Sidecar Privacy Policy

Last updated: 2026-07-09

Sidecar is a browser extension that acts as a Nostr signer (NIP-07) and a Lightning wallet client (Nostr Wallet Connect / NIP-47). It is designed so that your secrets stay on your own device. This policy explains what Sidecar stores, what it sends, and what it does not do.

The short version

What is stored, and where

All data is stored locally on your device using the browser's extension storage. None of it is transmitted to the developer.

There is no account recovery: if you forget your PIN/passphrase, your data cannot be recovered. Back up your nsecs.

What is sent over the network, and to whom

Sidecar only talks to services you choose:

Sidecar does not send any of this data to the developer. The services above are the only ones it contacts — those you configure (relays, wallet) or invoke by a specific action (a link preview, a media upload, an @-mention search) — and there is no analytics or tracking of any kind.

Permissions

Sidecar requests only the permissions it needs to function:

Remote code

Sidecar does not load or execute remote code. All code, including the Nostr cryptography library, is bundled in the extension package.

Changes

If this policy changes, the updated version will be posted here with a new "last updated" date.

Contact

Questions about this policy can be directed to the project maintainer via the project's repository.