How CoinWatch.space Encrypts Your Data
CoinWatch.space offers an optional Privacy Vault that uses client-side, zero-access encryption to protect your sensitive data. When enabled, your data is encrypted in your browser before it reaches our servers — only you hold the key, so only you can read your encrypted data.
Zero-Access Encryption
All sensitive data in your account is stored with zero-access encryption. This means nobody else can access your encrypted data — not even CoinWatch.space. Your vault password is used to derive an encryption key locally in your browser, and only ciphertext is sent to the server.
- Your vault password never leaves your browser — it is not transmitted to or stored on our servers.
- The server stores only encrypted ciphertext and sentinel values (zeros/nulls) for sensitive fields.
- Without your password, the encrypted data is mathematically unrecoverable.
How It Works
When you enable the Privacy Vault, a cryptographic key is derived from your vault password using PBKDF2 key derivation. This key is used to encrypt and decrypt your data locally using AES-256-GCM authenticated encryption — the same standards used by banks and governments.
AES-256-GCM Encryption
Your data is encrypted with AES-256 in GCM mode, providing both confidentiality and integrity. Each field gets a unique random IV (initialization vector), ensuring that encrypting the same value twice produces different ciphertext.
PBKDF2 Key Derivation
Your vault password is stretched into a 256-bit encryption key using PBKDF2-SHA256 with 600,000 iterations. This makes brute-force attacks computationally expensive while keeping unlock time at ~300ms for legitimate users.
What Is Encrypted
When the Privacy Vault is enabled and unlocked, the following sensitive data is encrypted client-side before being sent to the server:
| Data Type | Encrypted Fields |
|---|---|
| Portfolio Entries | Quantity, buy price, sell price, notes, fee, fee currency, exchange, acquisition type (staking/mining/airdrop), transaction type |
| Loan Entries | Collateral & loan amounts, total to return, interest rate, LTV, liquidation rate, outstanding balance, origination fee, notes, loan link |
| Composite Loan Collaterals & Assets | Per-collateral amounts, per-asset borrowed amounts, total to return, outstanding balance, origination fee |
| AI Chat Messages | User messages, assistant responses, conversation titles |
| AI Memories | Remembered facts stored by the AI assistant |
| AI Persona | Your assistant persona preference text |
| Tax Reports | Generated PDF report, transaction CSV, detailed breakdown, CSV report — encrypted in your browser after generation; the server never stores plaintext report files when the vault is active |
What Is NOT Encrypted
Some data must remain in plaintext for the application to function correctly. The following is not encrypted:
- Coin identifiers (symbol, name, coin ID) — needed for price lookups and display
- Loan metadata (platform, status, dates, period, composite flags) — needed for filtering and reminders
- Transaction currency — needed for portfolio valuation and price lookups
- Account information (username, email, settings) — needed for authentication and communication
- Portfolio and loan portfolio names — needed for navigation and display
AI Assistant Messages
AI chat messages use a special encryption approach because the server needs plaintext to communicate with the external AI model:
User Messages
Your message is sent as plaintext for the AI model to process, but the server stores only the encrypted version. The plaintext is used ephemerally for the AI call and then replaced with ciphertext.
Assistant Responses
The AI response is streamed to you in plaintext. After the response completes, your browser encrypts it and sends the ciphertext back to the server, which replaces the temporary plaintext. This creates a brief plaintext window of ~1-5 seconds.
Decentralized AI Inference via Morpheus
AI chats are processed through the Morpheus Inference API, which utilizes a decentralized compute marketplace and hardware-attested Trusted Execution Environments (TEEs) to protect your data. Designed to route requests across independent nodes rather than a centralized server, it offers built-in, decentralized privacy.
- Decentralized Routing — Your requests are sent to independent AI model providers rather than a single corporate entity.
- Data in Transit — Messages are typically stored only while in transit and utilize encryption.
- Hardware Protection — Trusted Execution Environments (TEEs) provide hardware-level isolation, ensuring that even the node operator cannot access your data in memory.
- No Centralized Data Retention — Unlike traditional AI providers that may log and retain your conversations, Morpheus nodes process requests ephemerally without persistent storage.
This means your AI chat data benefits from two layers of protection: CoinWatch.space's client-side encryption for storage, and Morpheus's decentralized TEE infrastructure for inference.
Decentralized AI Inference via Routstr
AI chats can also be routed through Routstr, a decentralized AI inference marketplace paid for with Cashu ecash rather than a registered account. Requests are relayed through a self-hosted Routstr gateway to independent compute providers, so no single corporate account handles your conversation end-to-end.
- Decentralized Routing — Requests are distributed across independent AI providers on the Routstr network rather than routed to a single corporate entity.
- Keyless, Anonymous Payment — Access is paid for with Cashu ecash tokens instead of a registered API key or account, so the payment method itself is not tied to your identity.
- Encrypted Transit — Requests reach the gateway over TLS before being relayed to the selected Routstr provider.
- No Central Account Trail — Because payment doesn't require registering an account, Routstr has no central customer database linking requests back to a billed identity.
This means your AI chat data benefits from two layers of protection: CoinWatch.space's client-side encryption for storage, and Routstr's decentralized, payment-anonymous infrastructure for inference.
Vault Unlock Persistence
You can choose how long your vault stays unlocked across page reloads:
- In-memory only (most secure) — the key is lost on page reload
- Browser session — auto-unlocks until you close the tab
- Device storage — auto-unlocks across browser restarts (encrypted with a device key on web, or stored in the native iOS Keychain / Android Keystore on mobile)
- Mobile keychain security — on mobile, your vault password is stored in the OS-native iOS Keychain or Android Keystore, which uses hardware-backed encryption at rest. Retrieval requires biometric authentication (Face ID, Touch ID, or device PIN/pattern), so even with filesystem access the stored password cannot be decrypted.
Disabling the Vault
You can disable the Privacy Vault at any time from Settings. Your browser decrypts all data locally and sends the plaintext back to the server, which restores the original fields and removes all ciphertext. Your data remains accessible without a password after disabling.