SafeAgent — Privacy Policy


Effective date: August 19, 2026
Legal

SafeAgent is a passive Web3 security extension by Holder (holder.io). It protects users from crypto phishing, wallet drainers, clipboard address substitution and seed-phrase theft.

SafeAgent collects no data. There are no accounts, no analytics and no tracking — every check runs locally on your device, and nothing you do in your browser leaves it.

We collect no data

SafeAgent does not collect, transmit, sell or share any user data. There are no accounts, no analytics, no tracking. Nothing you do in your browser leaves your device.

Everything is processed locally

To provide protection, SafeAgent processes the following exclusively on your device:

  • Page URLs — checked against a local phishing blacklist and look-alike domain heuristics.
  • Page content — scanned locally for seed-phrase input forms.
  • Wallet signature requests — inspected locally before they reach your wallet to block dangerous approvals.
  • Clipboard text — after you copy a crypto address, the clipboard is re-read locally for up to 60 seconds and matched against crypto-address patterns only, to detect address substitution. Clipboard content is never stored permanently and never transmitted.

SafeAgent stores locally (in Chrome extension storage): your settings, a log of detected threats, cached threat databases, and temporary tab/clipboard state. You can clear the threat log at any time from the popup.

Network activity

The only network request SafeAgent makes is a daily download of updated threat lists (domain and contract databases) from a public repository. No user data is attached to this request. The page holder.io/safeagent-report opens only when you explicitly click “Report false positive”.

Changes to this policy

We may update this page if the policy ever changes. The effective date at the top of the page reflects the latest revision.

Contact

Questions: me@holder.io

Related documents