Privacy policy for Wren Companion
Wren Companion by J.
Effective: August 15, 2026
Wren Companion connects browser dapps to a Wren desktop wallet on the same
computer. It has no analytics, advertising, telemetry, remote code,
developer-operated service, or cloud account.
The companion processes the active page origin and wallet JSON-RPC messages,
which can contain account addresses, chain identifiers, messages, and proposed
transactions. It routes them only between the requesting browser document and
Wren at ws://127.0.0.1:1248; the extension does not send them to the
maintainer or another third party.
For browser-store disclosure purposes, this local routing can involve financial
and payment information, authentication information, browsing activity, and
website content. These labels describe the data types that can pass between a
dapp and Wren; they do not mean the maintainer collects or receives that data.
Wren desktop and a dapp may separately communicate with RPC endpoints or other
services selected by their operators. Those communications are outside
Companion and are governed by their respective policies.
The companion stores a nonextractable P-256 control/page key bundle and the pinned
Wren installation identity in browser IndexedDB. They mutually authenticate the
local connection, are not wallet private keys, and cannot sign blockchain
transactions. They remain until the user resets pairing or removes the extension.
An optional per-site setting that makes Wren appear as a legacy MetaMask
provider is stored in that site's browser local storage. Request routing,
account and chain state, and pending messages otherwise remain in memory.
HTTP and HTTPS access lets Companion inject the provider at document start and
route requests on sites the user visits. It does not scrape arbitrary page
content or browsing history. scripting is used only when the user changes the
per-site legacy-provider setting, and alarms keeps the local Wren connection
state current.
The maintainer does not collect, retain, sell, or share user data. All handling
above occurs locally on the user's device, and the extension does not execute
remotely hosted code.
Wren Companion's use of information received from Chrome APIs is limited to
providing its single purpose: connecting browser dapps to the user's locally
running Wren wallet. It does not use or transfer that information for
advertising, creditworthiness, lending, or any unrelated purpose. It does not
sell user data or allow humans to read it. The only transfer is to the user's
local Wren application when necessary to provide the requested wallet feature.
For privacy reports, use the private contact method in Security,
or file a public issue when appropriate in the
issue tracker.