Security
Background monitoring. Zero execution authority.
Once you start monitoring, Lockinfy’s server checks your own rules about every 5 minutes, also while your browser is closed, using only public wallet addresses and prices. It holds no wallet keys and cannot sign, approve, swap, transfer or withdraw anything: when a rule triggers, Lockinfy can alert you by browser push and you act.
- Wallet access
- Public address only
- Keys or seed phrases
- Never held
- Signatures requested
- None
- Custody of funds
- None
- Execution authority
- None
- Monitoring
- Lockinfy’s server, read-only
Updated October 2026
01Principles
Restricted by design, not by policy.
Five properties of how Lockinfy is built today.
Read-only access
Lockinfy cannot move assets.
A connection shares your public address and nothing else. Lockinfy can send an EVM wallet four read-only requests; anything outside that allowlist is blocked in the browser before it reaches your wallet.
No seed phrases
Lockinfy will never ask for your recovery phrase.
No part of the product accepts a recovery phrase or private key. The one free-text field, for tracking a public address, rejects and clears anything that looks like a secret. Anyone asking for your phrase on Lockinfy’s behalf is not Lockinfy.
No custody
Your assets stay in your wallet.
Lockinfy holds no funds, operates no deposit address and keeps no balance on your behalf. There is nothing to withdraw, because nothing is ever sent to Lockinfy.
User-controlled rules
You decide how protection behaves.
Every trigger, threshold and share is visible and editable, and each rule can be switched off. Presets are starting points shown in full, never hidden defaults.
Zero execution authority
Lockinfy alerts you. You act.
Simulations show what your rules would have done, and are labelled as such. Monitor adds no permission: Lockinfy’s server works from public addresses and prices, and holds no key, signature, token approval or exchange API key. A trigger is a record and an alert: you review it and complete any protection yourself, from your own wallet. Automated execution comes later, only if you authorize it, and only once the requirements set out below are met.
02Access
What Lockinfy can access
The full scope of a connection today. Monitoring, on Lockinfy’s server, uses the same read-only access.
EVM request allowlist
Every request Lockinfy can send to an EVM wallet. Anything else is rejected in the browser before it reaches the wallet. Solana wallets are limited to connect and disconnect.
eth_requestAccountsRequest the public addresseth_accountsRead the connected addresseth_chainIdRead the active networknet_versionRead the network ID- Any other methodBlocked · EIP-1193 error 4200
03Connection
What happens when you connect
Four steps, in order. None of them asks for a signature.
Step 1 · Your wallet
Your wallet shares a public address
You approve one connection request, or paste an address to track. No signature, no approval.
Data out
Public address → Lockinfy
Step 2 · Lockinfy server
Lockinfy reads balances
The server asks read-only RPC providers for the address’s token balances. This lookup is not logged or stored. (Monitor keeps the addresses it watches: see Data handling.)
Data out
Address → RPC provider
Step 3 · Lockinfy server
Prices and history are fetched
Current and daily prices come from CoinGecko. Past values are estimated from today’s holdings and labelled as estimates.
Data out
Asset IDs → CoinGecko
Step 4 · Your browser · Lockinfy server
Your rules are checked
Your browser simulates your rules. Once you start monitoring, Lockinfy’s server checks them about every 5 minutes with the same engine, also while your browser is closed. Nothing is executed.
Data out
Simulation: nothing · Monitor: addresses, rules → Lockinfy
04Data
Data handling
What is kept, where, and for how long.
Your browser
Stored locally
Connected public addresses, your protection policy, monitoring state, trigger events and display preferences, in local storage on this device; once you start monitoring, also the sign-in session of your monitoring account.
Retention
Until you disconnect or clear site data
Lockinfy’s server
Stored once you start monitoring
Addresses sent to look up balances are not logged, cached or written to a database, and every response is marked private. Once you start monitoring, Lockinfy’s database (Supabase) keeps the records listed below, under a monitoring account.
Retention
Balance lookups: discarded after each request. Monitor: per record, below
Data providers
Lookups only
RPC providers see the balance queries Lockinfy’s server makes, for the addresses you track and at each Monitor check, not who asked. CoinGecko receives asset identifiers, never your address.
Retention
Subject to each provider’s policy
- Not sold
- Lockinfy does not sell your data.
- Account
- None until you start monitoring: then an anonymous monitoring account. No name, email or password.
Stored for Monitor
On Lockinfy’s server, only once you start monitoring a wallet: every record, and how long it is kept.
When you stop monitoring
Stopping monitoring deletes the monitor with its addresses, policy, state, activity, stop token, snapshots, triggers and delivery records. Your monitoring account, your notification settings and your push registrations stay. They hold no wallet data. Deleting them from the app isn’t available yet in the beta.
- From the browser that started it: Settings → Monitoring → Stop monitoring.
- Disconnecting your last wallet or clearing local data in Lockinfy also stops it and deletes its records.
- Clearing this site’s data in your browser settings doesn’t stop it, and leaves no way to reach it: stop it in Lockinfy first.
What Lockinfy cannot do
Today, neither the app nor Lockinfy’s server can:
- Access your private keys or seed phrase
- Sign transactions or messages
- Approve tokens or grant spending permissions
- Swap assets
- Transfer funds
- Withdraw funds
05Live protection
Before live protection
Automated execution isn't available today. It ships only when it meets every requirement below, and runs only if you authorize it.
Coming later · not available today
Non-custodial
PlannedExecution happens from a wallet you control. Lockinfy never takes custody of funds.
User-approved
PlannedNothing runs until you approve the strategy, and the permissions it needs, in your own wallet.
Scoped permissions
PlannedLimited to the assets, amounts and destinations you set. No open-ended approvals.
Rules you can pause
PlannedPause any rule, or revoke access entirely, at any time.
Independent audit before launch
PlannedThe execution layer will be audited by an independent security firm before release.
06Disclosure
Responsible disclosure
If you find a vulnerability in Lockinfy, report it to us privately first.
Report to
A security contact address will be listed here once its mailbox is live.
- Describe the issue, the affected page or component, and the steps to reproduce it.
- Give us reasonable time to investigate and fix it before any public disclosure.
- Do not access or modify data that is not yours, and do not degrade the service.