- RPC providers — reading chain state and broadcasting transactions. We use
more than one, and which one answers a given request depends on the request: currently Helius, Chainstack, Shyft, PublicNode and the Solana Foundation's public endpoint. This is for reliability — if one is unavailable, another answers — and it means any of them may see the addresses in that request.
- Cloudflare — serving the app and proxying our traffic.
We do not sell, rent, or share data with anyone for marketing. We have nothing to sell: there are no user records.
Children
The app is not directed at children under 13, and we knowingly collect no data from anyone, of any age.
Changes
If this policy changes, the date at the top changes with it. Material changes will be noted in the app's release notes.
Contact
Questions about privacy: info@lux8.net Lux8 Labs Ltd — Office A, RAK DAO Business, Ras Al Khaimah, United Arab Emirates