Source Signer / Privacy
Local signing, narrow access
Effective July 26, 2026. This page explains exactly what the SafeExit Source Signer handles and where that information goes.
01
Purpose and scope
This policy describes the SafeExit Source Signer browser extension. The extension has one purpose: review and locally sign short-lived, chain-bound EIP-7702 authorizations for a rescue plan initiated on safeexit.xyz.
The extension does not act as a wallet, take custody of assets, broadcast rescue transactions, or authorize activity without an explicit signing request and confirmation.
02
Source-key handling
A source private key is entered only inside the extension popup. It is used locally to create the displayed EIP-7702 delegation and clearing authorizations.
The source private key is not transmitted to safeexit.xyz, SafeExit servers, blockchain RPC providers, analytics services, or any third party. It is not written to Chrome storage, browser storage, logs, or a SafeExit database. The input is cleared after the signing attempt.
03
Other data processed
The extension processes public blockchain information needed to review a rescue: chain ID, source and destination addresses, factory and delegate addresses, action commitments, nonces, expiry, and plan hashes.
Only pending request metadata and status are held in chrome.storage.session. Session data is removed when the request is completed, discarded, expires, or the browser session ends.
04
Network access
The extension communicates only with safeexit.xyz and the two X Layer RPC endpoints declared in its production manifest. The SafeExit origin supplies the user-initiated signing package and receives the resulting authorization. The RPC endpoints receive read-only JSON-RPC requests used to verify the chain, factory bytecode, and predicted delegate.
RPC operators may receive ordinary network metadata such as an IP address under their own policies. The extension does not execute remotely hosted code; all executable JavaScript and WebAssembly are packaged with the extension.
05
Use, sharing, and retention
SafeExit does not sell extension data, use it for advertising, create behavioral profiles, or permit human review of source keys. Data is used only to provide the user-requested signing flow and protect the committed rescue destination and actions.
The extension has no long-term data-retention mechanism. Public blockchain transactions submitted later by the destination wallet are governed by the relevant blockchain and are not erasable by SafeExit.
06
Your choices and security
Do not use the extension unless you are authorised to control the displayed source wallet. You can discard a pending package, close the popup before signing, or uninstall the extension at any time.
Wallet recovery is best effort. If another person controls the same source key, they may race or invalidate a rescue before confirmation. SafeExit cannot guarantee recovery.