Bull Wallet Privacy Policy
Effective date: 07/15/2026
Contact: bitqaan@bitqaan.com
Overview
Bull Wallet is a non-custodial browser wallet for supported EVM networks. Bull Wallet helps users create or import a wallet, store an encrypted local vault, connect to app.bitqaan.com, view balances, switch networks, receive assets, sign messages, sign typed data, and approve transactions.
Bull Wallet is non-custodial. We do not hold user funds. We do not know, store remotely, or have access to recovery phrases, private keys, or wallet passwords. If a user loses their recovery phrase or password, Bull Wallet cannot recover the wallet.
Information Bull Wallet Processes
Bull Wallet processes wallet-related information needed to provide wallet functionality, including:
- Public wallet addresses
- Token balances
- Selected network
- Chain and token metadata
- Gas estimates
- Transaction requests
- Signed transaction payloads after user approval
- Transaction hashes
- Connected-site permission records
- Local encrypted wallet vault data
Bull Wallet also processes authentication information locally, including wallet passwords and recovery phrase/private key material used to create, import, encrypt, decrypt, and unlock the local wallet vault.
Information Stored Locally
Bull Wallet stores the following information locally in Chrome storage:
- Encrypted wallet vault
- Non-secret vault metadata, such as wallet address, vault version, and creation time
- Selected network
- Cached enabled-chain and token configuration
- Connected-site permission records for app.bitqaan.com
Recovery phrases and private keys are encrypted before storage. Wallet passwords are used locally to unlock the vault and are not sent to Bull Wallet servers, BitQaan servers, websites, or RPC providers.
Recovery Phrases, Private Keys, and Passwords
Recovery phrases, private keys, and wallet passwords remain on the user’s device. Bull Wallet does not send them to api.bitqaan.com, app.bitqaan.com, blockchain RPC providers, or any backend service.
When a user approves a message signature or transaction, Bull Wallet signs locally inside the extension. For transactions, the signed transaction may be sent to the configured blockchain RPC endpoint only after user approval.
Connected Website
Bull Wallet connects only to app.bitqaan.com in the Chrome Web Store production build. When a user approves a connection, Bull Wallet stores the approved origin, selected account address, chain ID, approval scopes, and timestamps locally.
Users can disconnect approved sites from the Bull Wallet interface.
Blockchain and RPC Data
Blockchain addresses, balances, transactions, token transfers, and related activity may be public on supported EVM networks.
Bull Wallet uses configured RPC endpoints to:
- Read balances
- Validate network chain IDs
- Estimate gas
- Broadcast user-approved signed transactions
RPC requests may include public wallet addresses, contract addresses, call data, gas estimation payloads, signed raw transactions, and transaction hashes.
Configured RPC endpoints may include Bull Chain RPC and public RPC endpoints for Ethereum, BNB Smart Chain, Polygon, and Avalanche C-Chain.
api.bitqaan.com Requests
Bull Wallet uses api.bitqaan.com to fetch enabled wallet networks and configured token metadata. This supports the wallet’s network selector and asset display.
Information Bull Wallet Does Not Collect
Bull Wallet does not intentionally collect:
- Names
- Email addresses
- Physical addresses
- Government identification numbers
- Health information
- Personal communications
- GPS location
- Browsing history
- Mouse position
- Scroll activity
- Keystroke logs
- General website content
Bull Wallet does not use user data for advertising, creditworthiness, resale, unrelated analytics, or unrelated profiling.
Data Sharing
Bull Wallet does not sell user data.
Bull Wallet may send public wallet addresses and transaction-related data to configured blockchain RPC providers when users use wallet features such as balance checks, gas estimation, and transaction broadcasting.
Bull Wallet does not share recovery phrases, private keys, or wallet passwords with Bull Wallet servers, BitQaan servers, websites, RPC providers, or third parties.
No Remote Code
Bull Wallet does not download or execute remote code. All executable JavaScript, HTML, and CSS are bundled inside the extension package. Remote network access is used only for API and blockchain RPC data requests needed to provide wallet functionality.
No Custody
Bull Wallet does not custody user funds and cannot reverse blockchain transactions. Users are responsible for verifying addresses, selected networks, token contracts, transaction details, and approval prompts before approving any operation.
Deletion and Reset
Users can remove local Bull Wallet data by disconnecting sites, clearing extension storage, resetting or removing the extension, or uninstalling it from Chrome.
Removing local extension data deletes the encrypted vault copy stored by the extension in that browser profile. It does not remove public blockchain activity.
Before deleting the extension or clearing storage, users should make sure they have safely backed up their recovery phrase. Without it, they may lose access to their wallet.
Security Limitations
Bull Wallet is browser software and depends on the security of the user’s device, browser profile, operating system, installed extensions, and websites visited. Malware, phishing sites, malicious browser extensions, compromised devices, or unsafe recovery phrase storage can lead to loss of funds.
Users should always review Bull Wallet approval prompts carefully before approving connection, signing, or transaction requests.
Changes to This Policy
We may update this Privacy Policy as Bull Wallet changes. Updates will include a new effective date.
Contact
For privacy or support questions, contact:
bitqaan@bitqaan.com
