Who is responsible
Simon Fundel
Aeplistrasse 4a
9008 St. Gallen
Switzerland
Controller within the meaning of the Swiss Federal Act on Data Protection (FADP) and, where it applies, the GDPR. Contact for every data protection request: hello@nextkey.li.
What this site does not do
No accounts, no registration, no newsletter. No tracking cookies, no analytics, no advertising, no social plugins. No content delivery network and no web fonts: every script and every font is served from this domain, which is also why the pages are large.
Your browser stores two things locally, on your own device, and sends them nowhere: the language you chose and whether you asked for the dark or light theme. Clearing your browser data removes them.
Hosting and server logs
The site is hosted by cyon GmbH, Basel, Switzerland, on servers in Switzerland. Like every web server, it writes access logs: IP address, date and time, the page requested, the referring page and the browser identification.
These logs exist to operate the site and to detect attacks and faults. They are not used to build a profile and are not combined with other data. Legal basis: the overriding legitimate interest in operating a secure service (Art. 31 FADP; Art. 6(1)(f) GDPR). They are deleted once they are no longer needed for that purpose.
What your browser contacts, and what that reveals
Reading the chain means asking a node. Pages that show on-chain data send requests from your browser to public Ethereum endpoints (ethereum-sepolia-rpc.publicnode.com and, on the donation page, ethereum-rpc.publicnode.com, operated by Allnodes). Those operators see your IP address and the queries you make — including which names you look up. We receive none of it, and we cannot promise anything about what they do with it.
There is now one exception, and it is ours: the read-only API at api.nextkey.li, which exists for callers with no node of their own. Using it means telling us which name you are looking up, on top of telling a node. So there is nowhere for that to be written down — the service has no request log, no analytics and no storage of any kind attached to it, and no API keys, so there is nothing to correlate lookups with even in principle. It is run on Cloudflare's network, which keeps its own edge logs that we do not control. Nothing on this site uses it: the pages read the chain from your browser as described above, and the Sandbox page is the only one that contacts it, once, to ask whether it is answering.
If you connect a wallet, the wallet is a separate program with its own privacy policy. The page learns the address you connect and nothing else; your private key never reaches it, and no transaction happens until you confirm it yourself.
Links to GitHub, Etherscan or the ENS portal only contact those services once you click them.
The Android app
The NextKey app for Android is the recipient's side of this site, and it keeps the same promises: it holds no funds, signs no transactions, writes nothing to the chain, and sends no secret anywhere. It has no account, no sign-in, no analytics and no crash reporting, and this version has no notifications either.
It keeps exactly one thing: the X25519 key others encrypt to. That key lives in the Android Keystore, is excluded from cloud backup and from device-to-device transfer, and is deleted when the app is uninstalled — which is also how you ask for its deletion. Nothing is lost by that: the key is derived from a wallet signature, so it can be derived again here.
Pairing puts that key on the phone by showing it as a QR code on this site, drawn in your browser and fetched from nobody. For those few seconds the private half of your identity key is a picture on your screen. Show it to your own camera, not to a room, and not to a screen that is being recorded or shared.
The app reads the chain the same way these pages do: directly from your phone to a public Ethereum node, which sees your IP address and which names you look up. It does not use api.nextkey.li.
The blockchain, and what cannot be undone
Anything written to the chain — a secret's ciphertext, a grant, a public key, a blog post, a donation — is public, permanent and copied to computers all over the world. It is not stored by us and it cannot be deleted by us. There is no button, no request and no court order that removes it from every copy.
This has a plain consequence: the rights to erasure and rectification described below cannot be fulfilled for data that is already on chain. Everything else can. So decide before you write, not after — and do not put a name, an address, a message or any other personal detail into a record or a post unless you are content for it to stay public for good.
The demonstration lends visitors a name whose key is published in this repository on purpose. Anything written under a lent name is public and attributable to that name. Use it for demonstration content only.
Your rights
You may ask what data about you we hold, and ask for it to be corrected or deleted; you may object to processing and, where the GDPR applies, ask for a copy in a portable form. One email to hello@nextkey.li is enough, and it costs you nothing.
In practice the answer is usually short, because the only personal data we hold is in the server logs. For anything on the blockchain, see the section above: we can neither retrieve it for you nor remove it. You also have the right to complain to a supervisory authority — in Switzerland the FDPIC, in the EU the authority of your country.
Changes, and the binding version
This notice describes the site as it stands today. It will be updated when the site changes, and the date below says when it last was.
This notice exists in several languages. The English version is the binding one; the translations are offered for convenience.