Privacy is treated as a system boundary, not a toggle.
QRX combines local wallet-key control, encrypted storage, application sandboxing and optional privacy transaction foundations. It also documents the limits instead of pretending metadata can never exist.
Wallet isolation
Third-party apps do not receive private keys. Sensitive actions stay in wallet-controlled confirmation flows, and .qrxapp permissions are explicitly scoped.
Private transaction foundations
Receive-address rotation, stealth receiving, shield/private-transfer/unshield concepts and hidden-balance/proof foundations exist as separate privacy layers.
Encrypted Drive
Private QRX Drive content uses encryption/key-envelope paths so storage providers do not need plaintext content to provide storage.
Browser separation
Generic pages do not automatically get wallet privileges. QRX-native DApp bridge permissions are separate from page rendering.
Relay minimization
AURA relays are transport infrastructure, not authorities that should receive provider wallet private keys or requester session secrets.
Safety Center
Backups, recovery health, migration and risky-operation separation are surfaced as beginner UX instead of leaving recovery to undocumented key files.
Strong privacy design ≠ independent privacy certification.
Timing, network observations, entry/exit transactions and other metadata can remain observable depending on the operation. QRX should not market every privacy path as independently audited until the relevant external cryptographic/security review is complete.
Read privacy handbook