Browser extension
session-lens wallet
Privacy Policy
Last updated 30 September 2026
session-lens wallet stores Solana keys in a password-locked vault on your own device and places take-profit ladders on your Jupiter Perps positions. It collects nothing.
The short version
There is no account, no sign-up, no telemetry, no analytics, and no crash reporting. There is no server of ours that this extension talks to. Nothing you type into it is transmitted to the developer, ever.
What is stored, and where
Everything the extension remembers lives in your own browser, on your own machine.
- Your private keys
- Encrypted in local extension storage: AES-256-GCM, under a key derived from your password by PBKDF2-SHA512 at 600,000 rounds.
- Wallet labels and count
- Inside that same encrypted blob. Only the wallet count is readable without your password, so the lock screen can say “3 wallets”.
- Your unlocked session key
- Memory-only session storage. Erased when the browser exits, and on idle lock if you enable it.
- Ladder preferences
- Plain, and numbers only — first take-profit distance, part count, step, as percentages.
Your password is never stored, in any form, anywhere. The derived key is kept only for the length of an unlocked session. If you forget the password the vault cannot be recovered — not by us, not by anyone.
Keys are never displayed, never written to a log, and never leave the device. Transactions are signed locally inside the extension; only the signed transaction is broadcast.
What leaves your device
The extension contacts three kinds of third-party endpoint. None of them is ours, and none of them receives your keys or your password.
- Jupiter Perps API
- perps-api.jup.ag — read-only: your open positions, their take-profit and stop orders, and your resting limit orders. It receives your wallet’s public address, which is public information on the Solana blockchain. Orders are not sent here: they are signed transactions, broadcast through the RPC node below.
- Binance public market data
- api.binance.com — anonymous public price candles for the chart. No account, no key, no identifier is sent. It is an open quote feed.
- A Solana RPC node
- solana-rpc.publicnode.com by default, or any endpoint you enter yourself. It receives your public address and the signed transactions you broadcast. This is how every Solana wallet works.
As with any network request, these services can observe your IP address. They are independent operators with their own privacy policies. If you prefer a different RPC provider the extension lets you supply one, and it will ask for permission for that specific host at the moment you add it — and for no other host.
Permissions, and why each exists
- storage
- Keeps the encrypted vault and your ladder preferences on your device.
- clipboardWrite
- Lets you copy a wallet address or a transaction signature. Nothing is ever read from the clipboard.
- Host access
- To perps-api.jup.ag, api.binance.com and solana-rpc.publicnode.com — the three endpoints above.
- Optional host access
- Requested at runtime, only if you type in a custom RPC URL, and granted only for that host. If you never add one, it is never requested.
What we never do
- We do not sell or transfer your data. There is no data to sell.
- We do not use your data for anything unrelated to placing your orders.
- We do not determine creditworthiness or lend anything to anyone.
- We serve no ads and embed no trackers.
- We execute no remote code. Every line the extension runs ships inside the package.
Financial risk
This extension places real orders with real money on a live venue. It is a tool, not advice. Leveraged perpetual futures can lose you your entire position, and an order can fail to fill. You are responsible for every order you place with it.
Questions or reports: [email protected]