Legal
Privacy policy
Last updated September 24, 2026
This policy explains what information the Oyster wallet browser extension, the Oyster data server (the “relay”) and this website handle, and why. Oyster is operated by UALIS CORP., British Virgin Islands (“Oyster”, “we”, “us”).
1. Information that stays on your device
The extension stores its data in your browser’s extension storage. We cannot read it.
- Your vault: seed phrases, wallet names and colors, and watch-only addresses. It is encrypted with a key derived from your password (scrypt, then AES-256-GCM). While the wallet is unlocked, the derived key (never the password itself) is held in the browser’s session storage and cleared when it locks.
- Settings and wallet data, stored unencrypted: network, relay address, theme and auto-lock time; your saved USDT sender addresses; recent transactions and last known balances; the addresses the wallet watches for incoming payments; your address book and transaction notes; price alerts; mining and auto-sell settings; and the sites you have connected.
A backup file you export contains your encrypted vault plus these settings in plain text. Keep it somewhere private.
2. Information sent to the Pearl network
To show balances and history, the extension looks up your addresses one at a time with a Pearl block explorer (Blockbook, operated by Pearl Research Labs at blockbook.pearlresearch.ai). It never sends your extended public key. Transactions you sign are broadcast through the same service. Anything on the Pearl blockchain is public by design.
3. Information our relay handles
Without signing in
Price, chart, order book and recent trade requests carry no identity. If you choose to watch an Ethereum address for wrapped PRL (wPRL), that address is sent to the relay so it can read the public balance.
When you use trading or buying power
The relay identifies you only by your wallet’s first receive address, which you prove with a signed message. There is no email or password. The relay stores:
- Your address and when your account was created.
- A ledger of every movement of your funds held by the relay: deposits, orders and fills, fees, PRL kept on the exchange, sells and payouts, including amounts, transaction ids and destination addresses.
- The USDT sender addresses you declare for each chain, and pending deposit claims.
- Sign-in challenges and sessions. Sessions last 24 hours; we store only a hash of the session token, and expired sessions are deleted.
Logs
Our servers log each request’s method, path (including query strings), status and duration, and the trading service logs addresses and amounts for sells and payouts. We use your IP address to rate-limit requests and to block abuse. We do not log request bodies. We keep logs only as long as we need them to run and protect the service, and ledger records for as long as we need them to account for funds and meet our legal obligations.
4. Third parties
To provide trading and buying power, the relay works with:
- SafeTrade (safe.trade), the exchange where orders are placed. Orders are placed from an account operated by Oyster; your wallet does not contact SafeTrade directly.
- CoinGecko, as a fallback price source.
- Public blockchain nodes for Pearl, Ethereum, Arbitrum, BNB Chain and Solana, to watch deposits and send payouts.
This website is hosted by Vercel, which processes standard request data such as IP addresses to serve pages. The site sets no cookies, uses no analytics, and serves its fonts itself.
We do not sell your information, and we do not share it except as described here or when required by law.
5. Notifications
If you allow browser notifications, the extension checks for new payments, mining rewards, filled orders and price alerts about every two minutes, including while locked. These checks use the address list stored on your device.
6. Your choices
- You can use Oyster to hold, send and receive PRL without ever signing in to the relay.
- You can remove the extension and its data at any time from your browser.
- You can ask us about, or to delete, the relay records tied to your address at hello@oysterwallet.app. Records we must keep to account for funds or to meet legal obligations may be retained.
7. Children
Oyster is not intended for anyone under 18.
8. Changes
We will update the date at the top when this policy changes, and for significant changes we will tell you in the extension or on this site.
9. Contact
Questions about privacy: hello@oysterwallet.app.