Last Updated: February 21, 2026
NostrKey is a browser extension developed by Humanjava Enterprises Inc that provides secure Nostr key management and cryptographic signing services. This privacy policy explains how we handle your data and protect your privacy.
TL;DR: We don't collect, transmit, or sell any of your data. Everything stays on your device.
NostrKey does NOT collect any user data.
We do not collect, transmit, or store any of the following:
NostrKey stores the following data locally on your device only using your browser's secure storage API:
If you enable "Sync across devices" in Settings, NostrKey mirrors a subset of your data to your browser's built-in sync storage:
storage.sync)storage.sync)What is synced: profiles (without per-site permissions), relay settings, feature flags, vault documents, and API keys.
What is never synced: master password hash, password salt, bunker session tokens, and per-site permission histories.
You can disable sync at any time in Settings. When disabled, no data is written to storage.sync.
NostrKey only transmits data in the following specific circumstances:
Important: NostrKey never transmits data to Humanjava Enterprises Inc or any third-party servers. All communication is directly between your browser and services you explicitly configure (relays or bunker).
NostrKey does not use any third-party analytics, tracking, or advertising services.
The extension communicates only with:
We do not integrate with or share data with any other services.
NostrKey requires certain browser permissions to function. Here's what each permission is used for:
Required to save your private keys, profiles, relay settings, and preferences locally in your browser. All data remains on your device.
Required to inject the NIP-07 window.nostr API into web pages, allowing Nostr applications to request signing operations. This is the core functionality of the extension.
Allows you to copy your public keys, relay URLs, and encrypted key exports to your clipboard when you click "Copy" buttons. Only activated by your explicit actions.
Provides a persistent side panel for managing profiles, viewing event history, and accessing your vault without interrupting your browsing.
We take security seriously and implement multiple layers of protection:
Security Best Practices:
You have complete control over your data:
NostrKey is not directed at children under the age of 13. We do not knowingly collect information from children. If you believe a child has provided data through our extension, please contact us.
NostrKey is open source software. You can review the complete source code at:
https://github.com/HumanjavaEnterprises/nostrkey.browser.plugin.src
This transparency allows security researchers and users to verify our privacy claims and audit the code for any concerns.
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this policy periodically.
Material changes will be communicated through:
If you have questions about this privacy policy or NostrKey's privacy practices, please contact us:
Humanjava Enterprises Inc
Website: humanjava.com
GitHub: NostrKey Repository
Issues: GitHub Issues
This privacy policy complies with:
Since we do not collect any user data, most data protection regulations do not apply to our extension's operation.