HoodXBack to site

Legal

Privacy Policy

Last updated July 27, 2026

HoodX Wallet collects nothing. There is no backend server, no account system, no analytics and no telemetry. Your keys are encrypted on your own device, your transactions are signed there, and the developers of HoodX never receive your keys, your password or your activity.

Who this covers

This policy applies to the HoodX Wallet browser extension and this website. HoodX is independent software for Robinhood Chain (network 4663) and is not affiliated with, endorsed by, or connected to Robinhood Markets, Inc. or X Corp.

What we collect

Nothing. We operate no servers that could receive your information, and the extension sends no data to the developers under any circumstance.

The Chrome Web Store requires us to disclose data the extension reads or transfers off your device, even when we never see it ourselves. Those disclosures cover the wallet address, balances and transactions handled by the blockchain node, the password read in memory to unlock your vault, and the tweet text read locally to detect token addresses. Each is explained below.

What stays on your device

Recovery phrase and private keys
Encrypted with AES-256-GCM using a key derived from your password via PBKDF2. Never written anywhere in plaintext.
Your password
Read only in memory to derive the encryption key. Never stored, never transmitted.
Unlocked session key
Held in extension session memory while the wallet is unlocked, then wiped when the browser closes or auto-lock fires.
Tracked tokens and preferences
Your token list and settings such as the auto-lock interval, kept in local extension storage.

None of this leaves your browser. We cannot read it, recover it or reset it, which is also why your recovery phrase is the only way to restore a wallet.

Services the extension contacts

To show prices, charts and safety information, the extension makes read-only requests to the public APIs below. These requests carry only what is technically necessary, plus the standard network metadata (such as your IP address) that any web request includes. Each service operates under its own privacy policy.

rpc.mainnet.chain.robinhood.com
Robinhood Chain node. Reads your balances and broadcasts transactions you have already signed on your device.
api.dexscreener.com
Token prices, market cap, liquidity and pair metadata. Receives token addresses only.
dd.dexscreener.com, cdn.dexscreener.com
Token logo images.
assets.parqet.com
Tokenized stock logo images.
api.geckoterminal.com
Candle data used to draw price charts. Receives pool and token addresses only.
openapi.gmgn.ai
Token safety checks and holder analytics. Receives token addresses only.
v2.bubblemaps.io, app.bubblemaps.io
Renders the holder distribution map inside the extension.

Only the Robinhood Chain node receives your wallet address, which is unavoidable for any wallet: it is how balances are read and how a signed transaction reaches the network. The market data and analytics services receive token addresses, never yours.

The panel on X

On x.com and twitter.com the extension scans visible tweet text for token contract addresses and supported stock cashtags, then renders an optional trading panel in an isolated shadow root. This scanning happens entirely in your browser. Tweet content, your timeline, your account and your browsing history are never collected, stored or uploaded.

Trades started from a tweet are passed to the extension's background worker, which is the only place signing occurs. The web page never receives key material.

Selling and sharing

We do not sell, rent or transfer user data to third parties. We do not use data to determine creditworthiness or for lending purposes. We do not use data for anything unrelated to the extension's single purpose. Since we collect nothing, there is nothing to sell or share.

Security

Your vault is encrypted with AES-256-GCM using a key derived from your password with PBKDF2-SHA256. The decrypted key exists only in session memory and is discarded when the browser closes or when the auto-lock timer, which you configure, expires. Revealing your recovery phrase or private key requires re-entering your password.

No security design removes your responsibility for your own keys. If you lose your recovery phrase, nobody, including us, can restore your wallet. If someone else obtains it, they control your funds.

Children

HoodX is not directed at children under 13 and we do not knowingly collect information from anyone, including children.

Changes to this policy

If this policy changes, the updated version will be published on this page with a new date above. Material changes affecting how data is handled will also be reflected in the extension's Chrome Web Store disclosures.

Contact

Questions about this policy or the extension: hoodxrh@gmail.com