Back to Home

Privacy Policy

Last Updated: February 21, 2026

Overview

NostrKey is a browser extension developed by Humanjava Enterprises Inc that provides secure Nostr key management and cryptographic signing services. This privacy policy explains how we handle your data and protect your privacy.

TL;DR: We don't collect, transmit, or sell any of your data. Everything stays on your device.

Data Collection

NostrKey does NOT collect any user data.

We do not collect, transmit, or store any of the following:

Data Storage

NostrKey stores the following data locally on your device only using your browser's secure storage API:

What We Store Locally

How Data is Stored

Cross-Device Sync (Optional)

If you enable "Sync across devices" in Settings, NostrKey mirrors a subset of your data to your browser's built-in sync storage:

What is synced: profiles (without per-site permissions), relay settings, feature flags, vault documents, and API keys.

What is never synced: master password hash, password salt, bunker session tokens, and per-site permission histories.

You can disable sync at any time in Settings. When disabled, no data is written to storage.sync.

Data Transmission

NostrKey only transmits data in the following specific circumstances:

To Nostr Relays (User-Configured)

To nsecBunker (Optional)

Important: NostrKey never transmits data to Humanjava Enterprises Inc or any third-party servers. All communication is directly between your browser and services you explicitly configure (relays or bunker).

Third-Party Services

NostrKey does not use any third-party analytics, tracking, or advertising services.

The extension communicates only with:

We do not integrate with or share data with any other services.

Permissions Explained

NostrKey requires certain browser permissions to function. Here's what each permission is used for:

Storage Permission

Required to save your private keys, profiles, relay settings, and preferences locally in your browser. All data remains on your device.

Host Permissions (All URLs)

Required to inject the NIP-07 window.nostr API into web pages, allowing Nostr applications to request signing operations. This is the core functionality of the extension.

ClipboardWrite Permission

Allows you to copy your public keys, relay URLs, and encrypted key exports to your clipboard when you click "Copy" buttons. Only activated by your explicit actions.

SidePanel Permission

Provides a persistent side panel for managing profiles, viewing event history, and accessing your vault without interrupting your browsing.

Security

We take security seriously and implement multiple layers of protection:

Security Best Practices:

  • Enable master password encryption
  • Backup your private keys securely
  • Review app permissions regularly
  • Consider using nsecBunker for maximum security

User Rights

You have complete control over your data:

Children's Privacy

NostrKey is not directed at children under the age of 13. We do not knowingly collect information from children. If you believe a child has provided data through our extension, please contact us.

Open Source

NostrKey is open source software. You can review the complete source code at:

https://github.com/HumanjavaEnterprises/nostrkey.browser.plugin.src

This transparency allows security researchers and users to verify our privacy claims and audit the code for any concerns.

Changes to This Policy

We may update this privacy policy from time to time. Any changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this policy periodically.

Material changes will be communicated through:

Contact Information

If you have questions about this privacy policy or NostrKey's privacy practices, please contact us:

Humanjava Enterprises Inc
Website: humanjava.com
GitHub: NostrKey Repository
Issues: GitHub Issues

Legal Compliance

This privacy policy complies with:

Since we do not collect any user data, most data protection regulations do not apply to our extension's operation.