Privacy
What xrpl.to keeps, and what it never sees
xrpl.to is a token analytics site and a browser wallet for the XRP Ledger. This page says what the site keeps about you, what it never has, and which features contact other services. Last updated 8 September 2026.
Your wallet stays in your browser
- A wallet you create or import is encrypted inside your browser’s own storage and is never uploaded. xrpl.to’s servers never hold a seed, a private key or a wallet password. Transactions are signed on your device.
- Your browser keeps a list of your accounts (addresses and the names you give them) so the site can show balances. That list contains no secrets. Watch-only accounts hold no key at all.
- If you connect an external wallet (Xaman, Joey through WalletConnect, or a browser-extension wallet), the transaction is signed inside that app. xrpl.to only prepares it.
- The trade-off this design accepts: while a wallet is unlocked on a device, that device can sign without asking again. Keep your device clean and keep a backup of your seed.
What our servers see
- Every request reaches our servers with your IP address, the page or API path you asked for and your browser’s identification string. A page about an address has that address in its path, so the log records that your IP looked at it.
- Raw web-server logs are kept for 14 days. Aggregated statistics per page or endpoint (request counts, status codes, timing) are kept for 90 days. Per-IP hourly request counts, used to stop abuse and plan capacity, are kept for 7 days.
- Cloudflare sits in front of the site for encryption, bot filtering and caching. It sees the same requests and keeps its own logs under Cloudflare’s privacy policy.
- There is no sign-up. The site never asks for an e-mail address or a name.
Cloudflare's policy: cloudflare.com/privacypolicy
No trackers, no advertising
- No analytics SDK, advertising pixel or fingerprinting script runs on the site. No third-party script runs at all: the site instructs your browser to block any script that does not come from xrpl.to itself.
- No cookies are set for visitors. One session cookie exists for staff sign-in to the admin area.
- Personal data is not sold or shared with anyone for advertising. A Global Privacy Control signal from your browser therefore changes nothing: it is honoured by construction, with no banner to click.
- Chrome’s advertising interest (Topics) API is switched off for this site.
The AI assistant
- Messages you send to the assistant go to the model provider you choose. With xrpl.to’s own models the request goes from our server to the provider named next to the model. With your own API key, our server relays the request to that provider using your key; the key is encrypted in your browser and is never stored or logged by xrpl.to.
- So the assistant can answer questions about your portfolio, each request includes your connected address, XRP balance, largest holdings, open orders, watchlist and running automations. All of that is public information on the XRP Ledger; nothing private is added.
- Conversations are kept in your browser. Our server records only which wallet used which model, the token counts and the cost, for billing.
- Voice input uses your browser’s speech recognition: Chrome sends the audio to Google and Safari to Apple for transcription. Only the resulting text reaches xrpl.to, and the site asks before the microphone is used for the first time.
Features that contact other services
- Automation scripts and the testnet faucet open a direct connection from your browser to a public XRP Ledger node (the mainnet cluster, testnet or devnet), which sees your IP address.
- Connecting a WalletConnect wallet uses the WalletConnect relay and its verification service.
- Artwork for NFTs that xrpl.to has not yet mirrored is loaded from public IPFS gateways.
- Everything else, including prices, charts, order books and the market data the assistant uses, is fetched by our servers and served to you from xrpl.to.
Questions
Write to hello@xrpl.to. Security researchers will find the reporting address and scope in security.txt. The terms of service are in the documentation.